SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Security Vision announces the release of a new version of the cybersecurity Threat Analysis and Cyber Intelligence (TIP) product

Security Vision announces the release of a new version of the cybersecurity Threat Analysis and Cyber Intelligence (TIP) product
17.11.2025

The Threat Intelligence Platform (TIP) product based on the Security Vision 5 platform meets the needs of each TI level. The solution helps to look for signs of attacks based on behavioral indicators and build an enterprise information security strategy in the long term, taking into account current threats and risks.


TIP provides the following functionality:


 · Receiving a stream of events from solutions of various classes (SIEM, NGFW, Proxy/e-mail server, data lakes, etc.), due to the large number of ready-made connectors, support for universal formats (Syslog, CEF, LEEF, EMBLEM, Event log), as well as a convenient constructor that allows you tocode to set up new integrations;

 · Automatic loading of all levels of indicators: technical (hash amounts, IP addresses, URLs, domains, e-mail, masks), tactical (registry keys, processes and JARM), operational (vulnerabilities, VPO, user data, etc.) and strategic;

 · Integration with dozens of different commercial and open-source feeds;

 · The ability to enrich both from external sources (VirusTotal, Shodan, LOLBAS, Kaspersky Parentip, IPGeolocation.io and others), and from embedded MITRE ATT&CK sources;

 · Integrated response and interaction with SPI, in particular, launching actions from an incident and an analytical graph of relationships, without the mandatory use of SOAR for automation;

 · Advanced indicator detection mechanics: phishing and DGA mechanisms using machine learning, match in the event stream, and retro-search through all collected data or specific IOCs.


In the new version of the product:


 · The deep cyber threat analytics engine second match has been significantly improved. It provides secondary verification of Compromise Indicators (IoC). The mechanism uses additional correlation with external systems (SIEM, VM, IDS) and internal data sources, which allows the formation of contextually enriched events, reducing the number of false positives, improving the quality of triage and increasing the effectiveness of incident response.

 · A package of feeds from Security Vision is integrated, with a daily update of about 50K IoC. It is available without a subscription and without a limit on the number of requests via the API or web interface (including in the customer's personal account). This package has key and operational feeds that allow you to immediately apply all TIP functionality out of the box. It also includes feeds from the Database of Information Security Threats of the FSTEC of Russia, NCCI, FinCERT, which take into account the specifics of attacks and threats for the Russian segment. By receiving Russian expertise in the form of feed data, you can use TIP to switch from a manual and reactive approach to a proactive one, when threats relevant to the Russian segment are automatically detected in your network as soon as possible.

 · Added support for more than a dozen new feed sources. New cyber intelligence data sources improve the elements of data analysis and exchange, improving the overall TIP user experience.

 · In order to make strategic decisions, the TIP product pays a lot of attention to working with newsletters. They help identify trends and plan an infrastructure protection strategy by providing operational information for analysts about new threats with descriptions of compromise indicators (malicious file hashes, suspicious IP addresses and domains, malicious URLs), tactics, techniques and procedures according to the MITRE methodology (i.e. how exactly an attacker acts and what he uses for his own purposes illegitimate actions), impact assessments, and recommendations for response. The product continues to develop the implementation of automatic integration and receipt of newsletters from individual suppliers and aggregators. ML models allow you to automatically process bulletins and link them to specific detection indicators with the ability to view them from the incident card or from the investigation graph.


The match analytical engine has been optimized to work on large data streams (from 100K EPS). The product also adds the possibility of an agent-based data collection scheme from individual high-load servers or collector servers, which also optimizes the processing of data flows.


рис 1.png


Recommended

How to react to cyber incidents: Roman Dushkov's article in BIS Journal
How to react to cyber incidents: Roman Dushkov's article in BIS Journal
Alina Drapeko, Antitrix: The Security Vision platform has proven itself to be a reliable and flexible core for building information security management systems
Alina Drapeko, Antitrix: The Security Vision platform has proven itself to be a reliable and flexible core for building information security management systems
What the court's decision to verify the authenticity of websites may lead to: Ruslan Rakhmetov's comments in Forbes
What the court's decision to verify the authenticity of websites may lead to: Ruslan Rakhmetov's comments in Forbes
Security Vision presented its experience on the international arena
Security Vision presented its experience on the international arena
Children and AI: Dmitry Semidotsky's comments in "CIPR-2025"
Children and AI: Dmitry Semidotsky's comments in "CIPR-2025"
Security Vision entered the top 4 leaders of the Russian UEBA market according to the popular IT portal IT-World
Security Vision entered the top 4 leaders of the Russian UEBA market according to the popular IT portal IT-World
Security Vision is among the leaders in the international SPARK Matrix™ rating
Security Vision is among the leaders in the international SPARK Matrix™ rating
Information security platform Security Vision entered the State System of Detection and Detection of Potential Effects of Computer Attacks (GosSOPKA) registry
Information security platform Security Vision entered the State System of Detection and Detection of Potential Effects of Computer Attacks (GosSOPKA) registry
Security Vision has accepted participation at Jet Security Conference 2025
Security Vision has accepted participation at Jet Security Conference 2025
Security Vision presented advanced solutions in the field of industrial cybersecurity at the Kaspersky Industrial Cybersecurity Conference 2025
Security Vision presented advanced solutions in the field of industrial cybersecurity at the Kaspersky Industrial Cybersecurity Conference 2025
Nikolay Goncharov on cybersecurity for SMEs expert opinion in Business Secrets
Nikolay Goncharov on cybersecurity for SMEs expert opinion in Business Secrets
How dangerous is it to connect to Wi-Fi in public places: comments by Viktor Goncharov in Komsomolskaya pravda
How dangerous is it to connect to Wi-Fi in public places: comments by Viktor Goncharov in Komsomolskaya pravda

