Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| Rhysidaactor | Uses | Drive-by Compromisetechnique | — | ATT&CK mapping | — |
| Sea Turtleactor | Uses | Remote Data Stagingtechnique | — | ATT&CK mapping | — |
| Dust Specteractor | Uses | Data Encoding: Standard Encodingtechnique | — | ATT&CK mapping | — |
| HEXANE (Lyceum)actor | Uses | Credentials from Password Storestechnique | — | ATT&CK mapping | — |
| Fox Kittenactor | Uses | Data from Network Shared Drivetechnique | — | ATT&CK mapping | — |
| Qilin (fka Agenda)actor | Uses | Query Registrytechnique | — | ATT&CK mapping | — |
| Qilin (fka Agenda)actor | Uses | Remote Services: SSHtechnique | — | ATT&CK mapping | — |
| HEXANE (Lyceum)actor | Uses | Email Accountstechnique | — | ATT&CK mapping | — |
| LockBit / LockBit 3.0actor | Uses | Execution Guardrailstechnique | — | ATT&CK mapping | — |
| HEXANE (Lyceum)actor | Uses | Visual Basictechnique | — | ATT&CK mapping | — |
| Earth Bogleactor | Uses | Obfuscated Files or Informationtechnique | — | ATT&CK mapping | — |
| Flame / Flameractor | Uses | Data from Local Systemtechnique | — | ATT&CK mapping | — |
| Medusaactor | Uses | Software Discovery: Security Software Discoverytechnique | — | ATT&CK mapping | — |
| MuddyWateractor | Uses | Spearphishing Linktechnique | — | ATT&CK mapping | — |
| unc5691actor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| bauxiteactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| CyberAv3ngersactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| shahid-kaveh-groupactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| storm-0784actor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| hydro-kittenactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| soldiers-of-solomonactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| irgc-cecactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| apt-iranactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| mr-soulactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| cyber-av3ngersactor | Targets | Rockwell Multiple Products Insufficient Protected Credentials Vulnerabilitycve | — | Rockwell | 2026-03-05 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Cl0pactor | — | ORKL | 2023-09-29 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2023-09-29 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2024-02-15 |
| TLP-CLEAR-From-espionage-to-PsyOps-Tracking-operations-and-infrastructure-of-UACs-in-2025-EN-1.pdfreport | Related to | RansomHubactor | — | ORKL | 2025-03-28 |
| Chinese APT: A Master of Exploiting Edge Devicesreport | Related to | Cleaveractor | — | ORKL | 2024-04-12 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Nemesis Kittenactor | — | ORKL | 2024-02-08 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | HEXANE (Lyceum)actor | — | ORKL | 2024-02-08 |
| Mandiant M-Trends 2025 Reportreport | Related to | MuddyWateractor | — | ORKL | 2025-04-24 |
| Mandiant M-Trends 2025 Reportreport | Related to | UNC1860actor | — | ORKL | 2025-04-24 |
| Kinsing Demystified A Comprehensive Technical Guidereport | Related to | Cleaveractor | — | ORKL | 2024-05-03 |
| Arid Viper poisons Android apps with AridSpyreport | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2024-07-25 |
| eset-apt-activity-report-q4-2025-q1-2026.pdfreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2026-05-22 |
| rapid7-threat-landscape-report-2026.pdfreport | Related to | RansomHubactor | — | ORKL | 2026-03-17 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-02-08 |
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | CyberAv3ngersactor | — | ORKL | 2026-03-25 |
| eset-apt-activity-report-q4-2025-q1-2026.pdfreport | Related to | MuddyWateractor | — | ORKL | 2026-05-22 |
| ESET APT Activity Report Q4 2024-Q1 2025report | Related to | HEXANE (Lyceum)actor | — | ORKL | 2025-05-12 |
| Iranian Cyber Actors May Target Vulnerable US Networks and Entities of Interestreport | Related to | CyberAv3ngersactor | — | ORKL | 2025-06-27 |
| Mandiant M-Trends 2025 Reportreport | Related to | Cyber Toufan (Al-Aqsa)actor | — | ORKL | 2025-04-24 |
| ShadowSyndicate infrastructure illuminationreport | Related to | RansomHubactor | — | ORKL | 2025-08-01 |
| From Albania To The Middle East: The Scarred Manticore Is Listeningreport | Related to | Scarred Manticore (Storm-0861)actor | — | ORKL | 2023-12-12 |
| Operation 99 North Korean State Sponsored Supply Chain Attack on Tech Innovationreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-01-14 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-02-15 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Anonymous Sudanactor | — | ORKL | 2023-09-29 |
| Down the Grayrabbit Hole – Exposing UNC3569 and its Modus Operandireport | Related to | Cleaveractor | — | ORKL | 2024-09-24 |