Last reviewed:
The same corpus, framed three ways. A SOC analyst triaging an alert, a detection engineer writing the rule that fires on it, and a threat hunter chasing the infrastructure behind it all need different entry points into the same intelligence — so each role gets its own page, its own default surfaces, and its own worked examples.
Most threat intelligence is sold to a buyer and delivered to nobody in particular. The feed lands in a ticket queue, the dossier lands in a quarterly report, and the person who actually has to do something with it spends the first twenty minutes working out which part applies to their job. Threadlinqs splits the difference: one dataset, three role-shaped front doors, each opening on the surfaces that role reaches for first.
The split is about sequence, not access. Every tier sees the same threats, the same 23,000+ detection rules, the same 63,000+ enriched indicators and the same 720+ actor dossiers. What changes per role is what loads first, which filters are pre-set, and which pivot the page hands you next.
Three roles, one shared dataset.
Alert triage against live tracked threats, daily debriefs, MITRE mapping, and indicator lookup for the queue you are working right now.
A rule library in SPL, KQL and Sigma, filtered by technique and threat, ready to copy into the SIEM you already run.
Indicator feeds, DNS and C2 infrastructure tracking, actor dossiers, and cross-actor correlation to turn a hunch into a hunt.
The roles are separate pages, not separate products, and the value shows up at the handoff. A SOC analyst who closes an alert as a true positive has just produced the exact context a detection engineer needs to harden the rule. A detection engineer who finds a technique with thin coverage has just handed a threat hunter a gap worth hunting. A hunter who identifies new infrastructure has just given the SOC a fresh indicator to watch. On most stacks those three exchanges cross three tools and lose their context at every boundary.
Because every surface reads from the same records, that loop stays inside one session. A threat carries its indicators, its ATT&CK mapping, its actor attribution where the evidence supports one, and its detection logic on the same page — so the pivot from alert to rule to infrastructure is a click rather than a re-query. That is the whole argument for treating role framing as a view over a shared corpus instead of three separate subscriptions. The LockBit actor dossier is that loop on one page: the campaigns attributed to the group, the ATT&CK techniques they run, the infrastructure they reuse, and the detection rules that fire on all three.
Start with whichever page matches the work in front of you. If you want the capability-first view instead, the platform overview walks the six surfaces directly, comparisons put Threadlinqs next to the incumbent vendors, and pricing has the tier breakdown.
Live threat feed, detection library, and MITRE coverage map — free on the Blue tier, whichever role you hold.
[ open_platform ] [ view_pricing ]