TLP:CLEARREF #CYN-6106SELF-HOSTED CTEM // ZERO EGRESSEN / عربي — RTL NATIVEUTC --:--:--
How Cyntelligence decides what matters to you.
The platform processes the same public data sources as competitors. The differentiator is post-ingestion processing that converts global intelligence into organization-specific priorities — computed, explained, and different for everyone.
Relevance × Confirmation × ThreatAnchored to SSVC · EPSS · KEVThe model never assigns severity
Each deployment maintains an org profile — the lens every global signal is scored through. Five components, curated by your analysts, kept current.
B
Brands
Names, product variations and spelling variants — for certificate and dump monitoring.
D
Domains
Owned domains, subdomains, subsidiary and group-company holdings.
V
Vendor watchlist
The technology stack that decides which vendor CVEs are local vulnerabilities.
R
Sector & region
Industry, operational geography, regulatory jurisdiction — for targeting signals.
K
Keywords
Analyst-curated terms for dark-web and paste-site monitoring.
FIELD NOTE — internal testing showed subsidiary-aware profiles detected threats that single-brand approaches missed entirely.
02 — Matching discipline
The system must be able to say no.
Raw data becomes structured facts through deterministic code, not generation: IOCs use validated pattern-matchers with false-positive exclusion; CVEs are enriched from vulnerability databases; threat actors resolve to canonical identities so aliases don't double-score. Then conservative matching decides what is truly yours.
R1
Word-boundary matching
Profile keywords match as anchored tokens, never substrings — “ACME” won’t fire on “placement”.
R2
Canonical entities
Actors, malware and techniques resolve to a canonical identity before matching, collapsing aliases.
R3
Stable dedup keys
Findings deduplicate on a stable identity, so the same fact never re-alerts.
R4
Trigger validation at alert birth
Evidence is validated against the raw source before an alert is ever created.
03 — Anchored severity
Severity is anchored to standards, not to a model.
SSVCCISA’s decision-tree methodology producing Act / Attend / Track from exploitation state, exposure and mission impact.
EPSSEmpirical probability that exploitation occurs in the wild.
KEVCISA’s Known-Exploited catalog — ground truth of active exploitation.
CVSS / CPETechnical severity and vendor-watchlist matching.
CORE PRINCIPLE — the local LLM is not allowed to assign severity. It phrases and prioritizes within the bounds the standards set.
Three multiplicative factors. Because they multiply, a high threat with zero relevance still scores near zero — which is how introducing this framework collapsed one critical-alert queue by two orders of magnitude. Try it:
SEVERITY CALCULATORadjust the factors →
RelevanceR
Does this concern your organization?
ConfirmationC
Is it real?
ThreatT
How bad if true?
0.75Relevance×0.70Confirm×1.00ThreatSCORE53
SSVC · ATTENDRelevant and confirmed, high threat — queued for attention, not a page.
SOURCE AUTHORITY — feeds with consistent early reporting get precedence; aggregators and re-publishers are down-weighted to separate independent reporting from repetition.
05 — Worked example
Same KEV-listed CVE. Two very different mornings.
One edge-appliance CVE, freshly added to KEV. Watch it land at the top of one queue and quietly into a digest in the other.
Org ATelecom · GCC region
Appliance in vendor watchlistHIT
Exposed instance in internal scanVISIBLE
Actor targets sector & regionMATCH
SSVC · ACTQueue position#1 — top, with evidence chain
Org BFintech · EU
Appliance in vendor watchlistNO MATCH
Exposed instance in internal scanNONE
Actor targetingELSEWHERE
SSVC · TRACKFiled intothe weekly digest
06 — Limits, stated plainly
Scoring augments judgment. It doesn't replace it.
Depends
Profile & collection quality
Relevance scoring is only as good as profile accuracy and the quality of data collection. Garbage profile, garbage priorities.
By design
Open & community sources only
The platform uses open and community sources — no proprietary primary collection. We operationalize; we don't run undercover analysts.
Trade-off
Conservatism trades recall for precision
Matching discipline is deliberately strict. That means fewer false alerts — and, honestly, the occasional edge case suppressed. Analyst curation covers dark-web keywords.
Verify this document in a POC
Test the profile
Build a real profile including suspected missed subsidiaries; observe how the queue responds.
Confirm the “no”
Check that non-applicable headline CVEs file quietly rather than alerting.
Audit the triggers
Trace high-severity alerts back to raw-source evidence, and review SSVC paths for top-queue CVEs.