Findings Table: Threat Insights

Threat Insights enriches Bitsight Findings with real-world threat intelligence, helping customers understand which findings matter most in today’s threat landscape.

Before you start, please note that:

  • Threat Intelligence does not change scores or ratings
  • This feature is designed purely to support prioritization and decision-making
  • Threat Insights is probabilistic, based on observed attacker behavior, historical patterns, and public frameworks. Thus, associations represent likelihood and relevance, not certainty.

Threat Insights Features 

Introduced in Phase 1 launch

Bitsight now connects Findings Security Issues to MITRE TTPs to Threat Actor Groups (APTs and Ransomware Groups). This data is surfaced directly on the Findings Table [menu-findings-spm.png Findings ➔ Findings Table], enabling users to easily identify findings linked to active attack techniques and known threat groups without affecting their ratings.

Introduced in Phase 2 roll-out

Bitsight has expanded Threat Insights with a dedicated adversary-centric view and activity metrics, helping you understand not just what threats exist, but who is behind them and how active they are. New features include:

  • Threat Groups Overview Page listing all tracked APT and Ransomware groups and associated findings.
    • In SPM, this is available in SPM standard or above
  • Findings Table Enhancements, including a new filter to display findinsg by a specific Threat Group, a new Threat Activity column, and the ability to filter finding by activity level.
  • SPM Threat Groups Dashboard that highlights finding volumes by specific Threat Groups.
    • This is only available in SPM
  • Activity Comparison Metrics in Threat Insights Table, including:
    • Trend Analysis: How the current activity level compares to the group's historical average.
    • Peer Comparison: Comparing the group's activity against other APTs or Ransomware groups.
    • Overall Comparison: Comparing the activity against all tracked APT and Ransomware groups.

Where to Find Threat Intelligence

Threat Intelligence is available as a Filter on the Findings Table [menu-findings-spm.png Findings ➔ Findings Table].

  • Select the YES filter to show the risk vectors that have associated threat insights applied to them.
  • Click on a risk vector to learn more about the associated threat insight.
  • March 26, 2025: Added phase 2 feature updates.
  • January 28, 2026: Published.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.