Threat Intelligence & OSINT
See what attackers can already learn about your organization before they turn it against you.

Attackers use publicly available information to craft highly targeted social engineering attacks. revel8 Threat Intelligence and OSINT gives you visibility into your organization's human attack surface, so you know your exposure before attackers do. Here is how it works.
How Threat Intelligence and OSINT works
1. Map your public footprint
revel8 looks at the information about your organization and employees that is publicly available, the same sources attackers use to prepare their attacks.
2. Identify exposed people and roles
See which employees and roles are especially visible and therefore especially attractive targets.
3. Understand what attackers could do with it
Translate exposure into realistic attack scenarios, for example personalized phishing or impersonation of executives.
4. Feed insights into realistic simulations
Use the findings to make your awareness simulations more realistic and relevant to your actual risk.
5. Prioritize what matters
Focus your attention on the exposure that creates the highest risk.
Why OSINT-based threat intelligence?
- Attacker's perspective: see your organization the way attackers do.
- Targeted attacks are rising: personalized attacks are built on public information.
- More realistic training: simulations based on real exposure are more effective.
- Clear priorities: know where to act first.
Use cases
- Executive and VIP exposure assessment.
- Preparing for spear phishing and impersonation attacks.
- Making simulations more realistic with real-world context.
Frequently Asked Questions.
Which channels does revel8 simulate?
Email, voice calls, SMS, WhatsApp, Telegram, Teams, and deepfake video: the same channels attackers actually use. Simulations can also run multichannel, starting in the inbox and escalating to a call, exactly as a real attack would.
Where does revel8's threat intelligence come from?
revel8 continuously pulls from multiple threat intelligence sources and prioritises the most relevant first. That's enriched by patterns reported by customer security teams and scenarios shared by other users, so one team's frontline experience becomes protection for everyone.
Can I generate my own training content?
Yes. Drop in a policy, a control document, or a compliance requirement and the AI builds a complete, on-brand module from it. You keep full control: reshape any slide, swap any visual, and rewrite any interaction until it reads the way your organisation communicates.
How do employees report suspicious messages?
In one click, through buttons in Gmail, Outlook, and on mobile, with instant feedback. A separate phone reporting app extends this to calls, SMS, and WhatsApp, deployed silently to managed devices over MDM.
What does revel8 do for a contact center?
It secures the contact center end to end. revel8 pentests your AI support agents for weaknesses the way a real adversary would, and runs voice attack simulations that train your human agents against the calls built to fool them.
Is SSO supported?
Yes. revel8 offers passwordless single sign-on through your existing identity provider, so employees get access without another set of credentials to manage.
Are revel8's deepfake and voice cloning tools free?
Yes. Both the Deepfake Simulation and the Voice Phishing (Vishing) Simulation are completely free to use.
What is AI-generated security awareness training?
AI-generated security awareness training uses artificial intelligence to create training content based on a defined learning objective. Instead of choosing from a fixed catalog, security teams describe what employees should learn and the AI builds a tailored module around it.
What is the revel8 Awareness Playlist?
The Awareness Playlist is an automated awareness program that delivers personalized, multi-channel simulations and trainings to each employee.
What is vishing?
Vishing is voice phishing: attackers call employees and use social engineering to obtain information, access or payments.
What is OSINT?
OSINT stands for open-source intelligence: information gathered from publicly available sources.
What is human cyber risk?
Human cyber risk describes how likely employees are to fall for social engineering and other attacks that target people rather than systems.
How are simulations created?
Threat Composer turns a one-line brief into a ready-to-run, multichannel simulation in minutes. Each one is grounded in real OSINT context, drawn from a catalog that stays current with live threats, and auto-translated for every region.
What is OSINT and why does it matter for simulations?
OSINT is the public footprint an attacker can already build about your organisation and people: leaked credentials, exposed infrastructure, vendor relationships, tooling from job posts, and public roles and posts. revel8 maps this and uses it as the pretext material behind each simulation, so every attack mirrors one that could actually reach you.
Does the training work across languages and teams?
Yes. Modules can be localised in 40+ languages, and learning paths adapt by role, so finance gets invoice fraud, developers get secure coding, and executives get deepfake awareness. The right content reaches the right people at the right level, automatically.
Won't more reports just mean more work for my team?
No. Every report is automatically enriched with relevant threat intelligence and the reporter's credibility, then scored and triaged. The volume is handled before anyone has to look at it.
How do you test our AI agents?
revel8 maps the full attack surface across every channel your agents operate on, flags the nodes most likely to be vulnerable or carry high exploit risk, then tests each one with the latest agentic prompt-injection techniques. The technique library stays current as new attacks emerge.
Is SCIM supported?
Yes. Connect Google, Microsoft, or your own SCIM provider and revel8 keeps your employee directory and its attributes in sync, with automatic provisioning, role changes, and offboarding. Setup takes a few guided steps, not a project.
How long does it take to create a deepfake or voice clone?
Only a few minutes. With the Deepfake Simulation you create your own deepfake in under two minutes. With the Voice Phishing (Vishing) Simulation your AI voice clone is ready within seconds after a short recording.
Can security awareness training be customized to company policies?
