# Liberty91 Documentation > Liberty91 is an AI-powered cyber threat intelligence platform that automates the collection, analysis, and reporting of cybersecurity events into tailored, organization-specific intelligence products. This file indexes the user documentation. ## Getting started - [What is Liberty91?](https://liberty91.com/docs/getting-started/what-is-liberty91): Liberty91 is an AI-powered cyber threat intelligence platform that turns raw security events into tailored intelligence for analysts, CISOs, and MSSPs. - [Quick Start](https://liberty91.com/docs/getting-started/quick-start): Set up Liberty91 from first login: choose data hosting, add users, populate Organizations, set Intelligence Requirements, and build your Threat Library. - [Data Hosting and Regions](https://liberty91.com/docs/getting-started/data-hosting-and-regions): Choose where Liberty91 hosts and processes your data on first login, and set a separate hosting region per Organization to meet residency needs. - [Users and Roles](https://liberty91.com/docs/getting-started/users-and-roles): Invite team members to Liberty91 from your Organization Profile and assign one of four roles: Viewer, Analyst, Admin, or Owner. - [Set Up Your Organizations](https://liberty91.com/docs/getting-started/set-up-your-organizations): Populate the Organizations the Liberty91 team created for you with Assets, Suppliers, and documents, and choose each one's hosting region for tailored reports. - [Add Stakeholders](https://liberty91.com/docs/getting-started/add-stakeholders): Add the people who receive your Intelligence Products in Liberty91, set their role, email, and interests, and subscribe them to Morning Reports. - [Seed Organization Documents](https://liberty91.com/docs/getting-started/seed-organization-documents): Upload documents to a Liberty91 Organization to extract Assets and Suppliers automatically and give the agents the context they need to contextualise events. - [Set Your Intelligence Requirements](https://liberty91.com/docs/getting-started/set-your-intelligence-requirements): Pick Intelligence Requirements from the Intelligence Library, assign them account-wide or per Organization, or create your own to tell Liberty91 what matters. - [Your Threat Library](https://liberty91.com/docs/getting-started/build-your-threat-library): Your Threat Library is the catalogue of Threat Actors, malware, and vulnerabilities. Open an entity and its profile and relevance are already written. - [Download the Mobile App](https://liberty91.com/docs/getting-started/download-the-mobile-app): Download the Liberty91 iOS app to use the platform on the move and produce intelligence products wherever you are. ## Core concepts - [Threat Events](https://liberty91.com/docs/core-concepts/threat-events): A Threat Event is the real-world occurrence that reports describe. Liberty91 merges every report about the same occurrence into one deduplicated record. - [Events](https://liberty91.com/docs/core-concepts/events): An Event is a single report: one news article, vendor report, advisory, or upload. Liberty91 enriches each one on arrival and matches it against your profile. - [Threat Entities](https://liberty91.com/docs/core-concepts/threat-entities): Threat Actors, malware, and vulnerabilities share one canonical record with aliases merged, then your own sources enrich your view of it. - [Organizations](https://liberty91.com/docs/core-concepts/organizations): An Organization is a company or business unit you protect. Each gets a dedicated agent that learns it from open sources and tailors every report. - [Documents](https://liberty91.com/docs/core-concepts/documents): Upload documentation about an Organization and the agent commits it to memory, using it to evaluate Events, write analyses, and extract Assets and Suppliers. - [Stakeholders](https://liberty91.com/docs/core-concepts/stakeholders): Stakeholders are the people who receive Intelligence Packages. Their role and interests tailor every alert, and they can subscribe to Morning Reports. - [Assets and Hosts](https://liberty91.com/docs/core-concepts/assets-and-hosts): Assets are the technologies your Organization hosts. They define your attack surface and crown jewels, and each gets its own maintained Asset Threat Profile. - [Supply