ATALAIA
  1. Home
  2. Services
  3. Threat Intelligence
17Station 17 · Run

Threat Intelligence

New zero-days, campaigns and supply-chain incidents, checked against your stack, with a clear answer: affected or not, and what to do.

Who gets asked what

A threat feed is a question, not an answer. Each team gets the one question only it can answer.

Zero-dayXML parser · 08:10CTImatches the stackSOCDo we see it?AppSecAre we exposed?OffensiveCan we test it?Answerby 14:202341
  1. 1
    08:10 · it matches the stack

    The parser is on the watch list, so it becomes a question.

  2. 2
    SOC · 09:00

    No exploit attempts in the gateway logs. A rule is added.

  3. 3
    AppSec · 09:30

    The partner callback parser uses an affected version. Patch shipped by 14:10.

  4. 4
    Offensive · 14:20

    The exploit works on the old build and fails on the patched one.

One morning, one zero-day

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Learn the stack

Languages, packages, clouds, vendors and exposed services.

ATALAIANode, Postgres, two clouds, nine vendors. That's the watch list.

APPSECAdd the partner SDK. It's in every build.

Leaves the roomWatch list: 212 packages, 2 clouds, 9 vendors

Step 2Watch what matters

Sources filtered to that stack, not the whole internet.

ATALAIAA zero-day this morning in an XML parser. It's on our list.

Leaves the roomSources filtered to the stack

Step 3Ask the right team

SOC: do we see it? AppSec: are we exposed? Offensive: can we test it?

ATALAIASOC: do we see exploit attempts?

SOCNothing in the gateway logs so far. Rule added.

ATALAIAAppSec: are we exposed?

APPSECThe partner callback parser uses it. Affected version.

ATALAIAOffensive: can you test it tonight?

OFFENSIVEOn staging, tonight.

Leaves the room3 questions, 3 teams

Step 4Report the answer

Affected or not, what we did, what's next.

OFFENSIVEThe exploit works on the old version, not on the patched one.

ATALAIAAffected, patched in six hours, monitored. One paragraph for leadership.

Leaves the roomAffected: yes, patched in 6 hours

  • ATALAIA
  • APPSEC
  • SOC
  • OFFENSIVE

Before and after

Before

Threat feeds tell you what happened somewhere. What you need is whether it touches your packages, your cloud and your code, this morning.

  • A big CVE lands and nobody knows if you're exposed
  • Feeds are read, but nobody acts on them
  • Supply-chain incidents are found on social media
After
  • A watch list built from your real stack
  • Same-day answers on major threats
  • Questions routed to SOC, AppSec and offensive
  • A short monthly brief for leadership

Typical shape: Ongoing, with a monthly brief.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.