Resources

Reference project · German defence sector

Measured, not asserted.

How an early-adopter customer took the IdoubleS platform from beta to operation on-premises, with a validation plan, a baseline built by both teams, independent raters and a number on every step. Including the first result, which missed the target.

The customer

Intelligence in abundance, no threat model.

A federal IT service provider in the German defence sector, commissioned in 2023 to have a Cyber Threat Modelling platform built and operated on-premises. Threat intelligence arrived daily, in volume and in natural language. Refining it by hand into bespoke models was essential and did not scale; before the project, no threat modelling was practised at all.

The objective

A validation plan, not a statement of intent.

  • Target:

    attack graphs with at least 80 % average accuracy against a baseline built jointly by IdoubleS and the customer's analysts

  • Method:

    six automated runs per report, compared technique by technique and relation by relation on both layers

  • Raters:

    the customer's analysts, three independent experts for detection logic, SVA's SIEM specialists and penetration testers for the native rules

  • Rule:

    the team that generates a graph, a pattern or a rule never declares it valid

The journey

  1. 2023

    Tender: provision of a threat intelligence platform, built and operated on-premises.

  2. Aug 2025

    Test scenario 1: relevant adversaries and threat scenarios prioritised from business parameters and events.

  3. Q4 2025
    Below target

    First automated runs against the baseline: about 61 % (Emotet delivery) and under 50 % (Ryuk ransomware). Below target, measured per technique, and said so.

  4. Apr 2026

    New release: context building, image analysis, technique classification, extended entity recognition, threat-actor intelligence, confidence pipelines.

  5. Q2 2026
    Re-validation

    Re-validation with the same baseline and runs: 99 % and 84.17 % exact technique match; 96.14 % and 93.57 % relation quality on the observable layer; up to 51.85 % additional correct techniques the analysts had missed.

  6. Jun 2026

    Test scenario 3: 14 STIX detection patterns scored by three independent experts on six criteria: 82.47 %.

  7. Aug–Sep 2026
    11 of 11 offenses

    Test scenario 4: 11 native SIEM rules scored on seven criteria: 90.47 %. Adversary emulation by SVA: 11 of 11 rules raised an offense, 9 complete, 2 partial. Three techniques needed a log source the lab did not have, reported as such.

  8. Q4 2026

    Next: attack vectors, attack paths (the bridge between adversary graphs and critical functions), the customer's integration environment.

Results

From one report to rules that fire.

  1. 1

    report

    prose, tables, code, images

  2. 99 %

    Attack graph

    of baseline techniques, plus ones the analysts missed

  3. 82.5 %

    14 STIX patterns

    quality, behaviour-based, portable

  4. 90.5 %

    11 native rules

    quality in the customer's SIEM

  5. 11 of 11

    offenses

    under adversary emulation

What changed for the analysts

From author to reviewer. Analysts validate instead of capturing reports by hand; confidence scores steer a sample check. One quality criterion of the plan had to be rewritten during the project, from “effort to rework AI-generated graphs” to “effort for quality assurance”, because the AI had found what the analysts had missed.

What changed for the SOC

Detection logic and native rules from the validated model, coverage per technique, mapping documented. Every re-validation reuses the same baseline, rubrics and test scenarios, so coverage is proven again after every change.

The flood of CTI reports used to be impossible to handle by hand. Today the IdoubleS platform refines it into a model we trust: traceable to the source, scored with confidence, validated by analysts, and at a quality and speed that were unthinkable before.

Head of Cyber Defence Center, reference customer

Results of a defined-scope pilot, 2025–2026. Scenarios from CrowdStrike Intelligence Tippers CSIT-22052 and CSIT-21260, used with CrowdStrike's approval. Evidence for the method, not a benchmark.

Contact

Operationalise Cyber Threat Intelligence.

Turn the reports and feeds you already receive into a governed Cyber Threat Model that your SOC and risk and management teams can act on. Tell us where you want to start.

This site is protected by reCAPTCHA. Details on how your data is processed can be found in our Privacy Policy.