Chain](https://liberty91.com/docs/core-concepts/supply-chain): Suppliers work like Assets but are not hosted by you. Each has a domain and a criticality, and gets its own maintained Third Party Threat Profile. - [Intelligence Requirements](https://liberty91.com/docs/core-concepts/intelligence-requirements): How Intelligence Requirements tell Liberty91 which threat topics matter to you, and self-learn from every event to ground your reports in relevant context. - [How the AI agents work](https://liberty91.com/docs/core-concepts/how-the-ai-agents-work): Liberty91 runs seven categories of agent on every event: integration, extraction, matching, tradecraft, self-learning knowledge, organization, and production. - [IOC enrichment and decay scoring](https://liberty91.com/docs/core-concepts/ioc-enrichment-and-decay-scoring): Every indicator carries two separate numbers: a score that decays with age, and a confidence that reflects how sure we are it is genuinely malicious. - [Intelligence Packages](https://liberty91.com/docs/core-concepts/intelligence-packages): An Intelligence Package is the deliverable: a report tailored to one Organization, with its artifacts, moving from generated through review to sent. - [The Mailroom](https://liberty91.com/docs/core-concepts/the-mailroom): The Mailroom is one page for everything you send: a dashboard, what has gone out, what is staged and waiting, and the templates that carry it. - [Leaked Credential Monitoring](https://liberty91.com/docs/core-concepts/leaked-credential-monitoring): How Liberty91 scans the dark web for credentials leaked in breaches and infostealer logs, ties each finding to your organizations, and classifies it by risk. ## Guides - [Work with the Organization page](https://liberty91.com/docs/guides/work-with-the-organization-page): A walkthrough of the two tabs on an Organization: the scoped dashboard with its quick filters, and the profile where you add, edit, and remove Assets, Suppliers, Stakeholders, and everything else. - [Search events with advanced queries](https://liberty91.com/docs/guides/search-events-with-advanced-queries): Use the advanced query builder on the Event Search page to combine groups of conditions with AND and OR logic, and find exactly the events you need. - [Save and reuse searches](https://liberty91.com/docs/guides/save-and-reuse-searches): Save a search from the Event Search page and find it under Searches in the sidebar, shared with your whole team, ready to run, refine, alert on, or pin to a dashboard. - [Generate a report from search results](https://liberty91.com/docs/guides/generate-a-report-from-search-results): Select up to 50 events from your search results and turn them into one tailored Intelligence Package, the same way you report on a single event. - [Create a report from an event](https://liberty91.com/docs/guides/create-a-report-from-an-event): Generate a tailored Intelligence Package from a single event: pick the organization, let the AI agents research it, then review, edit, and stage it for mailing. - [Report on a threat entity or requirement](https://liberty91.com/docs/guides/report-on-a-threat-entity-or-requirement): Build a report from a Threat Actor, Malware, Vulnerability, or Intelligence Requirement by selecting its linked events, tailored per organization. - [Send a report to a stakeholder](https://liberty91.com/docs/guides/send-a-report-to-a-stakeholder): Stage an Intelligence Package for mailing, choose your stakeholder recipients, and send it so the delivery becomes trackable in the Mailroom. - [Set up automatic alerting](https://liberty91.com/docs/guides/set-up-automatic-alerting): Create an alert rule in Liberty91: choose your criteria, set ALL or ANY match logic, pick destinations, and have matching events delivered automatically. - [Customise your Morning Reports](https://liberty91.com/docs/guides/customize-your-morning-reports): Set the time and timezone your Morning Reports go out, and choose per organization which artifacts they include: IOC lists, STIX bundles, and SIGMA rules. - [White-label your Liberty91 reports](https://liberty91.com/docs/guides/white-label-overview): Replace Liberty91 branding with your own across sender details, email templates, and report PDFs, and choose how each organization