Cybersecurity Management › Threat Detection & Response Management

Threat Detection & Response Management

BC-620.30 Level 2 Cross-Industry 96 providers 411 API surfaces 34 rated strong or better

SOC, SIEM, incident response.

Threat Detection & Response Management (BC-620.30) is a level-2 business capability under Cybersecurity Management in the Cross-Industry model. The catalog holds 411 API surface(s) from 96 provider(s) that can perform some part of it, 34 of them rated strong or better. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.

Where this capability definition comes from. This capability is part of a published business-architecture model that API Evangelist did not author. It is redistributed here under CC-BY-4.0. Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 Changes: Consolidated from 333 per-L1 YAML files into one JSON; English only (upstream i18n/ omitted); descriptions whitespace-normalised. No capability was added, removed, renamed or re-parented. Source repository · NOTICE and third-party framework attributions

Sub-capabilities

Security Monitoring and SIEM Operations BC-620.30.10

SIEM, SOAR, and security telemetry monitoring.

no catalog coverage

Threat Hunting BC-620.30.20

Proactive hypothesis-driven threat hunting.

no catalog coverage

Cyber Threat Intelligence BC-620.30.30

Collection, analysis, and dissemination of cyber threat intelligence.

no catalog coverage

Cyber Incident Response BC-620.30.40

Detection, containment, eradication, and recovery from cyber incidents.

no catalog coverage

Digital Forensics BC-620.30.50

Forensic acquisition and analysis in support of incidents and litigation.

no catalog coverage

Providers that reach this capability

Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.

Exemplar 8 Complete, well-documented, and agent-ready
Strong 26 Solid coverage with minor gaps
cPanelClamScannercPHulk2 APIs66.2OraclecloudGuardthreatintel2 APIs66.0Cisco XDRActorAsset PropertiesAttack PatternCOA24 APIs65.6FastlyEventsRules2 APIs65.2Microsoft GraphSecurity.alertSecurity.incidentdeviceManagement.mobileThreatDefenseConnectordeviceManagement.windowsMalwareInformation11 APIs63.5Cisco Catalyst SD-WANIPS Signature - Custom RuleIPS Signature - RuleIPS Signature - Rule Group3 APIs63.2Cisco UmbrellaAS Information for a DomainActivityCisco Secure Malware Analytics IntegrationCo-occurrences for a Domain19 APIs62.1Cisco Identity Services Engineclearthreatsandvulneribilities1 API61.9Synthient APIAnonymizersHeliosJA4TLookup4 APIs60.4Juniper NetworksFile AnalysisIndicators of CompromiseReportsThreat Intelligence4 APIs59.71PasswordAudit Events1 API59.6Amazon Web ServicesDetector1 API59.6MistOrgs Advanced Anti Malware ProfilesOrgs IDP ProfilesSites Skyatp3 APIs59.6ArmorAIP - Entity IntelligenceAIP - Incident DataDefender - InvestigationDefender - Machine Actions14 APIs59.4MalwarebytesAI Detection & ResponseCase ManagementDetectionsFlight-recorder11 APIs59.0CybelAngelAlertsIncident ReportsThreat Intelligencestix4 APIs58.9Amazon IoT CoreDetectMitigationactionsSecurity ProfilesViolation Events4 APIs58.8ALTRAlertsanomalies2 APIs58.6Amazon IoT Device ManagementActive Violations1 API58.6AptibleIntrusionDetectionReports1 API58.5Amazon IoT Device DefenderActive ViolationsDetectMitigationactionsSecurity Profile Behaviors7 APIs58.1Amazon GuardDutyDetector1 API57.7IRONSCALESDeepfakeEmailsIncidentMitigation4 APIs56.9Cisco Secure FirewallIntelligence1 API56.4DruvaThreat HuntingThreat IntelThreat Watch3 APIs54.8PantherAlertCommentRulecorrelation rule8 APIs54.6
Developing 34 Usable, with meaningful gaps to close
HuntressAgentsEscalationsIncident ReportsSIEM4 APIs54.1KentikMitigationsService1 API53.2Abnormal AIAI Security Mailbox (formerly known as Abuse Mailbox)CasesDashboard AggregationsDetection3609 APIs53.1RiotInbox1 API52.3CloudGuardIntelligence1 API51.9UpGuardBreachesdataleaksthreatmonitoring3 APIs51.7AbuseIPDBBlacklistReportsReputation3 APIs51.5Microsoft DefenderAlerts1 API51.4DNSFilterDomains1 API51.1Picus SecurityMitigation1 API49.3Sumo LogicthreatIntelIngestthreatIntelIngestProducer2 APIs49.1DomainToolsIris InvestigateLookups2 APIs48.3Google Cloud Security Command CenterFindings1 API48.1AkamaiBehavioral DDoS profile actionsBehavioral DDoS profilesBehavioral DDoS protection profilesMalware policy actions7 APIs48.0VirusTotalIoC Feeds - Domain intelligence feedIoC Feeds - File intelligence feedIoC Feeds - IP intelligence feedIoC Feeds - Sandbox analyses feed23 APIs47.8Trellix Web GatewayAnti-MalwareSecurity EventsStatistics3 APIs47.5TaniumAlertsEvidenceIntel DocumentsProcesses5 APIs46.9SysdigActivity AuditRules2 APIs46.8DragosIndicatorsProducts2 APIs46.2TracebitAlerts1 API45.6Juniper Mist AIOrgs Advanced Anti Malware ProfilesOrgs Antivirus ProfilesOrgs IDP ProfilesOrgs Integration SkyATP9 APIs45.2DoppelAlertsScan2 APIs44.5AdluminDetectionsFirewall2 APIs43.6Microsoft SentinelAlertRulesIncidentsThreatIntelligence3 APIs43.6TrellixAction HistoryAffected HostsAlertsDetections9 APIs43.3Google Safe BrowsingthreatMatches:find1 API43.2Vectra AIAccountsAssignment OutcomesAssignmentsDetections10 APIs43.2Google Cloud ChronicleAlertsFeedsRules3 APIs43.0SaaS AlertsEventsReports2 APIs41.2Rapid7Community ThreatsInvestigations2 APIs41.0WallarmAttacks1 API40.1SpyCloudBreachCompass2 APIs40.0Stream.SecurityDetection RulesNetwork & Identity LogsThreat Detection3 APIs39.5VaronisAlertsEventsThreat Models3 APIs39.3
Thin 26 Limited public surface area
Emerging 2 Early or largely undocumented
This page carries no rating. Capabilities are not rated. A capability is a description of what a business does, not a thing a company publishes, so a Kin Score would have nothing to measure.
The edge table is a Pro feature. This page shows which providers and tags reach Threat Detection & Response Management. The underlying tag → capability edges — each with the quoted fragment of the provider's own OpenAPI that evidences it, a calibrated confidence score, and the contract-provenance gate it passed — are available through the API, along with company-level capability maps. Only edges at confidence ≥ 0.7 with evidence found verbatim in the source contract are published at all.

See plans →  ·  How the edges are graded →