SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
GuardsArm Platform · Detect

Threat Intelligence & Threat Map

Enrich every detection with global threat context.

Intelligence is worth having when it changes a decision. GuardsArm enriches detections with indicator context and shows the external peers your endpoints are genuinely talking to.

  • File reputation
  • Real peer mapping
  • MISP integration
A world map showing the genuine external network peers of internal endpoints, with known-bad destinations highlighted and indicator context attached to an alert

What is at stake

Intelligence that requires a pivot to consult gets consulted during the post-incident review, by which point its value has passed.

Context arrives at the moment of decision

Enrichment attached at detection time is what moves an alert from "investigate when there is time" to "investigate now" — a judgement that currently depends on who is on shift.

Triage becomes consistent between analysts

When the same context is on the record for everyone, two analysts reach the same conclusion about the same alert. That consistency is what makes SOC output auditable.

A threat view that reflects your estate

Mapping where your endpoints genuinely communicate, rather than animating inbound internet noise, produces something an analyst can act on instead of something that looks impressive on a wall.

Who carries this

The SOC consumes it. The map is also, in practice, the artefact most often shown to executives — which is an argument for it being accurate rather than decorative.

The problem

Threat intelligence is usually bought, then filed

Most organisations that purchase a threat feed end up with a feed rather than a capability. The indicators arrive, they land in a platform, and the connection between them and the alert an analyst is currently looking at is made by the analyst — if they think of it, and if they have the time.

The failure is one of placement rather than quality. Intelligence that requires a pivot to consult is intelligence that gets consulted during post-incident review, not during triage. By then its main value, which was helping decide what to look at first, has already passed.

The second failure is more visible and less discussed: the threat map. Nearly every security product ships one, and nearly all of them animate inbound scanning traffic against an internet-facing address. That traffic is constant, affects everyone equally, and means nothing in particular. It makes an impressive display and a useless control.

A map of who scanned your firewall is a map of the internet. A map of where your endpoints are actually talking is a map of your risk.

Capabilities

What threat intelligence does here

Indicator ingestion at scale

Tens of thousands of threat indicators ingested and available to enrich detections as they fire.

File reputation

File hashes checked against threat-intelligence sources and malware databases, feeding both FIM and the Malware Center.

Endpoint threat map

Maps your endpoints' real external network peers against known-bad intelligence and geolocation. It shows the connections your estate is actually making, not a decorative globe of unrelated attacks.

MISP integration

MISP-based threat-intelligence integration for organisations already running a sharing platform.

How it fits the platform

Enrichment happens at detection time, so an analyst opening an alert sees the indicator context already attached rather than pivoting to a separate intelligence tool.

How it works

Ingestion, enrichment, and a map worth looking at

  1. Indicators are ingested

    Tens of thousands of indicators are brought in and kept current, including through MISP-based integration for teams that already run a MISP instance or subscribe to a sharing community.

  2. Enrichment happens at detection time

    Indicator context is attached as the finding is created, not looked up afterwards. An analyst opening an alert sees what is known about the address or hash already on the record.

  3. File reputation is checked

    Hashes from file integrity monitoring are checked against threat-intelligence sources and malware databases, which turns a file-change event into a verdict rather than a question.

  4. Real peers are mapped, not imagined ones

    The endpoint threat map plots the external hosts your endpoints are genuinely communicating with, matched against known-bad intelligence and geolocation. It is a map of your traffic, not a visualisation of global internet background noise.

The threat map

Two things called the same name

The distinction is not cosmetic. It changes whether anyone should act on what the map shows.

AspectThe usual inbound-attack mapGuardsArm endpoint threat map
What is plottedInbound scan and probe traffic hitting any internet-facing address.The external peers your endpoints actually connected to.
What a line meansSomeone on the internet touched a port. This happens continuously, to everyone.A host inside your estate communicated with that address.
What to do about itNothing. It is ambient.Investigate, because an internal host is the one that initiated it.
Who it is forA screen in a reception area.An analyst deciding where to look next.

In the queue

Where enrichment shows up

The value is almost entirely in placement — context on the finding, at the moment the finding is made.

  • An alert on an outbound connectionThe destination arrives with its intelligence context and geolocation already attached — no pivot to a separate intelligence portal.
  • A file integrity change on a sensitive pathThe hash is checked for reputation, so a routine-looking change on a server can surface as a known-bad file.
  • A detection naming an external addressKnown-bad status is on the finding, which is frequently what moves it from "investigate when there is time" to "investigate now".

Terms

The vocabulary, briefly

Indicator of compromise

An address, domain, hash or pattern associated with known malicious activity. Useful as enrichment and as a fast first filter; insufficient on its own, because indicators age out quickly.

MISP

A widely used open threat-intelligence sharing platform. Integration means a community or sector feed you already subscribe to flows into detection rather than sitting in a separate tool.

File reputation

Checking a file hash against intelligence sources and malware databases to establish whether it is already known. The cheapest high-confidence verdict available on a file.

Enrichment at detection time

Attaching context as the finding is created rather than when an analyst opens it. The difference shows up in triage speed and, more importantly, in triage consistency.

Background

Understand the concept first

Plain explainers on the underlying ideas, written for someone evaluating rather than buying.

Questions

Common questions

Is the threat map useful or decorative?

It maps your endpoints' real external network peers against known-bad intelligence and geolocation. It shows connections your estate is actually making, rather than a globe of unrelated attacks elsewhere.

Can we feed in our own intelligence?

Yes, through MISP-based integration, which suits organisations already running a sharing platform. Sector sharing communities tend to be more valuable per item than broad commercial feeds, because the relevance filtering has already happened.

When does enrichment happen?

At detection time, so an analyst opening an alert sees indicator context already attached rather than pivoting to a separate intelligence tool.

See Threat Intelligence & Threat Map running on your own infrastructure

We will walk through the console, the deployment model and what it takes to stand it up in your environment.