Glossary — Dragons Eye tracker terms

What the tracker's words mean — and, just as important, what they do not claim. Everything in Dragons Eye describes provider observations of group-published claims; no term below implies a verified attack.

Provider-observed (also seen as: observation, OBS)
Recorded because one of our monitored leak-site data providers observed it. Every record is something a provider saw a group publish — not something Dragons Eye verified happened.
Claim (also seen as: victim claim, allegation)
A group-published allegation that an organization was attacked, posted on the group's leak site. We report what the group posted, not what actually happened. Claims are unverified criminal allegations.
Canonical (also seen as: canonical record, canonical name)
The single merged identity we keep when several providers report the same group or victim under different names or spellings. All approved aliases collapse into one canonical record, and each record stays traceable back to the provider observations that produced it.
Alias (also seen as: approved alias)
An alternate name or spelling a provider uses for a group we already track. Approved aliases map to the group's canonical name so renames and re-spellings don't split one operation into many.
Corroboration (also seen as: corroborated)
An independent provider observed the same claim. Corroboration raises confidence that the claim was really posted — it does not verify that the attack occurred. Multiple providers do not verify a claim.
Authority-confirmed (also seen as: authority confirmation)
The claimed organization matches a primary US government breach record (California OAG registry, SEC EDGAR Item 1.05 filing, or HHS OCR breach report) in a matching time window. Confirms a breach was officially recorded — separate from provider corroboration, and it does not verify the group's claim.
LIVE (also seen as: live status, operational status)
A group status meaning the group's leak-site infrastructure was recently observed reachable by our providers. It describes site availability only — it is not evidence of current attack activity.
Coverage telemetry (also seen as: coverage)
Counters showing how much of the tracked ecosystem the current dataset enriches — for example how many groups have enrichment data or uptime monitoring. It measures our visibility, not threat activity.
Partial coverage (also seen as: partial enrichment)
One or more optional enrichment sources are currently unavailable, so some panels may show less context than usual. Canonical claim records remain valid and complete.
Provenance (also seen as: provider provenance)
The record of which providers observed a claim and when. Every canonical record carries its provenance, so you can always trace it back to the original observations.
Co-claim (also seen as: collision, co-claim collision)
Two or more groups named the same victim organization in separate provider-observed claims. Co-claims are overlap evidence only — they never imply coordination, affiliation, or which claim (if any) is genuine.
First blood (also seen as: novel target)
The earliest claim on an organization within the dataset window belongs to this group — no other tracked group claimed it first. It ranks claim order among observed posts, not the first actual compromise.
Contested organization (also seen as: contested orgs)
An organization named in claims by more than one group. Contested status records conflicting allegations — it does not resolve which group, if any, was actually involved.
Contested country (also seen as: contested-country claim)
Providers disagree about a victim's country, or the victim's own leak post contradicts the provider tag. Contested claims are excluded from every named-country surface — maps, country counts, exports, and leaderboards.
Quarantine (also seen as: quarantined)
Rows held out of the public dataset because classifiers flagged them as likely propaganda — for example news headlines or generated prose posted as victim names. Quarantine applies at ingest and retroactively as classifiers improve.
Monopoly Index (also seen as: claim-stream concentration)
A concentration measure of the provider-observed claim stream — how much of the total claim volume the busiest groups account for. It describes posting share, not market control or real-world impact.
Reference data (also seen as: MITRE ATT&CK reference)
General background definitions — like MITRE ATT&CK technique descriptions — that describe adversary behavior in the abstract. Reference data is not observed evidence about any specific group; provider-listed technique mappings reflect provider claims, not Dragons Eye confirmation.

MITRE ATT&CK technique definitions live in the Intelligence Lab playbook matrix, with full attribution. The evidence model behind these terms is documented in the methodology.

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.