Threat group directory
A static, alphabetical index of every named threat group in the MITRE ATT&CK knowledge base, one page each. No JavaScript, no search box to fight: pick a letter range and read. If you would rather filter and compare interactively, the ATT&CK Group Profiler does that on the same dataset.
- 174 profiles
- 97 with an attributed origin, across 8 countries
- 71 with tracked indicator data
- ATT&CK v19.1
What is on each profile
- Every name the industry uses. Each alias is listed with the report that first used it, so you can tell which vendor calls the actor what before you assume two reports describe two groups.
- Distinctive techniques, not just techniques. Each group's ATT&CK techniques are scored against how many other tracked groups use them, so the rare ones (the ones that actually carry signal) are separated from the near universal.
- Closest groups by technique overlap. Computed from shared ATT&CK techniques. Overlap is not attribution, but it is a useful pivot.
- Tracked indicators where they exist. Malware families attributed to the group with the number of indicators observed from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.
Related
Interactive ATT&CK Group Profiler for heat maps, shared TTPs and Navigator layer export · APT IOC aggregator to copy indicators by hash, domain, IP or URL · Single-page read-only lookup if you want every group inlined in one document · All analyst tools