Our Roadmap

See what's planned, what we're building, and what's already live — shaped directly by analyst feedback.

Planned

Bulk Import

Import existing entities, IOCs, and notes from spreadsheets or other CTI tools to migrate research in one step.

API Access

Programmatic access to captured intel, entities, and threat graphs for integration with internal tooling and SIEMs.

Advanced Search & Filtering

Filter and search across entities, evidence, and collections by tag, date, actor, technique, and more.

Audit Logs

Track changes to entities and collections across team workspaces for accountability and compliance.

In Progress

Export

Export entities along with their analyst notes, MITRE ATT&CK connections, and mapped TTPs for reporting, sharing, or archival outside the platform.

Export Format Options

Choose between structured formats (JSON, STIX-compatible) or readable formats (PDF, Markdown) when exporting entities and collections.

Automated Entity & Observable Extraction

Automatically extract entities and observables—such as IOCs, domains, email addresses, IP addresses, and file hashes—directly from highlighted text and connect them within your workspace.

Completed

Collaborative Workspaces

Share notes, entities, and comments in real-time with your team on the Enterprise plan.

Add Captured Intel to Collections

Organize highlighted evidence and captured intel directly into collections as you research, no extra steps.

Add Entities to Collections

Group threat actors, malware families, tools, and custom entities into collections alongside their supporting evidence.

Browser Extension Capture

Highlight text on any web page to instantly record excerpts with source URL, title, and timestamp preserved.

MITRE ATT&CK Mapping

Map findings, entities, and malware records directly to MITRE ATT&CK tactics, techniques, and adversary aliases.

Want to see another feature?

Tell us what tools or integrations you need most.