Back to home
Intelligence

Analyst workflow for evidence-linked threat intelligence.

SentriScope intelligence is not autonomous AI correlation. It gives analysts an investigation workspace, CTI review queues, IOC enrichment when providers are configured, and verdict-gated correlation into assets, identities, exposures, and incidents, with every decision traceable.

Investigation workspace

Where analysts turn signals into decisions

The investigation workspace is the center of intelligence operations: structured sessions, scenario workbench, and evidence-linked decisions that connect CTI to your canonical model.

CTI review & correlation

Enrich, review, and correlate with analyst control

CTI enrichment runs when providers are configured. Analysts review fusion scores, apply verdicts, and correlate indicators into canonical context: verdict-gated, evidence-linked, not autonomous.

Intelligence capabilities

Grouped by analyst workflow domain

Beyond investigation and CTI review, intelligence spans identity context, incident linkage, and bounded AI decision support.

  • CTI and IOC enrichment
    IOC management & fusion scoring Ingest, enrich from VirusTotal, AbuseIPDB, AlienVault OTX, and GreyNoise when configured, apply confidence decay, and derive verdicts from weighted fusion scores.
    Threat actors & campaigns Track threat actors and active campaigns. Link IOCs, actors, and campaigns to canonical assets and vulnerabilities for analyst review.
    CTI context correlation Correlate IOCs with incidents, assessments, exposures, vulnerabilities, and identities under analyst control. Verdict-gated correlation, not autonomous pipeline entry.
  • Identity and credential intelligence
    Credential leak monitoring Detect and track credential leaks linked to identity records. Correlate breach data with canonical identities; batch incident creation is tenant-configurable and often off by default.
    Identity Intelligence context Canonical identity model with privilege tier and credential risk scoring linked to CTI and exposure findings.
  • Incident and exposure context
    Scenario correlation Link attack scenarios to active threats and canonical context. Analyst-driven path analysis to explain how exposures relate to current intelligence.
    Incident readiness workflows Connect intelligence findings to incident lifecycle management with analyst-controlled escalation.
  • Guardrailed AI decision support
    LLM-assisted CTI explain Ask natural-language questions about threats and get structured, evidence-backed explanations that are guardrailed, schema-grounded, read-only, and tenant-configurable when enabled. No autonomous remediation.
Provider breadth

Enrichment and context from your configured stack

CTI enrichment and connector-backed context depend on what you configure. The integrations catalog shows available ingestion sources and CTI enrichment providers: a live registry, not static marketing claims.

CTI enrichment providers

When configured, indicators can be enriched through providers such as VirusTotal, AbuseIPDB, AlienVault OTX, and GreyNoise, with fusion scoring across provider responses.

Connector-backed context

Ingestion connectors bring exposure, vulnerability, identity, and asset data into the canonical model: the context analysts correlate against in investigation sessions.

Browse integrations catalog

Bounded AI

Read-only decision support, not autonomous intelligence

LLM assistance accelerates triage when enabled, but remains schema-grounded, SQL-validated, and read-only. It supports analyst decisions. It does not autonomously correlate, remediate, or act.

  • Schema-grounded queries over canonical risk data
  • Tenant- and plan-configurable when enabled
  • No credentials in context; output filtered and validated
  • No autonomous remediation or unsupervised pipeline actions

LLM guardrail specifications Published documentation

Explore further

Related platform areas

Product

Full capability catalog: exposure, prioritization, and investigation modules.

Integrations

Live connector and CTI provider catalog.

Platform

Architecture, governance, and operator workbench foundations.

Contact

CTI configuration, provider setup, and workflow evaluation.

See how analysts work with intelligence

Explore product capabilities, review your integration options, or talk to our team about investigation workflows and CTI configuration.