Liberty91

Do More Threat Intelligence, Faster.

Collect, analyse and share real-time, actionable and highly customised Threat Intelligence Reports with AI-powered agents trained on your organisation's unique threat profile.

Start Free Trial
https://platform.liberty91.com
The Liberty91 home dashboard with 30-day threat event, actor, malware, and IOC counts, top techniques and actors, and the source-country map

What is Liberty91?

Liberty91's AI-powered platform is designed to drastically reduce the time spent on threat intelligence and security research.

By automating the collection, analysis, and reporting of cyber-security events, Liberty91 allows you to focus on what truly matters. Our specialised AI agents, trained on your organisation's unique threat profile and applying real analytical tradecraft, rapidly identify and prioritise critical threats, enabling you to respond instantly.

7x

Faster intelligence

85%

Quicker response

24/7

Threat monitoring

An AI Analyst That Never Sleeps.

Liberty91 is a stack of AI agents that acts as your real-time junior threat intelligence analyst. Not one model, but specialised agents: knowledge agents that hold current expertise on the threats that matter to you, and tradecraft agents that put every event through real analytical technique, from source reliability scoring to Analysis of Competing Hypotheses.

The result is strategic and tactical analysis, Indicators of Compromise, Detection Rules and more, delivered as written reports, STIX bundles, or through integrations with your existing security tooling and productivity suites.

And it scales indefinitely. Whether you need one dedicated analyst for your organisation or hundreds for your MSSP customers, each gets its own agent stack, trained on its unique threat profile.

Liberty91 AI intelligence engine

Analyst or team of one?

Our free Community Tier is on the way, so any analyst can put AI-powered threat intelligence to work with no budget and no team. Join the waitlist to be first in line: the first 100 sign-ups get a month of our Analyst Tier free. Or grab our free, open-source CTI Skills for your AI coding agent today.

Intelligence Requirements.

An Intelligence Requirement is a question your team needs answered continuously, about a sector, a malware family, a threat actor, a supplier, an asset group, a VIP, anything that matters. Liberty91 turns each one into a self-maintaining knowledge base and reads every incoming event through every relevant requirement, so each one lands with cumulative expert context no single analyst could realistically carry.

Liberty91 keeps its own Intelligence Requirements continuously updated as a shared knowledge base. You, or your MSSP analysts on behalf of clients, can author additional Intelligence Requirements that stay private to you. They cross-reference each other, so a single question returns one answer with citations across everything relevant.

See how Intelligence Requirements work →
https://platform.liberty91.com
The Liberty91 Intelligence Requirements library, continuously updated knowledge bases for regions, threat sources, threat types, and threats to your environment

Platform Features.

https://platform.liberty91.com
Liberty91 Modules overview with the Collection grid including CrowdStrike, FalconFeeds, Group-IB, and X above the Analysis modules for enrichment

Real-time collection.

Collect Cyber Threat and security news from hundreds of sources in real-time.

  • Security News & Blogs, Vendor Reports
  • Premium Intelligence Sources
  • Darkweb
  • Social Media
Liberty91 relevance analysis on a Threat Event, naming the customer organization it matters to, the Intelligence Requirement it matched, and the MITRE ATT&CK techniques with how each was used

Instant analysis based on your profile.

Tradecraft agents assess every event with real analytical technique, from source reliability scoring to Analysis of Competing Hypotheses, then weigh its relevance to your threat profile. Integrate with your own Attack Surface Management Tools, Supply Chain Software and Asset inventories to dynamically keep your profile updated.

A finished Liberty91 intelligence report as a branded PDF, the cover with its TLP classification beside a body page of written analysis

Actionable reports and alerts.

Receive actionable alerts as soon as you need to know, or integrate with thousands of platforms like your ticketing system, SIEM, SOAR or TIP.

https://platform.liberty91.com
Liberty91 Mailroom dashboard for a month of sends, counting reports, IOCs, detection rules, STIX bundles, and alerts against the previous period, broken down per client organisation

Dispatch intelligence to the stakeholders who act on it.

Mailroom sends reports, IOCs, Sigma detection rules, and STIX bundles to the right recipients, and keeps an auditable Sent log of every dispatch, across every organisation in your account. The last mile of the CTI lifecycle, finally tooled.

The Documents section of a Liberty91 Organization, with the upload panel and two uploaded documents already extracted and reviewed

Set up an organisation in minutes.

Skip the manual data entry. Upload the documents you already have, asset inventories, supplier registers, network diagrams, or a corporate profile, and Liberty91 extracts the Assets and Suppliers for you to confirm in a couple of clicks. The agent that manages each organisation commits everything to memory, so every new event is judged against your real environment.

The SIGMA tab of a Liberty91 intelligence package for a WordPress pre-authentication RCE, with five generated detection rules including full detection logic and false-positive guidance

Use detection rules to take immediate action.

Our intelligence packages include not just Indicators of Compromise (IOCs), but also Sigma detection rules written for the specific threat they cover, ready for your SIEM and your next hunt. We'll tell you what to look for, where to find it, and what might trigger a false positive.

L91

Liberty91 Morning Report

to: security-team@acme.com

Daily Cybersecurity Morning Report, April 2, 2026

Tailored Threat Intelligence Report

Executive Summary

Critical cybersecurity threats including actively exploited Google Chrome vulnerabilities, regional scams targeting travelers and grieving families in the UK, and a complex web of data breaches and phishing campaigns impacting major technology companies.

Attack Surface Threats

Google Chrome, CVE-2026-5281

Actively exploited zero-day, CVSS 8.8. Patch by April 15.

EvilTokens Phishing-as-a-Service

New kit targeting Microsoft accounts via device code phishing.

SLSH / Scattered Spider Data Exfiltration

3M+ Salesforce records from major U.S. tech company.

Regional: United Kingdom

Reservation hijack scams targeting travelers via compromised booking systems.

View Full Report in Platform

Arrive at the office in-the-know.

Our daily emails are not just a round-up of the latest security news, they are a personalised summary, analysis and assessment of everything published in the last 24 hours. Arrive at the office with an up-to-date understanding of how the latest events are relevant to your organisation, sector and assets specifically.

Frequently Asked Questions.

Ready to do more with less?

Request a demo or start your free trial today. Get instant access to AI-powered threat intelligence tailored to your organisation.