Yes. With revel8 you can connect relevant internal security policies, so the generated training reflects your company's actual procedures rather than generic best practices.
Which channels does the Awareness Playlist cover?
Simulations can run across email, SMS, voice and video, reflecting how modern social engineering attacks reach employees.
How do AI vishing simulations work?
revel8 places realistic AI-powered calls to agents and checks whether they follow the correct verification steps.
Why does OSINT matter for security awareness?
Attackers use public information to make social engineering attacks more convincing. Knowing your exposure helps you prepare employees for the attacks they are most likely to face.
How is human risk measured?
revel8 uses how employees respond to realistic simulations to build a picture of risk across the organization.
Do you support custom simulations?
Yes. Every element of every simulation is editable, and you can build your own from scratch. No locked libraries and no template walls.
Do you collect personal information on our employees?
Personal OSINT is surfaced only for your highest-risk people and collected only with consent. It's used to make simulations realistic, never for individual surveillance.
How do employees get help with policy questions during training?
Every module has an embedded assistant. Employees can ask anything about your security policies and get a clear, specific answer on the spot, without leaving the training.
Is the monitoring compliant with GDPR and works-council requirements?
Yes. Completion records and reporting logs map to NIS-2, DORA, and ISO 27001, and the system is works-council conform with no individual surveillance, GDPR-safe by design. You can export everything via API, PDF, or CSV.
How do the voice simulations work without disrupting live operations?
revel8 navigates your phone trees and menu options on its own so each simulation reaches agents smoothly, using AI-generated voices, scripts, and pretexts modelled on real attacks. You can run across thousands of agents, scheduled for off-peak windows and routed around business-critical shifts.
Can employees report suspicious emails from inside their inbox?
Yes. Native Outlook and Gmail buttons let employees report a suspicious mail in one click, right where they already work. You roll the plugins out through your existing deployment process.
What happens to my voice and video recordings?
Your photo and voice recording are used solely to create your personal deepfake or voice clone demo and to send it to you. They are automatically deleted within 24 hours, together with any derived files such as the voice profile or call recording. The generated demo clip is deleted within 7 days, or earlier on request.
revel8 does not use your data to train AI models, and our service providers are contractually bound not to do so either. More details on legal bases, processors and your rights are in our Privacy Policy.
Can training be generated in multiple languages?
Yes. You choose the languages your workforce needs, so employees in different countries can complete the same training in their own language.
Is every employee's playlist the same?
No. Playlists are personalized, so employees receive simulations that are relevant to their role and situation.
Can the Contact Center Module be used in several languages?
Yes. It is designed to scale across multiple countries and languages.
How are the OSINT insights used?
They help you understand your human attack surface and make awareness simulations more realistic.
What happens with the risk monitoring results?
They are used to target training where it matters most and to track improvement over time.
What happens after an employee falls for a simulation?
Every simulation ships with a matching 60-second lesson, draftedI for that exact scenario. Employees learn the moment it's relevant, on the attack they just saw, rather than in a yearly module.
How does the intelligence turn into an actual simulation?
Three steps. revel8 sources and ranks live threats by the risk each group faces, enriches each scenario with your organisational and personal OSINT so it fits the exact recipient, then feeds it into the Awareness Playlist to reach the right people automatically.
Can I customize pre-built training content for my organization?
Yes. Every module in the catalog is fully editable: adjust the copy, swap visuals, and apply your brand to every frame. For topics not in the standard library, the AI builds a fully interactive module from any policy document or regulation text in minutes.
What happens when an agent falls for a simulated attack?
Coaching arrives on the call itself, not in a report a week later. The agent gets the correction in the moment it matters, which is when it sticks.
Can I run training in my own LMS?
Yes. Export any Academy module as SCORM for your own LMS, or deliver it inside revel8 and keep one unified evidence trail. The choice is yours, and either way the completion records stay audit-ready.
How quickly can a new awareness module be created?
Much faster than with manual authoring. Because revel8 generates the outline and content, the main effort for your team is reviewing and approving, which means new topics can be turned into training quickly.
How much effort does the security team need to put in?
After the initial setup, the playlist runs automatically. The team can focus on reviewing results instead of planning individual campaigns.
What do team leads get out of it?
Team leads receive insights from the simulation results that show where agents and processes need support.
Which compliance frameworks does revel8 cover?
revel8 includes maintained training modules for GDPR, NIS-2, DORA, ISO 27001, phishing, and more, updated as regulations change. For anything not in the catalog, the AI drafts a full module from your own policy or control document in minutes.
How does revel8 protect companies against voice cloning and deepfake attacks?
revel8's security awareness platform trains employees with realistic deepfake and vishing simulations across email, phone, SMS and video, so they learn to pause and verify before they act. Combined with clear verification rules, such as confirming payments and sensitive requests via a known, separate channel, this turns your workforce into an active line of defense. See how it works in a personal demo.
Can I review AI-generated training before publishing?
Yes. revel8 shows you an AI-generated outline before the content is created. Your security team can edit it and stays in control of what employees are taught.
How does AI-generated training differ from traditional security awareness training?
Traditional training typically relies on off-the-shelf courses that are the same for every company and are updated infrequently. AI-generated training is tailored to your organization, your policies and current threats, and can be localized and updated much faster.
