Recognize the group
Search the catalogue by name or known alias. Review cross-vendor names and the sources behind the profile before deciding which intelligence is relevant.
Cognitio brings threat-actor profiles and security advisories into one research workflow. Recognize an actor across vendor names, understand its techniques, and carry that context into detections and endpoint hunts.
Different vendor names.
A shared actor reference.
Russia · Espionage
Spearphishing attachment
PowerShell
Registry run keys
Choose the next action with actor context in hand.
A vendor alias is a starting point. Cognitio connects it to an actor profile with origins, motivations, references and available ATT&CK mappings, so your team can research the same adversary from a shared reference.
Search the catalogue by name or known alias. Review cross-vendor names and the sources behind the profile before deciding which intelligence is relevant.
For mapped actors, techniques are grouped by ATT&CK tactic. Referenced CVEs and known tools add context for what to investigate and where detection coverage may matter.
Open source references, related advisories and indicators attributed through the knowledge graph. An intelligence link helps direct research; it is not proof that an actor is present in your estate.
Cognitio matches available Sigma rules to an actor’s ATT&CK group or techniques. Review the matches, then choose a detection or endpoint investigation path.
Deploy available local rules through Detection Lake. With Virtus Optimus licensed, matched Library rules can be converted for a supported connected SIEM and queued for approval.
Review actor-related rule recommendations, then launch an endpoint Sigma hunt for Windows or Linux. Hunts require an Endpoint Agent Server connection and permission to create hunts.
Browse security advisories across sources, analyze their content and review the extracted actors, techniques, CVEs and indicators. Related-actor links connect the report back to the catalogue and show the evidence behind the association.
Actor mention
Cozy Bear → APT29Technique extracted
T1566.001 · AttachmentCarry the advisory’s techniques, CVEs and summary into a detection draft.
Draft for reviewSearch a known actor alias or select a relevant security advisory.
Check source references, mapped techniques and available rule matches.
Use connected tools and the permissions your team has been given.
No. Profiles and attributed indicators are intelligence references. Confirm activity in your environment through your own detection and investigation evidence.
Research does not deploy a rule. Authorized users can deploy local detection rules. The Optimus Library conversion path queues rules for human approval. Advisory SIEM pushes are optional and also create approval work.
The connected Endpoint Agent Server runs its bundled Sigma scanner for the selected Windows or Linux endpoints. Actor-matched rules are recommendations; this path does not send only those rules into the hunt.
Cognitio is part of the SecOps Platform entitlement. Virtus Optimus is separately licensed and is needed for the Library conversion, Design and SIEM retrospective-hunt paths described here. Available actions also depend on permissions and target capabilities.
Have a workflow in mind? Talk to our team
See how Cognitio connects actor research, advisories and the detection work your team needs to do.