Skip to content
Explore platformCognitio
Cognitio

Turn threat intelligence
into focused action.

Cognitio brings threat-actor profiles and security advisories into one research workflow. Recognize an actor across vendor names, understand its techniques, and carry that context into detections and endpoint hunts.

Cross-vendor aliasesMITRE ATT&CK contextAlerts & Advisories
Hostis CognitioIllustrative actor workflow
Search by a known alias

Different vendor names.
A shared actor reference.

Actor profile G0016

APT29

Russia · Espionage

Cross-vendor aliases · selected examples
Cozy BearMidnight BlizzardThe Dukes
Selected MITRE ATT&CK techniques
Initial accessT1566.001

Spearphishing attachment

ExecutionT1059.001

PowerShell

PersistenceT1547.001

Registry run keys

Choose the next action with actor context in hand.

Explore a profile, then choose an action. Rule availability, permissions and connected tools determine what can run. This example does not indicate activity in your environment.
01 - Actor intelligence

Build on the research behind the name.

A vendor alias is a starting point. Cognitio connects it to an actor profile with origins, motivations, references and available ATT&CK mappings, so your team can research the same adversary from a shared reference.

01

Recognize the group

Search the catalogue by name or known alias. Review cross-vendor names and the sources behind the profile before deciding which intelligence is relevant.

02

Understand how it operates

For mapped actors, techniques are grouped by ATT&CK tactic. Referenced CVEs and known tools add context for what to investigate and where detection coverage may matter.

03

Follow the evidence

Open source references, related advisories and indicators attributed through the knowledge graph. An intelligence link helps direct research; it is not proof that an actor is present in your estate.

02 - From a name to a hunt

Put actor context to work.

Cognitio matches available Sigma rules to an actor’s ATT&CK group or techniques. Review the matches, then choose a detection or endpoint investigation path.

Prepare detections

Deploy available local rules through Detection Lake. With Virtus Optimus licensed, matched Library rules can be converted for a supported connected SIEM and queued for approval.

Optimus Library pathConverted → queued for approvalA reviewer decides before a rule goes live.

Investigate endpoints

Review actor-related rule recommendations, then launch an endpoint Sigma hunt for Windows or Linux. Hunts require an Endpoint Agent Server connection and permission to create hunts.

Endpoint hunt scopeA sweep of the selected OSThe hunt runs the scanner’s bundled ruleset, not just the recommendations shown.
Explore Virtus Optimus
03 - Alerts & Advisories

Turn a new advisory into a detection plan.

Browse security advisories across sources, analyze their content and review the extracted actors, techniques, CVEs and indicators. Related-actor links connect the report back to the catalogue and show the evidence behind the association.

Alerts & AdvisoriesSynthetic advisory example
Analyzed advisory

Credential theft through malicious attachments

Actor mention

Cozy Bear → APT29

Technique extracted

T1566.001 · Attachment
Association evidence: alias mention
Generate detection

Virtus Optimus Design

Carry the advisory’s techniques, CVEs and summary into a detection draft.

Draft for review
Illustrates the advisory-to-Design handoff. Generating a draft requires Virtus Optimus and the appropriate permission; it does not deploy a rule.

Choose the response

The detection-profile workflow lets you select available detector, endpoint hunt and intelligence-ingestion actions. Review skipped steps and results to see what actually ran.

Check historical SIEM data

With Optimus, explicitly select a supported connected SIEM for a retrospective hunt. SIEM rule pushes and retrospective hunts are off by default; rule pushes create approval work.

04 - Getting started

Start with the threat your team is researching.

01

Find the context

Search a known actor alias or select a relevant security advisory.

02

Review the evidence

Check source references, mapped techniques and available rule matches.

03

Choose your action

Use connected tools and the permissions your team has been given.

Questions about Cognitio

01Does an actor profile mean we have been attacked?

No. Profiles and attributed indicators are intelligence references. Confirm activity in your environment through your own detection and investigation evidence.

02Does Cognitio deploy rules automatically?

Research does not deploy a rule. Authorized users can deploy local detection rules. The Optimus Library conversion path queues rules for human approval. Advisory SIEM pushes are optional and also create approval work.

03What do endpoint hunts run?

The connected Endpoint Agent Server runs its bundled Sigma scanner for the selected Windows or Linux endpoints. Actor-matched rules are recommendations; this path does not send only those rules into the hunt.

04Do we need Virtus Optimus?

Cognitio is part of the SecOps Platform entitlement. Virtus Optimus is separately licensed and is needed for the Library conversion, Design and SIEM retrospective-hunt paths described here. Available actions also depend on permissions and target capabilities.

Have a workflow in mind? Talk to our team

Bring the threat.
Explore your next move.

See how Cognitio connects actor research, advisories and the detection work your team needs to do.