The loop

Four steps. No leftover PDF.

Attack Nemesis is a production system. Collection without a destination in the stack is a newsletter. This is how intelligence becomes a signed action.

The four surfaces behind each step

  1. 01

    Gather

    The right sources, plus the stack you already run.

    Intake is partner reporting, commercial collections, ISAC shares, and the telemetry sitting in XDR, vulnerability scanners, and the SIEM. You do not get a firehose. You get the objects that match the environment you defend.

  2. 02

    Bind

    Indicators become an operational record.

    Models extract actors, malware, TTPs, and indicators and link them to assets, CVEs, and alerts. An analyst reviews the binding before it is trusted. Shared infrastructure is scored. Stale objects expire. The graph is the memory of the program.

  3. 03

    Judge

    Mission-aligned scoring, with a name on it.

    Every item carries victimology, confidence, freshness, TLP, and the reason it is in this picture rather than another. Role views keep CTI, detection, vuln, and IR on the same picture without making them read the same queue.

  4. 04

    Move

    If it cannot become a ticket, it is unfinished.

    Trusted actions open a ticket, export an indicator, or escalate a CVE in the tools you already run. Models can draft the ticket. They cannot sign it. Owners, evidence, and expiry travel with the action.

Analyst desk

On the floor

A two-person intel function can run this.

Most vendor diagrams assume a fusion center. The loop is designed for the team you actually have: intake handles the firehose, binding remembers, the workbench is the Friday picture, and action is the ticket — signed by the analyst who still has the context.

Attack Nemesis · Mission picture

Open cases

18

4 need a signature

Intel objects / 24h

142

structured, not raw

SIEM hits bound

37

Sentinel + Splunk

Vulns with active actors

11

Tenable + Qualys

Open cases

  • LOTL against civilian identity plane

    AN-4412 · SIEM · XDR

    Critical12m
  • Health-system VPN listed by an access broker

    AN-4408 · VM · ticket

    High28m
  • Help-desk BEC, payments processor

    AN-4401 · XDR · ITSM

    High41m
  • Jump-host reconnaissance, energy cooperative

    AN-4394 · OT sensors

    Watch1h

Stack activity

  • CrowdStrike

    12 endpoint hits on AN-4412 indicators

  • Microsoft Sentinel

    4 correlated incidents, identity plane

  • Tenable

    CVE on concentrator family used by AN-4408

  • ServiceNow

    3 tickets drafted — 1 signed, 2 waiting

Actor-bound exposure

11 open · −4 this week

Rollup — cases, stack bindings, and remaining exposure with a named actor.

Questions

Common questions

How does Attack Nemesis operationalize threat intelligence?
In four steps: gather, bind, judge, and move. It is built for CTI and SOC teams tired of reports that never leave the PDF; each step ends closer to a signed action in the tools you run. Attack Nemesis treats collection without a destination in the stack as unfinished.
What sources does Attack Nemesis gather?
Partner reporting, commercial collections, ISAC shares, and the telemetry already sitting in your XDR, vulnerability scanners, and SIEM. Analysts get the objects that match the environment they defend, not a firehose to triage. Attack Nemesis gathers for your environment, not for volume.
Who decides whether a model’s output is trusted?
An analyst. Models extract actors, malware, TTPs, and indicators and link them to assets, CVEs, and alerts; an analyst reviews the binding before anyone acts on it. Shared infrastructure is scored and stale objects expire, so the graph stays clean. In Attack Nemesis, the graph is the memory of the program and an analyst is its editor.
How does Attack Nemesis decide what reaches me?
Every item carries victimology, confidence, freshness, TLP, and the reason it reaches you rather than someone else. CTI, detection, vulnerability, and IR share the picture without sharing one queue. Attack Nemesis scores against your mission, and every score has a name on it.
When is a piece of intelligence "done" in Attack Nemesis?
When it becomes a ticket, an indicator export, or a CVE escalation in a tool you already run. Models draft the ticket; the analyst with the context signs it, and owners, evidence, and expiry travel with the action. In Attack Nemesis, if it cannot become a ticket, it is unfinished.
Can a two-person intel team run Attack Nemesis?
Yes, that is the team it was designed around. Intake handles the firehose, binding remembers, the workbench is the Friday picture, and action is the ticket, so two analysts are not doing a fusion center’s job by hand. Attack Nemesis is designed for the team you actually have.

Next step

Walk the loop against your own stack.

A forty-minute briefing: your sources, your stack, and the tickets that should already exist.