Corvus
Evidence · Source Records · Forensic Audit Trail

Evidence

Every claim in this report traces back to one of 30 evidence records below. Each was captured passively during recon, hashed at capture for chain-of-custody, and graded per the Admiralty Scale (NATO STANAG 2511). Click any ev_xxx chip elsewhere in the report to jump straight to its source record.

30
Records
30
Sources
24
High Grade
6
Moderate
0
Low Grade
2026-06-16
Captured
30 of 30 shown
ev_001 B-2
Source Wikipedia — Cyber threat intelligence · Captured
Cyber threat intelligence (CTI) is a part of cybersecurity that focuses on collecting, analyzing, and sharing information about potential or existing cyber threats. It gives organizations the information needed to predict, prevent, and respond to cyberattacks, enabling them to understand attackers’ behavior, tactics, and the vulnerabilities they exploit.
SHA-256
ev_002 B-2
Source Wikipedia — Threat Intelligence Platform · Captured
Threat Intelligence Platform (TIP) is an emerging technology discipline that helps organizations aggregate, correlate, and analyze threat data from multiple sources in real time to support defensive actions. … Modern threat intelligence platforms typically extend across many use-cases to encompass dark web monitoring, leaked credential monitoring, social media, and brand protection in addition to IOCs.
SHA-256
ev_003 B-1
Source Wikipedia — Mandiant · Captured
Mandiant, Inc. is an American cybersecurity firm and a subsidiary of Google. … In December 2013, FireEye acquired Mandiant for $1 billion. FireEye later sold its product line, name, and employees to Symphony Technology Group for $1.2 billion in June 2021. In March 2022, Google announced it would acquire Mandiant for $5.4 billion. The firm was fully incorporated into the Google Cloud division in September 2022.
SHA-256
ev_004 B-1
Source Wikipedia — Recorded Future · Captured
Recorded Future, Inc. is an American cybersecurity company founded in 2009, with headquarters in Somerville, Massachusetts. The company was acquired by Mastercard in 2024.
SHA-256
ev_005 B-2
Source Wikipedia — Anomali · Captured
Anomali Inc. is an American cybersecurity company that develops and provides threat intelligence products. In 2023, the company moved into providing security analytics powered by artificial intelligence (AI).
SHA-256
ev_007 B-1
Source Wikipedia — CrowdStrike · Captured
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides endpoint security, threat intelligence, and cyberattack response services. The company was co-founded in 2011 by George Kurtz, Dmitri Alperovitch, and Gregg Marston.
SHA-256
ev_008 B-1
Source Wikipedia — Palo Alto Networks · Captured
Palo Alto Networks, Inc. is an American multinational cybersecurity company with headquarters in Santa Clara, California. … It is home to the Unit 42 threat research team and hosts the Ignite cybersecurity conference.
SHA-256
ev_009 A-1
Source GLEIF LEI record — Mandiant, Inc. · Captured
MANDIANT, INC. (LEI 549300E9D2UJUFLLY524), previous legal name 'FireEye, Inc.', Delaware US-DE, registered at RA000602, registration LAPSED.
SHA-256
ev_010 B-1
Source Wikipedia — Splunk · Captured
Splunk Inc. is a subsidiary of Cisco Systems that produces software for indexing, searching, and analyzing machine-generated data … With a focus on cyber security and observability, Splunk describes its on-premises software and SaaS products as SIEM, SOAR, and observability solutions.
SHA-256
ev_015 B-2
Source Securonix press release — Securonix Acquires ThreatQuotient · Captured
Securonix Acquires ThreatQuotient to Deliver Industry's Broadest and Deepest Threat Detection Investigation and Response. The integration of Securonix and ThreatQuotient promises to deliver up to a 70% reduction in Mean Time to Respond (MTTR).
SHA-256
ev_016 B-2
Source Filigran — OpenCTI: Open Source Threat Intelligence Platform · Captured
OpenCTI offers valuable capabilities for managing cyber threat intelligence, particularly across tactical, technical, and strategic intelligence layers. Filigran provides open-source cybersecurity solutions covering threat intelligence management, breach and attack simulation, and cyber risk management.
SHA-256
ev_017 B-2
Source Wikipedia — MISP Threat Sharing · Captured
MISP Threat Sharing (MISP), formerly known as Malware Information Sharing Platform is an open source threat intelligence platform. The project develops utilities and documentation for more effective threat intelligence, by sharing indicators of compromise.
SHA-256
ev_018 B-1
Source Microsoft Security Blog — Microsoft acquired RiskIQ to strengthen cybersecurity of digital transformation and hybrid work · Captured
Microsoft Defender Threat Intelligence will be discontinued and merged into Microsoft Defender for a powerful unified experience. Organizations can leverage RiskIQ threat intelligence to gain context on attackers.
SHA-256
ev_019 B-3
Source Anomali — Leadership / company page · Captured
Anomali products include ThreatStream Next-Gen and Anomali Agentic AI for threat intelligence management.
SHA-256
ev_020 B-3
Source EclecticIQ — About us · Captured
EclecticIQ is ISO-certified. Headquartered in Amsterdam, and have offices in the UK, US and Singapore … From our AI-embedded threat intelligence platform to our services portfolio.
SHA-256
ev_021 B-1
Source Wikipedia — Kaspersky Lab · Captured
Kaspersky Lab is a Russian multinational cybersecurity and anti-virus provider company headquartered in Moscow, Russia. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky and Alexey De-Monderik. … The Kaspersky Global Research and Analysis Team (GReAT) has led the discovery of sophisticated espionage platforms.
SHA-256
ev_022 A-1
Source GLEIF LEI record — ThreatConnect, Inc. · Captured
ThreatConnect, Inc. (LEI 25490037QYZS1T3TJR73), HQ 3865 Wilson Blvd #550, Arlington VA 22203 US; Delaware corporation 5626320; creation date 2014-11-13.
SHA-256
ev_023 B-3
Source Crunchbase — Flashpoint company profile · Captured
Flashpoint is headquartered in New York, New York. Acquired by Audax Private Equity (majority investment, 2021).
SHA-256
ev_024 C-3
Source Flashpoint — Flashpoint vs Intel 471 · Captured
Unlike Intel 471, which focuses mainly on deep and dark web sources, Flashpoint covers a much broader range of sources.
SHA-256
ev_026 B-2
Source Wikipedia — Trellix · Captured
Trellix is a privately held cybersecurity company founded in 2022. It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks.
SHA-256