Threat Theaters

✈️ Aviation Security theater

Civil-aviation security across cyber and physical vectors: ADS-B spoofing, GPS-loss reroutes, airline/airport IT and ACARS exposure, drone incursions, and aerospace-sector espionage. Failures here carry mass-casualty and economic-shutdown potential.

Live indicators

3.7K
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

3
documented

Mapped sources

3
in catalog

🦠 Malware & Tools

PoshC2POWERTONCobalt Strike

🛡 Exploited Vulnerabilities

CVEVendor / ProductRansomwareMalware
CVE-2020-3433Cisco AnyConnect SecureKNOWNransomware (KEV-flagged)

📜 Aviation Security Playbook

  1. Stream ADS-B (OpenSky/ADS-B Exchange) and NOTAM/GNSS-outage data into a flight-safety picture.
  2. Detect ADS-B spoofing, GPS-loss reroutes, and airspace intrusions near conflict and airport zones.
  3. Analyze airline/airport IT and ACARS/ARINC exposure alongside physical drone and hijack threats.
  4. Attribute aerospace-sector intrusions to actors (APT33, APT41, Lazarus) via TTPs and malware overlap.
  5. Brief airline security, EASA/ICAO, and crews with route-risk and cyber-advisory bulletins.
  6. Recommend rerouting, GNSS-jamming NOTAMs, system patching, and counter-UAS deployment.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Add to case

Attach Aviation Security (Mission Domain) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php