Evidence traceability
Trace source, candidates, tests, provider evidence, tuning decisions, approvals, packages, and operational handoffs.
Threat Foundry platform
Understand the environment, model the threat, hunt and investigate, engineer and validate detections, then turn current evidence into governed risk and resilience decisions.
Guided Operations
Start with an outcome, see the prerequisites, and resume at the next accountable decision. Guided workflows keep the authoritative expert workspace available without pretending navigation performed an action.
Intelligence + Exposure
The Intelligence Library preserves normalized MISP, OpenCTI, and STIX-derived context. Threat Library adds the analyst decision: relevance, hypothesis, telemetry, expected evidence, and whether the current item can move forward.
Exposure Scanner + EASM
Exposure Scanner strengthens discovery and finding context within explicitly approved scope. EASM connects observed services, KEVs, identity exposure, DNS and email posture, scanner evidence, business assets, owners, due dates, and retest outcomes.
Hunting + Investigation
Hunt Builder and Attack Path Builder ground ATT&CK behavior in configured telemetry, field mappings, assets, time bounds, and query policy. The review checkpoint shows the selected AI provider and customer-authorized evidence before any provider contact or query execution.
Alert investigation + cases
Review the alert context, hypothesis, read-only query plan, observed and missing evidence, entity relationships, and analyst conclusion before routing the outcome to triage or a case.
FORGE by Threat Foundry
Forge brings evidence-grounded analysis into investigation, triage, cases, detection design, validation, and tuning. Closed tools retrieve bounded current context; the interface separates observed facts, deterministic findings, model inferences, missing evidence, recommendations, and draft proposals.
Detection Lifecycle
Begin with a governed request, CTI item, coverage gap, incident lesson, case, audit need, or analyst hypothesis. Carry that source through environment strategy, platform versions, testing, approval, and customer-controlled delivery.
Validation + Tuning
Detection Assurance binds positive and negative controls to frozen candidate, telemetry, mapping, connector, inventory, and test revisions. Results stay distinct and explainable instead of collapsing into a pass/fail promise.
Threat Modeling
Threat Blueprints model components, trust boundaries, typed flows, business context, and threat hypotheses; apply the reproducible STRIDE baseline; and carry scoped attack-path findings into hunts, detections, cases, and governed risk work.
Risk & Resilience
Move advisory findings through human review, treatment, shared remediation, implementation evidence, validation, and residual-risk decision. Customer-defined appetite thresholds keep portfolio status tied to approved policy rather than a product default.
BYOAI routing
Tenants can retain multiple provider configurations and activate exactly one. Supported AI-assisted workflows bind the selected provider and model at review time and stop if that route changes before execution.
Governance + Scale
Threat Foundry keeps source, versions, permissions, tenant scope, review, provider contact, approvals, and customer delivery attached to the work.
Trace source, candidates, tests, provider evidence, tuning decisions, approvals, packages, and operational handoffs.
Inspect the exact tenant, connector, content version, limits, provider-contact state, change boundary, warning, and action before confirmation.
Coordinate tenant lifecycle, work, SLAs, health, licensing, delivery, reporting, access, and evidence-free Forge guidance across an authorized service portfolio.
Explore MSSP/MSP operationsUse the tenant-scoped public API for bounded, paginated access to supported local evidence with explicit completeness state and review-preserving workflow actions.
Explore the public API boundaryCases + Reporting
Explore complete workflows
Select a product image for a full-resolution view. Capability summaries show the same decision boundaries for workflows without a public product capture.
Managed outcomes
Recurring reviewed hunts, investigation, publication, and follow-through.
Explore serviceApproved-scope discovery, prioritization, remediation tracking, retest, and reporting.
Explore serviceReviewed architecture assessment, resilience findings, remediation, and publication.
Explore serviceGoverned intake, multi-platform engineering, assurance, tuning, and package delivery.
Explore serviceStart with the workflow
Bring your current intelligence, exposure, telemetry, architecture, detection content, and analyst or service process. We will map the fastest path to a useful outcome.