Analyst workflow for evidence-linked threat intelligence.
SentriScope intelligence is not autonomous AI correlation. It gives analysts an investigation workspace, CTI review queues, IOC enrichment when providers are configured, and verdict-gated correlation into assets, identities, exposures, and incidents, with every decision traceable.
- Investigate Investigation session Guided sessions with evidence tracking and analyst notes.
- Review CTI & IOC queue Enrich indicators when configured; review fusion scoring.
- Verdict Analyst control Verdict-gated decisions before findings enter the risk pipeline.
- Correlate Canonical context Link to assets, identities, exposures, and incidents with evidence.
Investigation-first workflow: analysts control enrichment, verdicts, and correlation.
Where analysts turn signals into decisions
The investigation workspace is the center of intelligence operations: structured sessions, scenario workbench, and evidence-linked decisions that connect CTI to your canonical model.
Guided investigation sessions and scenario workbench
Open investigation sessions against prioritized findings with evidence tracking, analyst notes, and review queues. The scenario workbench links attack scenarios to active threats and canonical context, helping analysts understand how hypothetical paths relate to current exposure.
See investigation in Product- Guided investigation sessions with evidence tracking
- Analyst notes and verdicts before pipeline actions
- Scenario correlation across CTI, incidents, and exposures
- Evidence-linked decisions tied to Risk Decision Objects
Intelligence dashboard and review context
A single view of active threat indicators, provider health when configured, and correlated exposure context. The dashboard supports analyst review, not autonomous triage, so your team sees what needs attention and decides what to act on.
Tenant architecture- Active threat indicators with analyst review queues
- Provider health visibility when enrichment is configured
- Exposure and vulnerability context in one workspace
Enrich, review, and correlate with analyst control
CTI enrichment runs when providers are configured. Analysts review fusion scores, apply verdicts, and correlate indicators into canonical context: verdict-gated, evidence-linked, not autonomous.
IOC lifecycle: ingest, enrich, verdict, correlate
Full IOC lifecycle management: ingest indicators, enrich from configured providers (VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise), apply confidence decay and fusion scoring, then correlate with analyst control into incidents, assessments, exposures, vulnerabilities, and identities. Analyst verdict controls what enters your risk decision pipeline.
CTI provider integrations- IOC management with multi-provider enrichment when configured
- Fusion scoring with confidence decay and analyst verdicts
- Correlate with analyst control, not autonomous correlation
- Evidence-linked links to assets, identities, and exposures
Grouped by analyst workflow domain
Beyond investigation and CTI review, intelligence spans identity context, incident linkage, and bounded AI decision support.
-
CTI and IOC enrichmentIOC management & fusion scoring Ingest, enrich from VirusTotal, AbuseIPDB, AlienVault OTX, and GreyNoise when configured, apply confidence decay, and derive verdicts from weighted fusion scores.Threat actors & campaigns Track threat actors and active campaigns. Link IOCs, actors, and campaigns to canonical assets and vulnerabilities for analyst review.CTI context correlation Correlate IOCs with incidents, assessments, exposures, vulnerabilities, and identities under analyst control. Verdict-gated correlation, not autonomous pipeline entry.
-
Identity and credential intelligenceCredential leak monitoring Detect and track credential leaks linked to identity records. Correlate breach data with canonical identities; batch incident creation is tenant-configurable and often off by default.Identity Intelligence context Canonical identity model with privilege tier and credential risk scoring linked to CTI and exposure findings.
-
Incident and exposure contextScenario correlation Link attack scenarios to active threats and canonical context. Analyst-driven path analysis to explain how exposures relate to current intelligence.Incident readiness workflows Connect intelligence findings to incident lifecycle management with analyst-controlled escalation.
-
Guardrailed AI decision supportLLM-assisted CTI explain Ask natural-language questions about threats and get structured, evidence-backed explanations that are guardrailed, schema-grounded, read-only, and tenant-configurable when enabled. No autonomous remediation.
Enrichment and context from your configured stack
CTI enrichment and connector-backed context depend on what you configure. The integrations catalog shows available ingestion sources and CTI enrichment providers: a live registry, not static marketing claims.
CTI enrichment providers
When configured, indicators can be enriched through providers such as VirusTotal, AbuseIPDB, AlienVault OTX, and GreyNoise, with fusion scoring across provider responses.
Connector-backed context
Ingestion connectors bring exposure, vulnerability, identity, and asset data into the canonical model: the context analysts correlate against in investigation sessions.
Read-only decision support, not autonomous intelligence
LLM assistance accelerates triage when enabled, but remains schema-grounded, SQL-validated, and read-only. It supports analyst decisions. It does not autonomously correlate, remediate, or act.
- Schema-grounded queries over canonical risk data
- Tenant- and plan-configurable when enabled
- No credentials in context; output filtered and validated
- No autonomous remediation or unsupervised pipeline actions
Related platform areas
Product
Full capability catalog: exposure, prioritization, and investigation modules.
Integrations
Live connector and CTI provider catalog.
Platform
Architecture, governance, and operator workbench foundations.
Contact
CTI configuration, provider setup, and workflow evaluation.
See how analysts work with intelligence
Explore product capabilities, review your integration options, or talk to our team about investigation workflows and CTI configuration.