Liberty91

Glossary.

Last updated 26 Jul 20266 min read

This glossary defines the key terms used across Liberty91, each in a sentence or two. Where a fuller explanation exists, the term links to its own page. Terms are grouped alphabetically.

A

Admiralty scale

A long-standing intelligence convention, also called the Admiralty code, that rates source reliability from A to F and information credibility from 1 to 6. Liberty91 rates sources on the first and Threat Events on the second. See Source reliability and confidence.

Alert

A rule you set up so that you, your Stakeholders, or downstream systems are notified the moment an Event matches criteria you care about, such as a particular Threat Actor, sector, or source country. See Set up automatic alerting.

Asset

A technology hosted by an Organization, defined by vendor, product, version, and where it is hosted. Assets describe an Organization's attack surface and help surface relevant threats. See Assets and hosts.

C

Canonical entity

The single global record for a Threat Actor, malware family, or vulnerability, shared across the platform with its aliases merged into it. Canonical entities are maintained by Liberty91 rather than created by users. See Threat Entities.

Credibility

How much the reporting on a Threat Event can be believed, rated 1 to 6 on the Admiralty scale. It is computed across every report attached to the Threat Event, rising with corroboration and with more reliable sources, and falling when a reliable source disputes the account.

Criticality

The priority you assign to an Intelligence Requirement, Asset, or Supplier, from baseline through to emergency.

E

Enrichment Opportunity

A prompt that appears when an Event contains an IOC that an enabled Module (such as MISP, OTX, CrowdStrike, or Group-IB) has matched to a known malware or Threat Actor. Accepting it records the association between that indicator and the entity. See IOC enrichment and decay scoring.

Event

A single report: one news article, one vulnerability disclosure, one vendor report, one dark web post, or one report you upload. Events are the individual items that get matched together into Threat Events. See Events.

I

Intelligence Package

A tailored intelligence product generated for a specific Organization, found under that Organization's Intelligence Packages tab. Once generated, you can review, edit, and stage it for mailing to your Stakeholders.

Intelligence Requirement

A threat topic of material interest that tells Liberty91 what to prioritise and report on, drawn from the Intelligence Library or created by you. A dedicated agent learns each one from every relevant Event. See Intelligence Requirements.

IOC (Indicator of Compromise)

A technical artifact such as an IP address, domain, or file hash extracted from an Event. Liberty91 gives each IOC a score and confidence rating, and enabled Modules can enrich it with further context. See IOC enrichment and decay scoring.

M

Mailroom

The area where you track all the intelligence you have shared with your Stakeholders, broken down by time range and Organization, with delivery status for each report. Admins and Owners also manage email templates here. See The Mailroom.

Malware

A type of Threat Entity representing a malicious software family, held as a canonical record with its aliases, description, techniques, and linked reporting. See Threat Entities.

Masking

The rule that you only ever see the sources of a Threat Event you are entitled to. Reporting you do not have a licence or upload for is hidden from you, including from the source and report counts, and private reporting never crosses between customers. See Threat Events.

MITRE ATT&CK

A public knowledge base of adversary tactics and techniques. Liberty91 identifies the techniques described in each Event and explains how each was used in the campaign reported.

Module

An integration you turn on to extend the platform. Collection Modules pull in reports and data, analysis Modules enrich incoming data such as IOCs and Assets, and production Modules send your intelligence out to other systems. See How Modules work.

Morning Report

A scheduled digest sent to Users and subscribed Stakeholders at a time you choose, covering news relevant to an Organization and optionally including IOC lists, STIX bundles, and SIGMA rules. See Customize your Morning Reports.

O

Organization

A company, government entity, or business unit you protect, used to customize the intelligence the platform generates. Liberty91 builds and maintains a dedicated agent for each one, trained on its country, sector, Assets, Suppliers, and Documents. See Organizations.

R

Relevance

The assessment, written automatically for your organizations, of what a given Threat Entity means for you specifically, drawn from your sectors, countries, watched regions, technologies, and suppliers. It appears on the entity card without being requested. See Threat Entities.

S

SIGMA rule

A generic, shareable detection rule format. Liberty91 can include available SIGMA rules in Morning Reports and Intelligence Packages when you select them for an Organization.

Source reliability

How much a source can be relied on, rated A to F on the Admiralty scale. Reliability is a property of the source itself rather than of any one story it runs, which is why it is rated separately from credibility. See Source reliability and confidence.

Stakeholder

A person in an Organization who receives your intelligence products, with an optional role and interests that let the platform tailor Alerts and reports to them. See Stakeholders.

Stance

What a given report is doing in relation to a Threat Event: claiming it, corroborating it, updating it, mentioning it in passing, or disputing it. See Threat Events.

Standing Intelligence Requirement

An Intelligence Requirement applied tenant-wide, so it covers every Organization in your account equally, rather than being assigned to specific Organizations. See Intelligence Requirements.

STIX bundle

A structured, machine-readable package of threat data. Liberty91 can produce a STIX bundle for an Event and send it to systems such as MISP through a Module.

Supplier

A third party in an Organization's supply chain, defined by name, criticality, and domain. Liberty91 maintains a description for each one, effectively a third-party threat profile. See Supply chain.

T

Technique observation

A record that a particular Threat Actor was seen using a particular MITRE ATT&CK technique, grounded in the reporting that observed it and carrying the date it was seen. This is what makes an actor's technique list dated and evidenced rather than static. See Threat Entities.

Threat Actor

A type of Threat Entity representing an adversary or intrusion set, held as a canonical record with its aliases merged, such as APT35 and Charming Kitten under one entity. See Threat Entities.

Threat Card

The card for a single Threat Entity, holding its name, aliases, description, dated ATT&CK techniques, IOCs, linked reporting, and the relevance assessment written for your organizations.

Threat Entity

The collective term for the things the Threat Library holds: Threat Actors, Malware, and Vulnerabilities. See Threat Entities.

Threat Event

The real-world occurrence that one or more reports describe, such as a specific breach. Reports about the same occurrence are matched together into a single Threat Event, which carries every source attached to it along with each one's stance and reliability. See Threat Events.

V

Vulnerability

A type of Threat Entity representing a security weakness, held as a canonical record with its CVE identifier, severity scoring, description, and linked reporting. See Threat Entities.

Was this page helpful?