Skip to main content
Use this sample when a user asks what deserves attention first for a specific environment. Start with /v2/prioritize, then investigate the top ranked items instead of deep-diving every result. This showcases Kyberis value: normalized signals, deterministic ranking, visible environment-match reasons, evidence, and an ordered action plan.

Scenario

A customer asks:
What should a US healthcare company running Microsoft Exchange, Okta, Kubernetes, and public APIs care about this week?

REST flow

1. Rank items

Representative response excerpt:

2. Validate a top item

Use the item subject, title, or evidence references to run focused evidence and relationships calls. For a CVE-like signal, use a CVE assessment. For an actor or IOC-like signal, use the matching assessment endpoint.

Final answer example

Top action: Validate Exchange/OWA exposure first. Why now: Kyberis ranked the Exchange-related item highest because it matched Microsoft Exchange, OWA exposure, US healthcare context, and recent supporting evidence. Confidence: High for prioritization fit, medium-high for immediate action until exposure is confirmed. Supporting evidence: report--sample-exchange-activity. Request ID: req_sample_prioritize. Action plan:
  1. Confirm whether public OWA is exposed and whether affected versions are present.
  2. Review recent authentication, proxy, and endpoint telemetry for Exchange exploitation indicators.
  3. Then evaluate identity phishing activity tied to federated identity and Okta.

Decision gates

  • Do not turn the entire ranked list into equal-priority work.
  • Validate the top one to three signals with evidence or relationships before recommending disruptive action.
  • Use suppression_reasons and caveats when a signal is lowered or confidence is partial.