Liberty91

Glossary.

Last updated 29 Jul 202610 min read

This glossary defines the key terms used across Liberty91, each in a sentence or two. Where a fuller explanation exists, the term links to its own page. Terms are grouped alphabetically.

A

Admiralty scale

A long-standing intelligence convention, also called the Admiralty code, that rates source reliability from A to F and information credibility from 1 to 6. Liberty91 rates sources on the first and Threat Events on the second. See Source reliability and confidence.

Alert

A rule you set up so that you, your Stakeholders, or downstream systems are notified the moment an Event matches criteria you care about, such as a particular Threat Actor, sector, or source country. See Set up automatic alerting.

Artifact

One of the machine-readable outputs attached to an Intelligence Package: the Markdown report, the IOC CSV, the STIX 2.1 bundle, or the SIGMA rules. Each shows as an icon on the package and in the Mailroom. The branded PDF travels as an email attachment instead. See The Mailroom.

Asset

A technology hosted by an Organization, defined by vendor, product, version, and where it is hosted. Assets describe an Organization's attack surface and help surface relevant threats. See Assets and hosts.

C

Canonical entity

The single record that fixes the identity of a Threat Actor, malware family, or vulnerability, with its aliases merged into it. The identity is shared across the platform; the reporting, indicators, and observed techniques attached to it are the ones your own sources entitle you to, so two customers can see the same entity described in different depth. See Threat Entities.

Confidence

How sure Liberty91 is that a given indicator is genuinely malicious, from 0 to 100. It starts from how clearly the indicator was stated in the source report, rises as independent enrichment vendors confirm it, and is capped low if any vendor reports it as benign. Distinct from the indicator's score, which measures freshness. A dash means there is no signal either way. See IOC enrichment and decay scoring.

Credibility

How much the reporting on a Threat Event can be believed, rated 1 to 6 on the Admiralty scale and shown with its label: 1 Confirmed, 2 Probably True, 3 Possibly True, 4 Doubtful, 5 Improbable, 6 Cannot be judged. It is computed across every report attached to the Threat Event, rising with corroboration and with more reliable sources, and falling when a reliable source disputes the account. See Source reliability, credibility, and confidence.

Criticality

The priority you assign to an Intelligence Requirement, Asset, or Supplier, from baseline through to emergency.

D

Daily report

The scheduled digest of everything relevant to an Organization since the last one, produced as an Intelligence Package and labelled Daily report wherever it appears, so an automated digest is never mistaken for one someone put together by hand. See Intelligence Packages.

Direct exposure

One of the four routes to relevance: the Threat Event implicates an Asset or technology an Organization actually runs. See Organizations.

Discredit

An analyst action that marks a source as having been caught out. It drops the source's reliability grade by one band and permanently caps its ceiling at B, and the change ripples through the credibility of every Threat Event that source contributed to. See Source reliability, credibility, and confidence.

E

Enrichment Opportunity

A prompt that appears when an Event contains an IOC that an enabled Module (such as MISP, OTX, CrowdStrike, or Group-IB) has matched to a known malware or Threat Actor. Accepting it records the association between that indicator and the entity. See IOC enrichment and decay scoring.

Event

A single report: one news article, one vulnerability disclosure, one vendor report, one dark web post, or one report you upload. Events are the individual items that get matched together into Threat Events. See Events.

I

Intelligence Package

A tailored intelligence product generated for a specific Organization, found in the Intelligence Packages section of that Organization. It comes in kinds (Event, Threat, Entity, Daily report, Monthly) and moves through statuses (Generating, Draft, Staged, Sent, Failed). Once generated, you review, edit, and stage it for mailing to your Stakeholders. See Intelligence Packages.

Intelligence Requirement

A threat topic of material interest that tells Liberty91 what to prioritise and report on, drawn from the Intelligence Library or created by you. A dedicated agent learns each one from every relevant Event. See Intelligence Requirements.

IOC (Indicator of Compromise)

A technical artifact such as an IP address, domain, or file hash extracted from an Event. Each IOC carries a score, a confidence, and a verdict, and enabled Modules can enrich it with further context. Well-known public infrastructure, such as public DNS resolvers, is filtered out at extraction rather than pulled in and scored down. See IOC enrichment and decay scoring.

M

Mailroom

The area where you track all the intelligence you have shared with your Stakeholders, broken down by time range and Organization, with delivery status for each report. Admins and Owners also manage email templates here. See The Mailroom.

Malware

A type of Threat Entity representing a malicious software family, with one canonical record covering its aliases, description, techniques, and linked reporting. See Threat Entities.

Masking

The rule that you only ever see the sources of a Threat Event you are entitled to. Reporting you do not have a licence or upload for is hidden from you, including from the source and report counts, and private reporting never crosses between customers. See Threat Events.

MITRE ATT&CK

A public knowledge base of adversary tactics and techniques. Liberty91 identifies the techniques described in each Event and explains how each was used in the campaign reported.

