Skip to content
FortaRisks
The whole platform

Forta Radar

Threat intelligence (CTI)

See what targets you, not the noise

50M+ IOCs and 100+ sources, correlated every day and filtered to what targets your country, sector and stack. Pull IOCs and YARA rules to block threats proactively, before they reach you.

Forta Radar

100+

Intelligence sources

2,000+

Threat actors tracked

50M+

IOCs correlated daily

80% of alerts are duplicates. None are contextualized.

Raw feeds flood your team with noise that is never tied to your stack or your real exposure.

Value you can see

Outcomes your team will feel.

  • 2,000 alerts, 5 to 10 actions

    Your team works the few alerts that matter.

  • 20-minute triage

    What took hours now takes minutes.

  • 0 extra feeds to buy

    100+ sources included, nothing to license.

Key capabilities

  • 50M+ IOCs, correlated every day

    IOCs, CVEs, actors, campaigns and domains from 100+ sources, deduplicated and correlated daily, including 1,200 MITRE ATT&CK patterns and 397K enriched CVEs.

  • Threats targeting you, not the world

    Victimology filtered by your country, sector, organization and tech stack: see exactly who is being hit like you, before you are next.

  • Emerging threat tracking

    New TTPs, active campaigns and CISA KEV the moment they appear, mapped to the technologies you actually run.

  • Threat actor patterns

    Understand how each actor operates: their TTPs (MITRE ATT&CK), tooling, target profile and recent victims.

  • Block proactively: IOCs and YARA

    Pull correlated IOCs and ready-to-use YARA rules straight into your firewall, EDR and SIEM to block threats before they reach you.

  • Breach and dark web intel

    Spot organizations, and your own vendors, hit by data breaches, with leaked credentials surfaced before they are used against you.

Intelligence that becomes protection, not a feed you read.

Every relevant threat becomes a prioritized action: block these IOCs, deploy this YARA rule, patch this exposed CVE. The Action Center turns intelligence into proactive protection, automatically.

Three examples, three situations

  • Example · Manufacturer

    A campaign targets the controllers used in your sector

    On a Monday morning, Forta Radar flags a ransomware campaign aimed at parts manufacturers like you. It shows which of your exposed equipment matches the attack method. Your IT lead knows what to check before the end of the day, without reading ten bulletins.

  • Example · Multi-site company

    One critical flaw, eighteen sites, a single answer

    An already exploited vulnerability is announced on a firewall you run at several sites. Forta Radar ties it to the sites concerned and moves it to the top of the list. The rest of the week's alerts can wait.

  • Example · Prime contractor

    One of your suppliers shows up in a leak

    Credentials tied to a critical supplier's domain are circulating. Forta Radar flags it, Forta Suppliers opens the verification request. You call your supplier with facts, before the incident reaches you.

What's included

Intelligence sources

  • MITRE ATT&CK Enterprise, Mobile and ICS
  • ATT&CK matrix adapted to your context
  • NVD
  • CISA KEV and Vulnrichment
  • EPSS
  • CERT-FR and CERT-EU
  • CCCS Canada
  • AlienVault OTX
  • MISP
  • ThreatFox, URLhaus, MalwareBazaar
  • Ransomware.live
  • Official breach registries: CNIL, ICO, OAIC, US attorneys general, SEC EDGAR, CanadaBreaches
  • and around forty more

Correlation & alerts

  • Leaked credentials correlated with exposed surface
  • Ransomware victimology, families and YARA rules
  • Watchlists on your technologies, CVEs, actors and domains
  • System watchlist “threat to my organization”
  • CTI inbox and email digest
  • CVSS + EPSS + KEV + SSVC prioritization
  • EPSS trend per vulnerability
  • Ransomware usage flagged on the vulnerability

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In CTI, AI targets reading: summarizing a campaign, explaining in plain language why a vulnerability concerns you, querying the threat graph in natural language. Sources, scores and correlations stay computed by the engine, verifiable one by one.

Sovereignty: the platform is built and hosted in Canada, by a Canadian company. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

Forta Radar is not a silo. All modules feed on it.

CTI has little value if it stays in its tool. That's what differentiates a platform from a feed. FortaRisks pushes CTI signals into the other modules, continuously, so that every decision is informed by the day's actual threat.

  • Forta Radar → Forta Compliance

    Expected controls per framework are enriched by the TTPs of actors targeting your sector. You see which controls have immediate defensive value vs theoretical ones.

  • Forta Radar → Forta Exposure

    Each EASM finding is automatically correlated to active CVEs for detected services (exposed versions). An Apache HTTP 2.4.49 exposed becomes immediately a critical finding if a KEV CVE applies.

  • Forta Radar → Forta Suppliers

    CTI signals are filtered by each third party's industry sector. If Lockbit targets healthcare and one of your healthcare suppliers has an exposed CVE, you see it before the attack.

  • Forta Radar → Forta Cockpit

    CTI provides the "sector targeting" and "exploitation probability" components of the risk score. Without CTI, the AI would treat an unexploited CVSS 9.8 like a CVSS 6.5 in CISA KEV.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.

Frequently asked questions

Do I need to buy extra threat feeds?

No. 100+ public and commercial sources are aggregated, deduplicated and enriched inside your plan. There is no separate feed to license.

How is intelligence tied to my environment?

Each indicator is correlated to your assets, your exposure and your sector. A CVE only rises in priority when it actually reaches something you expose.

How fresh is the intelligence?

Sources are ingested continuously, with enrichment within minutes of a new advisory. Critical items like CISA KEV trigger an immediate update.

Can I query it in plain language?

Yes. You can ask questions in natural language across millions of CTI records and get an answer tied to your environment.