
Threat Intelligence
DeCYFIR
Preemptive external threat management: attack surface discovery, vuln prioritization, digital risk.
DeCYFIR Overview
What it does
DeCYFIR is an External Threat Landscape Management (ETLM) platform that combines predictive, personalized, and contextualized threat intelligence with attack surface discovery and digital risk insights in a single platform. Rather than working from reactive indicators, DeCYFIR identifies threats at the reconnaissance and weaponization stages, before adversaries begin exploitation, giving security teams time to close gaps preemptively across their industry, geography, and technology stack.
How it works
The platform operates through a nine-pillar framework spanning attack surface discovery, vulnerability intelligence, brand and online exposure management, digital risk and identity protection, third-party risk, situational awareness, predictive threat intelligence, threat-adaptive awareness training, and sector-tailored deception intelligence. Discovery combines passive DNS analysis, SSL certificate parsing, and dark web monitoring to map exposed assets, while image recognition, natural language processing, and domain analysis surface impersonation across surface, deep, and dark web sources including hacker forums and closed communities. Intelligence connects threat actors, motives, campaigns, and methods, tracking indicators of intent and attack, delivered at strategic, management, and tactical levels.
Credentials and traction
CYFIRMA DeCYFIR is SOC 2 Type II and ISO 27001 certified and GDPR compliant. CYFIRMA was named a Visionary in the inaugural 2026 Gartner Magic Quadrant for Cyber Threat Intelligence. DeCYFIR serves enterprise customers and government agencies across multiple industries and geographies, with named users including Mitsubishi Motors, NEC, and Subaru.
Key Capabilities
mapped to solution categoriesMonitors and alerts on deep and dark web, domain abuse, brand impersonation, social media and geopolitical risk.
Profiles threat actors with associated TTPs and attribution context.
Provides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.
Produces finished intelligence reports at technical, operational and strategic levels.
Covers advanced DRP use cases including disinformation, deepfakes and sentiment analysis across social, messaging and open internet.
Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.
Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.
Offers analyst support such as requests for information, recurring analyst augmentation and takedown services.
Enriches intelligence with external telemetry such as passive DNS, sinkhole traffic and global sensor networks.
Discovers or ingests external attack surface and digital asset data to curate organization-specific risk.
Aggregates indicators from multiple sources into comprehensive, deduplicated coverage.
Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.
Monitors newly registered domains using typosquatting, homograph, and combosquatting techniques against the organization's brand, surfacing phishing infrastructure before campaigns launch.
Submits abuse reports to registrars, hosting providers, and platform operators to remove confirmed phishing pages, fake profiles, and impersonating applications.
Identifies the organization's internal documents, source code, credentials, and PII on paste sites, code repositories, and dark web data markets.
Monitors geopolitical and physical risk signals relevant to the organization, its locations and its people.
Monitors external sources for leaked personal data, credential exposure, targeted phishing infrastructure, and social media impersonation targeting named executives.
Monitors social media and collaboration platforms for brand abuse, impersonation and organizational exposure.
Monitors dark web forums, marketplaces, and access broker listings for mentions of the organization, active threats, and sale of stolen access or data.
Detects disinformation, deepfakes and adverse sentiment campaigns targeting the organization.
Discovers fake websites, social media profiles, and mobile applications impersonating the organization, using domain similarity, visual fingerprinting, and content analysis.
Ranks discovered exposures by combining exploitability signals, asset business context, and active threat intelligence to produce an actionable remediation queue.
Identifies software stacks, versions, and components running on discovered assets through passive banner analysis and active probing, mapping CVE exposure without authenticated scanning.
Enumerates and monitors the attack surface of subsidiaries, acquired companies, and affiliated brands, common gap during M&A activity when new infrastructure is inherited without full visibility.
Continuously enumerates internet-exposed assets (domains, IPs, subdomains, certificates, cloud storage, APIs) using passive DNS, certificate transparency logs, and active probing, including assets outside the official inventory.
Identifies cloud resources, SaaS applications, and exposed services deployed by business units without IT or security team visibility or approval.
Tracks SSL/TLS certificate expirations, newly registered lookalike domains, and subdomain takeover opportunities (dangling DNS records pointing to deprovisioned cloud services).
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on August 23, 2026
Buyers
See how DeCYFIR fits your stack
Add DeCYFIR to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.