State-sponsored actor infrastructure
🔄 Pivot:📁 Nation-State
Malware
Ransomware
APT / Targeted
Nation-State
Trojan / Banker
Infostealer
Loader / Dropper
RAT
C2 / Beacon
Botnet
Cryptominer
Backdoor / Webshell
Spyware
Wiper
Phishing
Exploit / CVE
Scanner / Recon
DDoS
Tor / Dark Web
Proxy / VPN
Spam / Malspam
Crypto
Sanctions
Organized Crime
Fraud / Scam
Threat Hunting
Total Nation-State
0
New (7d)
0
Types
0
This theater matches on attribution signals (actor, malware family, auto-assigned tags). If it looks empty, run the Auto-Tag Engine and Resolve Everything to populate them, then reload.
30-Day Trend
Type Mix
Top Nation-State Indicators Export
| Indicator | Type | Category | Sightings | Threat | Actions |
|---|---|---|---|---|---|
| No Nation-State indicators yet. | |||||
Nation-State Resources
↗ CISA Advisories — Nation-state alerts ↗ OFAC SDN List — Sanctioned entities ↗ NSA Cybersecurity Advisories — Joint advisories ↗ MITRE ATT&CK Groups — State-sponsored TTPs ↗ Google TAG — Gov-backed threat trackingAI Skills & Automation
🧠 Correlate IOCs with sanctioned entities
🧠 Summarize the advisory and required mitigations
🧠 Build a briefing for leadership
🔍 Pivot & investigate
🏹 Related theaters & actors
🧩 Advanced Capabilities
🔐 Detection & sharing
📜 Playbook — Nation-State response
- Direction — frame the requirement for Nation-State: what decision does this support, by when?
- Collection — triage the 0 Nation-State indicators, corroborate across sources, and action them; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports