Share on social
Sep 1, 2026
Lorem ipsum

What’s New
Searchlight Threat (Investigate) now surfaces structured threat intelligence from RST Cloud’s Threat Library directly in your search results – enriching investigations with comprehensive profiles on threat actors, campaigns, malware, tooling, and vulnerabilities. This threat intelligence is continuously updated from thousands of threat reports from around the world – so analysts spend less time searching and more time investigating.
Threat Report Use Case
Genians recently published a security report on North Korean activity in Korean that was over 6,200 words long. This would take an average reader 26 minutes to read.
Security analysts cannot afford to spend hours reading reports just to establish who they're dealing with – especially if they are mid-crisis.
RST Cloud was able to extract and validate over 170 objects from this report – including over 70 indicators – which can now be searched directly in the Searchlight platform. These insights, combined with Searchlight’s proprietary data, result in faster investigations, better decisions under pressure, and more time spent on the work that actually matters.
How it Works
When you search in Searchlight Threat, relevant threat context now appears alongside Searchlight’s existing data. The integration is powered by RST Cloud's structured Threat Library, which automatically aggregates and validates intelligence from thousands of open-source threat reports globally, delivering profiles on over 5,000 malware families and tools and more than 1,000 threat actor groups.
Key Benefits
- Threat Actor and campaign profiles: Data on 1,000+ threat actor groups, including their geolocations, motivations, victimology, and historical campaigns – with direct links to the original reports.
- Technical analysis of malware and tools: Breakdowns of malware strains and hacker tools, including how they work and what to look for during incident triage.
- CVE and campaign intelligence: Ties specific vulnerabilities to the actual threat actors and campaigns exploiting them in the wild – so patch teams can prioritize based on real-world risk, not severity scores.
Multilingual translation, trained on more than 167 million dark web data points, covers the top ten dark web languages including Russian criminal slang, and cross-language search returns results in all languages simultaneously. An analyst working in English investigates sources written in any of them.
The Searchlight platform is API-first. Findings, alerts, and surface changes flow into Splunk, Jira, and your SIEM, SOAR, and ticketing tools through native integrations, or anywhere else through the API. Searchlight feeds the tools your team already works in rather than replacing them.



.jpg)

.png)

