Mallory Threat Briefing
Delivers a briefing from Mallory on the stories, vulnerabilities, actors, and malware that matter to your stack and sector, with what changed since the last briefing and the action for each item.
What this agent does
This read-only agent writes a threat briefing from Mallory on a schedule. It reads the stories that match the workspace's followed entities, topics, and sources, the stories with assets matched to the team's inventory, and the vulnerabilities, threat actors, and malware trending over the window. It compares with the previous briefing and leads with what is new or changed. For each item it states why it matters to this organization and the action, such as a product to check in the inventory or a CVE to hand to the triage agents. It proposes entities the workspace should follow and does not yet.
The challenge
Threat intelligence arrives as a stream of articles, and the question each one raises is whether it applies here. Someone reads the feed every morning and forwards what looks relevant, and the forward says nothing about which of the team's systems it touches. The stories that matter most, the ones about a product the team runs, look the same as the rest until someone connects them.
The solution
The agent reads what the workspace follows and what matches the assets, and it writes each item with the connection to this organization stated. It separates stories about the team's products from stories about its sector from general trends. It keeps the briefing short by leaving out what did not change. Unlike a Mallory schedule, it compares with the previous briefing and hands CVEs to the triage agents. Provides a briefing a security lead reads in a few minutes, with the items that need action marked.
Workflow
- 01
Read the workspace
Read the workspace's followed entities, topics, sources, industries, and locations.
- 02
Read matching stories
Read stories matching the workspace since the last briefing, and stories with a matched asset count above zero.
- 03
Read trends
Read vulnerabilities, threat actors, and malware by the trending sort for the window, and stories by reference count.
- 04
Compare and write
Compare with the previous briefing, lead with what changed, and state the connection and the action for each item.
- 05
Propose follows
List entities that appeared in asset-matched stories and are not followed, for a person to add.
Agent template
# Mallory Threat Briefing
## Measurable outcomes
Every story with a matched asset in the window appears in the briefing with its connection and action. Every briefing names the stories that touch the organization's products, sector, and followed entities since the last one, with the action for each. Track the new items, the changed items, and the open action items on every run.
## Procedure
Run on the schedule I set, daily or weekly, for the Mallory workspace I set. Read the entities, topics, and sources the workspace follows, and its industries and locations. Read the stories that match the workspace since the last briefing, with each story's summary, key entities and their roles, timeline events, and references. Read the stories with a matched asset count above zero, and list each one's matched entities. Read vulnerabilities, threat actors, and malware by the 1-day trending sort for a daily briefing and the 7-day sort for a weekly one, and stories by reference count. Call an item trending when it ranks within a rank I set on that sort. Group the briefing in this order: stories about products or packages the organization runs, stories about the organization's sector and locations, stories about followed actors and malware, and general trends. For each item, state the connection to this organization in one sentence, such as the product and version in the inventory or the followed actor, and the action, such as hand the CVE to the triage agents, check the inventory for the product, or no action. Compare with the previous briefing and lead with what is new or changed, and leave out items that did not change. Never claim a story affects the organization without a matched asset or a followed entity behind the claim. List the products, actors, and malware that appeared in asset-matched stories and are not followed, and propose them as follows for a person to add. Never add follows itself. Link each item to its story and its references. In reports, replace internal hostnames with stable pseudonyms.
## Requirements
It needs a Mallory API key for a tenant member, not an owner, to read the workspace's stories, entities, and follows and the intelligence library, and nothing more. The asset-matched section needs an asset sync integration in the tenant. Without one, report that section as not checked. It never changes workspace follows, creates findings, or changes anything in Mallory. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools