The loop
Four steps. No leftover PDF.
Attack Nemesis is a production system. Collection without a destination in the stack is a newsletter. This is how intelligence becomes a signed action.
The four surfaces behind each step
01
Gather
The right sources, plus the stack you already run.
Intake is partner reporting, commercial collections, ISAC shares, and the telemetry sitting in XDR, vulnerability scanners, and the SIEM. You do not get a firehose. You get the objects that match the environment you defend.
02
Bind
Indicators become an operational record.
Models extract actors, malware, TTPs, and indicators and link them to assets, CVEs, and alerts. An analyst reviews the binding before it is trusted. Shared infrastructure is scored. Stale objects expire. The graph is the memory of the program.
03
Judge
Mission-aligned scoring, with a name on it.
Every item carries victimology, confidence, freshness, TLP, and the reason it is in this picture rather than another. Role views keep CTI, detection, vuln, and IR on the same picture without making them read the same queue.
04
Move
If it cannot become a ticket, it is unfinished.
Trusted actions open a ticket, export an indicator, or escalate a CVE in the tools you already run. Models can draft the ticket. They cannot sign it. Owners, evidence, and expiry travel with the action.

On the floor
A two-person intel function can run this.
Most vendor diagrams assume a fusion center. The loop is designed for the team you actually have: intake handles the firehose, binding remembers, the workbench is the Friday picture, and action is the ticket — signed by the analyst who still has the context.
Open cases
18
4 need a signature
Intel objects / 24h
142
structured, not raw
SIEM hits bound
37
Sentinel + Splunk
Vulns with active actors
11
Tenable + Qualys
Open cases
LOTL against civilian identity plane
AN-4412 · SIEM · XDR
Critical12mHealth-system VPN listed by an access broker
AN-4408 · VM · ticket
High28mHelp-desk BEC, payments processor
AN-4401 · XDR · ITSM
High41mJump-host reconnaissance, energy cooperative
AN-4394 · OT sensors
Watch1h
Stack activity
CrowdStrike
12 endpoint hits on AN-4412 indicators
Microsoft Sentinel
4 correlated incidents, identity plane
Tenable
CVE on concentrator family used by AN-4408
ServiceNow
3 tickets drafted — 1 signed, 2 waiting
Actor-bound exposure
11 open · −4 this week
Questions
Common questions
- How does Attack Nemesis operationalize threat intelligence?
- In four steps: gather, bind, judge, and move. It is built for CTI and SOC teams tired of reports that never leave the PDF; each step ends closer to a signed action in the tools you run. Attack Nemesis treats collection without a destination in the stack as unfinished.
- What sources does Attack Nemesis gather?
- Partner reporting, commercial collections, ISAC shares, and the telemetry already sitting in your XDR, vulnerability scanners, and SIEM. Analysts get the objects that match the environment they defend, not a firehose to triage. Attack Nemesis gathers for your environment, not for volume.
- Who decides whether a model’s output is trusted?
- An analyst. Models extract actors, malware, TTPs, and indicators and link them to assets, CVEs, and alerts; an analyst reviews the binding before anyone acts on it. Shared infrastructure is scored and stale objects expire, so the graph stays clean. In Attack Nemesis, the graph is the memory of the program and an analyst is its editor.
- How does Attack Nemesis decide what reaches me?
- Every item carries victimology, confidence, freshness, TLP, and the reason it reaches you rather than someone else. CTI, detection, vulnerability, and IR share the picture without sharing one queue. Attack Nemesis scores against your mission, and every score has a name on it.
- When is a piece of intelligence "done" in Attack Nemesis?
- When it becomes a ticket, an indicator export, or a CVE escalation in a tool you already run. Models draft the ticket; the analyst with the context signs it, and owners, evidence, and expiry travel with the action. In Attack Nemesis, if it cannot become a ticket, it is unfinished.
- Can a two-person intel team run Attack Nemesis?
- Yes, that is the team it was designed around. Intake handles the firehose, binding remembers, the workbench is the Friday picture, and action is the ticket, so two analysts are not doing a fusion center’s job by hand. Attack Nemesis is designed for the team you actually have.
Next step
Walk the loop against your own stack.
A forty-minute briefing: your sources, your stack, and the tickets that should already exist.