Skip to main content

Threat Intelligence

ATIP

Avint Threat Intelligence Platform

Every CVE ever published, with the adversaries, malware and exploits attached.

ATIP is an enriched threat intelligence feed that consolidates all relevant context into a single view: who exploits a vulnerability, how they do it, and why. Available within AlloyGRC today, with subscription and API access coming soon.

370,000

CVEs, 1999 to today, one enriched record each

700+

threat actors linked to the vulnerabilities they use

110+

ransomware families tied to the CVEs they exploit

620+

ATT&CK techniques mapped on CVEs from 2020 onward, tactic first

Corpus figures as of September 2026, rounded to the nearest ten thousand. Refreshed daily.

What makes it different from every other feed

Most threat feeds stop at the CVE and its score. ATIP starts there and adds real time context: which threat actors exploit the vulnerability, what malware and ransomware campaigns use it, and which industries are targeted. Further, it shows you the likelihood of the CVE being exploited that month along with the MITRE ATT&CK Tactic and Techniques associated with it. One record per CVE, the same field set on every one, refreshed every day by the Avint pipeline. Even better, you can configure your sources too. You get the best of your vendor's intelligence and ours.

Other feeds tell you a CVE exists. This one tells you who is using it.

What you get

  • Every CVE NVD has published since 1999 (over 370,000) verified against NVD's own set year by year and refreshed daily

  • Nine dimensions of enrichment: actors, malware, ransomware, exploits and industries across the whole corpus; CWE, platform, EPSS and the ATT&CK mapping on every CVE from 2020 onward

  • Consistency flags on every enrichment field, so an inconsistent record is reported rather than trusted

  • Searchable and filterable by actor, ransomware family, platform, CWE or industry

Where the boundaries are

  • Vulnerability listings are universal, not limited to those present on your assets

  • ATIP does not discover new findings of its own. It only reflects new CVEs published elsewhere

  • The feed itself does not offer any ranking of its own; EPSS and CVSS scores are assigned by other reliable sources

  • Continuous monitoring attaches relevant context to your scan data, system by system

  • It enriches CVE listings with all available data; your scanners still do the discovering

  • It is one input to the AREA algorithm, which ranks your findings within your system context

How it works

How ATIP builds the record

The stages the Avint pipeline runs to turn public reporting into one enriched record per CVE.

STAGE 01

Data Ingestion

Dedicated script tasks collect intelligence from varied sources that are either subscription-based or open threat feeds.

Distinct threat intelligence collections per source

STAGE 02

Data Curation

Data from the various collections are aggregated into a single collection.

Aggregate collection with fixed schema.

STAGE 03

Data Update

All documents are re-assigned the most recent EPSS scores. Similarly, past documents with changes to their details are updated and flagged for re-mapping.

Updated collection with current data.

STAGE 04

MITRE TTP Mapping

Current information pertaining to CVEs are fed to an ML pipeline to produce Tactic and Technique mappings

Final search and export-friendly enriched dataset

One record

What a single CVE looks like once ATIP is done with it

Every CVE carries the same field set. Where nothing is known, the field says so rather than guessing. The record below is illustrative: the fields are real, the values are not.

CVE-2025-00000 ATIP RECORD
Description Improper input validation in a widely deployed remote management service allows unauthenticated code execution.
CVSS base 9.8
EPSS Score 0.94
EPSS Percentile 0.99
Exploits Public exploitexploitation framework module
Threat actors InceptionMana Team
Ransomware Blackcat
Malware Loaderbackdoor
Industries GovernmentHealthcareEnergy
CWE CWE-20
Platform Network appliance
ATT&CK tactics Initial AccessExecution
ATT&CK techniques T1190T1059

Illustrative record. Field set is real, values are invented.

Fields on every record

  • CVE and description

    The identifier and the published description

  • CVSS base score

    Severity as published, kept as one signal among several

  • EPSS score and percentile

    Exploit Prediction Scoring System: a public daily estimate of how likely the CVE is to be exploited in the next 30 days, with its percentile across all CVEs

  • Exploit names

    Known public exploits and framework modules

  • Threat actors

    Named groups observed using the vulnerability

  • Malware and ransomware

    Families known to carry or exploit it

  • Target industries

    Sectors reported as targets in campaigns using it

  • CWE and platform

    Weakness class and the platform it affects

  • ATT&CK tactics and techniques

    Adversary behavior the vulnerability enables, mapped to the tactic first and then to the techniques under it

Where the record goes

ATIP is the second stage. The last two happen in AlloyGRC over your own findings, which is where a global record becomes your exposure. Subscribers outside AlloyGRC take the feed at stage two.

01

Public sources

Vulnerability databases, exploit repositories, and threat actor and ransomware reporting, collected daily by the Avint pipeline.

Raw intelligence

Outside the app

02

ATIP corpus

One enriched record per CVE, deduplicated and normalized, with consistency flags for every enrichment field.

Enriched CVE record

ATIP

03

Your findings

Continuous monitoring joins each finding from your scanners to its ATIP record, system by system, scoped to what you own.

Findings with context

AlloyGRC

04

AREA ranking

AREA scores, tiers and schedules those findings, weighting exploitation evidence over raw severity.

Priority table

AlloyGRC

How teams use it

  • Look up a CVE and see the actors, malware and ransomware families associated with it

  • Filter by threat actor, ransomware family, platform, CWE or industry to see what they touch

  • Check the ATT&CK tactics and techniques on a CVE before writing a risk narrative

  • Use the exploit and actor context to argue for prioritizing something CVSS alone would rank lower

Planned: a standalone ATIP subscription with API access, for teams who want the feed without the platform. Not available today.

Straight answers

Is this scoped to just my systems?

No. ATIP is a global CVE reference corpus and is not filtered to your assets. Per system correlation happens where it is consumed, in continuous monitoring, which joins this enrichment against your own scan data.

Where does the data come from and how fresh is it?

Public vulnerability databases, exploit repositories and threat actor reporting, aggregated and normalized by the Avint threat intelligence pipeline. The corpus refreshes daily.

Has this been through AREA?

ATIP is enrichment. The AREA Risk Level you see on the Vulnerabilities page comes from AREA running over your own findings, with ATIP as one of its inputs.

Can we subscribe to ATIP on its own?

That is planned: a standalone subscription with API access. Today ATIP is delivered inside AlloyGRC.

Look up a CVE you already know.

Bring one to the demo and see what ATIP has on it that your current feed does not, then watch AREA decide where it lands in a ranked list.