DECISION TOOLS
Operational tools with the evidence boundary visible
Use focused tools for indicator triage, current threat context and vulnerability decisions without treating automation as analyst authorization.
CURRENT INTELLIGENCE
Threat Action Pack
Review a human-approved release with current redistributable IOCs, source context, telemetry requirements and incident-response triggers.
Open the current packINDICATOR TRIAGE
IOC Decision Lookup
Identify an IOC type automatically and review source, freshness, lifecycle state and operational interpretation.
Check an IOCRISK DECISION
Vulnerability Decision Brief
Apply official CISA SSVC while keeping KEV, EPSS, CVSS and local context separate in an exportable decision record.
Build a decision briefOPERATING PRINCIPLE
Decision support, not automatic authorization
Every tool states what is known, what is missing and where local context or human approval is still required.
Review the evidence method