BRIEF
My landing screen every morning. A digest of what actually needs attention — not a raw NVD dump — answering what broke overnight and whether it matters to my environment.
- Morning brief action queue: KEV due soon, EPSS movers, new KEV, stack match (reason chips)
- Hero stats — critical / high counts, exploited-in-wild, patches available
- What changed panel — CVSS, EPSS, KEV, and PoC deltas (24h / 48h / 7d)
Full feature list in docs →
FEED
The full paginated CVE list behind the brief — stack filtering, asset-profile matching, and everything I need to get a CVE out the door as a report.
- Stack filtering and asset profile wizard (CPE-based exposure matching)
- KEV, EPSS, PoC, and severity filters; vendor chips; KEV due-date sidebar
- CSV / XLSX export and digest generation straight from the feed toolbar
Full feature list in docs →
CVE DETAIL
The investigation surface for a single CVE — operational priority, enrichment, Sigma/SIEM snippets, and explainable correlation without leaving the feed.
- Overview: CVSS, EPSS, KEV, affected products, patch links
- Intel: OTX pulses, campaigns, GreyNoise, three-level correlation
- Detect: SigmaHQ, Elastic, SIEM quick queries, YARA
Full feature list in docs →
IOC LOOKUP
Enrich IPs, file hashes, and domains across the sources I actually use — with quota tracking so I know when I am about to hit a limit.
- VirusTotal, AbuseIPDB, GreyNoise, OTX, MalwareBazaar, URLhaus
- Per-source quota display (daily / weekly where applicable)
- IP, file hash, and domain indicator types (6-hour result cache)
Full feature list in docs →
INVESTIGATE
Graph browser over intel BRIEFR already stores — CVE, IOC, technique, and publication hops. Search once, expand nodes to pivot like an Obsidian map; no live enrichment on each click.
- Stored-intel graph over CVE, IOC, technique, campaign, and publication nodes
- Pan and zoom canvas — scroll to zoom, drag to pan, drag nodes to rearrange
- Expand hops — double-click nodes to load neighborhood edges from stored data
Full feature list in docs →
ADVISORIES & INTEL
Real-world attack context alongside CVE work — curated headlines, structured security publications, and MITRE ATLAS case studies with technique mapping, served from scheduler-built snapshots.
- Headlines from major RSS security sources with CVE cross-links
- Structured CISA advisories and durable publication ingest
- MITRE ATLAS case studies with technique tags
Full feature list in docs →
FORGE
Detection engineering inside the intel pane — not log execution. See where ATT&CK techniques linked to my CVE feed have community rules, saved packs, or gaps, then generate hunt content per CVE.
- MITRE ATT&CK coverage map (yours / community / gap) by tactic
- Hunt pack generation: Sigma rules + Elastic, Splunk, Sentinel, QRadar snippets
- Per-CVE Detect drawer tab (SigmaHQ, Elastic community, SIEM quick queries)
Full feature list in docs →
ADMIN · ANALYST
The analyst-facing admin slice — enough visibility to trust the feeds and tune alerts without touching scheduler jobs, API secrets, or destructive operator actions.
- Intel status overview and per-source feed health
- Alert channel configuration and security posture (read-only)
- Pinned CVE watchlist and personal display preferences
Full feature list in docs →
ADMIN · OPERATOR
Full operator console for keys, rate limits, feed freshness, and scheduler health — the surfaces I check when something stops syncing or a provider quota is exhausted.
- API key presence and masked status per upstream source
- Feed health vs circuit state (HTTP OK vs sync freshness)
- Scheduler jobs, durable outbound queue, and manual catch-up
Full feature list in docs →