INTEL6 / PREVENTIVE INTELLIGENCE

See their hand
before they play it.

Intel6 reveals what adversaries are doing and preparing against your organization, bringing their infrastructure, access and targeting into view.

Intel6
Acme workspace Preventive IntelligenceAC
PREPARATION OBSERVED

The target is your VPN.

Access and infrastructure converge on the same environment.

High confidence
ADVERSARYRansomware affiliatePreparation observed
ACCESS3 corporate credentialsVPN access referenced
Acme Corporationacme.com · YOUR ORGANIZATION
INFRASTRUCTURELookalike login domainlogin-acme-support[.]com
YOUR ASSETvpn.acme.comInternet-facing VPN
EVIDENCE TIMELINE
Yesterday · 18:42Access activity observed
Today · 06:15Infrastructure connected
Today · 07:30Customer relevance established
Acme Corporation
What are they preparing to do?See preparation against your organization before execution.
The status quo

Other vendor alerts often tell you what happened after the fact.

IOCs, vulnerabilities, dark-web mentions and campaign reports provide useful information. Much of it describes past activity or broad threats, leaving your team to infer whether it applies to your organization.

Intel6 looks for the preparation. Infrastructure taking shape, credentials appearing and access activity connected to you.

Desktop monitor showing a generic threat intelligence dashboard
IOC Feed

14 new IPs and domains added to the feed.

PREVENTIVE INTELLIGENCE

See what the adversary is doing before the attack reaches you.

Conventional feeds describe indicators and known campaigns. Intel6 adds visibility into the activity behind them through Unit6’s own intelligence collection, while adversary preparation is still taking shape.

ATTACKER-SIDE VISIBILITY

See inside adversary activity.

Unit6’s Watcher Intelligence Network observes activity inside adversary environments, bringing access, credentials and preparation into view.

INFRASTRUCTURE & TARGETING

Watch preparation take shape.

Honeypots, tripwires and global scanning reveal attacker infrastructure, tooling and reconnaissance. Intel6 connects those observations to the domains, technologies and infrastructure they concern.

ACCESS & CAMPAIGN ACTIVITY

See the activity behind the indicators.

A credential appearing in an adversary environment. Related infrastructure being staged. Campaign activity developing around your organization. Intel6 brings these observations together so your team can see what is being prepared.

HOW INTEL6 WORKS

From your organization to
credible adversary intelligence.

Define your scope. Intel6 looks outward, corroborates what it observes, and delivers intelligence with the evidence your team needs to investigate.

Define your organization.

Set your domains, identities, technologies, infrastructure and suppliers. This defines scope; it does not ingest telemetry from your security tools.

Identities
Technologies
Domains
Infrastructure
Suppliers
External Attack Surface

Look toward the adversary.

Observe targeting, infrastructure, credentials and access activity around your organization through Unit6’s collection systems.

UNIT6 COLLECTION SYSTEMS
WIDER SOURCE ECOSYSTEM

Adversary infrastructure

Open, deep & dark web

External intelligence

Select a collection system to explore

Corroborate the signal.

Correlate sources, enrich artifacts and assess confidence. Intel6 validates intelligence; Red6 tests exploitability.

EVIDENCE, CORROBORATED
Multi-source correlationRelated observations align
Artifact validationExamine the evidence
EnrichmentAdd technical context
Confidence assessmentWeigh corroborating evidence
Evidence establishes confidence

Intelligence your team can use.

Review observed activity, affected entities and supporting evidence. Deliver intelligence and alerts to your team’s tools.

PREPARATION OBSERVED

Activity connected to your environment.

WHY IT MATTERS

Relevant access and infrastructure converge on a technology you use.

KEY EVIDENCE
  • Credential activity connected to your organization
  • Related infrastructure and domains
  • Technology relevant to your environment
RECOMMENDED NEXT STEP

Review the affected identity and access before execution.

Clear, actionable intelligence

Illustrative intelligence outcome

Your scope. Adversary observations. Corroborated intelligence.

Sources and confidence vary by finding.

THE INTEL6 PLATFORM

One intelligence
layer.

Every angle of exposure.

Connected evidence. Decisions that matter to you.

From adversary activity to your identities, infrastructure, software, brands and suppliers, Intel6 brings the intelligence your team needs into one connected system.

One organization. Every intelligence discipline.
Intel6 · Intelligence workspace
Acme CorporationKNOW. PROVE. ACT.
Preparation observed

An access path is taking shape.

