Threat Theaters

🎭 Fraud & Identity theater

Covers consumer and enterprise fraud — phishing, account takeover, synthetic identity, BEC, OTP-bot, and card fraud — powered by stealer logs, breach corpora, and phishing kits. Protects identities and brands by mapping fraud infrastructure and the crews that run it.

Live indicators

182.9K
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

4
documented

Mapped sources

8
in catalog

📜 Fraud & Identity Playbook

  1. Collect phishing kits, stealer logs, spam feeds, and breach corpora from APWG, PhishTank, and abuse.ch.
  2. Normalize and correlate compromised identities, domains, and ATO infrastructure across campaigns.
  3. Analyze fraud typologies (phishing, synthetic identity, BEC, OTP-bot, card fraud) and phishing-kit lineage.
  4. Attribute operations to fraud crews (Scattered Spider, Black Axe, FIN7) via TTPs and shared infrastructure.
  5. Disseminate takedown packages and victim alerts to registrars, brands, and financial institutions.
  6. Execute domain takedowns, credential resets, and account-takeover blocks.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php