Liberty91

Do More Threat Intelligence, Faster.

Our AI agents learn what your organisation runs and who is likely to come after it, then collect security news as it breaks, work out what it means for you, and write up reports you can act on and pass on.

Start Free Trial
https://platform.liberty91.com
The Liberty91 home dashboard with 30-day threat event, actor, malware, and IOC counts, top techniques and actors, and the source-country map

What is Liberty91?

Keeping up with what is happening in security takes hours nobody has. Liberty91 is built to drastically reduce the time you spend on threat intelligence and security research.

It gathers security events, works out what they mean, and writes them up for you, so your time goes to the work only you can do. Our AI agents know what your organisation looks like and apply the same methods a trained analyst would, so they rapidly identify and prioritise critical threats and you can respond instantly.

7x

Faster intelligence

85%

Quicker response

24/7

Threat monitoring

An AI Analyst That Never Sleeps.

Liberty91 is a group of AI agents that works alongside you as a real-time junior threat intelligence analyst. It is not one model but several specialists: knowledge agents that stay current on the threats that matter to you, and tradecraft agents that put every event through the methods a trained analyst uses, from rating how reliable a source is to weighing each possible explanation against the evidence (Analysis of Competing Hypotheses).

What comes back is analysis at both the big-picture and the day-to-day level, indicators of compromise (the IP addresses, domains, and file hashes tied to an attack), detection rules and more. You get it as written reports, as STIX bundles, or pushed into the security tools and workplace apps you already use.

And it scales indefinitely. Whether that is one dedicated analyst for your own organisation or hundreds across your MSSP customers, each one gets its own set of agents that knows that customer's environment.

Liberty91 AI intelligence engine

Analyst or team of one?

Our free Community Tier is on the way, so any analyst can put AI-powered threat intelligence to work with no budget and no team. Join the waitlist to be first in line: the first 100 sign-ups get a month of our Analyst Tier free. Or grab our free, open-source CTI Skills for your AI coding agent today.

Intelligence Requirements.

An Intelligence Requirement is simply a question your team needs answered on an ongoing basis: about a sector, a malware family, a threat actor, a supplier, a group of systems, a senior executive, anything that matters to you. Liberty91 turns each question into a knowledge base that keeps itself current and reads every incoming event against every requirement it touches, so each event arrives carrying everything learned on that topic so far.

We keep our own Intelligence Requirements up to date as a shared knowledge base, and you can add your own on top, which stay private to you, whether you run them for your own organisation or, as an MSSP, on behalf of your clients. They also refer to each other, so a single question comes back as one answer with citations across everything relevant.

See how Intelligence Requirements work →
https://platform.liberty91.com
The Liberty91 Intelligence Requirements library, continuously updated knowledge bases for regions, threat sources, threat types, and threats to your environment

Platform Features.

https://platform.liberty91.com
Liberty91 Modules overview with the Collection grid including CrowdStrike, FalconFeeds, Group-IB, and X above the Analysis modules for enrichment

Real-time collection.

We watch hundreds of sources for security news and threat reporting, all day, every day.

  • Security News & Blogs, Vendor Reports
  • Premium Intelligence Sources
  • Darkweb
  • Social Media
Liberty91 relevance analysis on a Threat Event, naming the customer organization it matters to, the Intelligence Requirement it matched, and the MITRE ATT&CK techniques with how each was used

Instant analysis based on your profile.

Every event goes through the methods a trained analyst would use, from rating how reliable the source is to weighing each possible explanation against the evidence, and is then judged on how much it matters to you specifically. Connect your attack surface, supply chain, and asset inventory tools, and that picture of your environment keeps itself up to date.

A finished Liberty91 intelligence report as a branded PDF, the cover with its TLP classification beside a body page of written analysis

Actionable reports and alerts.

Get an alert the moment there is something you need to know, or send it straight into any of thousands of platforms you already run: your ticketing system, SIEM, SOAR, or threat intelligence platform.

https://platform.liberty91.com
Liberty91 Mailroom dashboard for a month of sends, counting reports, IOCs, detection rules, STIX bundles, and alerts against the previous period, broken down per client organisation

Get intelligence to the people who act on it.

Mailroom sends reports, indicators of compromise, Sigma detection rules, and STIX bundles to the people who need them, and keeps an auditable Sent log of everything that went out, across every organisation in your account. It covers the last step of the intelligence cycle, actually getting the work into the right hands.

The Documents section of a Liberty91 Organization, with the upload panel and two uploaded documents already extracted and reviewed

Set up an organisation in minutes.

Skip the manual data entry. Upload documents you already have, asset inventories, supplier registers, network diagrams, or a corporate profile, and Liberty91 pulls out the Assets and Suppliers for you to confirm in a couple of clicks. The agent looking after each organisation remembers all of it, so every new event is judged against your real environment.

The SIGMA tab of a Liberty91 intelligence package for a WordPress pre-authentication RCE, with five generated detection rules including full detection logic and false-positive guidance

Use detection rules to take immediate action.

Every intelligence package gives you more than indicators of compromise (IOCs). You also get Sigma detection rules written for the specific threat the package covers, ready for your SIEM and your next hunt. We'll tell you what to look for, where to find it, and what might trigger a false positive.

L91

Liberty91 Morning Report

to: security-team@acme.com

Daily Cybersecurity Morning Report, April 2, 2026

Tailored Threat Intelligence Report

Executive Summary

Critical cybersecurity threats including actively exploited Google Chrome vulnerabilities, regional scams targeting travelers and grieving families in the UK, and a complex web of data breaches and phishing campaigns impacting major technology companies.

Attack Surface Threats

Google Chrome, CVE-2026-5281

Actively exploited zero-day, CVSS 8.8. Patch by April 15.

EvilTokens Phishing-as-a-Service

New kit targeting Microsoft accounts via device code phishing.

SLSH / Scattered Spider Data Exfiltration

3M+ Salesforce records from major U.S. tech company.

Regional: United Kingdom

Reservation hijack scams targeting travelers via compromised booking systems.

View Full Report in Platform

Arrive at the office in-the-know.

The daily email is more than a round-up of the latest security news. It summarises everything published in the last 24 hours, works out what it means, and says how much of it applies to you. You arrive at the office already knowing how the latest events touch your own organisation, your sector, and the systems you actually run.

Frequently Asked Questions.

Want to see this on your own organisation?

Request a demo or start your free trial today, and get straight to AI-powered threat intelligence built around your organisation.