The platform
Turn security evidence into institutional memory.
Felswerk captures what your organization learns, connects it across time, and transforms it into the context required for better security decisions.
One system, four stages
Every capability serves the same discipline.
Knowledge decay begins when organizational evidence is trapped in documents and disconnected systems. Felswerk is engineered against it — one system in which every stage makes the next possible: evidence is captured into structure, connected to everything already known, compounded into institutional memory, and turned into decisions your organization can defend.
Evidence becomes structure
Turn fragmented security evidence into durable structure.
Everything your organization pays to learn arrives as documents: pentest reports, scanner output, incident records, architecture reviews. Capture is where those documents stop being files and become structured knowledge.
- Report ingestionPentest, red-team, and assessment reports parsed into findings, techniques, and affected assets — not pages.
- Scanner importsBurp, Nessus, and Qualys output joined to the same knowledge structure as narrative reports.
- Incident recordsWhat happened, what was decided, and what it cost — preserved as part of the organizational record.
- Policies and architecture reviewsThe written intent of your program, captured alongside the evidence of its practice.
- Structured extractionAI-assisted extraction with a human-readable trail from every structured element back to its source document.
Observations become relationships
Relate every new observation to everything the organization already knows.
A finding in isolation is a data point. A finding connected to three years of history is understanding. Connect is where each new observation takes its place in the larger record.
- Cross-report correlationNew findings are matched against every prior engagement — the same weakness, seen again, is recognized as such.
- First-class entitiesAssets, identities, techniques, and controls are tracked across reports, not trapped inside them.
- Context enrichmentEvery finding is placed in the shared language of MITRE ATT&CK and enriched with known-exploited-vulnerability context.
- Recurring-weakness detectionRoot causes that keep producing findings are surfaced as patterns, not rediscovered as surprises.
- Source traceabilityEvery connection and conclusion links back to the evidence that produced it.
Knowledge accrues value
Make every engagement increase the value of those that came before it.
This is the stage the industry skips. Reports are consumed and filed; Felswerk keeps them working. By the tenth assessment, every conclusion is informed by the nine that came before it — and every new observation increases the value of the entire record.
- Institutional memoryA durable, queryable record of everything your organization has learned about its own security — ask it questions in plain language, with cited answers.
- Knowledge-decay detectionEvidence that is aging, unowned, or contradicted by newer observations is flagged before it silently expires.
- Historical trendsPosture, coverage, and remediation velocity measured across years, not quarters.
- Persistent entities and root causesChronically exposed assets and repeat-offender weaknesses tracked across every engagement that touched them.
- Maturity and remediation progressProgram maturity computed from what your organization actually does — not from a self-assessment survey.
Memory becomes action
Transform accumulated knowledge into defensible action.
Institutional memory earns its keep when a decision has to be made. Decide is where the record becomes ranked priorities, executive narratives, and an auditable trail of what was chosen and why.
- Ranked next actionsOne prioritized queue across every surface, ordered by risk reduction per unit of effort.
- Executive narrativesBoard briefings, budget memos, and program summaries composed from evidence — every claim linked to its source.
- Detection prioritiesWhat to detect first, based on what your engagements actually demonstrated, translated to your detection stack.
- Security roadmapsDependency-aware sequencing of the work your record says matters most.
- Incident and regulatory contextDuring an incident, the record identifies potentially applicable notification obligations and computes their deadlines. The resulting context is designed to inform counsel; Felswerk does not provide legal advice.
Built on the foundation
What teams run on top of the record.
Because the four stages produce one connected body of knowledge, entire workflows come with it — each one drawing on the same institutional memory.
Executive Intelligence
Board narratives, budget memos, maturity scoring, peer benchmarks, and insurance-gap analysis — leadership answers grounded in your own evidence.
Detection Engineering
Prioritized detection plans from observed techniques, rules translated to your stack, and validation tracking so coverage claims stay honest.
Incident Intelligence
A working surface per incident — timeline, evidence, obligations, and communications — that feeds the record instead of evaporating after the post-mortem.
