# CTIPilot > Swiss public-sector cyber threat intelligence. CTIPilot is a continuous cyber threat intelligence (CTI) pipeline for Swiss government entities (national, cantonal and communal administration, emergency services, police, armed forces): per-finding entries, a time-window brief, source-linked, IOC-free, autonomously generated by an LLM. Fully AI-generated cyber threat intelligence with no human review; every finding cites its primary sources and carries a NATO Admiralty reliability/credibility rating. Audience: Tier 2/3 incident responders, threat hunters and detection engineers, and automated SOC/triage agents. No IOCs are published: entries are TTP/behavior-level knowledge, ATT&CK-mapped in frontmatter. One permalink per finding for its whole life; later developments and corrections are appended as dated changelog records on the same entry, never as duplicates. Generated 2026-09-19 05:46 UTC · 916 entries · 2421 entities · 1122 CVEs on file. ## Reading surfaces - [Live brief](https://ctipilot.ch/): the landing page, everything verified or updated in the last 24 h, newest first - [Daily briefs](https://ctipilot.ch/daily/): the settled record of each UTC day (latest: https://ctipilot.ch/daily/2026-09-18/) - [Recent changes](https://ctipilot.ch/changes/): every dated development, correction and improvement, store-wide - [Entries](https://ctipilot.ch/entries/YYYY-MM-DD/slug/): one permalink per finding with full changelog and revision history - [Entities](https://ctipilot.ch/entities/): actors, campaigns, malware, incidents, with typed, sourced relationships - [CVEs](https://ctipilot.ch/cves/): every vulnerability on file with its appearance trail - [ATT&CK](https://ctipilot.ch/attack/): technique coverage matrix, Navigator-layer exports - [Sources](https://ctipilot.ch/sources/): the curated source catalogue, reliability-rated - [About](https://ctipilot.ch/about/): how the pipeline works, docs and the runtime prompts ## Machine endpoints (prefer these over scraping HTML) - [briefbook.json](https://ctipilot.ch/data/briefbook.json): last 35 days of entries + runs as JSON; each entry carries `url` and `markdown_url` - Raw entry Markdown: append `index.md` to any entry permalink (https://ctipilot.ch/entries/YYYY-MM-DD/slug/index.md) for the exact source file, frontmatter + body - [search.json](https://ctipilot.ch/data/search.json): site-wide search index (days, entries, entities, techniques, sources) - [alerts.json](https://ctipilot.ch/data/alerts.json): last-7-days critical/high entries - [RSS](https://ctipilot.ch/feeds/): daily digest, per-entry (one item per changelog record too), and sector-sliced feeds - [STIX 2.1](https://ctipilot.ch/stix/): full / recent / entity-graph / per-sector bundles with stable ids - [sitemap.xml](https://ctipilot.ch/sitemap.xml)