APT-attributed indicators & campaigns
🔄 Pivot:📁 APT / Targeted
Malware
Ransomware
APT / Targeted
Nation-State
Trojan / Banker
Infostealer
Loader / Dropper
RAT
C2 / Beacon
Botnet
Cryptominer
Backdoor / Webshell
Spyware
Wiper
Phishing
Exploit / CVE
Scanner / Recon
DDoS
Tor / Dark Web
Proxy / VPN
Spam / Malspam
Crypto
Sanctions
Organized Crime
Fraud / Scam
Threat Hunting
Total APT / Targeted
0
New (7d)
0
Types
0
This theater matches on attribution signals (actor, malware family, auto-assigned tags). If it looks empty, run the Auto-Tag Engine and Resolve Everything to populate them, then reload.
30-Day Trend
Type Mix
Top APT / Targeted Indicators Export
| Indicator | Type | Category | Sightings | Threat | Actions |
|---|---|---|---|---|---|
| No APT / Targeted indicators yet. | |||||
APT / Targeted Resources
↗ MITRE ATT&CK Groups — APT group TTP profiles ↗ MITRE ATT&CK Navigator — TTP heatmaps ↗ Mandiant APT reports — Threat actor research ↗ MISP galaxy: threat-actor — Actor aliases & mapping ↗ ETDA APT groups & ops — Encyclopaedia of actors ↗ Malpedia actors — Actor/malware mappingAI Skills & Automation
🧠 Attribute activity to a known APT by TTP overlap
🧠 Summarize campaign infrastructure and pivots
🧠 Generate hunt queries for the actor's techniques
🔍 Pivot & investigate
🏹 Related theaters & actors
🧩 Advanced Capabilities
🔐 Detection & sharing
📜 Playbook — APT / Targeted response
- Direction — frame the requirement for APT / Targeted: what decision does this support, by when?
- Collection — triage the 0 APT / Targeted indicators, corroborate across sources, and action them; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports