Threat intelligenceROADMAP
Dedicated IOC and threat-feed monitoring, layered on top of the findings you already have.
Threat intelligence — correlating your assets against live indicator-of-compromise feeds, not just CVE databases — is on the roadmap, not shipped yet. Today, every finding already carries CVE context (description, known references, CVSS) inline, which covers most of what teams need day to day. We're not shipping a placeholder version of this to look more complete than we are; when it's real, this page will say so.
- Not in v1 — basic CVE context already lives inside every finding today
- Planned: IOC/threat-feed correlation against your asset inventory
What ships today is CVE context, not IOC monitoring
CyberSpec already enriches findings with vulnerability context: CVE identifiers, CVSS scores and vectors, CWE references, affected host and port, and remediation guidance. That is useful for day-to-day triage, but it is not the same thing as threat intelligence. A CVE tells you what a weakness is; an IOC feed tells you whether an address, domain, file hash, or behaviour is associated with active malicious infrastructure. Treating those as interchangeable would make the product look broader than it is.
What the roadmap item will add
The planned version is correlation against threat feeds and indicators that matter to an external attack surface: suspicious infrastructure touching your domains, services that match actively exploited campaigns, and findings whose exploitability is being observed in the wild. The goal is not to drown every scan in feed noise. It is to identify the smaller set of findings where threat activity changes the remediation order.
Why it depends on the asset inventory first
Threat intelligence only works when the asset graph is clean. Before CyberSpec can make a useful claim about a suspicious signal, it has to know which domains, IPs and ranges are yours, which ones were verified, and which findings are still open. That is why network scanning, ownership verification and vulnerability management ship first. They give the threat layer something reliable to correlate against instead of a loose list of hostnames.
This isn't built yet — no screenshots or fake previews above, this page reflects what actually ships today.
Explore the rest of CyberSpec
Vulnerability management
Every finding deduplicated across scans, triaged by severity, with CVSS scoring and remediation guidance built in.
Network scanning
On-demand and scheduled scans against domains, IPs, and CIDR ranges, with live progress and CVE correlation.
Compliance mapping
Every open finding mapped to the SOC 2, ISO 27001, and PCI DSS control families it touches — automatically.
SOC 2, ISO 27001 & PCI DSS
What CyberSpec covers framework by framework, for the compliance side of the house.
Pricing
Free for one asset, $20/month for twenty, custom above that.