01
Use recognised sources at the point of work
Search CAPEC attack patterns, CWE weaknesses, MITRE ATT&CK techniques, OWASP Top 10 and BSI threats together and retain a reference to the source.
Threat intelligence
KaitoSec brings recognised catalogues to the security and risk workflow, where entries connect to affected assets, existing controls and exercise context.
Where friction starts today
Everyone knows about MITRE ATT&CK, CWE, and the OWASP Top 10. The catalogues are open, thorough, and almost never touched after the kickoff workshop. They live in a browser tab while the risk register fills up with vague entries like 'malware' and 'human error', because copying a real attack pattern into a structured scenario by hand is tedious and nobody has the afternoon.
Threat data is only worth keeping current if it drives something. An ATT&CK technique should turn into a risk scenario with the assets it targets and the controls that blunt it. A Grundschutz Gefährdung should map to its safeguard without a manual lookup. When the catalogue feeds your risks, your continuity exercises, and your control selection directly, the intelligence does work instead of gathering dust.
One data model
Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.
This module
Threat Intelligence
Shared data model
One asset, one risk, one control, one piece of evidence
Entry to evidence
An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.
One change
A risk is re-assessed
Written with it
Where it surfaces
01
Search CAPEC attack patterns, CWE weaknesses, MITRE ATT&CK techniques, OWASP Top 10 and BSI threats together and retain a reference to the source.
02
Each threat entry connects to the assets it targets, the controls that mitigate it and the continuity scenarios it triggers. Threat intelligence becomes part of the same operating model used by your ISMS, BCMS and AIMS.
03
Use a catalogue entry as the starting point for a structured risk scenario. The risk owner adds affected assets, likelihood, impact and suitable treatment in the organisation's own context.
01
Search and filter across every built-in catalogue from one interface. Browse MITRE ATT&CK by tactic, find CWE weaknesses by software category, look up CAPEC patterns by asset type and push any entry into your risk register or BC exercise in one click.
02
Bring a threat entry into a risk or exercise scenario, then add the relevant assets and controls in your own context. Security and continuity work from the same referenced source.
03
Review BSI Grundschutz threats together with their related modules and safeguards. Links to other standards remain visible and can be professionally confirmed for your own scope.
KaitoSec adopts published versions of upstream sources as part of product updates and shows the source and version. An assessment therefore remains traceable to the catalogue state it used.
Yes. Workspace-specific threats can be created and linked to catalogue entries for reference. Custom threats appear alongside the built-in catalogues and can be used in risk scenarios, gap analyses and BC exercise design.
ATT&CK techniques are mapped to ISO 27001 controls and NIS2 security measures. When an ATT&CK-based scenario is added, KaitoSec suggests the controls most likely to mitigate the technique and flags continuity dependencies that may need rehearsal.
Yes. OWASP Top 10 is included as a built-in catalogue and can be linked to software assets and development processes. It is particularly useful for SOC 2 and ISO 27001 work and for AI system due diligence under ISO 42001.