receives its reports. - [Set the email sender name and reply-to](https://liberty91.com/docs/guides/white-label-sender-and-reply-to): Change the sender name and reply-to address on the emails your Stakeholders receive, so reports go out under your own brand and replies reach the right inbox. - [Customise your email templates](https://liberty91.com/docs/guides/white-label-email-templates): Change the design of the Alert, Morning Report, and Intelligence Package emails in the Mailroom, using variables, images, and a live preview before you send. - [Customise your report branding](https://liberty91.com/docs/guides/white-label-report-branding): White-label the PDF reports Liberty91 sends: enable custom branding, then set the cover, body, back page, header and footer, typography, and logos. - [Configure leaked-credential alerts](https://liberty91.com/docs/guides/configure-leaked-credential-alerts): Set who hears about leaked credentials in Liberty91, per recipient, per domain, and per category, and learn what the alert email and CSV attachments contain. - [Configure ransomware domain alerts](https://liberty91.com/docs/guides/configure-ransomware-domain-alerts): Get told the moment a ransomware leak-site claim names a domain you care about: turn on domain-hit alerts, choose what they match, pick destinations, and read the alert correctly. ## Dashboards - [Home dashboard](https://liberty91.com/docs/dashboards/home-dashboard): The shape of the threat landscape over a timeframe you choose: counts against the previous period, top actors, malware, techniques, vulnerabilities, sources, sectors, and a source-country map. Every panel clicks through. - [Recent Threats dashboard](https://liberty91.com/docs/dashboards/recent-threats): The Recent Threats dashboard is your main entry point into Liberty91, showing the most recent Events chronologically across Open Source, Premium Feeds, and X. - [Team Dashboards](https://liberty91.com/docs/dashboards/team-dashboards): Build shared dashboards from your saved searches: up to six live tiles per dashboard, arranged how your team wants to watch the threat landscape. ## Modules & integrations - [How Modules work](https://liberty91.com/docs/modules/how-modules-work): Understand the three Module types in Liberty91: Collection modules pull data in, Analysis modules enrich it, and Production modules push intelligence out. - [CrowdStrike Intelligence module](https://liberty91.com/docs/modules/crowdstrike): Connect CrowdStrike Falcon Intelligence to import intelligence reports and Recon alerts, enrich IOCs, and pull threat-actor profiles into your Threat Library. - [FalconFeeds module](https://liberty91.com/docs/modules/falconfeeds): Import the FalconFeeds.io threat feed into your Liberty91 tenant, where every Event is enriched for relevance, IOCs, MITRE ATT&CK, Assets, and Suppliers. - [Group-IB module](https://liberty91.com/docs/modules/group-ib): Ingest Group-IB reports and events into Liberty91 by whitelisting our IP, generating a personal token, and entering your credentials in the Group-IB module. - [Google Threat Intelligence module](https://liberty91.com/docs/modules/google-threat-intelligence): Collect Google Threat Intelligence reports, enrich Threat Entity profiles and the IOCs in your Events, using your VirusTotal key and a paid GTI subscription. - [Cyber News and Reports module](https://liberty91.com/docs/modules/cyber-news-and-reports): Choose which vendor reports, security blogs, government advisories, and vulnerability databases you receive in Liberty91, all curated for quality over quantity. - [PDF Import module](https://liberty91.com/docs/modules/pdf-import): Import a PDF report into Liberty91 as an Event that is analysed and enriched for threats, Assets, MITRE ATT&CK techniques, and IOCs, just like any other Event. - [X (Twitter) module](https://liberty91.com/docs/modules/x-twitter): Follow security researchers on X for free in Liberty91, and their tweets populate the far-right column of your Recent Threats dashboard as they post. - [Ransomware.live module](https://liberty91.com/docs/modules/ransomware-live): Bring ransomware leak-site victim claims into your feed as Events: what the Ransomware.live module collects, how to turn it off, and why a claim is not a confirmed breach. - [HexioSec