Events.
An Event is a single report: one news article, one vulnerability disclosure, one vendor report, one dark web post, or one PDF you upload yourself. It is the raw material the platform works from, and it is deliberately small. One report in, one Event.
Events are one half of how Liberty91 organises the threat landscape. The other half is the Threat Event: the real-world occurrence that a report describes. Several reports about the same breach are Events in their own right, and they are matched together into one Threat Event so you read the occurrence once rather than seven times. This page covers the report layer. The Threat Event page covers what happens when reports are brought together.
What happens when an Event arrives
Liberty91 enriches every Event before you look at it. The platform extracts Indicators of Compromise, identifies the MITRE ATT&CK techniques described, and pulls out the Threat Entities mentioned. It rates the source and the data using the Admiralty scale, so that well-sourced reporting carries more weight than thin reporting.
It then matches the Event against everything it knows about you: your Alerts, sectors, Assets, regions, Suppliers, and Intelligence Requirements. Where something matches, the platform acts on it, whether that means sending an alert or adding the Event to an Intelligence Requirement's knowledge base.
This is also how the platform stays current. Each Event informs what Liberty91 knows about a topic, and grounding every Intelligence Package in that corpus is what keeps reporting accurate and reduces hallucination.
The Event page
Each Event opens on its own page. The header carries the title, the product, the source, and the creation date.
Header actions
Under the title you have a set of actions: delete the Event, visit the original source, share it, generate a report (see Create a report from an Event), or download the STIX bundle.
If you have Modules turned on, more actions appear here. With MISP active you get Send to MISP, and with a webhook configured you get an action such as Send to SOAR, depending on how that webhook is set up.
Summary and analysis
On the right you find Summary & Analysis. Click Analyse for relevance to generate a summary of the Event together with an assessment of how it relates to each of your Organizations. The button reads Analysing... while the job runs.
There is a similarly named control elsewhere in the platform. On an entity card, relevance is generated automatically and there is no button to press. See Threat Entities.
Linked entities
Below the summary you see the Threat Entities linked to this Event. Liberty91 links them automatically as it reads the report. Each one is a chip you can click through to that entity's card, and you can unlink an entity from the Event if it does not belong.
Enrichment Opportunities
Enrichment Opportunities come from the enrichments run against the IOCs in the Event. With the free OTX Module turned on, for example, an IP address in the report that OTX associates with VenomRAT surfaces VenomRAT as an Enrichment Opportunity. Accepting it records the association between that indicator and the entity, so the connection is captured against the canonical entity rather than kept in a silo. Where the match is ambiguous, nothing is recorded. See IOC enrichment and decay scoring.
MITRE ATT&CK techniques
Below that you see the MITRE ATT&CK techniques identified in the Event. These cover every technique the report describes, not only the ones named outright, and each carries a short note on how it was used.
Indicators of Compromise
At the bottom you find the Indicators of Compromise extracted from the Event, if there are any. Each gets a score and a confidence rating, and a range of integrations can enrich them with further context.
Frequently asked questions
What counts as an Event in Liberty91?
A single report or source item: one news article, one vulnerability disclosure, one vendor report, one dark web post, or one report you upload yourself. Each one becomes its own Event.
What is the difference between an Event and a Threat Event?
An Event is one report. A Threat Event is the real-world occurrence that report describes. Several Events covering the same occurrence are matched together into a single Threat Event.
What happens to an Event when it arrives?
Liberty91 extracts IOCs, MITRE ATT&CK techniques, and Threat Entities, rates the source, matches the Event against your alert rules, sectors, assets, regions, suppliers, and Intelligence Requirements, and takes any follow-up action.