ThreatQ Threat Intelligence Platform 76
ThreatQ Threat Intelligence Platform
To understand and stop threats more effectively and efficiently your existing security infrastructure and people need to work smarter, not harder. ThreatQ is a data-driven threat intelligence platform that allows you to automate the intelligence lifecycle, quickly understand threats, make better decisions and accelerate threat detection, investigation and response.
ThreatQ serves as an open and extensible platform that accelerates security operations.
The  DataLinq Engine, Threat Library, Smart Collections, ThreatQ TDR Orchestrator, ThreatQ Investigations and the Open Exchange allow you to quickly understand threats, make better decisions and accelerate detection and response.

THREAT LIBRARY Relevant, Contextual Intelligence Shared Across Systems and Teams
The threat library automatically scores and prioritizes threat intelligence based on parameters you set. Prioritization is calculated across many separate sources, both external and internal, to deliver a single source of truth using the aggregated context provided. This removes noise and reduces the risk of false positives:
• Self-tuning
• Context from external + internal data
• Structured and unstructured data import
• Automatic prioritization based on all sources
• Custom enrichment source for existing systems. 

THREATQ INTEGRATION FRAMEWORK Framework drives depth & breadth of bidirectional integrations. 
A set of tools and technologies to enable easy creation and maintenance of integrations with external feeds and internal security infrastructure, resulting in the largest technology ecosystem, with the most capability, in the market. Import and aggregate external and internal data sources, integrate with existing enrichment and analysis tools, and export the right intelligence to the right tools at the right time to accelerate detection and response. Get more from your existing security investments by integrating your tools, teams and workflows through standard interfaces and an SDK/API for customization.
• Bring your own connectors and tools
• Marketplace apps for easy integrations
• SDK / API for customization
• Standard STIX/TAXII support

SMART COLLECTIONS Puts the “smarts” in the platform and not the individual playbooks.
ThreatQ TDR Orchestrator puts the “smarts” in the platform and not the individual playbooks by using Smart Collections™ and data-driven playbooks. The application of Smart Collections and data-driven playbooks provides for simpler configuration and maintenance, and provides a more efficient automation outcome. This approach further addresses all three stages of automation – Initiate, Run and Learn – easily and efficiently by enabling users to curate and prioritize data upfront, automate only when relevant, and simplify actions taken. To improve the platform “smarts”, it will also capture what has been learned to improve data analytics, which in turn improves the initiation stage of automation. Smart Collections improves detection and response by automatically:
• Generating dashboard analytics
• Controlling data shared via ThreatQ Data Exchange feeds
• Sharing data with select ThreatQ integrations to support a wide range of use cases
• Launching automated workflows

DATALINQ ENGINE Make sense of data in order to accelerate detection, investigation and response
Connecting disparate systems and sources, this adaptive data engine imports and aggregates external and internal data; curates and analyzes data for decision making and action; and exports a prioritized data flow across the infrastructure for improved prevention, and accelerated detection and response.
• Ingest and aggregate structured and unstructured data via Marketplace apps and an open API
• Normalize automatically from different sources, formats and languages into a single object
• Correlate across atomic pieces of data to identify relationships and provide a unified view
• Prioritize via customer controlled, dynamic scoring to ensure relevance and filter noise
• Translate data into the format and language necessary for consumption across systems

THREATQ TDR ORCHESTRATOR Simplify Security Automation, TIP and SOC initiatives by making them data-driven, open and efficient
ThreatQ TDR Orchestrator is the industry’s first solution to introduce a simplified, data-driven approach to Security Automation, TIP, and TDIR initiatives that accelerates threat detection and response across disparate systems, resulting in more efficient and effective security operations. Key Benefits:
• Easy to set up and maintain
• Reduce playbook runs by 80%
• Ensure output is relevant and high priority
• Learn from the actions taken, and improve over time

THREATQ INVESTIGATIONS The Industry’s First Cybersecurity Situation Room
ThreatQ Investigations solves the silo challenge and eliminates inefficiencies that exist across security operations to accelerate detection and response. As the first cybersecurity situation room, it streamlines investigations and improves active collaboration among and across teams.
• Fuse together threat data, evidence and users
• Accelerate investigation, analysis and understanding of threats in order to update your defense posture proactively
• Drive down mean time to detect (MTTD) and mean time to respond (MTTR)
• Build incident, adversary and campaign timelines
• Perform standard actions and responses throughout your security infrastructure from the investigation interface

 
Category Products