Signal × coverage → gap · recomputed daily
Detection rules for techniques that are exploited and undetected — computed daily from live intel, not asserted.
Of the 155 ATT&CK techniques showing live exploitation signal this window, 14 have no community detection coverage. The gap is computed — CISA KEV, EPSS, MISP OSINT, ransomware leak sites and SEC 8-K filings, crossed against the SigmaHQ rule index — and it is where thrunt authors.
Data as of 2026-07-14 20:11:34 UTC · sources: CISA KEV, EPSS, NVD, GHSA, MISP, SigmaHQ, URLhaus, ransomware.live, SEC EDGAR
Lead · the daily brief briefs/2026-06-11
6 exploit probability movers, 10 emerging critical cves, 10 supply chain, 55 ransomware activity, 1254 ioc volume, 25 multi-source iocs, 4 intel feeds, 1 hand-authored sigma, and 20 detection gaps.
Cross-referenced 1,385 entries this window across material breaches, federal patching priority, exploit-probability movers, emerging CVEs, ransomware, IOC volume, OSINT, MISP×KEV correlation, hand-authored Sigma and the detection-gap ledger. Read the brief →
The gap ledger · exploited, undetected 14 open · full map T1497 Virtualization/Sandbox Evasion· T1573.001 Symmetric Cryptography· T1499.002 Service Exhaustion Flood· T1530 Data from Cloud Storage· T1003.008 /etc/passwd and /etc/shadow· T1491.002 External Defacement· T1498.001 Direct Network Flood· T1602 Data from Configuration Repository· T1071.002 File Transfer Protocols· T1011 Exfiltration Over Other Network Medium· T1001 Data Obfuscation· T1542.005 TFTP Boot· T1114.002 Remote Email Collection· T1601 Modify System Image
3 former gaps now carry hand-authored thrunt rules: T1037, T1098.004 and T1566.002 — the queue below is the rest of the ledger, scored and waiting.