Our Roadmap
See what's planned, what we're building, and what's already live — shaped directly by analyst feedback.
Planned
Bulk Import
Import existing entities, IOCs, and notes from spreadsheets or other CTI tools to migrate research in one step.
API Access
Programmatic access to captured intel, entities, and threat graphs for integration with internal tooling and SIEMs.
Advanced Search & Filtering
Filter and search across entities, evidence, and collections by tag, date, actor, technique, and more.
Audit Logs
Track changes to entities and collections across team workspaces for accountability and compliance.
In Progress
Export
Export entities along with their analyst notes, MITRE ATT&CK connections, and mapped TTPs for reporting, sharing, or archival outside the platform.
Export Format Options
Choose between structured formats (JSON, STIX-compatible) or readable formats (PDF, Markdown) when exporting entities and collections.
Automated Entity & Observable Extraction
Automatically extract entities and observables—such as IOCs, domains, email addresses, IP addresses, and file hashes—directly from highlighted text and connect them within your workspace.
Completed
Collaborative Workspaces
Share notes, entities, and comments in real-time with your team on the Enterprise plan.
Add Captured Intel to Collections
Organize highlighted evidence and captured intel directly into collections as you research, no extra steps.
Add Entities to Collections
Group threat actors, malware families, tools, and custom entities into collections alongside their supporting evidence.
Browser Extension Capture
Highlight text on any web page to instantly record excerpts with source URL, title, and timestamp preserved.
MITRE ATT&CK Mapping
Map findings, entities, and malware records directly to MITRE ATT&CK tactics, techniques, and adversary aliases.
Want to see another feature?
Tell us what tools or integrations you need most.