1/1 evidence rows
Collection running
Watchlist Terms
SearchingSearching
Overview
ready20% confidence
Activity
ready1 item
Targeting
review0 rows
Infrastructure
review0 patterns
Sources
ready2 provenance rows
Evidence
ready1 supported
Watchlist relevance
review1 candidate
Related alerts/cases
review1 candidate
Collection gaps
review6 open
Actions
blocked0/5 ready
Collection running
0 queued collection tasks, 0 metadata review tasks, 0 unsafe target blocks, 0 rejected sources
First seen
2026-06-30T18:41:36.213Z
Source
TI search service
Confidence
20%
Provenance
live_search
Source context
1 row tied to selected evidence
| Source | Timestamp | Confidence | Capture | Next action |
|---|---|---|---|---|
Live discovery unavailable Live source discovery is not available from this API process | Not dated | 20% | needed | Open the returned source and attach capture evidence before case replay if no capture ID is present. |
Evidence priority
Review missing source, watchlist, alert, or freshness context before routing.
Priority basis
- 1 source row returned.
- Watchlist candidates: company: watchlist-terms.
- Capture reference is missing.
- No related alert ID is attached.
- Actor freshness is acceptable for review.
Backed references
- Organization context is required before watchlist, alert, case, or delivery handoff can mutate customer state.
- Candidate watchlist terms exist, but no persisted organization watchlist item is attached.
- No generated alert ID is attached to this actor result.
Source drilldown
Source rows, capture status, and handoff blockers for the selected queue item.
Live discovery unavailable
source live:search:unavailable · 20%
Live source discovery is not available from this API process
Open the returned source and attach capture evidence before case replay if no capture ID is present.
Capture ID or source hash is required before replayable case evidence.
Alert handoff
/dashboard/dwm
Authenticated organization ID; owner/admin/member watchlist permission
Case handoff
case workflow
DWM alert ID from /v1/dwm/alerts or alert rebuild; Authenticated organization ID
Capture ID or source hash is required before replayable case evidence.; Attach capture IDs or source request IDs to the provenance rows.
Customer Alert Fit
This finding strengthens watchlist and detection context, but should not become a customer alert until it matches a watched organization, domain, vendor, or portfolio term.
Matched watchlists
Watch terms
Organizations
Sectors / countries
Evidence
- No evidence rows returned yet.
Recommended Analyst Action
- Leave this query open while polling continues.
- Search an alias, domain, company name, CVE, or supplier term.
- Open the customer console for persisted queue work.
Overview
Threat intelligence query
Attribution not returned by the search service
First seen
Not returned
Last seen
2026-06-30
Confidence
20%
Freshness
Current
Freshness gate
Evidence dates are usable, but source coverage still needs capture or provenance references before stronger handoff.
Newest evidence
Not dated
Generated
2026-06-30
Source rows
2
Capture rows
0
Source blockers
- Source collection: Attach capture IDs or source request IDs to the provenance rows.
Handoff blockers
- Organization: Open the authenticated console and choose the customer organization before saving watchlist terms.
- Organization: Create or select the customer watchlist, then rebuild alerts from the saved items.
- Alert workflow: Rebuild alerts from persisted watchlist items and return the alert ID.
Next owner: Organization.
Motivation
Tooling
Campaigns
Indicators
Targeting
Geographies
Infrastructure
Techniques
No mapped technique rows returned.
Queue technique enrichment before detection or case routing.
Activity timeline
No dated campaign rows returned.
Queue campaign enrichment before trend or case review.
Confidence reasoning
- 1 returned source records are attached to the profile.
- No recent activity rows were returned.
- No tradecraft rows were returned.
Source coverage
Refresh source coverage before alert-ready handoff.
Source rows
2
Dated rows
0
Captures
0
Latest
Not dated
Source provenance
Live discovery unavailable
Live source discovery is not available from this API process
Returned source record for watchlist-terms.
Actor profile reference
Live source discovery is not available from this API process
Used to support actor enrichment when newer source rows are not returned.
Operations matrix
TTPs, infrastructure, and targeting rows with source context.
| Type | Name | Source | Freshness | Confidence | Action |
|---|
No TTP, infrastructure, or victim rows returned.
Select a row to inspect details.
Country Context
Source-backed country coverage for operator attribution and targeting observations.
2 candidate terms for monitoring
Candidate actor, alias, sector, country, campaign, tool, and source-domain terms are present only when returned by the profile or source rows.
company: watchlist-terms
Candidate term requires authenticated organization review before monitoring.
company: Watchlist Terms
Candidate term requires authenticated organization review before monitoring.
Authenticated organization ID; owner/admin/member watchlist permission
Live clear-web search
IncludedReal-time public web discovery plus approved scraper captures
Darknet/leak metadata
Monitoring dataMetadata-only actor/victim/date claims; no leaked file downloads
RansomLook and ransomware.live
Seed coverageGood starting mix for recent victim claims, actor names, company names, claimed dates, sector/country context, and claimed-data descriptions.
Useful for bootstrapping coverage and cross-checking our captures, but not enough by itself because anyone can index the same public rows.
Direct actor infrastructure collection
Owned monitoringcompany-first collection from actor-controlled public leak/extortion infrastructure where policy allows.
This is where defensible value comes from: faster discovery, verified claims, freshness deltas, actor-page changes, and watchlist alerts that are not just copied from another index.
Infostealer and credential-exposure records
Owned monitoringPotentially high-value if collected as reviewable records and routed through safety review.
Valuable for company/domain exposure alerts, but it must avoid credential values, raw dumps, private access, auth bypass, and unsafe redistribution.
Live discovery unavailable
Source
Live source discovery is not available from this API process