Threat Intelligence
ATIPAvint Threat Intelligence Platform
Every CVE ever published, with the adversaries, malware and exploits attached.
ATIP is an enriched threat intelligence feed that consolidates all relevant context into a single view: who exploits a vulnerability, how they do it, and why. Available within AlloyGRC today, with subscription and API access coming soon.
370,000
CVEs, 1999 to today, one enriched record each
700+
threat actors linked to the vulnerabilities they use
110+
ransomware families tied to the CVEs they exploit
620+
ATT&CK techniques mapped on CVEs from 2020 onward, tactic first
Corpus figures as of September 2026, rounded to the nearest ten thousand. Refreshed daily.
What makes it different from every other feed
Most threat feeds stop at the CVE and its score. ATIP starts there and adds real time context: which threat actors exploit the vulnerability, what malware and ransomware campaigns use it, and which industries are targeted. Further, it shows you the likelihood of the CVE being exploited that month along with the MITRE ATT&CK Tactic and Techniques associated with it. One record per CVE, the same field set on every one, refreshed every day by the Avint pipeline. Even better, you can configure your sources too. You get the best of your vendor's intelligence and ours.
Other feeds tell you a CVE exists. This one tells you who is using it.
How it works
How ATIP builds the record
The stages the Avint pipeline runs to turn public reporting into one enriched record per CVE.
STAGE 01
Data Ingestion
Dedicated script tasks collect intelligence from varied sources that are either subscription-based or open threat feeds.
Distinct threat intelligence collections per source
STAGE 02
Data Curation
Data from the various collections are aggregated into a single collection.
Aggregate collection with fixed schema.
STAGE 03
Data Update
All documents are re-assigned the most recent EPSS scores. Similarly, past documents with changes to their details are updated and flagged for re-mapping.
Updated collection with current data.
STAGE 04
MITRE TTP Mapping
Current information pertaining to CVEs are fed to an ML pipeline to produce Tactic and Technique mappings
Final search and export-friendly enriched dataset
One record
What a single CVE looks like once ATIP is done with it
Every CVE carries the same field set. Where nothing is known, the field says so rather than guessing. The record below is illustrative: the fields are real, the values are not.
Illustrative record. Field set is real, values are invented.
Fields on every record
-
CVE and description
The identifier and the published description
-
CVSS base score
Severity as published, kept as one signal among several
-
EPSS score and percentile
Exploit Prediction Scoring System: a public daily estimate of how likely the CVE is to be exploited in the next 30 days, with its percentile across all CVEs
-
Exploit names
Known public exploits and framework modules
-
Threat actors
Named groups observed using the vulnerability
-
Malware and ransomware
Families known to carry or exploit it
-
Target industries
Sectors reported as targets in campaigns using it
-
CWE and platform
Weakness class and the platform it affects
-
ATT&CK tactics and techniques
Adversary behavior the vulnerability enables, mapped to the tactic first and then to the techniques under it
Where the record goes
ATIP is the second stage. The last two happen in AlloyGRC over your own findings, which is where a global record becomes your exposure. Subscribers outside AlloyGRC take the feed at stage two.
01
Public sources
Vulnerability databases, exploit repositories, and threat actor and ransomware reporting, collected daily by the Avint pipeline.
Raw intelligence
Outside the app02
ATIP corpus
One enriched record per CVE, deduplicated and normalized, with consistency flags for every enrichment field.
Enriched CVE record
ATIP03
Your findings
Continuous monitoring joins each finding from your scanners to its ATIP record, system by system, scoped to what you own.
Findings with context
AlloyGRC04
AREA ranking
AREA scores, tiers and schedules those findings, weighting exploitation evidence over raw severity.
Priority table
AlloyGRCHow teams use it
-
Look up a CVE and see the actors, malware and ransomware families associated with it
-
Filter by threat actor, ransomware family, platform, CWE or industry to see what they touch
-
Check the ATT&CK tactics and techniques on a CVE before writing a risk narrative
-
Use the exploit and actor context to argue for prioritizing something CVSS alone would rank lower
Planned: a standalone ATIP subscription with API access, for teams who want the feed without the platform. Not available today.
Straight answers
Look up a CVE you already know.
Bring one to the demo and see what ATIP has on it that your current feed does not, then watch AREA decide where it lands in a ranked list.