Skip to main content

AdversaryGraph Use Cases

This page organizes AdversaryGraph workflows into three levels:

  • 10 simple use cases: one or two steps for fast analyst actions.
  • 10 intermediate use cases: three to five steps for structured CTI, SOC, and detection tasks.
  • 10 complex platform workflows: full workflows using multiple modules. Five are investigation workflows and five are defense / MITRE coverage workflows.

For a complete v3 walkthrough, read the public 1200km workflow article: From Log to Report: Using AdversaryGraph to Turn Firewall and EDR Noise Into a CTI Investigation.

Simple Use Cases

  1. Check One IOC - Check whether one IP, domain, URL, or hash has useful enrichment context.
  2. Open One Actor Profile - Review the core context for one ATT&CK group or actor.
  3. Show Actor TTPs On The Matrix - Visualize one actor's known ATT&CK behavior.
  4. Search The IOC Library - Find whether an observable already exists in local or synced intelligence.
  5. Sync ThreatFox IOCs - Refresh open-source IOC data for actor and malware context.
  6. Import A Navigator Layer - Load an existing ATT&CK layer for review or comparison.
  7. Export A PDF Report - Create a shareable analyst report from reviewed findings.
  8. Run Deployment Selftest - Check whether the deployment is healthy before analysis.
  9. Add A Custom IOC Feed - Connect a private or custom IOC feed.
  10. Open Troubleshooting For An Error - Move from a popup error to practical remediation.

Intermediate Use Cases

  1. Map A Report To ATT&CK - Turn one report into reviewed ATT&CK techniques.
  2. Compare Incident TTPs To Actors - Use TTP overlap to generate actor hypotheses.
  3. Build A Sector Threat Brief - Create a practical threat brief for one sector/customer.
  4. Enrich Actor IOCs - Add current observable context to one actor profile.
  5. Import MISP JSON - Bring MISP event or attribute exports into IOC Library.
  6. Pull TAXII Or Import STIX - Exchange structured intelligence with CTI platforms.
  7. Sync YARA And Sigma Feeds - Connect detection-rule context to IOCs and malware.
  8. Compare Two Reports - Assess whether two reports describe related activity.
  9. Review One Coverage Gap - Compare a threat layer to existing coverage.
  10. Use A Local LLM For Private Reports - Analyze sensitive content without public LLM routing.

Complex Investigation Workflows

  1. Investigation: From Log To Report - Turn firewall and EDR telemetry into IOC extraction, enrichment, relationship graph review, an Investigation workspace, ATT&CK leads, actor-overlap hypotheses, and an AI-assisted report.
  2. Investigation: Cloud And Kubernetes Incident - Investigate a cloud/Kubernetes incident using sector, TTP, IOC, and detection context.
  3. Investigation: Cluster Multiple APT Reports - Assess whether several reports belong to one campaign cluster.
  4. Investigation: Malware Family Behavior Mapping - Build an ATT&CK and IOC profile for a malware family.
  5. Investigation: Validate A Third-Party CTI Report - Validate a vendor or public CTI report before using it operationally.

Complex Defense And MITRE Coverage Workflows

  1. Defense: Build MITRE Coverage Baseline - Create a baseline of current coverage across MITRE ATT&CK.
  2. Defense: Create Sector-Based Detection Roadmap - Create a detection roadmap for a sector/customer environment.
  3. Defense: Build IOC Enrichment Pipeline - Create a repeatable SOC enrichment pipeline for incoming IOCs.
  4. Defense: Create Detection Content From CTI - Turn CTI findings into detection content candidates.
  5. Defense: Executive Risk And Coverage Report - Produce an executive report showing threat relevance and coverage posture.

Selection Guide

  • Start with simple workflows when you need a fast lookup, sync, export, or troubleshooting action.
  • Use intermediate workflows when you need analyst review, comparison, enrichment, or structured handoff.
  • Use complex workflows when you need an end-to-end investigation, a sector roadmap, a MITRE coverage baseline, or a full CTI-to-detection package.