module](https://liberty91.com/docs/modules/hexiosec): Train your Liberty91 instance on your attack surface by importing a HexioSec JSON export, with a free managed loading service for current subscribers. - [FullHunt module](https://liberty91.com/docs/modules/fullhunt): Dynamically scan the external attack surface of your Organizations with FullHunt, keep an up-to-date threat profile, and flag zero-days against exposed Assets. - [MISP module](https://liberty91.com/docs/modules/misp): Connect multiple MISP instances to enrich IOCs against your events and send reports as STIX bundles, working as both an analysis and production module. - [AlienVault OTX module](https://liberty91.com/docs/modules/alienvault-otx): Enrich IOCs from every source for free with AlienVault OTX: paste an API key and Liberty91 checks each indicator for pulses, tags, and linked actors or malware. - [URLScan module](https://liberty91.com/docs/modules/urlscan): Enrich your URL and domain indicators with urlscan.io: paste an API key and Liberty91 checks recent scans for signs of malicious activity, then records a verdict and a score. - [GreyNoise module](https://liberty91.com/docs/modules/greynoise): Tell mass internet scanning apart from activity aimed at you: connect a GreyNoise API key and Liberty91 labels every IP indicator with its scan-noise classification. - [Shodan module](https://liberty91.com/docs/modules/shodan): See what an address is actually running: connect a Shodan API key and Liberty91 adds open ports, exposed services, and known CVEs to every IP and domain indicator. - [AbuseIPDB module](https://liberty91.com/docs/modules/abuseipdb): Add community abuse reporting to your IP indicators: connect an AbuseIPDB API key and Liberty91 records the abuse confidence and report count on every address it sees. - [Censys module](https://liberty91.com/docs/modules/censys): Connect a Censys API token to enrich your IP indicators with exposed services and certificate data, and see when a host is running known malware families. - [ReversingLabs module](https://liberty91.com/docs/modules/reversinglabs): Point Liberty91 at your ReversingLabs Spectra Analyze appliance and every file hash, URL, domain, and IP indicator picks up file reputation and malware classification. - [Miro module](https://liberty91.com/docs/modules/miro): Send Events from Liberty91 to a Miro board through Alerts or directly, after a one-time app setup in the Miro developer portal with the boards:write permission. - [Slack module](https://liberty91.com/docs/modules/slack): Send Events from Liberty91 into a Slack channel through Alerts or directly, using an incoming webhook URL, with a separate integration per channel. - [Webhooks module](https://liberty91.com/docs/modules/webhooks): Route intelligence out of Liberty91 into your SIEM, SOAR, or any HTTP endpoint, sending Events directly or streaming every Event that matches an Alert. ## Reference - [User roles and permissions](https://liberty91.com/docs/reference/user-roles-and-permissions): A full reference for the four Liberty91 user roles, Viewer, Analyst, Admin, and Owner, and what each can do across analysis, reporting, and administration. - [Source reliability, credibility, and confidence](https://liberty91.com/docs/reference/source-reliability-and-confidence): The three trust judgements Liberty91 makes: how reliable a source is, how credible a Threat Event is, and how confident we are in an indicator. What each means and how each is set. - [Glossary](https://liberty91.com/docs/reference/glossary): Plain-language definitions of the core Liberty91 platform terms, from Events and Threat Events to Threat Entities, Modules, IOCs, and the Admiralty scale. ## Solutions by role - [For Analysts](https://liberty91.com/solutions/analysts): How CTI analysts use Liberty91 to bring all collection into one platform, enrich automatically, set alerts on their top threats, produce tailored products for human, machine, and agentic readers, and reply to Requests for Intelligence in minutes instead of days. - [For MSSPs](https://liberty91.com/solutions/mssp): How MSSPs deliver white-label, per-customer threat intelligence as a margin play, with a dedicated AI stack per client and an auditable dispatch trail. - [For Security