Exposure Prioritization
Vulnerability lifecycle with known-exploited-vulnerability awareness, SLA clocks, and remediation ranked by what your history says recurs.
Engineered for institutions
Your knowledge. Your rules.
- Data ownershipYour evidence remains yours: encrypted at rest and in transit, never sold, never used to train AI models.
- Access controlsSSO and SAML, role-based access, and per-workspace isolation.
- AuditabilityA full audit trail and a signed decision journal — the record regulators and boards ask for.
- IntegrationsSlack, Teams, PagerDuty, Jira, Splunk, and Elastic; exports to PDF, CSV, JSON, STIX, and MITRE Navigator.
For the thorough
The complete inventory.
Everything above is the system. Below is the full parts list — every surface, feed, and workflow currently in the platform.
Explore all capabilities →
Command Center
CISO Command Center
One synthesis home for the whole program: unified posture score, ranked next actions across every surface, 30-day trend sparkline, per-module drill-downs, and a board-ready PDF summary.
Morning Brief
A daily, auto-generated stand-up: what changed overnight across incidents, KEV additions, detections, and deadlines.
Threat Digest
Periodic org-specific digest correlating your reports and exposure against fresh external intelligence.
On-Call Brief
Handoff-ready situational summary for the incoming on-call: open incidents, live obligations, and what to watch.
Incident Response & Regulatory
Incident Manager + Regulatory Engine
Declare an incident and Felswerk identifies potentially applicable notification obligations (GDPR, SEC 8-K, HIPAA, state AGs, and more) and computes each deadline. The resulting context is designed to inform counsel; Felswerk does not provide legal advice.
Regulatory Countdown
A live header countdown on every page showing the tightest regulatory clock as deadlines approach.
Live Incident War Room
A single working surface per incident: timeline, tasks, evidence, obligations, and comms in one place while the incident is hot.
Breach Comms Drafting
AI-drafted regulator and customer notifications from templates keyed to each regulation — reviewed, versioned, and delivery-tracked.
Post-Mortem Generator
Structured after-action reports composed from the incident record: timeline, root cause, action items, and lessons.
Decision Journal
Sign off risk decisions with owners, rationale, and expiry — the audit trail regulators and boards ask for.
Executive Intelligence
Budget Memo Composer
Turn a security ask into a finance-grade memo: loss modeling, risk-reduction assumptions, peer-spend comparison, and linked findings as evidence.
Meeting Prep Packs
Paste an agenda, get a briefing pack tuned to the audience — board, exec team, finance, audit committee, or regulator.
Security Program Maturity
Continuous maturity scoring across program dimensions, computed from what you actually do in the platform.
Security Roadmap Sequencer
Orders your backlog of security work by risk reduction per unit effort, with dependency-aware sequencing.
Peer Benchmark
How your posture, coverage, and velocity compare to anonymized peers in your industry and size cohort.
Cyber Insurance Gap Analyzer
Maps your evidenced posture against common policy warranties and exclusions — know your coverage gaps before renewal.
M&A Due Diligence
Rapid security due-diligence memos for acquisition targets, exportable as Markdown or PDF.
Policy Drift Detector
Paste (or upload) a security policy and Felswerk flags where written policy has drifted from observed practice in your data.
Analyst Skill-Gap Analysis
Identifies the technique and tooling areas where your team's demonstrated coverage is thinnest, with a training plan.
Detection Engineering
Detection Engineering Advisor
Paste findings or pick techniques and get a prioritized detection plan: what to detect first, which rules to deploy, and per-verdict evidence.
Alert Triage Intelligence
Point your SIEM at a signed webhook and Felswerk re-prioritizes alerts against your real exposure, with analyst-feedback learning.
Detection Stack Translation
Declare your stack (Splunk, Sentinel, Elastic, CrowdStrike, 30+ platforms) and every Sigma rule and detection recommendation is translated to your query language.
Detection Rule Validation
Scheduled validation tasks track which deployed rules have actually been tested — unvalidated detections feed the Defensive Debt score.
