For NCA & SAMA-regulated institutions

See which actively-exploited threats and regulated exposures put your institution at risk — today.

RaqibCTI tracks the MENA-regional actors targeting your sector, maps actively-exploited (KEV) vulnerabilities to the groups using them, and turns that exposure into NCA/SAMA-ready compliance evidence. Free and open for the MENA security community.

Free to browse — no account needed · Your own private, isolated workspace when you sign up
app.raqibcti.com/landscape

Threat Landscape

MENA · updated 04:00 UTC ✓
109
Regional actors
5
Targeting your sector
12
MENA KEV
3
KEV on your stack
Who’s targeting you · mapped to exploited exposure
UNC1549 — aerospace & finance targeting in the GulfACTIVE
MuddyWater — new C2 infrastructure, gov & telecomACTIVE
CVE-2023-27997 (KEV) — exploited by groups active in your sectorEXPOSED
Qilin ransomware — Gulf victim claims this quarterCLAIM
Built for SOCs across the regionBankingEnergyTelecomGovernment
◦ THE PLATFORM

From regional actor to regulator-ready evidence.

Curated, sourced regional intelligence — one platform from who’s targeting your sector to the evidence your auditor asks for.

Who’s targeting you

109 MENA-regional groups with Diamond Model, Kill Chain, ATT&CK techniques, and sector-targeting history — filtered to the ones that matter to you.

KEV → actor exposure

Actively-exploited vulnerabilities (CISA KEV) tied to the actors using them against the region — so "patch this" comes with "because this group is exploiting it here".

NCA/SAMA compliance lens

Map threats and controls to NCA ECC and SAMA CSF, and export the evidence your regulator and auditors ask for.

Alerts that matter

High-confidence signals tied to your requirements — not a firehose. Each says why it matters and what to do next.

Threat & IOC graph

Pivot hashes, domains, and IPs to the actors behind them. Correlation is never sold as confirmation.

Fits your stack

STIX 2.1 bundles for your SIEM, SOAR, or TIP. TLP-marked, no rip-and-replace.

Your workspace

A private, isolated workspace of your own — free.

Anyone can read the shared regional corpus. Create a free account to complete the picture: your requirements, alerts, threat profile, and compliance evidence, visible only to you.

  • Isolated by default. Your data is separated in the database itself — no other account can ever see it.
  • NCA/SAMA compliance mapping with exportable evidence, and STIX 2.1 export — no rip-and-replace.
  • Yours in seconds. Sign up free and your workspace is provisioned instantly — no sales call, no trial clock.
Example workspaces
R
Regional bank · SOC analyst
Private workspace
E
Energy-sector CTI analyst
Private workspace
C
National CERT analyst
Private workspace

Know your exposure before your regulator asks.

Free and open for the MENA security community. Browse the shared picture with no account, or create a free account for the full analyst workspace.

Create a free account →