Intelligence
Every failed verification is a sensor
Fromenance is a communication provenance platform whose second product is threat intelligence: every Not verified or Known fraud submission is a real impersonation sample delivered by the person it was written to deceive. Indicators are extracted and exportable from day one; clustering, enrichment, and cross institution early warning are the intelligence tier on the roadmap.
Why this signal is different
Threat intelligence vendors answer whether infrastructure is malicious. Fromenance answers whether the institution issued this communication, and holds both datasets: the authoritative positive set of what you sent, and a victim sourced negative set of what your customers received and doubted.
Authoritative positive dataset
Communications your institution definitely sent, registered at send time with a recipient bound code and a content fingerprint. Ground truth, not inference.
Victim sourced negative dataset
Lures convincing enough that a real customer hesitated and asked. Not a honeypot sample and not a feed of everything on the internet: the attacks that were actually reaching your customers this week.
Shipping in v1
The schema, the indicator store, and the intelligence queue exist from the first submission so nothing has to be backfilled.
Indicator extraction on every non verified submission
URLs, domains, IPs, phone numbers, email addresses, QR payloads, and wallet addresses, normalized, with first seen, last seen, and submission count. Your own domains are skipped. Stored per tenant.
Fraud list and Known fraud
An analyst marks a submission as fraud and its indicators and fingerprint join your fraud list. The next customer who receives that lure gets Known fraud in seconds. Entries never come from a single anonymous submission.
Replay flags
A copied verify footer is the attacker telling you which template they are imitating. Replay attempts are flagged with high priority and counted on the overview.
Imitated template guess
Every Not verified submission records the nearest registered template by fingerprint, so you can see which of your communications a campaign is copying.
CSV and STIX 2.1 export
From the Indicators table or through GET /v1/indicators with an Accept header. Bulk add to the fraud list from the same view.
Signed webhooks
verdict.created, submission.replay_detected, and indicator.new to your SIEM, SOAR, or takedown vendor. HMAC-SHA256 with a per endpoint secret, 24 hour retry with backoff, replay from the delivery log.
The intelligence tier (roadmap)
Built only after a tenant is paying for verification, and the network layer only after an analyst has confirmed a campaign from real submissions. These are commitments to sequence, not to dates.
IOC enrichmentRoadmap
URL unshortening and redirect chain following in an isolated fetcher, landing page screenshot to R2, TLS certificate fingerprint, hosting ASN, WHOIS age, and phishing kit fingerprint from landing page structure.
Campaign clusteringRoadmap
Submissions cluster on shared indicators, fingerprint proximity (distance 10 or less), and kit fingerprint. Three or more submissions in 72 hours becomes a campaign. Analysts name, merge, split, and close.
Campaign viewRoadmap
Timeline, members, shared infrastructure, lure summary, the registered template it imitates, status, and one click export to your takedown vendor's webhook.
FeedsRoadmap
campaign.detected webhooks, STIX 2.1 and TAXII 2.1 endpoints, CSV, and Splunk and Sentinel saved searches in the docs.
Automatic Known fraudRoadmap
Once an analyst confirms a campaign, its indicators and fingerprints join the fraud list so later customers get Known fraud in seconds. Confirmation stays manual.
Cross institution early warningRoadmap
Correlation on indicators and kit fingerprints only, never on submissions or content. "Infrastructure associated with this campaign was observed targeting another financial institution 72 hours ago." Tenant identities are never disclosed to each other. Opt in.
What closes the loop
Once an attack is identified, the indicators can feed the systems you already run.
- SIEM
- SOAR
- Email gateway blocklists
- Web and DNS security
- Takedown vendors
- Fraud platforms
- Contact center scripts
- Customer alert banners
Start with verification. The intelligence is already accumulating.
A pilot on one stream produces the first indicators in the first week. The report at day 90 includes intelligence yield: indicators not present in your existing feeds, verified by your team.