An analytic instrument correlating public ransomware claims into adversary behavior patterns and tactical playbooks over a selectable analysis window.
Panels include provider-asserted group relationships, a repeat-victim radar, contested and multi-group claims, an attack-playbook matrix with MITRE ATT&CK technique definitions and attribution, most-exploited CVEs with CISA KEV and EPSS context, and sector crosshairs. Everything is an analytic view of public claims — not proof of attacks, attribution, or causation.
The lab correlates canonical claim records over a selectable analysis window anchored to the latest observation. Panels include provider-asserted group relationships, a repeat-victim radar, contested and multi-group claims, an attack-playbook matrix with MITRE ATT&CK technique definitions and attribution, most-exploited CVEs with CISA KEV and EPSS context, and sector crosshairs.
Enrichment sources are labeled and bounded: ATT&CK, KEV, EPSS, and threat-intel aggregates provide defensive context around the claims, and enrichment never verifies a claim or adds corroboration. Every panel is an analytic view of public claims — not proof of attacks, attribution, or causation.
Example reading: a CVE ranked high in the most-exploited panel with a KEV listing and high EPSS score is well-supported context for patch prioritization. The supported statement is about the CVE's ecosystem prominence — not that any specific claimed victim was compromised through it.
Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.