Cyber knowledge graph · MCP server · Analyst assistant

Cybersecurity answers you can check

Lattice is a read-only knowledge graph of public cybersecurity sources. Use it from your own AI agent over MCP, or from the Lattice Analyst, the assistant that gives SOC specialists a verdict, the evidence and the next steps.

Alert triage in the Lattice Analyst: a Contain now verdict with reasons and the techniques the text shows

Show the work

Every answer comes with its query plan and its evidence

You should not have to trust an assistant. Open the query plan to see each graph call and model call and how long it took. Open the evidence pane to see the exact nodes the answer rests on, why each one is there, and how many hops it sits from your question.

The query plan for CVE-2021-44228: four graph calls with their time, a code step that works out the facts, one model call with its tokens, and a check of the answer against the evidence
Query plan. Every graph call, code step and model call, with its time and the slowest call flagged. The facts are worked out in code; the model call is shown with its tokens in and out; the answer is then checked against the evidence.
The evidence pane: nodes such as the CISA known-exploited record and the NVD entry, each with why it is there and its hop, and the graph context path from the CVE through the weakness to the techniques
Evidence pane. Each node with its kind, why it is there and its hop, the share of cited ids that were verified, and the graph path from the CVE through the weakness to the ATT&CK techniques.

Two ways in

One graph, two products

Both answer from the same graph of public sources. Every link says which source stated it, or that it was inferred.

For analysts

Lattice Analyst

A chat for SOC specialists. Paste an alert, an email, logs or a list of CVEs, or ask about a CVE or a technique.

  • Verdict first, then the evidence and the steps
  • Triage, investigate, respond and improve recipes
  • A query plan that shows every call and its time

For developers and agents

Lattice MCP

A Model Context Protocol server with seven read-only tools over the graph, for Claude, Cursor and any MCP client.

  • Look up a CVE, technique, weakness or group
  • Follow links, with the source of each
  • Fixed multi-hop questions such as CVE to detections

Lattice Analyst

The assistant that shows its work

Facts, verdicts and structure are written in code from the graph. A small local language model only words the explanation, and a person always decides.

Verdict first

Every answer opens with a clear label and the reasons, so you can act or escalate without reading a wall of text.

Evidence you can check

A query plan lists every graph call and model call with its time, and an evidence panel shows the nodes behind the answer.

Honest about gaps

It never says “safe” and never claims something happened on your systems. Each answer lists what is missing.

Local model

Answers are written with a local language model. No external AI service is called.

Ask about any CVE

The verdict line is written from CISA's record in code: whether it is exploited, whether ransomware use is recorded, the deadline and the fixed versions. The model then explains in plain words, and its steps are checked before you see them.

  • Query plan with timing for every call
  • Evidence panel with the source of each link
  • One tap to a checklist, hunt or containment plan
Analysis of CVE-2021-44228 with a verdict line and a query plan

Triage what you paste

Alerts get a label (contain now, escalate, investigate, monitor or need more information) from behaviour rules, with the technique behind each finding and what to check next. Emails are judged by structure, such as failed sender checks and look-alike domains, not by wording alone.

  • No model is used for the verdict
  • A claim of approval is to be verified, never believed
  • Containment steps are suggestions for a person to approve
The Lattice Analyst home with recipe buttons and the zero-day and ransomware watch lists

Draft, review, copy

Detection rules, messages and incident reports are drafted from reviewed templates and the facts you pasted. Anything unknown stays a visible blank, and code blocks have a Copy button.

  • Sigma rule drafts with their false positives
  • Management, user and customer message drafts
  • A post-incident report in a copyable block
A Sigma rule draft with a Copy button

The activities an analyst repeats every day

StageRecipes
TriageToday's briefing · Triage an alert · Triage an email · Triage scanner output
InvestigateBuild a timeline from logs · Investigation checklist · Hunt hypotheses · What usually follows
RespondDraft the messages · Containment plan · Ask the runbook · Which CVEs to patch first
ImprovePost-incident report · Draft a detection rule
PersonalMy products: save what you run in your browser, then ask “Does this CVE affect me?”

