SecNoteHelp / FAQ

SecNote Help

Operational guidance for using the morning brief, configuring exposure scope, reading source health, and handing work to owners.

Dashboard
HelpMethodologySourcesPrivacy

Start here

Daily Triage Flow

  • Use Overview for the cross-section morning brief, lead story, and section map.
  • Use Blue Team for defensive actions, exposure matches, vendor signals, malware, patch, hunt, and monitor work.
  • Use Feed when you need the full queue, search, saved items, or source health.
  • Use Exposure when you need to map public reporting to operated products or platforms.
  • Use Vendor when you need a supplier, SaaS, cloud, endpoint, or hardware watch.
  • Use US News and World News when you want non-cyber daily-brief context without mixing it into Global Risk.
  • Use Methodology when a score, route, label, or match needs explanation before escalation.

Exposure support

First-run Exposure Setup

  • Start with systems you actually operate: cloud providers, identity platforms, endpoint/browser estate, edge devices, SaaS tools, data platforms, and security tooling.
  • Use starter presets for broad coverage, then remove terms that create noise for your environment.
  • Add aliases people use internally, such as product names, business-unit vendors, managed service names, and critical third-party platforms.
  • Add active CVEs only when you want a short-term watch. Remove them after remediation or when the threat window closes.
  • If the Exposure page stays quiet, add product aliases before assuming the environment has no relevant exposure.

FAQ

Common Questions

What is the fastest way to use SecNote each morning?

Open Overview for the section map and lead story, then use Blue Team for patch, hunt, monitor, exposure, vendor, and malware work. Use Feed when you need the full queue.

What does Source Health mean?

Source Health reports whether each public feed or API returned data during the latest pull. Failed sources are retried on refresh; degraded sources may be reachable but return no usable items.

Why did a broad world news story appear in Global Risk?

Global Risk is a security-adjacent context lane, not a confirmed incident lane. Broad non-cyber headlines should usually appear in US News or World News instead.

What belongs in US News and World News?

They carry broad non-cyber daily-brief headlines from public media feeds. Cyber, vulnerability, AI, and security-adjacent geopolitical stories stay in their dedicated lanes.

Where is my saved/read state stored?

Saved items, read items, exposure groups, vendor selections, custom vendors, and sync timeline state are stored in this browser local storage.

Does SecNote replace source verification?

No. SecNote ranks and routes public-source signals. The linked source remains the authority for facts, attribution, exploit details, and remediation guidance.

Handoffs

Analyst Output Templates

Morning brief

Generate the styled PDF from Overview, then lead with the top story and section counts, Blue Team actions, critical/high items, exposure matches, vendor signals, source failures, and global, US, world, or AI context worth monitoring.

Patch owner

Use the Patch Owner PDF for affected product, CVE or advisory link, severity, exploit/KEV/EPSS signal, exposure match, recommended owner, and the article URL.

Hunt owner

Use the Hunt Owner PDF for the triggering report, suspected tactic, detection links, relevant logs or telemetry to search, and why the item is hunt work instead of background news.

Vendor escalation

Use the Vendor Escalation PDF for watched vendor, breach/advisory/action count, lead source, affected product aliases, and whether the match is source-backed or name-only context.
For scoring details, source coverage, and browser storage behavior, see Methodology, Sources, and Privacy.