AdversaryGraph Use Cases
This page organizes AdversaryGraph workflows into three levels:
- 10 simple use cases: one or two steps for fast analyst actions.
- 10 intermediate use cases: three to five steps for structured CTI, SOC, and detection tasks.
- 10 complex platform workflows: full workflows using multiple modules. Five are investigation workflows and five are defense / MITRE coverage workflows.
For a complete v3 walkthrough, read the public 1200km workflow article: From Log to Report: Using AdversaryGraph to Turn Firewall and EDR Noise Into a CTI Investigation.
Simple Use Cases
- Check One IOC - Check whether one IP, domain, URL, or hash has useful enrichment context.
- Open One Actor Profile - Review the core context for one ATT&CK group or actor.
- Show Actor TTPs On The Matrix - Visualize one actor's known ATT&CK behavior.
- Search The IOC Library - Find whether an observable already exists in local or synced intelligence.
- Sync ThreatFox IOCs - Refresh open-source IOC data for actor and malware context.
- Import A Navigator Layer - Load an existing ATT&CK layer for review or comparison.
- Export A PDF Report - Create a shareable analyst report from reviewed findings.
- Run Deployment Selftest - Check whether the deployment is healthy before analysis.
- Add A Custom IOC Feed - Connect a private or custom IOC feed.
- Open Troubleshooting For An Error - Move from a popup error to practical remediation.
Intermediate Use Cases
- Map A Report To ATT&CK - Turn one report into reviewed ATT&CK techniques.
- Compare Incident TTPs To Actors - Use TTP overlap to generate actor hypotheses.
- Build A Sector Threat Brief - Create a practical threat brief for one sector/customer.
- Enrich Actor IOCs - Add current observable context to one actor profile.
- Import MISP JSON - Bring MISP event or attribute exports into IOC Library.
- Pull TAXII Or Import STIX - Exchange structured intelligence with CTI platforms.
- Sync YARA And Sigma Feeds - Connect detection-rule context to IOCs and malware.
- Compare Two Reports - Assess whether two reports describe related activity.
- Review One Coverage Gap - Compare a threat layer to existing coverage.
- Use A Local LLM For Private Reports - Analyze sensitive content without public LLM routing.
Complex Investigation Workflows
- Investigation: From Log To Report - Turn firewall and EDR telemetry into IOC extraction, enrichment, relationship graph review, an Investigation workspace, ATT&CK leads, actor-overlap hypotheses, and an AI-assisted report.
- Investigation: Cloud And Kubernetes Incident - Investigate a cloud/Kubernetes incident using sector, TTP, IOC, and detection context.
- Investigation: Cluster Multiple APT Reports - Assess whether several reports belong to one campaign cluster.
- Investigation: Malware Family Behavior Mapping - Build an ATT&CK and IOC profile for a malware family.
- Investigation: Validate A Third-Party CTI Report - Validate a vendor or public CTI report before using it operationally.
Complex Defense And MITRE Coverage Workflows
- Defense: Build MITRE Coverage Baseline - Create a baseline of current coverage across MITRE ATT&CK.
- Defense: Create Sector-Based Detection Roadmap - Create a detection roadmap for a sector/customer environment.
- Defense: Build IOC Enrichment Pipeline - Create a repeatable SOC enrichment pipeline for incoming IOCs.
- Defense: Create Detection Content From CTI - Turn CTI findings into detection content candidates.
- Defense: Executive Risk And Coverage Report - Produce an executive report showing threat relevance and coverage posture.
Selection Guide
- Start with simple workflows when you need a fast lookup, sync, export, or troubleshooting action.
- Use intermediate workflows when you need analyst review, comparison, enrichment, or structured handoff.
- Use complex workflows when you need an end-to-end investigation, a sector roadmap, a MITRE coverage baseline, or a full CTI-to-detection package.