Skip to main content
{ Threat Intelligence / Reporting and Compliance }

Mallory Threat Briefing

Delivers a briefing from Mallory on the stories, vulnerabilities, actors, and malware that matter to your stack and sector, with what changed since the last briefing and the action for each item.

What this agent does

This read-only agent writes a threat briefing from Mallory on a schedule. It reads the stories that match the workspace's followed entities, topics, and sources, the stories with assets matched to the team's inventory, and the vulnerabilities, threat actors, and malware trending over the window. It compares with the previous briefing and leads with what is new or changed. For each item it states why it matters to this organization and the action, such as a product to check in the inventory or a CVE to hand to the triage agents. It proposes entities the workspace should follow and does not yet.

The challenge

Threat intelligence arrives as a stream of articles, and the question each one raises is whether it applies here. Someone reads the feed every morning and forwards what looks relevant, and the forward says nothing about which of the team's systems it touches. The stories that matter most, the ones about a product the team runs, look the same as the rest until someone connects them.

The solution

The agent reads what the workspace follows and what matches the assets, and it writes each item with the connection to this organization stated. It separates stories about the team's products from stories about its sector from general trends. It keeps the briefing short by leaving out what did not change. Unlike a Mallory schedule, it compares with the previous briefing and hands CVEs to the triage agents. Provides a briefing a security lead reads in a few minutes, with the items that need action marked.

Workflow

  1. 01

    Read the workspace

    Read the workspace's followed entities, topics, sources, industries, and locations.

  2. 02

    Read matching stories

    Read stories matching the workspace since the last briefing, and stories with a matched asset count above zero.

  3. 03

    Read trends

    Read vulnerabilities, threat actors, and malware by the trending sort for the window, and stories by reference count.

  4. 04

    Compare and write

    Compare with the previous briefing, lead with what changed, and state the connection and the action for each item.

  5. 05

    Propose follows

    List entities that appeared in asset-matched stories and are not followed, for a person to add.

Agent template

# Mallory Threat Briefing

## Measurable outcomes

Every story with a matched asset in the window appears in the briefing with its connection and action. Every briefing names the stories that touch the organization's products, sector, and followed entities since the last one, with the action for each. Track the new items, the changed items, and the open action items on every run.

## Procedure

Run on the schedule I set, daily or weekly, for the Mallory workspace I set. Read the entities, topics, and sources the workspace follows, and its industries and locations. Read the stories that match the workspace since the last briefing, with each story's summary, key entities and their roles, timeline events, and references. Read the stories with a matched asset count above zero, and list each one's matched entities. Read vulnerabilities, threat actors, and malware by the 1-day trending sort for a daily briefing and the 7-day sort for a weekly one, and stories by reference count. Call an item trending when it ranks within a rank I set on that sort. Group the briefing in this order: stories about products or packages the organization runs, stories about the organization's sector and locations, stories about followed actors and malware, and general trends. For each item, state the connection to this organization in one sentence, such as the product and version in the inventory or the followed actor, and the action, such as hand the CVE to the triage agents, check the inventory for the product, or no action. Compare with the previous briefing and lead with what is new or changed, and leave out items that did not change. Never claim a story affects the organization without a matched asset or a followed entity behind the claim. List the products, actors, and malware that appeared in asset-matched stories and are not followed, and propose them as follows for a person to add. Never add follows itself. Link each item to its story and its references. In reports, replace internal hostnames with stable pseudonyms.

## Requirements

It needs a Mallory API key for a tenant member, not an owner, to read the workspace's stories, entities, and follows and the intelligence library, and nothing more. The asset-matched section needs an asset sync integration in the tenant. Without one, report that section as not checked. It never changes workspace follows, creates findings, or changes anything in Mallory.