SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Searchlight Cyber adds RST threat data to Investigate

Searchlight Cyber adds RST threat data to Investigate

Thu, 3rd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Searchlight Cyber has partnered with RST Cloud to add threat intelligence data to Searchlight Threat. The integration is available to all Searchlight Threat customers.

It brings the RST Threat Library, RST Threat Feed and RST Report Hub into Searchlight Threat, also known as Investigate. The addition is intended to give analysts direct access to structured threat data within the platform, rather than requiring separate searches across open-source reports.

The combined offering covers threat actor groups, campaigns, malware families, vulnerabilities, tools and indicators of compromise. The companies said it includes profiles on more than 1,000 threat actor groups and analysis of more than 5,000 malware families and hacking tools.

The integration also links specific CVEs to the threat actors and campaigns exploiting them, giving users a way to connect vulnerability information with active threat activity during investigations and remediation.

The partnership comes as security teams face growing pressure to process an increasing volume of fragmented cyber threat information. Analysts often have to move between internal tools, open-source reporting and external intelligence databases to build a picture of an incident or emerging campaign.

Searchlight Threat is used by cybersecurity teams, managed security service providers and law enforcement to track threat actors, monitor illicit marketplaces and investigate cybercriminal activity. RST Cloud focuses on collecting and structuring threat intelligence data for security operations and analysis.

Analyst workflow

The integration is designed to reduce time spent on manual research during investigations. Users will be able to view structured intelligence alongside their investigation results, including information on group motivations, geolocations, victimology, historical campaigns and source reporting.

The material also extends to malware and tools. According to Searchlight, the dataset includes behavioural characteristics and indicators that can be used during incident triage.

David Osler, Head of Product, Searchlight Cyber, said: "Security analysts were hired to investigate threats, not spend hours reading reports just to establish who they're dealing with. By partnering with RST Cloud, we're giving teams the context they need, exactly when they need it. The result is faster investigations, better decisions under pressure, and more time spent on the work that actually matters."

RST Cloud said its role in the partnership is to automate the parsing and normalisation of threat reports and reconcile inconsistent naming across cyber threat intelligence sources. The aim is to turn unstructured reporting into datasets analysts can use more directly.

Yury Sergeev, Director, RST Cloud, said: "As analysts ourselves, we understand that high-quality threat intelligence is the foundation of effective decision-making - and also one of the most time-consuming things to obtain. That's why we built RST Threat Feed, RST Report Hub and RST Threat Library: to automate the parsing and normalization of threat reports, reconcile inconsistent naming across CTI sources, and transform fragmented intelligence into structured, analysis-ready datasets. This allows organizations to unlock the full potential of Searchlight Threat, spending less time collecting and cleaning data, and more time investigating threats and making informed security decisions."

Customer groups

Searchlight identified several user groups for the integration. For cyber threat intelligence analysts and security teams, the main benefit is access to threat context without leaving the investigation workflow.

For security leaders, structured profiles can support faster internal briefings during live incidents. For law enforcement and criminal investigators, the added data can help establish group origins, known tactics, techniques and procedures, and previous campaigns.

Managed security service providers are another target market. Those firms could use the integration across multiple clients to shorten response times and improve reporting consistency.

Searchlight also cited feedback gathered during development from a Cyber Threat Intelligence Manager. "This will save us hours of time that would otherwise be spent searching online reports to identify a group's operations and origins," the manager said.

The partnership expands Searchlight's threat intelligence offering as cybersecurity vendors seek to bring more external intelligence into investigation tools. The goal is to reduce reliance on separate research processes and present technical and contextual data in one place for analysts handling live threats.