CATIS

Predictive intelligence generated from live attacker behaviour

CATIS is AST’s managed proactive threat intelligence service. Reactive platforms aggregate Indicators of Compromise — technical artefacts of attacks that already succeeded somewhere else, were documented, and were then published. By construction, an IOC-based defence is behind the attacker; closing that gap is the whole argument for preemptive cybersecurity.

CATIS generates original Indicators of Future Attacks: intelligence specific to your own environment, derived from direct observation of attacker activity on BaitHive Decoy and TCP Mirage deception infrastructure, at the moment of exploitation — before disclosure, and before the technique is used against you.

IOC vs. IOFA: the core distinction

Dimension IOC (reactive) IOFA (preemptive, CATIS)
Source Attacks that already occurred elsewhere, later documented and published Live attacker behaviour observed directly on your own deception infrastructure
Detection window Available only after exploitation, confirmation, and publication Typically 1–2 days ahead of vulnerability confirmation; documented cases 30–45 days ahead
Specificity Generic, applied equally to every customer Specific to the attackers, techniques, and infrastructure targeting you
Zero-day coverage Effectively none; dependent on known signatures Core capability, generated while a zero-day is actively being exploited
False-positive rate High; requires ongoing tuning and triage Near zero — all input originates from our own deception infrastructure, where every interaction is adversarial by definition

A continuous four-phase pipeline

Phase 1 — TTP telemetry collection

CATIS receives zero-noise telemetry directly from BaitHive Decoy and TCP Mirage. Because every interaction with our decoys is hostile by architectural definition, the input requires no triage or filtering: payloads, attack sequences, JA4H and JA4T fingerprint signatures, and complete behavioural sequences.

Phase 2 — Enrichment and correlation

Events are enriched with contextual metadata and cross-correlated across the global AST sensor network, surfacing coordinated multi-phase campaigns, attacker-group signatures, and early signals of a campaign forming against a specific industry vertical.

Phase 3 — Novel tradecraft and zero-day detection

Statistical and behavioural analysis identifies previously unseen payload structures and attack sequences as IOFA while they are actively in use — ahead of any public disclosure or vendor acknowledgement.

Phase 4 — Packaging and autonomous distribution

Processed IOFA is packaged and distributed without manual intervention: to NanoFirewall and ShenDNS for preemptive blocking, to ASPEN for correlation and investigation context, and, where applicable, to your existing SIEM, SOAR, and endpoint stack.

Ahead of disclosure, on the record

Two documented cases, with the dates stated precisely. In both, customers with CATIS-fed prevention were protected without a signature, a patch, or a public advisory.

Case AST observed Public disclosure Interval
Microsoft SharePoint zero-day 5 June 2025 20 July 2025 45 days ahead
React Server Components
(CVE-2025-55182, CVSS 10.0)
1 December 2025 3 December 2025 2 days ahead

The React Server Components flaw was an unauthenticated remote code execution issue rated CVSS 10.0, patched on the same day it was disclosed. AST saw it being used against its deception infrastructure on 1 December 2025, during the coordinated-disclosure embargo, while public vulnerability trackers still reported no in-the-wild exploitation. That is what zero-noise deception input buys: a technique is visible while it is in use, rather than once somebody else has reported it.

AI Agent TTP Intelligence

An autonomous AI attacker leaves a different kind of evidence than a human operator. A person leaves a set of requests; an agent leaves a sequence of decisions — what it examined, what it disregarded, and what it attempted next after each result. That sequence is more informative than any single request within it.

CATIS analyses those sequences as it analyses any other attacker behaviour on the deception surface. What they can reveal:

  • Reconnaissance priorities — what the agent looked for first
  • Resource selection — which assets it judged worth pursuing
  • Privilege-seeking behaviour
  • Intended targets
  • Likely next actions
  • Attack objectives

The purpose is the one IOFA has always served, applied to a new adversary: understand what the autonomous attacker is trying to achieve, and what it is likely to do next — early enough for that understanding to be worth something. This is part of AST’s wider work on autonomous AI agent security.

This analysis is built on observable actions and behavioural sequences. It does not recover an attacker’s original instructions, and we do not claim that it does. Inference of intent from behaviour is assessed, not certain, and is reported as such.

Collective intelligence, under your control

Participation is opt-in and governed by an explicit data-sharing policy. Where data sovereignty requires it, isolated intelligence pools are available, so your telemetry never leaves its boundary.

Within those controls, IOFA detected on one participant’s deception infrastructure is processed and redistributed as protection to other participants — so a technique observed once is blocked broadly before it is successfully used elsewhere.

Output formats and integration

Format Description
REST API Structured IOFA feed for real-time consumption by SIEM, SOAR, DNS, and endpoint platforms
STIX/TAXII Compatible export for integration with your existing threat intelligence infrastructure
SOC content packages SIEM detection rules, TTP-based hunting queries, and response playbooks derived from live attacker data
Monthly report Analytical overview tailored to both technical and management audiences

What you receive

  • A summary of detected attacks and attacker profiles for the period
  • Identified TTP patterns and technique shifts relevant to your environment
  • A summary of distributed intelligence and preemptive blocks executed
  • Recommendations for detection and response tuning