CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Core module 04 · LIVE

In-flight enrichment from live intel sources.

OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise enrich detections as they flow — joined to Threat Atlas context for IoT/ICS operators.

What it delivers

Live in Core today.

Multi-source in-flight enrichment

IOC matching against Edge and connector events

STIX/TAXII exchange patterns

Threat Atlas operator board

SOC

Where every Core module lands

  • Live, partial, and roadmap labeled honestly on the platform page.
  • Detection, risk, compliance, and identity share the same incident.
  • Click a module, then come back to the operator board.
CyberDragon Unified SOC dashboard
How it works

From signal to sealed evidence.

01

Capability 1

Multi-source in-flight enrichment

02

Capability 2

IOC matching against Edge and connector events

03

Capability 3

STIX/TAXII exchange patterns

04

Capability 4

Threat Atlas operator board

Playbooks

SOAR module in the workspace

  • Run from the incident, not from a disconnected automation island.
  • OT guardrails stay in the path.
  • YAML for teams who version playbooks.
CyberDragon Response playbooks
Key capabilities

Built for regulated IT/OT estates.

Explore Now
Explore Now
Explore Now
Explore Now
Signal sources

What feeds this module.

Threat Intelligence Fusion

OTX, Abuse.ch, ThreatFox, MITRE TAXII, GreyNoise — in-flight enrichment.

Kafka event pipeline

Ingest, normalize, enrich, detect, and respond on shared topics.

Edge & connectors

Passive OT capture plus syslog, HEC, and cloud telemetry.

Evidence vault

Detections and decisions hash-chained for auditors.

UEBA

User and entity behavior

  • Anomaly signals join the same kill chain as OT protocol events.
  • Useful when identity abuse starts the campaign in enterprise.
  • Not a stand-alone UEBA SKU.
UEBA dashboard
Proof points

Measured in the lab — not marketing adjectives.

LIVE
Module maturity
4
Core module number
6/6
Lab attack scenarios
62
Core microservices
Lab-validated metrics. Proof of Value results may vary.
FAQ

Frequently asked questions.

Is Threat Intelligence Fusion available in the free trial?
The 7-day trial includes Core modules marked LIVE. PARTIAL modules are visible with honest maturity labels.
Does this page replace the platform overview?
No. Each module has its own URL so buyers can deep-link a capability without landing on a generic platform dump.
Where does this module sit in the stack?
OTX, Abuse.ch, ThreatFox, MITRE TAXII, GreyNoise — in-flight enrichment.

Try Threat Intelligence Fusion on your traffic.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.