Track adversary tradecraft via ATT&CK Groups (G-IDs) and Software (S-IDs). 130+ threat groups documented including APT1 (PLA Unit 61398) + APT28 Fancy Bear (Russia GRU) + APT29 Cozy Bear/Midnight Blizzard (Russia SVR) + APT38 Lazarus financial (DPRK) + APT41 Wicked Panda (China Civilian/PLA) + FIN7 financial crime + Conti ransomware + LockBit + ALPHV BlackCat + Scattered Spider + Sandworm (Russia GRU disruptive) + Volt Typhoon (China ICS prepositioning) + Salt Typhoon (China telco) + Storm-0501 + Charming Kitten APT35 + Pioneer Kitten + MuddyWater + APT34 + Equation Group + Turla + Comment Crew. 700+ Software tools including dual-use (Cobalt Strike + Mimikatz + Empire + Metasploit + ProcDump + WMIExec + PsExec + Sliver + Brute Ratel C4 + Havoc) + malware (Emotet + TrickBot + Qakbot + Pikabot + Latrodectus + WikiLoader + Akira + RansomEXX + BlackByte + AsyncRAT + Remcos + AgentTesla + Snake Keylogger). Threat actor tracking integration with MISP + ThreatConnect + Anomali + Recorded Future + Mandiant Advantage + CrowdStrike Falcon Intelligence + Microsoft Threat Intelligence Center (MSTIC) + Talos + Unit 42 + Sophos X-Ops + Trend Micro Research + Kaspersky GReAT + ESET Research + SecureWorks Counter Threat Unit (CTU). Threat intelligence prioritisation using ATT&CK Group profiling + ATT&CK Navigator overlay + STIX 2.x exchange.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.