Signal × coverage → gap · recomputed daily
Detection rules for techniques that are exploited and undetected — computed daily from live intel, not asserted.
Of the 164 ATT&CK techniques showing live exploitation signal this window, 15 have no community detection coverage. The gap is computed — CISA KEV, EPSS, MISP OSINT, ransomware leak sites and SEC 8-K filings, crossed against the SigmaHQ rule index — and it is where thrunt authors.
Data as of 2026-10-05 09:42:46 UTC · sources: CISA KEV, EPSS, NVD, GHSA, MISP, SigmaHQ, URLhaus, ransomware.live, SEC EDGAR
Lead · the daily brief briefs/2026-09-23
1 material breach disclosures, 4 federal patching priority, 20 exploit probability movers, 10 emerging critical cves, 10 supply chain, 32 ransomware activity, 880 ioc volume, 13 active malware families, 3 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps.
Cross-referenced 1,011 entries this window across material breaches, federal patching priority, exploit-probability movers, emerging CVEs, ransomware, IOC volume, OSINT, MISP×KEV correlation, hand-authored Sigma and the detection-gap ledger. Read the brief →
The gap ledger · exploited, undetected 15 open · full map T1497 Virtualization/Sandbox Evasion· T1573.001 Symmetric Cryptography· T1499.002 Service Exhaustion Flood· T1530 Data from Cloud Storage· T1003.008 /etc/passwd and /etc/shadow· T1491.002 External Defacement· T1498.001 Direct Network Flood· T1602 Data from Configuration Repository· T1071.002 File Transfer Protocols· T1011 Exfiltration Over Other Network Medium· T1001 Data Obfuscation· T1542.005 TFTP Boot· T1114.002 Remote Email Collection· T1601 Modify System Image· T1573.002 Asymmetric Cryptography
16 former gaps now carry hand-authored thrunt rules: T1098.005, T1111, T1027.013, T1557, T1036.005, T1566.004, T1055, T1071.004, T1574.002, T1102.001, T1195.002, T1204.004, T1105, T1037, T1098.004 and T1566.002 — the queue below is the rest of the ledger, scored and waiting.