Use cases
Who ThreatBharat is for, the defensive workflows it supports, and — for each audience — what is genuinely available today.
ThreatBharat publishes reviewed intelligence about threats relevant to India. What follows is how different defenders use it. Each section ends with a plain note on availability, because a use case you cannot act on today is not a use case.
Two things hold across all of them. Publication is not confirmation — a report describes a claim that was made unless it says otherwise. And intelligence informs a defensive decision; it does not prevent an attack, and nothing here should be read as promising that it will.
Government and public sector
Publicly availableDepartments and public bodies are named in breach claims and leak-site listings before anyone tells them. The first notice is often a journalist’s phone call, and by then the question is already “is this real?” rather than “what do we do?”.
Relevant capabilities
- Published reporting on claims naming Indian public-sector organisations
- Verification labels that separate an unverified claim from a corroborated one
- Correction and retraction history, so a withdrawn claim is visibly withdrawn
Example defensive workflow
- Watch the India view and the public feed for reporting that names your department or a supplier.
- Read the verification label and confidence before escalating — an unverified listing is not a confirmed breach.
- Use the structured assessment to brief internally on what is observed, what is confirmed, and what remains unknown.
- If reporting about your organisation is wrong, submit a correction request; corrections are published, not quietly edited.
Available today: The public feed, the India view and correction requests are open today. ThreatBharat is an independent commercial platform — it is not affiliated with, endorsed by, or acting on behalf of any government body.
CERT and CSIRT teams
Publicly availableA national or sectoral response team has to triage claims about a constituency far larger than it can monitor directly, and most of the noise resolves to recycled or fabricated listings.
Relevant capabilities
- Reviewed publications with explicit verification and confidence labelling
- Threat actor profiles built from observed activity, with attribution caveats
- Ransomware victim-listing reporting, presented as claims
- Defensive guidance written for responders rather than for buyers
Example defensive workflow
- Triage inbound claims against published reporting to see whether a listing has already been assessed.
- Use the confidence rationale and intelligence gaps to decide what still needs independent verification.
- Pass the defensive guidance — immediate, investigation, monitoring — to the affected constituent.
- Where an actor is named, carry the attribution caveats through into your own advisory rather than dropping them.
Available today: All of this is publicly readable today. Coordination arrangements beyond public reporting are handled case by case through an access request.
Critical infrastructure
Limited organisational accessPower, transport, water, telecom and financial operators carry third-party and supply-chain exposure they do not directly control, and a supplier’s breach becomes their incident without warning.
Relevant capabilities
- Sector-level views of published reporting
- Third-party and supply-chain incident reporting
- Organisation and asset profiles, so reporting can be matched to named suppliers
- Watchlists for your own brands, domains and suppliers
Example defensive workflow
- Record the suppliers and brands that matter to you as watched assets.
- Review candidate matches between new published reporting and those assets — a human confirms each one.
- Where a supplier is named, use the report’s observed-versus-confirmed breakdown to scope your own exposure.
- Feed the monitoring guidance into your existing detection and log review, rather than treating it as a separate stream.
Available today: Sector views and published reporting are public. Asset profiles, watchlists and candidate matching require a reviewed organisational access grant.
SOC and incident response teams
Publicly availableDuring an incident the useful question is narrow and urgent: has this actor, this technique or this infrastructure been seen against organisations like ours, and what should we be looking for in our own logs?
Relevant capabilities
- Defensive guidance split into immediate, investigation, monitoring and legal steps
- Indicators published in defanged form with context and confidence
- MITRE ATT&CK techniques labelled as observed or assessed
- Related-report links that state why two reports are related
Example defensive workflow
- Search published reporting for the actor, technique or sector in front of you.
- Pull the indicators with their context and confidence — each is labelled, so you can decide what to hunt on and what to merely watch.
- Distinguish observed techniques from assessed ones before building a detection on top of them.
- Use the monitoring guidance to decide what to keep watching after the incident closes.
Available today: Indicators, techniques and defensive guidance are published with every report and are readable today. ThreatBharat is an intelligence source, not a detection or response product — it informs your defence, it does not perform it.
Threat intelligence teams
Limited organisational accessMost India-relevant reporting arrives either as an unlabelled feed of claims or as vendor marketing, and an intelligence team has to redo the assessment work before it can use any of it.
Relevant capabilities
- Structured assessments: observed, confirmed, unverified, likely impact, intelligence gaps
- Explicit confidence rationale and severity rationale on each report
- Threat actor profiles with aliases, observed forums and targeted sectors
- Priority intelligence requirements, so standing questions are recorded rather than re-explained
Example defensive workflow
- Record your standing intelligence requirements so review can be pointed at what you actually need.
- Consume published assessments with the reasoning attached, rather than re-deriving it from a raw claim.
- Track where our assessment and yours diverge — the intelligence-gaps field is written to make that easy.
- Where we are wrong, tell us; corrections are published with the reasoning intact.
Available today: Structured assessments and actor profiles are public. Recording priority intelligence requirements requires a reviewed organisational access grant. We do not claim complete visibility of underground activity, and no source coverage is exhaustive.
Enterprise security leadership
Publicly availableA CISO is asked whether a headline affects the organisation, usually within the hour, and needs an answer that distinguishes a claim from a confirmed compromise without overstating either.
Relevant capabilities
- Verification labels and confidence levels on every published claim
- The standing distinction between a claim that was made and a breach that was confirmed
- Sector-level reporting for peer context
- Correction and retraction history, so a withdrawn claim can be shown as withdrawn
Example defensive workflow
- Check whether the headline traces to a published report and what its verification label says.
- Brief upward using the observed-versus-confirmed split rather than the headline.
- Use sector reporting for context on whether a campaign is broader than one organisation.
- Where your organisation is named and the reporting is wrong, submit a correction request.
Available today: Everything in this section is publicly readable today. Nothing on this platform guarantees prevention of an attack or completeness of coverage.
Researchers and trusted partners
Publicly availableResearchers studying India-relevant threat activity need reporting whose method is stated and whose corrections are visible, so their own work can cite something stable.
Relevant capabilities
- A published methodology covering source assessment, labelling and redaction
- A responsible publication policy and a source handling policy
- Correction and retraction history
- Research write-ups
Example defensive workflow
- Read the methodology before citing a verification label, so the label means in your work what it means in ours.
- Cite reports by their permanent reference; corrections stay attached rather than rewriting history.
- Where you can corroborate or refute a published claim, tell us — that is how the labels improve.
Available today: Methodology, policies and published research are open. Deeper collaboration is arranged individually through an access request; there is no privileged or classified tier, and we do not offer one.
What we do not claim
We are an independent commercial platform. We are not affiliated with, endorsed by, or operating on behalf of any government body, and we hold no classified or privileged access. We do not claim complete visibility of underground activity — no source coverage is exhaustive, and reporting reflects what we observed. Attribution is stated with its confidence and caveats and is never presented as certain. And no intelligence product, including this one, can guarantee that an attack is prevented.
Where we get something wrong, we correct it in public. See methodology and corrections.
Request access
If one of these describes your team and you need more than the public feed, tell us what you are trying to defend and we will review it.
Submitting a request does not create an account or guarantee access. Every request is reviewed by a person.
Request access