Security Stack Logo
DeCYFIR logo

Threat Intelligence

DeCYFIR

Preemptive external threat management: attack surface discovery, vuln prioritization, digital risk.

DeCYFIR Overview

What it does

DeCYFIR is an External Threat Landscape Management (ETLM) platform that combines predictive, personalized, and contextualized threat intelligence with attack surface discovery and digital risk insights in a single platform. Rather than working from reactive indicators, DeCYFIR identifies threats at the reconnaissance and weaponization stages, before adversaries begin exploitation, giving security teams time to close gaps preemptively across their industry, geography, and technology stack.

How it works

The platform operates through a nine-pillar framework spanning attack surface discovery, vulnerability intelligence, brand and online exposure management, digital risk and identity protection, third-party risk, situational awareness, predictive threat intelligence, threat-adaptive awareness training, and sector-tailored deception intelligence. Discovery combines passive DNS analysis, SSL certificate parsing, and dark web monitoring to map exposed assets, while image recognition, natural language processing, and domain analysis surface impersonation across surface, deep, and dark web sources including hacker forums and closed communities. Intelligence connects threat actors, motives, campaigns, and methods, tracking indicators of intent and attack, delivered at strategic, management, and tactical levels.

Credentials and traction

CYFIRMA DeCYFIR is SOC 2 Type II and ISO 27001 certified and GDPR compliant. CYFIRMA was named a Visionary in the inaugural 2026 Gartner Magic Quadrant for Cyber Threat Intelligence. DeCYFIR serves enterprise customers and government agencies across multiple industries and geographies, with named users including Mitsubishi Motors, NEC, and Subaru.

Key Capabilities

mapped to solution categories
Cyberthreat Intelligence Technologies

Monitors and alerts on deep and dark web, domain abuse, brand impersonation, social media and geopolitical risk.

Profiles threat actors with associated TTPs and attribution context.

Provides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.

Produces finished intelligence reports at technical, operational and strategic levels.

Covers advanced DRP use cases including disinformation, deepfakes and sentiment analysis across social, messaging and open internet.

Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.

Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.

Offers analyst support such as requests for information, recurring analyst augmentation and takedown services.

Enriches intelligence with external telemetry such as passive DNS, sinkhole traffic and global sensor networks.

Discovers or ingests external attack surface and digital asset data to curate organization-specific risk.

Aggregates indicators from multiple sources into comprehensive, deduplicated coverage.

Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.

Digital Risk Protection (DRP)

Monitors newly registered domains using typosquatting, homograph, and combosquatting techniques against the organization's brand, surfacing phishing infrastructure before campaigns launch.

Submits abuse reports to registrars, hosting providers, and platform operators to remove confirmed phishing pages, fake profiles, and impersonating applications.

Identifies the organization's internal documents, source code, credentials, and PII on paste sites, code repositories, and dark web data markets.

Monitors geopolitical and physical risk signals relevant to the organization, its locations and its people.

Monitors external sources for leaked personal data, credential exposure, targeted phishing infrastructure, and social media impersonation targeting named executives.

Monitors social media and collaboration platforms for brand abuse, impersonation and organizational exposure.

Monitors dark web forums, marketplaces, and access broker listings for mentions of the organization, active threats, and sale of stolen access or data.

Detects disinformation, deepfakes and adverse sentiment campaigns targeting the organization.

Discovers fake websites, social media profiles, and mobile applications impersonating the organization, using domain similarity, visual fingerprinting, and content analysis.

Attack Surface Management (ASM)

Ranks discovered exposures by combining exploitability signals, asset business context, and active threat intelligence to produce an actionable remediation queue.

Identifies software stacks, versions, and components running on discovered assets through passive banner analysis and active probing, mapping CVE exposure without authenticated scanning.

Enumerates and monitors the attack surface of subsidiaries, acquired companies, and affiliated brands, common gap during M&A activity when new infrastructure is inherited without full visibility.

Continuously enumerates internet-exposed assets (domains, IPs, subdomains, certificates, cloud storage, APIs) using passive DNS, certificate transparency logs, and active probing, including assets outside the official inventory.

Identifies cloud resources, SaaS applications, and exposed services deployed by business units without IT or security team visibility or approval.

Tracks SSL/TLS certificate expirations, newly registered lookalike domains, and subdomain takeover opportunities (dangling DNS records pointing to deprovisioned cloud services).

Compliance

certifications
GDPRISO 27001ISO 27017ISO 27018ISO/IEC 42001SOC 2 Type II

Integrations

compatible tools
D3 SecurityMicrosoft SentinelPalo Alto NetworksServiceNowSplunkSwimlane

Implementation & support

Deployment model
SaaS
Support channels
24/7 SupportEmail Support

Info last updated on August 23, 2026

Buyers

See how DeCYFIR fits your stack

Add DeCYFIR to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.