Skip to content

Capability

Detection & Response

Ingest CISA KEV, MITRE ATT&CK, and ENISA threat intelligence; match it to the organization's assets and posture; and propose a structured Threat, Asset, Method, and Effect scenario for analyst confirmation before promotion.

Design partnerPublic capability

What Valty does

Incidents, current public threat intelligence, workspace matching, four-part FAIR-aligned scenario drafts, ATT&CK coverage, remediation, and closure evidence. Valty turns this domain's signals into priced, proof-backed risk you can act on.

Where the boundary sits

AI‑assisted workflow. Proposed scenarios remain drafts until a human confirms or dismisses them; Valty does not claim to own response execution by default.

Best next step for SOC, CISO: choose “See how this attaches to CRQ” to review the workflow, evidence boundary, and fit for your environment.

Detection & Response product surface
Detection & ResponseThreat-source provenance, workspace context, four-part FAIR-aligned draft, analyst lifecycle decision, incident-to-proof trail, and response validation summaryOpen full-size product view ↗

Threat intel to scenario

Turn current threat intelligence into a draft scenario matched to your environment.

Valty ingests current public threat sources, matches them to your organization’s assets and posture, and proposes a structured FAIR-aligned scenario for analyst review. Threat, Asset, Method, and Effect stay explicit; the model does not approve its own scenario.

Ingest

CISA KEV, MITRE ATT&CK, and ENISA feed the draft

The daily path brings current public threat intelligence into one structured proposal workflow.

Match

Threats are matched to real workspace context

Asset inventory, cloud and identity graphs, session posture, and AI-agent telemetry determine whether a scenario fits the environment.

Structure

Every proposal uses a four-part FAIR-aligned schema

Threat, Asset, Method, and Effect remain explicit so the draft can feed the same quantification and evidence model.

Review

Analyst confirmation is the promotion boundary

The proposed scenario stays in draft until a reviewer confirms or dismisses it, with the lifecycle action recorded.

Source convergence

Every draft keeps its sources and human decision.
3 sources / 1 gate
01CISA KEVSignal
02MITRETechnique
03ENISAContext
04AnalystDecision
Human gate

The model proposes; an analyst decides. A scenario remains a draft until it is confirmed or dismissed, and that decision stays in the record.

Review the CISO workflow

Proof matrix

Capability proof requirements

Every claim shows its source, confidence, and limits, so you can trust the number before you act on it.

ClaimSourceConfidenceFreshness
Capability claimIncidents, current public threat intelligence, workspace matching, four-part FAIR-aligned scenario drafts, ATT&CK coverage, remediation, and closure evidenceDesign partnerPublic capability
Evidence artifactThreat-source provenance, workspace context, four-part FAIR-aligned draft, analyst lifecycle decision, incident-to-proof trail, and response validation summarySource-linkedReviewed before publish
BoundaryAI‑assisted workflow. Proposed scenarios remain drafts until a human confirms or dismisses them; Valty does not claim to own response execution by default.Claim-reviewedQuarterly or on product change