Liberty91

Do More Threat Intelligence, Faster.

There is something in this morning's security news that matters to you. Finding it, and working out what it means for the systems you actually run, is the part nobody has a spare two hours for. That is the part we built Liberty91 to do.

Start Free Trial
https://platform.liberty91.com
The Liberty91 home dashboard with 30-day threat event, actor, malware, and IOC counts, top techniques and actors, and the source-country map

What is Liberty91?

Somewhere in the last 24 hours of security news there are a handful of things that genuinely matter to you, and telling them apart from everything else is a couple of hours a day nobody has spare. Liberty91 exists to drastically reduce the time you spend on threat intelligence and security research.

So it reads the events for you, works out what they mean, and writes them up against what your organisation actually runs. The agents apply the same tradecraft you would, which is how they rapidly identify and prioritise critical threats and you can respond instantly. Your own time goes back to the work that genuinely needs a person.

7x

Faster intelligence

85%

Quicker response

24/7

Threat monitoring

An AI Analyst That Never Sleeps.

Think of it as a real-time junior threat intelligence analyst who started this morning, already knows your environment, and never goes home. Behind that there are several specialists rather than one model doing everything: knowledge agents that keep themselves current on the threats you care about, and tradecraft agents that put every event through the methods you would use yourself, rating the source on the Admiralty scale and weighing each possible explanation against the evidence (Analysis of Competing Hypotheses).

What comes back is analysis at both the big-picture and the day-to-day level, the indicators of compromise tied to an attack (the IP addresses, domains and file hashes), and detection rules to go with them. Take it as a written report, as a STIX bundle, or pushed straight into whatever security tools and workplace apps you already run.

And it scales indefinitely. One dedicated analyst for your own organisation, or hundreds across your MSSP customer base, each running its own set of agents that knows that customer's environment.

Liberty91 AI intelligence engine

Analyst or team of one?

If you are the security team, or close enough to it, our free Community Tier is on the way so you can put AI-powered threat intelligence to work without a budget behind you. Join the waitlist to be first in line, and the first 100 sign-ups get a month of our Analyst Tier free. Want something to use today? Our CTI Skills are free, open source, and run inside your AI coding agent.

Results customers measured.

From analyst teams to MSSPs to the office of the CISO: what changed, measured in their own numbers. Each study is drawn from a customer interview, with role and organisation verified by Liberty91.

All case studies

Intelligence Requirements.

An Intelligence Requirement is just a question you need answered on an ongoing basis. Which ransomware crews are working our sector? Is anyone selling access to our suppliers? What is being said about this one executive? Liberty91 turns each question into a knowledge base that keeps itself current, and reads every incoming event against every requirement it touches, so by the time something reaches you it already carries everything learned on that topic so far.

We keep our own Intelligence Requirements up to date as a shared knowledge base, and you write your own on top of it. Yours stay private to you, whether you are running them for your own organisation or, as an MSSP, on behalf of your clients. They also refer to each other, so one question comes back as a single answer with citations drawn from everything relevant, rather than a pile of separate results.

See how Intelligence Requirements work →
https://platform.liberty91.com
The Liberty91 Intelligence Requirements library, continuously updated knowledge bases for regions, threat sources, threat types, and threats to your environment

Platform Features.

https://platform.liberty91.com
Liberty91 Modules overview with the Collection grid including CrowdStrike, FalconFeeds, Group-IB, and X above the Analysis modules for enrichment

Real-time collection.

We watch hundreds of sources for security news and threat reporting around the clock, so nothing lands at three in the morning with nobody reading it.

  • Security News & Blogs, Vendor Reports
  • Premium Intelligence Sources
  • Darkweb
  • Social Media
Liberty91 relevance analysis on a Threat Event, naming the customer organization it matters to, the Intelligence Requirement it matched, and the MITRE ATT&CK techniques with how each was used

Instant analysis based on your profile.

Every event goes through the tradecraft you would apply yourself, from rating the source through to weighing each possible explanation against the evidence, and then gets judged on how much it matters to you in particular. Connect your attack surface, supply chain and asset inventory tools and that picture of your environment keeps itself current, so the judgement stays right as things change.

A finished Liberty91 intelligence report as a branded PDF, the cover with its TLP classification beside a body page of written analysis

Actionable reports and alerts.

You get an alert the moment there is something you need to know. The same thing can go straight into whatever you already run, whether that is your ticketing system, your SIEM, your SOAR or your threat intelligence platform.

https://platform.liberty91.com
Liberty91 Mailroom dashboard for a month of sends, counting reports, IOCs, detection rules, STIX bundles, and alerts against the previous period, broken down per client organisation

Get intelligence to the people who act on it.

Mailroom gets the finished work to the people who act on it: reports, indicators of compromise, Sigma detection rules, STIX bundles. Everything that goes out lands in an auditable Sent log you can filter per organisation, so there is one record of what was sent, to whom, when, and in what format.

The Documents section of a Liberty91 Organization, with the upload panel and two uploaded documents already extracted and reviewed

Set up an organisation in minutes.

There is no manual data entry to sit through. Upload what you already have, an asset inventory, a supplier register, a network diagram, a corporate profile, and Liberty91 pulls out the Assets and Suppliers for you to confirm in a couple of clicks. The agent looking after that organisation remembers all of it, so every new event is judged against your real environment rather than a generic one.

The SIGMA tab of a Liberty91 intelligence package for a WordPress pre-authentication RCE, with five generated detection rules including full detection logic and false-positive guidance

Use detection rules to take immediate action.

Every intelligence package comes with more than indicators of compromise (IOCs). You also get Sigma detection rules written for the specific threat in that package, ready to drop into your SIEM or take on your next hunt, and each one tells you what to look for, where to find it, and what is likely to set off a false positive.

L91

Liberty91 Morning Report

to: security-team@acme.com

Daily Cybersecurity Morning Report, April 2, 2026

Tailored Threat Intelligence Report

Executive Summary

Critical cybersecurity threats including actively exploited Google Chrome vulnerabilities, regional scams targeting travelers and grieving families in the UK, and a complex web of data breaches and phishing campaigns impacting major technology companies.

Attack Surface Threats

Google Chrome, CVE-2026-5281

Actively exploited zero-day, CVSS 8.8. Patch by April 15.

EvilTokens Phishing-as-a-Service

New kit targeting Microsoft accounts via device code phishing.

SLSH / Scattered Spider Data Exfiltration

3M+ Salesforce records from major U.S. tech company.

Regional: United Kingdom

Reservation hijack scams targeting travelers via compromised booking systems.

View Full Report in Platform

Arrive at the office in-the-know.

The daily email does more than round up last night's security news. It summarises what was published in the last 24 hours, works out what it means, and tells you how much of it applies to you, so you walk into the office already knowing which of it touches your organisation, your sector and the systems you actually run.

Frequently Asked Questions.

Want to see this on your own organisation?

Request a demo or start your free trial, and you will be looking at threat intelligence built around your own organisation rather than a generic one.