What are intel tags?

Intel tags are labels used in Recon to highlight specific intelligence signals associated with a vulnerability. They help you quickly understand why a vulnerability matters, without manually reviewing multiple threat intelligence sources.

Each tag represents a signal identified by Cytidel — such as public discussion about a vulnerability, evidence of exploitation, new proof-of-concept code, or vendor and security advisories. By surfacing these signals directly in the platform, intel tags give you quick context for prioritising vulnerabilities. Jump to a section:

Why intel tags matter

Security teams often review hundreds or thousands of vulnerabilities. Intel tags help you quickly identify which ones deserve attention. They let you:

  • spot emerging threats faster
  • understand why a vulnerability's risk is increasing
  • detect vulnerabilities gaining attention from researchers or attackers
  • prioritise remediation based on real-world threat activity

Rather than relying only on static metrics like CVSS, intel tags surface dynamic intelligence signals collected from many sources.

Where you'll see intel tags

Intel tags appear throughout Recon, including:

Tags are displayed alongside each vulnerability to highlight the intelligence signals associated with it, and can appear in two states:

  • Active — the signal applies. The tag is fully visible, indicating the intelligence condition has been detected (for example, a public proof-of-concept or confirmed exploitation).
  • Inactive — the signal doesn't currently apply. The tag stays visible but appears dimmed, so you can quickly see which signals are not present for that vulnerability.

Cytidel's intel tags

Each tag indicates a specific type of context that may affect how urgently a vulnerability should be investigated or remediated.

  • CISA — the vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalogue, meaning it has been confirmed as actively exploited in the wild.
  • NVD — the vulnerability has not yet been published in the National Vulnerability Database, indicating it may originate from early disclosures such as vendor advisories or security research.
  • POC — a public proof-of-concept or exploit code has been identified, which can increase the likelihood of exploitation.
  • KTA — the vulnerability is associated with a known threat actor, suggesting it may be discussed, analysed, or used by attackers.
  • TUE — the vulnerability was disclosed as part of Microsoft Patch Tuesday, often affecting widely used Microsoft products and systems.
  • PPE — signals suggest potential public exploitation, indicating the vulnerability may already be abused in real-world attacks.
  • SPOT — the vulnerability has been highlighted in Cytidel Spotlight, meaning it has been flagged by Cytidel's threat analysts as particularly relevant.

These tags provide quick insight into the threat landscape surrounding a vulnerability, helping security teams prioritise remediation more effectively.

Use intel tags to prioritise vulnerabilities

Intel tags help you move beyond severity scores and prioritise based on real-world threat signals. When reviewing vulnerabilities, look for tags that indicate:

  • emerging signals — e.g. Not published to NVD
  • increased attention from researchers or threat actors — e.g. POC, KTA
  • potential exploitation — e.g. PPE
  • confirmed exploitation — e.g. CISA KEV

Vulnerabilities carrying these signals are often higher priority for investigation or remediation.

Questions about intel tags? Email us at [email protected].


Did this page help you?