KNOW. PROVE. ACT.

See their hand.Know if it works.

Intel6 brings preventive intelligence into view: what attackers are preparing against you.

Red6 tests whether those attack paths would work.

You know what to stop first.

Their hand: hidden
Book a demo
  • Visibility inside adversary environments
  • Autonomous validation against your environment
  • Intelligence and proof in one connected platform
Three attacker cards are concealed. Your three cards read Know, Prove, Act.
THEIR HAND

Their hand is hidden.

Switch on Unit6 to see their hand.
YOUR HANDKnow the threat. Test your defenses.

UNIT6 — KNOW. PROVE. ACT.

  • Papaya
  • Horizon Farm Credit
  • Scale Venture Partners
  • AgGeorgia Farm Credit
  • REALM
  • Puerto Rico Farm Credit
  • Foster Moore
  • AgFirst Farm Credit Bank
  • Farm Credit of Northwest Florida
  • GeoWarehouse
  • AgSouth Farm Credit
  • River Valley AgCredit
  • Farm Credit of Florida
  • Teraview
  • AgCarolina Farm Credit
  • Goveyance
  • AgCredit
  • Colonial Farm Credit
  • SureFund
  • First South Farm Credit
  • Teranet
  • Farm Credit of the Virginias
  • ArborOne Farm Credit
  • PurView
  • Central Kentucky Ag Credit
  • Teranet eXpress
  • Southwest Georgia Farm Credit
  • Farm Credit of Central Florida

The shift security leaders want

“It is very focused on identifying the pretexts to actual attacks rather than alerting you to something that has already occurred.”

VP & CISOHR services organization
Why we built Unit6

You’re already betting,
and others are betting on you.

You have to win every time. They only need to once.
Unit6 connects adversary activity to your identities and exposures, then validates which paths work so you can act before impact.

See

See what the adversary is doing.

Targeting, exposed credentials and prepared infrastructure reveal what is taking shape against your organization.

See their preparation before they act.

Sequence: Targeting. Access. Infrastructure. → Unit6 (Preparation observed) → Attacker activity.

Validate

Does it matter to us?

Connect observed activity to your identities, assets and technologies. Establish where their preparation intersects with your environment.

Your environment makes the evidence relevant.

Sequence: Observed activity → Unit6 (Customer context) → Your identities. Your assets.

Act

Put evidence where action happens.

Bring validated evidence to the teams and tools responsible for responding, with the context they need to decide what to do.

Your team controls the next move.

Sequence: Validated evidence → Unit6 (Evidence to action) → Your tools. Your team.

THE APPROACH

Threat intelligence that leads to a decision.

Unit6 connects what attackers are preparing to what matters in your environment, then tests the path before your team acts.

See the case studies

What is preventive intelligence?

It uses evidence of attacker preparation, such as targeting, access and infrastructure, to help a team act before an attack executes. Intel6 connects those observations to the organization’s identities, assets and technology.

Where does predictive intelligence fit?

Predictions estimate what may happen. Unit6 grounds forward-looking decisions in observed adversary activity, customer context and Red6 validation of whether a relevant attack path works. A signal is not treated as a confirmed incident.

What should a CISO prioritize?

Start with observed attacker activity, exposure relevant to the business and proof of which paths can actually be used. Unit6 brings that evidence together so the right team can address the clearest risk first.

Intelligence, corroborated

How we see their hand.

Intel6 combines open-internet context, attacker infrastructure and evidence from adversary environments. Honeypots, tripwires and global scanning reveal behavior and exposure, connected to your attack surface.

Enrichment EngineConnect the signals.
example.comTHEIR SIDE
OPEN + TECHNICAL INTELLIGENCE

An IP is a starting point. Its relationships tell the story.

  1. IP OBSERVATION203.0.113.42Starting signal
  2. INFRASTRUCTUREC2 infrastructureRelated infrastructure
  3. MALWARELinked malware familyTechnical relationship
  4. ACTORRansomware affiliateAssociated activity
  5. CAMPAIGNRelated campaignContext to investigate

The Enrichment Engine adds context to evidence collected across Unit6.

Scroll to connect the evidence

One signal is interesting.
Corroborated evidence changes the decision.

Their preparation. Your environment. One connected picture.

Intel6

See what matters.
Before it becomes an incident.