Collective Intelligence
Anonymized cross-tenant signal sharing: see which techniques and CVEs are trending across the Felswerk fleet. Privacy-first with easy opt-out.
Vulnerability Management
Vulnerability Manager
Full lifecycle tracking with SLA clocks, KEV-aware due dates (BOD 22-01), breach lists, MTTR, and per-vulnerability detail pages.
Scanner Imports
Ingest Burp XML, Nessus CSV, and Qualys XML directly — findings are indexed, scored, and joined to the same analytics as report uploads.
KEV Intelligence Suite
KEV burndown, remediation velocity, vendor concentration, ransomware exposure, detection heatmap, a next-KEV predictor, and per-CVE adversary emulation plans.
Newly-KEV'd Alerts
When CISA adds a CVE that appears in your reports, affected findings are flagged and the right people are notified automatically.
Intelligence
Threat Intelligence Feeds
Real-time CISA KEV plus additional sources. Automatic IOC enrichment and campaign attribution.
APT Playbook Library 290+ Groups
Match reports to known APT groups. Generate targeted campaigns from MITRE + GapMATRIX.
Advanced Threat Intel
Dark web monitoring, peer benchmarking, threat actor timelines, campaign correlation.
Ransomware Readiness
55 techniques, 11 kill chain phases, and real-world group profiles (LockBit, BlackCat, Cl0p, Akira).
RaaS Ecosystem Mapping
RaaS vs independent groups. Fastest encryptors, highest ransoms among matched groups.
GapMATRIX Integration
290+ actors, 300+ CVE mappings, weekly sync. 74+ ransomware groups.
Global Threat Heatmap
Technique frequency across all tracked actors. Full MITRE ATT&CK matrix by tactic.
CVE-Actor Correlations
Which actors exploit which CVEs — and vice versa. 300+ documented relationships.
Deep Intel — Novel Analytics
Technique Maturity Index (TMI)
Per-technique 0-100 readiness score across 6 dimensions: Detection, Compliance, Testing, Remediation, Intelligence, Assessment.
Compliance Blast Radius
Cross-framework regulatory impact — shows which controls are violated per technique with estimated penalties.
Defensive Debt Score
Compound risk metric from overdue tasks, unvalidated detections, recurring techniques, and compliance gaps.
Entity Persistence Map
Cross-report infrastructure graph revealing repeatedly targeted assets and chronic compromises.
Technique Dependency Graph
Causal DAG showing attack supply chains — which techniques enable which.
Attacker ROI Calculator
Adversary economic modeling — effort, cost, success probability, and potential payout per attack path.
Kill Chain Velocity Tracker
How quickly attackers progress through kill chain phases. Detects acceleration or deceleration across reports.
Threat Actor Convergence Warnings
Detects when multiple unrelated threat actors show simultaneous interest in the same techniques or CVEs.
Adversary Adaptation Predictor
Game-theoretic forecast of how adversaries will shift tactics based on your defensive improvements.
Industry Threat Weather Map
Anonymized peer data showing active, intensifying, or declining threats across your sector.
Finding Correlation Fingerprints
Root-cause clustering via CWE/OWASP similarity — group reports by underlying security problems.
Automated Threat Briefings
Personalized weekly intelligence digests with urgency signals and prioritized action items.
Shadow IT Discovery Engine
Unmanaged infrastructure detected by mining entity graphs from offensive reports.
Predictive Compliance Drift
Detects where emerging threats are concentrating in areas of weak compliance coverage.
NL Remediation Orchestrator
Natural language commands trigger multi-step remediation workflows with full audit logging.
Enrichment Data Sources
LOLDrivers Integration
Complete catalog of vulnerable and malicious kernel drivers with hashes, CVEs, and publisher metadata. Cross-referenced during report analysis.
DeTT&CT Visibility Mapping
Technique-to-data-source visibility map. Know exactly which telemetry covers which ATT&CK techniques.
Elastic Detection Rules
1,000+ open-source detection rules parsed with MITRE technique mappings, severity, and risk scores.
