Who is Harry?
Your Real-Time Junior Threat Intelligence Analyst AI-agent.
Subscribers to Liberty91 receive instant alerts from Harry every time a cyber event happens they should know about. Harry provides a summary detailing what’s happening, why it is relevant to them, and what they should probably do about it. And every morning, Harry sends them a curated, personalized summary of everything that’s been going on in the cyber threat landscape.
But who is this Harry, how does he know all these things, and how does he make it personal?
Liberty91 works through a stack of AI-agents, personified in Harry. Harry effectively acts as a Real-Time Junior Threat Intelligence Analyst, by synthesizing raw content material from hundreds of cybersecurity sources upon publication, and presenting anything relevant to our subscribers’ security teams. Harry provides strategic and tactical analysis, Indicators of Compromise, Detection Rules and more, and shares these as written reports, STIX-bundles, or through countless integrations with security toolings and productivity suites.
Real-Time Collection
Our users can ‘feed’ Harry with any cybersecurity source they have access to. Open Source content like Cybersecurity news & blogs, vendor reporting, vulnerability databases, ransomware Data Leak Sites and Darkweb monitoring are provided out-of-the-box. If they subscribe to premium vendor intelligence reporting from (for example) Google Threat Intelligence, CrowdStrike or Group-IB, those can be included in Harry’s collection efforts as well.
Harry reads everything in real-time. Meaning that as soon as something is published from any of the monitored sources, it will be analyzed.
Training
Harry must then decide what’s important to our subscribers, and what is not. Which means he needs to be trained. At Liberty91, we’ve made this as effortlessly as possible: our analysts have been in the cybersecurity industry for a long time, and we use that experience to ‘pre-train’ AI-agents based on sector and geography. Even without any additional training, this makes Harry pretty effective at providing relevant information and reports.
Subscribers can also integrate with their Attack Surface Management (ASM) solution of choice. This means that Harry will always have the most up-to-date information of what your attack surface looks like, and will be able to inform you of anything relevant. Are you exposing OpenSSH, and a new zero-day is discovered? Harry will be able to tell you about it as soon as it happens, why it is relevant to you, where your exposed assets are and what actions you need to take.
On top of that, Harry learns over time. Our subscribers use our platform to track new threats and threat actors, and assign a criticality to them. These actions help Harry understand what’s relevant to each organization, and what’s not.
Analysis
When Harry finds something that matches your collection requirements, he first checks it for relevance. Our subscribers want to monitor for multiple types of threats, but some things are more critical than others. If a new threat meets that threshold, it will generate an analysis, based on and customized to the subscribers’ threat profile. No more generic reporting that’s hard to action, but tailored, actionable insights in real-time.
Production
Harry’s analysis is available in multiple formats and languages. His reports contain executive summaries, a strategic and tactical analysis, plus Indicators of Compromise and Detection Rules. He can send tickets to JIRA, create events in MISP, or integrate with thousands of other tools through webhooks and our versatile API. Your (human) senior Threat Specialists receive ready-made reports - again: in real-time - to immediately share with stakeholders.
Security Teams can even choose to bypass this step and let Harry send reports directly to stakeholders. He will even tailor reporting and alerts to their role: a CISO will receive a strategic analysis of the event, while product owners might receive immediate notifications about a new critical vulnerability, complete with remediation steps.
Get access to Harry today
Harry helps our subscribers significantly scale and speed up their threat intelligence production, freeing your human analysts up for the complex and important stuff. Reach out today if you are interested in saving time and money, reducing dwell time, empowering your intelligence team and increasing your security.