Collected outside. Correlated to you. Delivered inside.
Vigil turns collected external signals into contextualised findings for security operations. This page explains the collection, correlation, prioritisation and delivery workflow, together with a typical on-premises implementation.

From signal to action in four steps.
Collect
Underground forums, lawfully accessible messaging communities, stealer log collections, breach datasets, paste services, exposed repositories, certificate transparency records, phishing feeds, ransomware leak sites and vulnerability intelligence.
Correlate
Every record is matched against your watchlist — domains, people, brands, products, subsidiaries and vendors — and chained back to its source, actor and timestamp.
Prioritise
Freshness, privilege, actor reputation, live content and asset criticality contribute to a reviewable score. Recent records containing session data can be prioritised above older, lower-context records.
Act
Findings can be routed to SIEM, SOAR, Jira / ServiceNow, Teams / Slack and e-mail with supporting evidence and auditable activity history.
A structured route to operational use.
A standard on-premises implementation is generally completed within four weeks, subject to infrastructure readiness, security approvals and integration scope.
- Week 1
Install & license
OVF/OVA appliance in your virtualisation environment, isolated database, 2FA + RBAC, CentralSync connection, watchlist import (domains, brands, VIPs, vendors).
- Week 2
Integrate
Configure supported SIEM / SOAR, case-management, collaboration, SMTP and REST API integrations. Define alert routing by severity and module.
- Week 3
Tune & train
Threshold tuning on real findings, noise reduction, response-workflow review, analyst and administrator training, and management-reporting templates.
- Week 4
Live + first executive report
Production operation, first CTI Scan of your domain, first executive brief — and a handover pack so your team runs it from here.
What we deliver with the platform.
Five operational workstreams with defined deliverables and measurable outcomes, designed to integrate the platform into day-to-day security operations.
Deploying GNSAC in Your Environment
Deploy GNSAC Vigil and GNSAC Phishing with documented configuration, supported integrations, alert routing and operational handover.
- On-premises or managed deployment with documented configuration
- Supported SIEM and SOAR integration for alert ingestion
- Role-based access configuration and customer isolation
- Operational runbooks and handover documentation
- Deployment documentation and configuration records
- Integration architecture and data flow diagrams
- Operations handover pack with escalation paths
- Platform configured against agreed acceptance criteria
- Documented workflows for customer security teams
Configuring GNSAC Vigil for Your Environment
Configure GNSAC Vigil for the organisation’s authorised monitoring scope, alert priorities and intelligence workflows.
- Domain and subsidiary exposure monitoring configuration
- Custom alert rules and severity-based prioritisation
- Dark web monitoring scope definition and tuning
- Intelligence workflow design aligned to your incident response process
- Monitoring scope document and alert configuration
- Documented intelligence and response workflow
- Tuning report with noise-reduction metrics
- Findings aligned with the authorised organisational scope
- Documented tuning intended to reduce avoidable alert noise
GNSAC Vigil Credential Scanning
Credential-exposure analysis in GNSAC Vigil supports investigation of affected identities, session risk and exposure patterns across collected datasets.
- Authorised domain and subsidiary credential-exposure analysis
- Stealer log analysis with session-risk context
- Executive and VIP exposure review
- Historical exposure trends and repeated-exposure analysis
- Credential exposure report with risk scoring
- High-risk user list with remediation priorities
- Executive summary for leadership briefing
- Context for organisational credential-risk review
- Prioritised remediation recommendations based on available evidence
GNSAC Phishing Campaign Builder
Design and run authorised multi-channel phishing simulations with GNSAC Phishing to measure behavioural risk across e-mail, SMS and voice scenarios.
- Multi-channel campaign design (email, SMS, voice)
- Intelligence-informed simulation templates based on real threat activity
- Department-level metrics with reporting rate tracking
- Role-based training curriculum and feedback workflows
- Campaign plan with scheduling and segmentation
- Simulation results dashboard and risk heatmap
- Quarterly awareness report with trend analysis
- A measurable baseline and trend for employee reporting behaviour
- Evidence to guide awareness and follow-up training
GNSAC Vigil Reporting & Alerts
Customisable dark web monitoring scope, executive reporting, and scheduled intelligence delivery — all configured within GNSAC Vigil to match your requirements.
- Custom dark web monitoring scope and keyword configuration
- Scheduled intelligence reports with executive summaries
- Brand protection and impersonation monitoring
- Automated alert delivery via email, webhook, or API integration
- Custom monitoring configuration document
- Scheduled report templates and delivery setup
- Brand protection scope and detection rules
- Continuous monitoring with analyst review workflows
- Structured reporting on organisational threat exposure
Before you ask.
How does the appliance receive intelligence updates?+
Through CentralSync, using a documented, appliance-initiated channel to the GNSAC intelligence service. Synchronisation frequency, permitted data flows and restricted-network options are confirmed during security review and scoping.
What do you need from us to start?+
A virtualisation environment for the appliance, your watchlist (domains, brands, executives, vendors) and the integration endpoints you want findings delivered to.
Can our team operate it without GNSAC?+
Yes. Operational handover is part of the implementation. GNSAC engineering support remains available for new sources, tailored response workflows and upgrades.
Review the workflow against an authorised domain.
A focused live-platform session covering CTI Scan, representative findings and a scope-dependent implementation plan. Customer-domain checks begin only after authorisation is confirmed.
