A Google sheet spreadsheet containing a comprehensive list of APT groups and operations, providing a reference for tracking and mapping different names and naming schemes used by cybersecurity companies and antivirus vendors. The spreadsheet includes tabs for different countries and regions, as well as an 'Unknown' tab for groups with no attribution. It also highlights overlaps between different groups and provides a search function for easy lookup. The spreadsheet is licensed under CC Creative Commons - Attribution 4.0 International (CC BY 4.0) and is open for contributions from threat intel researchers, malware analysts, and vendor representatives.
FEATURES
ALTERNATIVES
The Ransomware Tool Matrix is a repository that lists and categorizes tools used by ransomware gangs, aiding in threat hunting, incident response, and adversary emulation.
A PowerShell script to interact with the MITRE ATT&CK Framework via its own API using the deprecated MediaWiki API.
ONYPHE is a cyber defense search engine that discovers exposed assets and provides real-time monitoring to identify vulnerabilities and potential risks.
Sigma is a generic and open signature format for SIEM systems and other security tools to detect and respond to threats.
ThreatMiner is a threat intelligence portal that aggregates data from various sources and provides contextual information related to indicators of compromise (IOCs).
In-depth threat intelligence reports and services providing insights into real-world intrusions, malware analysis, and threat briefs.
Open Source Intelligence solution for threat intelligence data enrichment and quick analysis of suspicious files or malware.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.