CTI Workbench
Phase 1: Planning & Direction
Priority Intelligence Requirements (PIRs) driving the collection lifecycle.
Select Threat Report
Current Intelligence Priorities
Detect GitHub credential leaks & code scans
Monitor for intelligence indicating adversary intent to exploit leaked personal access tokens (PATs), scan private repositories, or target developer workspaces.
Track AI Platform API key exposure
Identify behavioral anomalies indicative of exposed OpenAI/Anthropic/AWS model keys, dynamic proxy tunneling, and unauthorized high-cost GPU cluster usage.
Track LOTL activity on edge infrastructure
Identify Living-Off-The-Land techniques and valid account abuse originating from anonymizing proxies targeting cloud perimeter gates.
Monitor SaaS Access Broker chatter
Track dark web forums and Telegram channels for Initial Access Brokers (IABs) auctioning access to enterprise Salesforce portals, CRM databases, or OAuth configurations.
Strategic Direction
The intelligence lifecycle begins here. Without formally defined PIRs, collection efforts become aimless ("hunting in the dark").
These PIRs dictate the parameters for our automated Collection engines (Phase 2) and the semantic weighting utilized by the AI Normalization layer (Phase 3).
Cloud & AI Security Warning
PIR-02 remains escalated due to automated scraping of public Git repositories and OpenAI platform key abuse. All behavioral telemetry is currently weighted to surface token leakage and unauthorized GPU resource hijacking.