
The First Automated AI Engine Built to Extract Adversary Procedures
NARC automatically transforms unstructured intelligence into ATT&CK-aligned Procedures and connects groups, campaigns, and software, saving analyst hours and accelerating threat-led defense.
NARC is Tidal Cyber's AI engine that transforms unstructured intelligence (e.g., CTI reports, blogs, IR documents, pentest outputs, red teaming, or free text) into structured, ATT&CK-aligned knowledge.
By running a report or free-text input through NARC, each sentence with threat relevance is analyzed and mapped to the MITRE ATT&CK framework.
What begins as raw text is transformed into structured knowledge: tactics, techniques, and most importantly, procedures that are ready to be operationalized in the Tidal Cyber platform.
NARC doesn't stop there: It also creates the relationships between procedures and threat objects (software, groups, and campaigns) and generates new threat objects and map the relationships between new and existing objects, for a richer, fully linked knowledge base.
NARC eliminates the manual effort usually required by skilled analysts to comb through large volumes of OSINT or internal reporting, turning text into structured procedures and relationships.
Defenders get a living knowledge base of adversary behavior that scales across CTI, Detection, IR, Hunting, and Red Team workflows.
NARC is the first automated Al engine designed to extract adversary procedures from unstructured intelligence, ensuring defenders build strategies around how attackers really operate.
Speed & Automation
From Reports to Procedures In Minutes
NARC automatically extracts unstructured text and converts it into ATT&CK-aligned procedures and connected threat objects, saving 20 hours per week and $75,000 per year in resources & costs.
Build Relationships
Expand the Threat Picture
NARC automatically builds the connections between procedures and groups, campaigns, and software, including creating new threat objects and mapping the relationships between new and existing objects.
Depth & Fidelity
Unlock the Value of Procedures
NARC extracts the procedures, not just tactics & techniques, that defenders need for accurate detection, hunting, and incident response.
Accuracy & Consistency
Automate What Analysts Do Manually
Lower analyst workload and accelerate faster time-to-intelligence without sacrificing accuracy. NARC produces precise mappings that normally require an experienced CTI analyst.
Scalable & Seamless
Scalable & Usable Across the SOC
Customers no longer face the overwhelming task of manually structuring internal reports into procedures. NARC operationalizes CTI across the SOC.
Unify CTI
Multi-Team Impact
By unifying intelligence across functions, NARC processes and unifies OSINT (CTI) and unstructured text so that everyone is working from the same intelligence source.
Enterprise Edition
What's included:
- Threat-Informed Defense Capabilities
- User Created Technique Sets and Matrices
- User Created Notes
- Tidal Curated Extensions to ATT&CKand Product Registry
- Single Cloud Tenant with Region Flexibility
- Integrations to Defensive Solutions (e.g. XDR, EDR, SIEM, etc)
- Continuous ATT&CK Assessment
- Tidal Confidence Score
- Prioritized Remediation Recommendations
- Customer Support
Key Features
• Automated Extraction: Converts any text source into ATT&CK-aligned objects in minutes.
• Procedures Extraction: Extracts the how behind adversary behavior, not just tactics and techniques.
• Relationship Automation: Builds connections between procedures and groups, campaigns, and software automatically.
• Expands the threat picture: Generates new threat objects and maps the relationships between new and existing objects.
• Connected Knowledge: Produces a living, linked threat knowledge base that scales across teams.
• Multi-Team Ready: Supports CTI, Detection Engineering, IR, Threat Hunting, and Red Teams.
• Self-Service: No analyst bottleneck: Operationalize intelligence instantly.
Enterprise Edition
What's included:
- Threat-Informed Defense Capabilities
- User Created Technique Sets and Matrices
- User Created Notes
- Tidal Curated Extensions to ATT&CKand Product Registry
- Single Cloud Tenant with Region Flexibility
- Integrations to Defensive Solutions (e.g. XDR, EDR, SIEM, etc)
- Continuous ATT&CK Assessment
- Tidal Confidence Score
- Prioritized Remediation Recommendations
- Customer Support
Key Benefits
• Save Analyst Time: Automates tedious tagging, mapping, and linking work.
• Increase Accuracy & Consistency: Outputs rival senior CTI analysts at scale.
• Detection & Response Ready: Procedures and relationships are instantly usable for detections, hunts, and IR.
• Break Down Silos: Every team gets the adversary context they need in their own workflow.
• Connected Intelligence: Deliver richer, structured knowledge by linking procedures with related objects.
• Unique Capability: NARC is the only engine that automates both procedure extraction and relationship creation.
• Operationalize: NARC won't just create Procedures and map their relationships, it will also generate new threat objects and link them to existing ones.
