/v2/prioritize, then investigate the top ranked items instead of deep-diving every result. This showcases Kyberis value: normalized signals, deterministic ranking, visible environment-match reasons, evidence, and an ordered action plan.
Scenario
A customer asks:What should a US healthcare company running Microsoft Exchange, Okta, Kubernetes, and public APIs care about this week?
REST flow
1. Rank items
2. Validate a top item
Use the item subject, title, or evidence references to run focused evidence and relationships calls. For a CVE-like signal, use a CVE assessment. For an actor or IOC-like signal, use the matching assessment endpoint.Final answer example
Top action: Validate Exchange/OWA exposure first. Why now: Kyberis ranked the Exchange-related item highest because it matched Microsoft Exchange, OWA exposure, US healthcare context, and recent supporting evidence. Confidence: High for prioritization fit, medium-high for immediate action until exposure is confirmed. Supporting evidence:report--sample-exchange-activity. Request ID: req_sample_prioritize.
Action plan:
- Confirm whether public OWA is exposed and whether affected versions are present.
- Review recent authentication, proxy, and endpoint telemetry for Exchange exploitation indicators.
- Then evaluate identity phishing activity tied to federated identity and Okta.
Decision gates
- Do not turn the entire ranked list into equal-priority work.
- Validate the top one to three signals with evidence or relationships before recommending disruptive action.
- Use
suppression_reasonsand caveats when a signal is lowered or confidence is partial.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)