Threat Insights enriches Bitsight Findings with real-world threat intelligence, helping customers understand which findings matter most in today’s threat landscape.
Before you start, please note that:
- Threat Intelligence does not change scores or ratings
- This feature is designed purely to support prioritization and decision-making
- Threat Insights is probabilistic, based on observed attacker behavior, historical patterns, and public frameworks. Thus, associations represent likelihood and relevance, not certainty.
Threat Insights Features
Introduced in Phase 1 launch
Bitsight now connects Findings Security Issues to MITRE TTPs to Threat Actor Groups (APTs and Ransomware Groups). This data is surfaced directly on the Findings Table [ Findings ➔ Findings Table], enabling users to easily identify findings linked to active attack techniques and known threat groups without affecting their ratings.
Introduced in Phase 2 roll-out
Bitsight has expanded Threat Insights with a dedicated adversary-centric view and activity metrics, helping you understand not just what threats exist, but who is behind them and how active they are. New features include:
-
Threat Groups Overview Page listing all tracked APT and Ransomware groups and associated findings.
- In SPM, this is available in SPM standard or above
- Findings Table Enhancements, including a new filter to display findinsg by a specific Threat Group, a new Threat Activity column, and the ability to filter finding by activity level.
-
SPM Threat Groups Dashboard that highlights finding volumes by specific Threat Groups.
- This is only available in SPM
-
Activity Comparison Metrics in Threat Insights Table, including:
- Trend Analysis: How the current activity level compares to the group's historical average.
- Peer Comparison: Comparing the group's activity against other APTs or Ransomware groups.
- Overall Comparison: Comparing the activity against all tracked APT and Ransomware groups.
Where to Find Threat Intelligence
Threat Intelligence is available as a Filter on the Findings Table [ Findings ➔ Findings Table].
- Select the YES filter to show the risk vectors that have associated threat insights applied to them.
- Click on a risk vector to learn more about the associated threat insight.
- March 26, 2025: Added phase 2 feature updates.
- January 28, 2026: Published.
Comments
Please sign in to leave a comment.