Recommended

How to react to cyber incidents: Roman Dushkov's article in BIS Journal
How to react to cyber incidents: Roman Dushkov's article in BIS Journal
Alina Drapeko, Antitrix: The Security Vision platform has proven itself to be a reliable and flexible core for building information security management systems
Alina Drapeko, Antitrix: The Security Vision platform has proven itself to be a reliable and flexible core for building information security management systems
What the court's decision to verify the authenticity of websites may lead to: Ruslan Rakhmetov's comments in Forbes
What the court's decision to verify the authenticity of websites may lead to: Ruslan Rakhmetov's comments in Forbes
Security Vision presented its experience on the international arena
Security Vision presented its experience on the international arena
Children and AI: Dmitry Semidotsky's comments in "CIPR-2025"
Children and AI: Dmitry Semidotsky's comments in "CIPR-2025"
Security Vision entered the top 4 leaders of the Russian UEBA market according to the popular IT portal IT-World
Security Vision entered the top 4 leaders of the Russian UEBA market according to the popular IT portal IT-World
Security Vision is among the leaders in the international SPARK Matrix™ rating
Security Vision is among the leaders in the international SPARK Matrix™ rating
Information security platform Security Vision entered the State System of Detection and Detection of Potential Effects of Computer Attacks (GosSOPKA) registry
Information security platform Security Vision entered the State System of Detection and Detection of Potential Effects of Computer Attacks (GosSOPKA) registry
Security Vision has accepted participation at Jet Security Conference 2025
Security Vision has accepted participation at Jet Security Conference 2025
Security Vision presented advanced solutions in the field of industrial cybersecurity at the Kaspersky Industrial Cybersecurity Conference 2025
Security Vision presented advanced solutions in the field of industrial cybersecurity at the Kaspersky Industrial Cybersecurity Conference 2025
Nikolay Goncharov on cybersecurity for SMEs expert opinion in Business Secrets
Nikolay Goncharov on cybersecurity for SMEs expert opinion in Business Secrets
How dangerous is it to connect to Wi-Fi in public places: comments by Viktor Goncharov in Komsomolskaya pravda
How dangerous is it to connect to Wi-Fi in public places: comments by Viktor Goncharov in Komsomolskaya pravda

Other news

Security Vision has confirmed its status as a leader in SOAR solutions for the third year in a row
Security Vision has confirmed its status as a leader in SOAR solutions for the third year in a row
The Security Vision SOAR platform will strengthen CyberART Innostage's SOC as part of a technology alliance
The Security Vision SOAR platform will strengthen CyberART Innostage's SOC as part of a technology alliance
Pavel Lyubomsky to speak at CyberGen 2025
Pavel Lyubomsky to speak at CyberGen 2025
Security Vision has created a product for monitoring and protecting personal data
Security Vision has created a product for monitoring and protecting personal data
How to manage cyber risk in the supply chain and avoid supply chain attack: comments by Nikolay Goncharov in Cyber Media
How to manage cyber risk in the supply chain and avoid supply chain attack: comments by Nikolay Goncharov in Cyber Media
Security Vision is a partner of Softline Security Summit
Security Vision is a partner of Softline Security Summit
Security Vision became a partner of the forum "Cyber Resistant Arctic 2025"
Security Vision became a partner of the forum "Cyber Resistant Arctic 2025"
Security Vision introduced new platform features: updated interface, improved workflows and ways to provide data
Security Vision introduced new platform features: updated interface, improved workflows and ways to provide data
Security Vision presented its experience on the international arena
Security Vision presented its experience on the international arena

Other news

Security Vision has confirmed its status as a leader in SOAR solutions for the third year in a row
Security Vision has confirmed its status as a leader in SOAR solutions for the third year in a row
The Security Vision SOAR platform will strengthen CyberART Innostage's SOC as part of a technology alliance
The Security Vision SOAR platform will strengthen CyberART Innostage's SOC as part of a technology alliance
Pavel Lyubomsky to speak at CyberGen 2025
Pavel Lyubomsky to speak at CyberGen 2025
Security Vision has created a product for monitoring and protecting personal data
Security Vision has created a product for monitoring and protecting personal data
How to manage cyber risk in the supply chain and avoid supply chain attack: comments by Nikolay Goncharov in Cyber Media
How to manage cyber risk in the supply chain and avoid supply chain attack: comments by Nikolay Goncharov in Cyber Media
Security Vision is a partner of Softline Security Summit
Security Vision is a partner of Softline Security Summit
Security Vision became a partner of the forum "Cyber Resistant Arctic 2025"
Security Vision became a partner of the forum "Cyber Resistant Arctic 2025"
Security Vision introduced new platform features: updated interface, improved workflows and ways to provide data
Security Vision introduced new platform features: updated interface, improved workflows and ways to provide data
Security Vision presented its experience on the international arena
Security Vision presented its experience on the international arena