Coality by Terrabit Coality by Terrabit
New service
Terrabit Networks
Terrabit Networks · Managed service for Coality clients

Contextual Data Builder

Threat intelligence knows what is dangerous in the world. It does not know your organisation. We build a dataset of what is critical, sanctioned and normal inside your business, so Coality can judge every alert the way your most experienced analyst would.

Raw alerts from your SIEM and EDR Explained by your context, closed with evidence Confirmed and escalated
Fewer false positivesAlerts that your own policies, people and patterns already explain are closed with evidence, instead of waking an analyst.
Sharper verdictsLow-severity alerts that touch something critical, or something never seen before, are raised instead of ignored.
A head start for threat huntingBuilding the dataset exposes gaps and weak points that hunters can go after first.
The problem

The same alert means different things in different organisations

An internal host scanning hundreds of machines could be an attacker mapping the network. It could also be the vulnerability scanner IT runs every Tuesday. Generic intelligence cannot tell the two apart. Your context can.

Coality with threat intelligence only
src=10.20.4.17 · smb_session × 340 hosts · user=svc-vulnscan · 02:14
?Is this host allowed to scan?
?Who owns this account?
?Has this happened before?
Suspicious · page the on-call analyst
Coality with your contextual dataset
src=10.20.4.17 · smb_session × 340 hosts · user=svc-vulnscan · 02:14
POLICYApproved vulnerability scanner, inside its Tuesday scan window
IDENTITYRegistered service account owned by IT Security
MEMORYLast six identical alerts closed as a scheduled scan
Expected activity · closed with evidence
How we build it

A multi-layered picture of your organisation

Terrabit builds your context in layers. Some come from you at onboarding. Others Coality learns from your own telemetry and your analysts' decisions once it is live. A few of the layers are shown below. Select one to see what it changes.

Further layers in Terrabit's methodology cover threat context and your rules of engagement.
Given at onboarding Learnt after go-live
Delivery · two ways to start

From workshop to a living dataset

Clients can start the dataset ahead of their current SOC or MDR contract renewal, or as part of a Coality SOCaaS or MDR service with Terrabit.

01

Discover

Workshops with your IT, security, HR and operations teams. We gather your asset inventory, identity directory, policies and change calendar.

02

Collect

Read-only exports from the SIEM, EDR, firewall and identity tools you already run. Where a source is missing, Terrabit deploys its own lightweight collectors.

03

Structure

Context is normalised into the dataset. First baselines are built from the log history you already keep, and past ticket outcomes are loaded where they can be exported.

04

Review

We hand over a coverage score and a gap and exposure report, then refresh the dataset on a schedule so it stays current.

05

Ready for renewal

When your current contract ends, the dataset connects to Coality from day one. Triage starts with your context already in place.

Delivered before renewal
  • The context dataset itself, versioned and owned by you
  • Context coverage score
  • Gap and exposure report you can act on now
  • Historical baselines from logs you already retain
Starts when Coality goes live
  • Alert triage and verdicts. Your current provider keeps running operations until then
  • Baselines that learn from live telemetry
  • Continuous drift checks, instead of scheduled refreshes
  • Analyst verdicts feeding the dataset in real time
Use case · a Singapore healthcare group (illustrative)

Two alerts, before and after the dataset

The first is a false positive the dataset removes. The second is a real attack that generic triage would have rated as low priority. Switch between the two views to see how the verdict changes.

Scenario A

BenignMalicious

Context Coality found

What changes for your analysts

The queue keeps only what needs a human

Alerts that your context fully explains are closed with an evidence pack, inside the auto-close limits you set. What remains is smaller, better described and ranked by what it touches.

Closed with evidence: explained by policy, identity, baselines or past verdicts
Still needs an analyst, now with context attached
Escalated: context made the risk clearer, not quieter
Illustrative proportions, not a measured result.
Threat hunting

Building the dataset also shows where you are exposed

Once your assets, identities, policies and normal behaviour sit in one place, the gaps between them become visible. Terrabit's threat hunters start from these findings instead of a blank page.

Crown-jewel servers without EDR coverageCritical assets in the inventory that have sent no endpoint telemetry this week.
Leavers' privileged accounts still activeHR records say the person left. The directory says the account still logs in.
Service accounts logging on interactivelyAccounts meant for automation, used from a desktop outside their baseline.
Exclusions that attackers would loveEndpoint exclusions covering folders any user can write to.
Direct paths from user zones to crown jewelsNetwork routes that let an ordinary laptop reach a critical system.
Data leaving to unsanctioned servicesEgress to cloud services that appear in no approved tools list.
What you receive

Four things you keep

Your context dataset

Structured, versioned and owned by you. Any past verdict can be replayed against the context that existed at the time.

Context coverage score

How complete each part of your context is. A leading indicator of how accurate triage will be.

Environment
Policy
Identity
Baselines

Gap and exposure report

The weak points found while building the dataset, ranked and handed to threat hunting as starting hypotheses.

Ongoing upkeep

Drift checks flag new assets and accounts the dataset has not seen. Analyst decisions keep feeding it after go-live.

Get started

Start with a context discovery workshop

Your Terrabit account team will scope the workshop around your environment, then show you a first coverage score and the early exposures it reveals.

  • Works with the SIEM, EDR and identity tools you already run
  • Built and maintained by Terrabit's SOC engineers
  • Feeds Coality triage, reporting and threat hunting from one dataset