Skip to main content
Use this sample when a user asks about a named threat actor, alias, or intrusion set. Actor names are often overloaded, so handle ambiguous resolution before pivoting.

Scenario

A security engineer asks for a demo investigation:
Show how Kyberis investigates APT29 and returns evidence-backed recommendations.

REST Flow

1. Resolve the Actor Alias

Representative response excerpt:
Representative response excerpt:

3. Retrieve Observed Activity Evidence

4. Run the Actor Assessment

Representative response excerpt:

Final Answer Example

Recommendation: Hunt for APT29-aligned phishing and identity abuse signals before making blocking decisions. Why now: Kyberis resolved APT29 with high confidence and found relationship context around government and technology targeting plus phishing-related techniques. Confidence: Medium-high for actor identity. Medium for environment relevance unless the customer has matching sector, identity, or cloud exposure. Supporting evidence: report--sample-apt29-sector. Request IDs: req_sample_actor_resolve, req_sample_actor_relationships, req_sample_actor_assessment. Next actions: Review identity-provider alerts, check recent phishing reports, and validate whether related indicators appear in DNS/proxy logs.

Decision Gates

  • If resolution.status is ambiguous, show candidate actors and ask for clarification.
  • Treat relationships as pivots, not proof.
  • Use evidence calls to support current-activity or sector-targeting claims before recommending action.