Skip to main content
Use this sample when you need to demonstrate why Kyberis asks for environment context. The same threat can require immediate validation in one environment and only monitoring in another.

Scenario

Two teams ask about current Exchange exploitation activity:
  • A US healthcare company runs Microsoft Exchange with public OWA exposure.
  • A SaaS company runs Linux workloads, Kubernetes, and public APIs, but has no Exchange footprint.
Without environment-aware ranking, both teams might receive the same alert. With Kyberis, the ranking response explains why the signal matters or why it was lowered.

Healthcare environment

Representative excerpt:

Linux-only SaaS environment

Representative excerpt:

Final answer example

Recommendation: Validate Exchange exposure immediately for the healthcare environment. Monitor the Exchange signal for the Linux-only SaaS environment unless asset inventory changes. Why now: Kyberis ranked the same activity differently because the first environment includes Microsoft Exchange and public OWA exposure, while the second does not. Confidence: High confidence that the signal is active. Environment-specific priority depends on the supplied asset and exposure context. Supporting evidence: report--sample-exchange-activity. Request IDs: req_sample_context_healthcare, req_sample_context_saas. Next actions: Confirm the Exchange asset inventory, hydrate the supporting evidence if the recommendation will drive incident response, and validate the top one to three ranked items before assigning remediation work.