Module

An integration you turn on to extend the platform. Collection Modules pull in reports and data, analysis Modules enrich incoming data such as IOCs and Assets, and production Modules send your intelligence out to other systems. See How Modules work.

Morning Report

A scheduled digest sent to Users and subscribed Stakeholders at a time you choose, covering news relevant to an Organization and optionally including IOC lists, STIX bundles, and SIGMA rules. See Customise your Morning Reports.

O

Organization

A company, government entity, or business unit you protect, used to customise the intelligence the platform generates. Liberty91 builds and maintains a dedicated agent for each one, trained on its country, sector, Assets, Suppliers, and Documents. See Organizations.

Q

Quick filters

The clickable chips on an Organization's Dashboard tab, one per sector, region, and Intelligence Requirement on its profile. Clicking one opens the Threat Events list already filtered to it. See Work with the Organization page.

R

Relevance

The assessment, written automatically for your organizations, of what a given Threat Entity means for you specifically, drawn from your sectors, countries, watched regions, technologies, and suppliers. It appears on the entity card without being requested. See Threat Entities.

S

Score (IOC)

How much weight an indicator deserves right now, from 0 to 100. It is set from the indicator's type, its source, and the criticality of the associated threat, then decays with age until it expires below a threshold. Distinct from confidence. See IOC enrichment and decay scoring.

SIGMA rule

A generic, shareable detection rule format. Liberty91 can include available SIGMA rules in Morning Reports and Intelligence Packages when you select them for an Organization.

Source class

The category a source falls into, which sets the reliability grade it starts at: Government sources start at A, vendor sources at B, and news sources at C. C is also the fallback for anything else. See Source reliability, credibility, and confidence.

Source reliability

How much a source can be relied on, rated A to F on the Admiralty scale. Reliability is a property of the source itself rather than of any one story it runs, which is why it is rated separately from credibility. It starts at a grade set by the source class and then moves on evidence, through validation credits or a discredit. See Source reliability, credibility, and confidence.

Stakeholder

A person in an Organization who receives your intelligence products, with an optional role and interests that let the platform tailor Alerts and reports to them. See Stakeholders.

Stance

What a given report is doing in relation to a Threat Event: claiming it, corroborating it, updating it, mentioning it in passing, or disputing it. See Threat Events.

Standing Intelligence Requirement

An Intelligence Requirement applied tenant-wide, so it covers every Organization in your account equally, rather than being assigned to specific Organizations. See Intelligence Requirements.

STIX bundle

A structured, machine-readable package of threat data. Liberty91 can produce a STIX bundle for an Event and send it to systems such as MISP through a Module.

Supplier

A third party in an Organization's supply chain, defined by name, criticality, and domain. Liberty91 maintains a description for each one, effectively a third-party threat profile. See Supply chain.

T

Technique observation

A record that a particular Threat Actor was seen using a particular MITRE ATT&CK technique, grounded in the reporting that observed it and carrying the date it was seen. This is what makes an actor's technique list dated and evidenced rather than static. See Threat Entities.

Threat Actor

A type of Threat Entity representing an adversary or intrusion set, with its aliases merged into one canonical record, so APT35 and Charming Kitten are a single entity. See Threat Entities.

Threat Card

The page for a single Threat Entity, showing its name, aliases, description, dated ATT&CK techniques, IOCs, linked reporting, and the relevance assessment written for your organizations. Threat Cards are not created by users; the entity is already in the catalogue. See Threat Entities.

Threat Entity

The collective term for what the Threat Library covers: Threat Actors, Malware, and Vulnerabilities. See Threat Entities.

Threat Graph

The first-degree relationships around a Threat Entity: the malware an actor uses, the vulnerabilities it exploits, the entities it appears alongside. Downloadable as a STIX 2.1 bundle. See Threat Entities.

Threat Event

The real-world occurrence that one or more reports describe, such as a specific breach. Reports about the same occurrence are matched together into a single Threat Event, which carries every source attached to it along with each one's stance and reliability. See Threat Events.

V

Validation credit

What a source earns each time it is independently corroborated on a Threat Event. Five consecutive credits promote the source one reliability band, up to a ceiling of A. See Source reliability, credibility, and confidence.

Verdict

The plain classification enrichment vendors have converged on for an indicator: Malicious, Suspicious, Benign, or Unknown. It takes the worst reading across the vendors that have an opinion. See IOC enrichment and decay scoring.

Verification stage

Where a Threat Event stands overall, shown as a badge. Machine-created means it came from a single source and is not yet corroborated. Corroborated means at least two independent sources reported it, and is reached automatically. Analyst-verified, Disputed, and Rejected are analyst judgements the automatic pipeline never overwrites. Merged means it was folded into another Threat Event as a duplicate. Rejected and merged events drop out of entity pages, reports, and dashboards. See Threat Events.

Vulnerability

A type of Threat Entity representing a security weakness, with one canonical record covering its CVE identifier, severity scoring, description, and linked reporting. See Threat Entities.

Was this page helpful?