ATT&CK for ICS
Full ICS/OT threat matrix — brings industrial control system techniques into all existing analytics.
RE&CT Framework
45+ incident response actions mapped to ATT&CK techniques across 6 response stages.
MITRE ATLAS
40+ AI/ML adversarial techniques including prompt injection, model poisoning, and LLM jailbreaks.
VERIS-ATT&CK Mappings
Real-world incident classification patterns mapped to ATT&CK for compliance and benchmarking.
OSSEM Event Metadata
40+ security event sources across Windows, Linux, and Cloud with ATT&CK technique coverage.
OpenSSF Scorecard
Supply chain security scores for 20+ critical OSS packages. Tracks code review, maintenance, and vulnerabilities.
MITRE Engage
26+ adversary engagement activities for deception, denial, and disruption mapped to ATT&CK techniques.
Analysis & Operations
Report Analysis
Upload pentesting or red team reports. AI maps to MITRE ATT&CK, STRIDE, DREAD, CIS, NIST.
Purple Team Exercises
Track execution vs detection. Automated scoring and gap identification.
Adversary Emulation Plans
Generate from APT groups or import MITRE Navigator layers. Full technique enrichment.
Campaign Tracking
Group reports into campaigns. Compare over time, track remediation progress.
Blast Radius & Dwell Time
Lateral movement reach. Dwell time informed by published industry research.
Data Exfiltration Analysis
Map exfil pathways. Detect double/triple extortion risk patterns.
Ransomware Exercise Templates 8 Templates
Step-by-step purple team exercises with tool recommendations.
AI Studio
Ask the Corpus
Ask in plain English across everything you've uploaded. RAG-powered answers with inline citations and deep links back to the source.
Investigation Copilot
Guided investigation sessions: the copilot proposes hypotheses, pulls the relevant evidence from your corpus, and keeps a case log.
Peer Review Simulator
Adversarial AI review of your report drafts and findings — catches weak evidence, missing impact, and unclear reproduction steps before a client does.
Predictive Threat Modeling
Forecast attack patterns. Technique trends, APT targeting, risk trajectory, and what-if scenario simulation against specific APT groups.
AI Remediation Suggestions
Code snippets, config changes, detection rules for every finding.
What-If Simulator
Model control changes. See the posture impact instantly.
Reporting & Insights
CISO Dashboard
Executive KPIs, ransomware intelligence, financial exposure, regulatory impact.
Security Trends
Posture score, detection coverage, remediation velocity. Technique drift and co-occurrence.
Security Insights
Risk attribution, compliance mapping, CVE dedup, detection gaps, confidence calibration.
Financial Impact Analysis
Exposure estimates informed by published breach-cost research, with industry multipliers.
Regulatory Impact Mapping
8 frameworks: HIPAA, PCI-DSS, GDPR, SEC, FISMA, NERC CIP, NYDFS, CCPA.
Reports & Exports
PDF, Excel, CSV, JSON, STIX, MITRE Navigator, Attack Flow. Jira integration.
Critical Findings Alerts
Compound-evidence email alerts across 6 signal types. Only fires when 2+ signals converge.
Report Completion Emails
Automatic notification with posture summary and direct link when processing finishes.
Scheduled Reports
Daily, weekly, or monthly. Email delivery.
Custom Dashboards
Configurable widgets: posture score, coverage, techniques, heatmaps.
Integrations & Enterprise
Integrations
Slack, Teams, PagerDuty, GitHub, Splunk, Elasticsearch. Real-time alerts and SIEM export.
Technique Explorer
Full MITRE ATT&CK catalog. Which tracked actors use each technique.
Finding Libraries
Organization-wide reusable finding database. Templates and usage tracking.
Admin & Enterprise
SSO/SAML, custom frameworks, AI config, data retention, multi-region.
Audit Logs
Full audit trail. Filter, search, export for compliance.
API Usage & Rate Limits
Monitor request counts, endpoint utilization, rate limit consumption.
Start compounding what you learn.
Your organization's workspace is created automatically the first time you sign in. Setup takes about a minute.