Threat group directory
A static, alphabetical index of every named threat group in the MITRE ATT&CK knowledge base, one page each. No JavaScript, no search box to fight: pick a letter range and read. If you would rather filter and compare interactively, the ATT&CK Group Profiler does that on the same dataset.
- 174 profiles
- 97 with an attributed origin, across 8 countries
- 72 carrying live indicator data
- ATT&CK v19.1
What is on each profile
- Every name the industry uses. Each alias is listed with the report that first used it, so you can tell which vendor calls the actor what before you assume two reports describe two groups.
- Distinctive techniques, not just techniques. Each group's ATT&CK techniques are scored against how many other tracked groups use them, so the rare ones (the ones that actually carry signal) are separated from the near universal.
- Closest groups by technique overlap. Computed from shared ATT&CK techniques. Overlap is not attribution, but it is a useful pivot.
- Live indicators where they exist. Malware families attributed to the group with the number of indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
Related
Interactive ATT&CK Group Profiler for heat maps, shared TTPs and Navigator layer export · APT IOC aggregator to copy indicators by hash, domain, IP or URL · Single-page read-only lookup if you want every group inlined in one document · All analyst tools