Cyver Core transitions your organization to a collaborative, intelligence-driven Security Operations Center (SOC). By connecting offensive testing with continuous defensive monitoring, your team can validate real threat exposure and improve detection coverage.
Follow this onboarding flow to set up your SOC operations: Templates & Mappings > Tooling & Integrations > Attack Validation & Mapping > Purple Team Collaboration > Reporting.
1. Preparing Your Templates & Mappings
To successfully transform attack scenarios into actionable operational insights for your SOC, you must first establish your testing frameworks and reporting structures.
Configure Frameworks: Navigate to Settings > Compliance Norms to ensure your tactical mappings (like MITRE ATT&CK) are ready to be linked to your operations.
Prepare your Templates: Configure your Report Template and Pentest Template to support scenario-based testing, attack chain visualization, and recurring validation workflows.
For a complete walkthrough on styling, Markdown, and using tokens, read our detailed guide on Customizing Report Templates.
To learn more about bundling these settings, read our article on Customizing Pentest Templates.
Tip: You don't have to build frameworks from scratch! You can download comprehensive, globally recognized standards from our GitHub repository and import them directly into your portal.
2. Tooling & Integrations
Security operations rely on a massive ecosystem of tools. Connecting these systems ensures findings and detection insights are centralized without forcing your team to replace existing monitoring platforms.
-
Connect your custom tools: For bespoke tools, you can use the Cyver Core API to continuously import vulnerabilities straight into your ongoing projects.
To learn how to authenticate using JSON Web Tokens or API keys to push vulnerabilities via API, read our documentation on Working with the API.
-
Connect an Integrated Scanner: Seamlessly parse scan outputs directly by utilizing our built-in integrations for reNgine and Tenable to bring continuous scanning data into your workspace.
To learn how to execute pre-configured continuous scans, explore our guides on Integrated Vulnerability Scanner (reNgine), Integrated Vulnerability Scanner (Tenable Web App Scanning), and Integrated Vulnerability Scanner (Tenable Vulnerability Management).
Enable Purple Team Collaboration: Bridge the gap between your offensive experts and the client's defenders. Navigate to the Clients tab to onboard the Blue Team as Client Users. This connects them with your internal Red Team, creating a unified workspace where both sides can collaborate on validated vulnerabilities and operational security workflows.
Explore our guides on ServiceNow Integration, Jira Integration, and Azure DevOps Integration to learn how to enable your Blue Team to push validated threats directly from their portal into their internal incident response and remediation pipelines.
3. Attack Validation & Technique Mapping
This phase focuses on understanding which vulnerabilities are actually exploitable, how attackers move across environments, and whether existing detections truly work.
Start the Operation: Create a new project to perform pentests, red team exercises, or attack simulations across your environments.
Detection Validation: Import findings to evaluate your monitoring coverage against real-world threats and identify where detection gaps exist. For step-by-step instructions on uploading files from tools like Burp or Nessus, read our guide on Importing Findings.
Document Attack Paths: Navigate to the Attack Chains tab to map adversary behavior. Document exactly how attackers move across systems, identities, and assets, linking these techniques directly to the MITRE ATT&CK framework.
To master scenario building and step mapping, explore our full guide on Attack Chains.
4. Purple Team Collaboration & Continuous Improvement
Offensive testing becomes exponentially more valuable when its results directly strengthen incident response capabilities. Cyver Core helps you maintain this visibility continuously.
Real-Time Continuous Visibility: Configure your project as a Continuous Project with the Real-time use case setting activated. This ensures that any vulnerabilities imported via the API feed directly into an ongoing scenario, rather than waiting for periodic batch runs. Clients (or the Blue Team) see all findings live as they are ingested, providing instant visibility into threat exposure.
SOC Feedback Loop: Share validated findings and detection gaps across offensive and defensive teams. Use live ticketing to ensure the SOC can update SIEM rules or patch vulnerabilities immediately.
For a deeper dive into how the platform handles continuous monitoring visibility, read our guide on Continuous Projects.
5. Reporting
Translate complex attack paths and detection validations into curated, executive-ready insights.
Deliver Validated Insights: Navigate to the Report tab to instantly generate a branded PDF. Showcase exactly how offensive testing connects to defensive operations, complete with graphics and risk tables, in a fraction of the time.
For advanced reporting features and token management, explore our article on Generating, Changing, and Duplicating Report Templates.