Cyber threat intelligence answer engine

Intelligence management,prioritised

AI-enabled intelligence management platform built on prioritised intelligence requirements. Automated collection, analysis, and dissemination, and source-checked reporting, so you always have the answers that matter.

Conundrum Intelligence

Automated, Open-Source Cyber Threat Intelligence Cross-Referenced against

MITRE ATT&CK® is a registered trademark of The MITRE Corporation.

The problem

Getting the data isn't the hard part. Deciding what to do first is.

The gap between what gets published and what anyone has observed being exploited. Counted from the public catalogues, not estimated.

7,030
Vulnerabilities published

Disclosed in the last twelve months, across every vendor and product.

302
Known to be exploited

Added to CISA's Known Exploited Vulnerabilities catalogue over the same period.

1 in 23
Worth dropping everything for

Which is the whole argument for working from requirements rather than from a feed.

1,716
In the catalogue all told

Every vulnerability CISA has recorded as exploited since the catalogue opened in 2021.

Counted from CISA KEV and FIRST.org EPSS, as held on 21 September 2026. Conundrum ingests both daily; these figures are read from that data rather than written into the page.

The intelligence cycle, end to end

One platform for the whole cycle

Direction through feedback, with the evidence attached at every step.

Capabilities

What you can do with Conundrum

Prioritised requirements

PIRs at organisation, sector and global tiers, tuned to your industry.

Automated collection

Open-source collection across the five major attack vectors, plus geopolitics.

Finished reporting

Reports scored against their own sources before publication.

Grounded chat

Ask questions of your own intelligence and get cited answers, or a refusal.

Vulnerability triage

CISA SSVC decisions with KEV and EPSS, personalised by your requirements.

Leak-site monitoring

Ransomware leak-site listings tracked and matched against your watchlists.

Analyst workbench

Edit, annotate and publish, with version history on every published report.

Integrations

Signed outbound webhooks and a read-only agent interface over your intelligence.

The output

What a finished report looks like

Every report the platform generates answers a requirement you set, and is checked before anyone reads it.

  • Tied to a requirement. The report names the priority intelligence requirement it answers, so its relevance is a matter of record rather than of judgement.
  • Checked against its own sources. Assertions the sources do not support hold the report for review instead of publishing it.
  • The same shape every time. Executive summary, situation, assessment, recommendations, so a reader knows where to look before they start.
A finished Conundrum report: title, the requirement it answers, then executive summary, situation, assessment and recommendations.
Restraint

What we deliberately do not automate

The judgements that carry consequences stay with your analysts. This is a design position rather than a roadmap gap, and it is the part of the product we are least likely to change.

No autonomous dissemination

Nothing reaches a recipient on a machine's initiative. Routing follows rules your admins set, and a person decides who is told what.

No autonomous attribution

Naming the actor behind an intrusion is an analytic judgement with consequences. It is made by an analyst who can defend it, never inferred on your behalf.

No confidence percentages

We do not show a number a model produced about its own certainty. Where sourcing strength matters, it is described in the terms analysts already use.

Refusal over invention

Asked something your intelligence cannot answer, the assistant says so. On the benchmark we hold it to, nothing was invented to fill the gap.

Resources

Latest from Conundrum

Why teams choose us

Built by intelligence people, for intelligence people

Software alone doesn't make an intelligence capability. The methodology comes first; the platform operationalises it.

The requirement comes first. Everything the platform collects, scores and reports is answerable to a question somebody actually asked.

How the platform is built

Tools change. The intelligence cycle does not, and a team that runs it well outperforms a team with better software and no discipline.

Knowledge Base

The intelligence reference library

Priority intelligence requirements, collection planning, intelligence gaps, the intelligence cycle, explained properly by the author of the methodology and cross-linked so it reads as a reference library rather than a blog.

See it against your own requirements

A demo runs on your sector's intelligence, not a canned dataset.