Intel6 connects attacker activity to your people, identities, assets, technologies and supply chain—so your team can focus on what is relevant to you.

Intel6
Acme workspace Preventive IntelligenceAC
PREPARATION OBSERVED

The target is your VPN.

Access and infrastructure converge on the same environment.

High confidence
ADVERSARYRansomware affiliatePreparation observed
ACCESS3 corporate credentialsVPN access referenced
Acme Corporationacme.com · YOUR ORGANIZATION
INFRASTRUCTURELookalike login domainlogin-acme-support[.]com
YOUR ASSETvpn.acme.comInternet-facing VPN
EVIDENCE TIMELINE
Yesterday · 18:42Access activity observed
Today · 06:15Infrastructure connected
Today · 07:30Customer relevance established
Acme Corporation
What are they preparing to do?See preparation against your organization before execution.
RED6

We’ve shown you their hand.
Now let’s look at yours.

Red6 autonomously tests your environment to determine whether the attacks and exposures that matter would actually work against you.

Swipe or drag to explore 1 / 3
RED6 / RECONAcme Corporation

Start with your environment.

The outside view becomes your attack surface.

Unit6Unit6
Graph Mapacme.com
PROJECT acme.com
acme.com Start Recon Pipeline
Graph Map Node Inspector RoE
39
FiltersNodes 39Links 74
KNOW → PROVE
Intel6What are they preparing?
Red6Would it work against us?

Attacker context sharpens the question.
Your environment is where Red6 tests it.

Where could an attacker get in?1 of 3
Charlie
CHARLIE / INTELLIGENCE REASONING

The connections become a conclusion.

Customer-specific reasoning. Evidence you can follow.

WHY THIS MATTERS

Prioritize your external VPN.

A ransomware affiliate is staging infrastructure associated with your VPN. [1]

Three corporate credentials linked to that environment appear in recent access activity. [2]

Your VPN technology matches exposure associated with the same campaign. [3]

Red6 demonstrated read access to the diagnostic resource. [4]

RECOMMENDED PRIORITYHigh · review access and exposure
Not a confirmed incident.
SUPPORTING EVIDENCE
01
Infrastructure relationshipWatcher + Enrichment · today 06:15
02
Corporate identity exposureIdentity context · today 07:10
03
Customer technology matchAsset context · today 07:30
04
Validated resource accessRed6 · vpn.acme.example/diagnostics
CHARLIE PULSE 08:00

3 things changed since yesterday.

  1. New infrastructure connected to a relevant actor.
  2. A corporate identity observed in access activity.
  3. Exploit activity relevant to your exposed VPN.
NEEDS ATTENTION1 priority: review VPN access.
Charlie Pulse

Don’t go looking for the signal.
Let it come to you.

The changes that matter, brought into focus. Charlie Pulse turns connected evidence into a briefing your team can act on.

Intel6
Charlie PulseAcme Corporation
YOUR MORNING INTELLIGENCE BRIEF

Good morning.
Here’s what changed.

08:00 · daily briefing

CHARLIE PULSE 08:00

3 things changed since yesterday.

  1. New infrastructure connected to a relevant actor.
  2. A corporate identity observed in access activity.
  3. Exploit activity relevant to your exposed VPN.
NEEDS ATTENTION1 priority: review VPN access.
WATCHING · 02

Supplier access context Monitoring

Related infrastructure Developing

CHARLIE PULSE HAS ARRIVED

The signal finds you.

Three meaningful changes.
One priority to review.

Integration availability to be confirmed.

ACT / EVIDENCE TO A DECISION

Proof changes
the decision.

A demonstrated path. A reason to act.

ILLUSTRATIVE SCENARIOValidated

Attack path validated.

vpn.acme.example/diagnostics
DEMONSTRATED

Diagnostic response returned.

HTTP 200 · service: gateway-status
Request
No session or credentials supplied.
Impact
Read access to this diagnostic resource only.

YOUR TEAM / THE NEXT MOVE

Close the path
that matters.

Restrict access to this diagnostic resource.

Give the application team the affected resource and supporting evidence to remediate the demonstrated access.

Then verify the change.

Retest this path within approved scope to confirm the restriction holds.

Team-owned next step.

Leave nothing
to chance.

  1. Know.What are they preparing to do?
  2. Prove.Would it actually work?
  3. Act.What do we need to do right now?
Get a demo