Leaders](https://liberty91.com/solutions/security-leaders): How CISOs get the output of a mature CTI function without building one, mapped to their assets and suppliers. - [Product overview](https://liberty91.com/product): How the Liberty91 platform fits together: Intelligence Requirements as the spine, Document Upload to learn what each organization owns, the agent stack that does the reading and analysis, and Mailroom for getting the result to whoever acts on it. - [Intelligence Requirements](https://liberty91.com/product/intelligence-requirements): The configurable spine of the platform. Priority Intelligence Requirements (PIRs) turned into self-maintaining agents that evaluate every new event in your context. - [Threat Intelligence Platform](https://liberty91.com/solutions/threat-intelligence-platform): An end-to-end threat intelligence platform that runs collection through delivery for you and tailors the output to each organization. - [Threat Intelligence as a Service](https://liberty91.com/solutions/threat-intelligence-as-a-service): The full intelligence lifecycle run for you, producing finished, tailored intelligence for each organization it covers. - [CTI Skills (open source)](https://liberty91.com/cti-skills): Free, MIT-licensed pack of 75 CTI skills for any Agent Skills-compatible AI coding agent, covering IOC investigation, threat actor profiling, detection writing, and Microsoft Sentinel threat hunting with table-adaptive KQL. - [AI Threat Hunting in Microsoft Sentinel](https://liberty91.com/cti-skills/lookup-sentinel): The /lookup-sentinel skill discovers which tables a Microsoft Sentinel workspace actually ingests, then runs read-only IOC exposure sweeps and ATT&CK TTP hunts with KQL generated only for tables that exist. - [Liberty91 API Integration](https://liberty91.com/cti-skills/lookup-liberty91): The /lookup-liberty91 skill is the pack's two-way, first-party bridge to the Liberty91 platform: deduplicated real-world Threat Events with Admiralty-graded sources, IOC checks against your own account, the canonical threat actor catalogue, and the write path for ingesting your own reports. ## Blog and insights - [A Practitioner's Guide to the Intelligence Lifecycle](https://liberty91.com/blog/cti-trenches-what-cti-actually-is): What cyber threat intelligence actually is, why teams confuse it with information management, and the six-phase lifecycle in practice. - [How to Build a Collection Plan in 5 Steps](https://liberty91.com/blog/cti-trenches-intelligence-sources): Building collection discipline so sources serve your Intelligence Requirements instead of sprawling. - [Analysis of Competing Hypotheses: A Step-by-Step Guide for CTI](https://liberty91.com/blog/cti-trenches-analyst-tradecraft): Applying the ACH structured analytic technique to counter confirmation bias in attribution and assessment. - [Cognitive Biases in CTI](https://liberty91.com/blog/cti-trenches-cognitive-biases): The biases that distort analysis and the tradecraft that mitigates them. - [Threat Actor Profiling for Defenders](https://liberty91.com/blog/cti-trenches-threat-actors-attribution): A pragmatic, TTP-focused framework for profiling actors when attribution is not the point. - [From Intelligence to Detection: Operationalising MITRE ATT&CK](https://liberty91.com/blog/cti-trenches-frameworks-in-practice): Closing the gap between referencing ATT&CK and turning it into detection engineering. - [How to Evaluate a TIP: A Practitioner's Checklist](https://liberty91.com/blog/cti-trenches-tools-and-platforms): Choosing a threat intelligence platform around your operating model, with a buyer, seller, and builder perspective. - [PIRs in Practice](https://liberty91.com/blog/cti-trenches-reporting-and-stakeholders): Using Priority Intelligence Requirements and audience-specific reporting to make intelligence impossible to ignore. - [What Is a Threat Intelligence Platform (TIP)?](https://liberty91.com/blog/what-is-a-threat-intelligence-platform-tip): A clear definition of a TIP and how it differs from a feed and from a service. - [The 80/20 Problem in Cyber Threat Intelligence](https://liberty91.com/blog/analyze-every-cyber-threat-instantly): Why analysts spend most of their time on collection and formatting rather than analysis, and why it is structural.