What Conundrum monitors, analyses and reports on, and where the intelligence for each one comes from.
Malicious software designed to damage, disrupt or gain unauthorised access to systems: ransomware, trojans, worms, spyware and more.
Sources include VirusTotal, MalwareBazaar, ThreatFox and AbuseIPDB.
Distributed denial-of-service attacks that overwhelm systems with traffic to disrupt availability, increasingly used as part of wider campaigns.
Sources include Shadowserver, CISA advisories and Spamhaus.
Social engineering that tricks users into revealing credentials, installing malware or transferring funds, including spear phishing and business email compromise.
Sources include PhishTank, URLhaus, OpenPhish and APWG feeds.
Threats originating inside an organisation, whether malicious, negligent or compromised: data exfiltration, privilege abuse and account takeover.
Sources include CISA advisories, breach databases and ransomware leak-site monitoring.
Unauthorised access through exploitation of vulnerabilities, misconfigurations and zero-days, including web application attacks.
Sources include NVD, CISA KEV, Exploit-DB and vendor advisories.
Continuous collection from dozens of sources, correlated against your Priority Intelligence Requirements.
Collected intelligence becomes finished reporting (entities resolved, assessments written, recommendations drawn) checked against its sources.
Configurable distribution groups and scheduled delivery, so the right intelligence reaches the right stakeholders.