Three observations converge on your external VPN.

CONNECTED OBSERVATIONS
  1. Access · yesterday

    Corporate credential observed

    alex.morgan@acme.example

  2. Infrastructure · today

    Lookalike login infrastructure

    login-acme-support[.]example

  3. Targeting · today

    Your VPN appears in access activity

    vpn.acme.example

RECOMMENDED NEXT STEP

Review the exposed credential. Scope a Red6 test of the VPN access path.

Identity & security teams
Preparation observed. Access not yet tested.
3 source records
SOURCE CONTEXT · ILLUSTRATIVE RECORDS
Credential artifact · record 01

The artifact references the employee identity and the corporate VPN login destination. Credential usability has not been tested.

Infrastructure observation · record 02

The hostname and observed login presentation reference Acme. This establishes an impersonation relationship, not a compromised customer asset.

Adversary access observation · record 03

The access reference names the same VPN destination as the credential artifact. Intel6 connects the observations to Acme’s external asset.

See the attack being prepared.

See targeting, access, credentials, infrastructure and adversary activity taking shape around your organization before execution.

Illustrative product views.
One fictional organization throughout.

INTEL6 IN THE REAL WORLD

See what happens when you know first.

Real intelligence. Real organizations. Real action before impact.

MORE FIELD EVIDENCE

Different threats. Documented action.

Five more ways Unit6 intelligence surfaced what mattered.

  1. 01Two nation-state operations interrupted before significant impactUnit6 found active intrusion in a file-transfer environment before internal alerts.
  2. 02Access broker operation disrupted before direct compromiseA broker advertised access to mission-critical messaging; the organization secured potentially exposed accounts.
  3. 03Ransomware blocked before a payload was deployedA compromised SaaS provider gave the actor a trusted admin path into pharmaceutical systems.
  4. 04False positives fell 95% as malicious sites came down fasterVisual analysis and CDN honeytokens brought average takedown below four hours.
  5. 05Helpdesk access contained before reported lateral movementWatcher Network telemetry distinguished password guessing from a valid session.
View all case studies
INTEGRATIONS

Intelligence where your team already works.Intel6 connects directly to your security stack.

Push Unit6 intelligence, alerts and actions into the tools your team already uses, from SIEM and endpoint security to identity, ticketing and collaboration.

UNIT6 INTELLIGENCE NETWORK
Intel6INTELLIGENCE LAYER

Security operations

  • Microsoft Sentinel
  • Splunk
  • Cortex XDR
  • Elastic
  • CrowdStrike
  • SentinelOne
  • Microsoft Defender
  • Google SecOps

Identity & response

  • Microsoft Entra ID
  • Okta
  • FortiGate
  • Palo Alto Networks
  • Zscaler
  • Cisco
  • Cloudflare

Cloud & exposure

  • AWS
  • Google Cloud
  • Microsoft Intune
  • Tenable
  • Qualys
  • Wiz
  • Rapid7

Workflow

  • ServiceNow
  • Jira
  • GitHub
  • GitLab

Collaboration

  • Slack
  • Microsoft Teams
Illustrative intelligence deliveryUnit6 collects intelligence through its own intelligence network. Intel6 sends the resulting intelligence, alerts and actions outward to customer tools. Example deliveries: compromised identity to Microsoft Entra ID, Microsoft Sentinel and ServiceNow; malicious infrastructure to Microsoft Sentinel, Cortex XDR and Slack; priority vulnerability to Jira, ServiceNow and Microsoft Teams. These sequences are illustrative.
THE NEXT QUESTION

You know what they’re preparing.
Now prove whether it would work.

Intel6 brings adversary preparation into view. Red6 takes the next step: testing your authorized environment to determine which attack paths can be demonstrated. Your team sets the objective and scope.

THEIR SIDE / INTEL6

Preparation comes into view.

INTEL6 · ADVERSARY OBSERVATION Preparation observed
ACCESS & INFRASTRUCTURE

Corporate VPN access

Credentials observedRelated infrastructure stagedTargeting connected to your organization
Intel6 correlationIllustrative scenario
YOUR SIDE / RED6

Would it work against us?

Corporate VPN accessRED6
YOUR AUTHORIZED ENVIRONMENT

Can the observed access become a demonstrated attack path?

Validation begins with your objective and scope.

See what happens when intelligence meets validation.

Explore Red6

STOP GUESSING.

Start knowing.

See what attackers are preparing before they make their move.

Book a demo