On the desk and on the phone

The chat works on a phone as well as on a desktop, follows the light or dark system theme and can be installed as an app. Your conversation stays in the page: go Home to the watch lists and come back to it.

Alert triage on a phone in dark mode

Lattice MCP

A cyber knowledge graph for your AI agent

Give an agent reference answers it can cite. It looks up an id, follows the links and reports where each fact came from, instead of filling gaps from memory.

Look up and follow links

Find a CVE, technique, weakness or threat group by its id, then walk to the techniques, detections and procedures connected to it.

Provenance on every link

Each link is declared by a named source or inferred, and inferred links carry a confidence figure that ranks guesses against each other.

Honest about gaps

A step with no data, or from a source that is not published, is reported as a gap.

Licence notices included

Responses can return the licence and attribution requirements of the sources they used.

Install

Endpoint: https://lattice.namiq.io/mcp over streamable HTTP. Send your key in the X-API-Key header. initialize and tools/list work without a key, so you can see the tools before you sign up.

claude mcp add --transport http lattice https://lattice.namiq.io/mcp --header "X-API-Key: YOUR_KEY"

Get a key. Sign up in the Lattice Analyst to receive a trial key. Keys are rate limited, and verifying your account raises the limits. Also listed in the official MCP Registry as io.namiq/lattice.

Tools

ToolWhat it does
graph_lookup(id, label?)Find nodes by exact external id, such as CVE-2021-44228 or T1059.001.
graph_search(id_prefix, label?, limit?, cursor?)List ids that start with a prefix. Ids only, not free text; page with cursor.
graph_node(uid)One node's properties.
graph_neighbors(uid, direction?, verb?, label?, limit?, cursor?)Directly connected nodes with each link's verb, source and whether it is declared or inferred.
graph_path(template, id, label?)A fixed multi-hop question from an external id.
graph_notices(ids?)Licence notices and attribution for the sources used.
graph_meta()Snapshot id, labels, verbs, sources and path templates.

Path templates: cve-to-defense (techniques a CVE enables, then detections and procedures), cve-context, technique-coverage, weakness-chain, actor-ttps.

Example prompts

  • “Look up CVE-2021-44228. Which ATT&CK techniques does the graph associate with it, and for each say whether a source declared the link or it was inferred.”
  • “For T1059, what detections does the graph hold, and which sources do they come from?”
  • “What does the graph not know about CVE-2024-10001? List every step that came back empty or unpublished.”

Trust and safety

Designed so a person stays in charge

What it will not do

It will not say something is safe, close a ticket, send a message or run an action. It cannot see your systems, so every answer says what to verify. Drafts are labelled as drafts and unknown facts are left blank.

Privacy by design

The list of products you run is kept in your browser and is sent only inside a question about exposure. The service does not keep what you paste.

Public sources, with notices

Answers rest on public cybersecurity sources, and each link states which source said it or that it was inferred.

Read-only

The graph is reference data. Nothing in it or in the tools changes your systems.

Data, not instructions

Returned text is data from public sources. Agents should never follow instructions found in it.

FAQ

Common questions

Does it connect to my SIEM or scan my network?

No. It works on what you paste and on public data. It cannot tell you whether you are affected, exploited or covered by a rule.

Which AI model does the Analyst use?

A local language model, with no external AI service. The model words the explanation; verdicts, facts and structure are written in code.

How do I get access?

Open the Lattice Analyst and sign up for a trial key. The same key works for the MCP server. Keys are rate limited, and verifying your account raises the limits.

Can I use it for bulk extraction?

No. The graph is for answering questions, and a cap on the nodes retrieved stops large retrievals. For unlimited or commercial use, contact contact@namiq.io.

Is it production ready?

It is in private beta, provided as is, with no warranty and no service level, under the Lattice beta terms.

Try it on your own alert

Paste something you triaged today and compare.