● Built for security engineers, SOC analysts, and detection-engineering teams.
Engineering site Company Resources
Resources

Things to forward, things to download, things to bookmark.

Forwardable PDFs for your CISO. Technical reference cards for your team. Articles for the engineer who wants context. No registration walls; the relevant ones link straight to the file.

For your CISO / leadership
One-pager · PDF

The Layer 1 inventory gap, in two pages

For the executive who has to fund the answer. Names the problem, the cost of the gap, and the path to closing it. Forward-able without prep.

Download PDF →
One-pager · PDF

Compliance evidence pack, what the auditor sees

How the framework-mapped evidence pack reads against PCI 4.0, SOC 2, HIPAA, NIST 800-171, CMMC L2. Send to the GRC team.

Download PDF →
Briefing · PDF

C-suite briefing on the audit category nobody is closing

One-page executive summary. Inventory accuracy as a board-level question. Why now, what changed, what to do.

Read briefing →
For your detection-engineering team
Reference card

Event type → MITRE technique → SOAR action

The full event taxonomy with technique IDs and recommended SOAR branches. Print and pin above the SOC desk.

View on web →
Reference card

On-call runbook, what to do at 2am

Per-event response runbook. Three checks in 90 seconds. Escalation criteria. SOAR-friendly field reference.

View on web →
Template

SIEM correlation rules for Splunk, Sentinel, Chronicle, Elastic

Pre-tuned correlation rule templates for the top six event types. Drop into your existing SIEM with minimal modification.

See integrations →
For your procurement / vendor evaluation
Comparison

CybrIQ vs Forescout, Armis, Asimily, Claroty, Nozomi

Honest head-to-head feature matrix. Where each tool wins, where each doesn't, when to run combinations.

View comparison →
FAQ

25 questions security engineers ask during evaluations

Direct answers. Includes the "no, we don't do that" responses.

View FAQ →
For your detection-engineering integration
API reference

CybrIQ API for security engineers

Authentication, event stream, inventory queries, drift history, compliance export, SOAR action endpoints. The subset you actually live in.

View API reference →
Full reference

Full API documentation (314 endpoints, 31 tag groups)

The complete OpenAPI-backed reference for every endpoint, including admin and configuration surfaces outside the detection-engineering subset.

Open full docs →
Reference

Threat model & limits

Trust boundaries, defended attacks, undefended attacks, attacks against CybrIQ itself, failure modes. Vendor-questionnaire-ready.

View threat model →
For your own context-building
Article · 9 min read

The asset register lies, why your CMDB is wrong about your network

The foundational article on why every enterprise's stated inventory diverges from reality, and what to do about it.

Read article →
Article · 7 min read

Five reports, one truth

Why NAC, EDR, asset management, vulnerability scanner, and SIEM all produce different device counts, and which one auditors actually believe.

Read article →
Article · 8 min read

"Looks good" is not evidence

How the language of audit evidence changed between 2022 and 2026, and why "screenshot of dashboard" stopped being acceptable.

Read article →
Report · annual

State of Layer 1, 2026 annual report

Aggregate findings from the CybrIQ install base. Inventory-accuracy benchmarks, NDAA hit rates by sector, audit-prep time data, the most-common drift events.

Read report →
Subscription · monthly

Threat-intel briefings

Anonymized Layer 1 attacks observed across the install base. Monthly email, engineering-detail level, free.

Subscribe →
Hands-on
Interactive

Product tour

Click-through walk of the per-port dashboard. See what the security team actually looks at every day.

Start tour →
Quick-wins map

What to show your CISO at week 2, week 4, and month 3

Concrete demonstrable progress at every pilot milestone. Built so the engineer running the eval has something to take upward.

View milestones →

Need something not on this page?

Email seceng@cybriq.io with the specific question or asset. Engineering responds within one business day.

Book a working session