Cyber threat intelligence
Scry
Seeing threats before they arrive. Scry is the Dr. Chaos defensive threat intelligence platform: it watches the public threat landscape, extracts the signal, and surfaces what is about to matter to defenders.
What it does
Collect
Ingests public threat reporting, vendor research, CISA KEV and intel feeds, with source provenance kept on everything.
Extract
Pulls out indicators, threat actors, malware, claims and relationships, and keeps the evidence text that supports each one.
Enrich and score
Adds infrastructure, CVE, ATT&CK and reputation context, then scores confidence and risk with a transparent breakdown.
Review and report
Routes uncertain or high-stakes items to analyst review, raises alerts, and produces daily and weekly reports.
Share
Exports JSON, CSV and STIX 2.1, and serves a read-only TAXII 2.1 feed that other tools can poll.
The model behind it: claims, relationships, context, confidence and provenance are the intelligence. Indicators are the evidence for those claims, not the product itself. Scry is built for defensive use only.