Liberty91

How Modules work.

Last updated 14 Jun 20263 min read

Modules are how Liberty91 connects to the outside world. They fall into three types: Collection modules pull reports and data in, Analysis modules enrich what comes in, and Production modules push your finished intelligence out. Most modules need nothing more than a few clicks, though premium Collection modules ask you to bring your own licence and API key for the source you have subscribed to. This page explains the three types so you can decide which Modules to turn on.

What are the three Module types?

Use this table to find the right Module for what you want to do, then open its page for setup steps.

TypeWhat it doesExample Modules
CollectionPulls reports and data from a source, either open source or a premium feed where you bring your own licence and API keyCrowdStrike Intelligence, FalconFeeds, Group-IB, Google Threat Intelligence, Cyber News and Reports, PDF Import, X (Twitter)
AnalysisEnriches incoming data, whether that is your attack surface or the IOCs found in EventsFullHunt and Hexiosec for attack surface; MISP, CrowdStrike, Google Threat Intelligence, and free AlienVault OTX for IOC enrichment
ProductionSends your analysis and finished products out to other systemsMiro, MISP, and Webhooks to your SIEM or SOAR

Collection modules and Threat Events

Collection modules do not just fill a feed. The reporting they bring in feeds the Threat Event layer, where reports about the same real-world occurrence are matched together, so a breach covered by your licensed vendor reporting and by three news outlets reads as one occurrence with four sources rather than four separate items.

This applies to reporting sources generally, including the reports you upload yourself. Analysis modules do not contribute, because enriching an indicator is not reporting on an occurrence, and neither do production modules, which send your finished work outward.

Your licensed and uploaded reporting stays yours. Anyone without the same entitlement does not see it: not the report, not its contents, and not its existence in the source and report counts. If the only reporting on an occurrence is reporting you are not entitled to, the Threat Event does not appear for you at all. Private and uploaded reports also never write to the shared record itself, so the victims, technologies, dates, and credibility attached to a Threat Event are always computed from public reporting. See Threat Events for the full picture.

How the types fit together

Collection modules feed your Recent Threats dashboard with Events. As those Events arrive, Analysis modules enrich them: attack-surface tools like FullHunt keep your Assets current, and IOC enrichment tools check every indicator against MISP, CrowdStrike, Google Threat Intelligence, or the free AlienVault OTX. Once you have produced an alert or a report, Production modules route it onward, whether that is a board in Miro, a finished report into MISP, or a webhook into your SIEM or SOAR.

Note

Some modules sit in more than one type. CrowdStrike Intelligence, Google Threat Intelligence, and MISP each act as both a Collection source and an enrichment or Production endpoint, so you configure them once and use them in several ways.

Was this page helpful?