Track actors and pivot the graph
Find the threat actors that matter to you, filter by type and country, and pivot across infrastructure and indicators in the graph.
The Actors index is the curated roster of groups active against the region. Each row carries the actor’s type, origin, targeted sectors and recent activity; open one for the full profile with its techniques, campaigns and indicators.
Filter to what matters
Use the filters to narrow by actor type (APT / ransomware / financially motivated) or by country — the same facets appear as quick links in the Knowledge panel. Deep-links work, so /actors?type=apt or /actors?country=Saudi%20Arabia are shareable views.
Pivot in the graph
When you want relationships rather than a list, open the Threat Graph to pivot actor ↔ infrastructure ↔ campaign, or the IOC Graph to cluster indicators and find shared infrastructure. The ATT&CK matrix shows the same actors’ techniques as a heatmap of what MENA actors use most — that is threat prevalence, not your own detection coverage. Signed in, Detection Inventory overlays your detections on the same matrix. Together they turn a name into a picture of how a group actually operates.
Attribution is provisional: the Attribution Changelog records when and why an actor’s attribution or aliasing changed, so a pivot never rests on a name treated as settled fact.