Intelligence Lab

An analytic instrument correlating public ransomware claims into adversary behavior patterns and tactical playbooks over a selectable analysis window.

Panels include provider-asserted group relationships, a repeat-victim radar, contested and multi-group claims, an attack-playbook matrix with MITRE ATT&CK technique definitions and attribution, most-exploited CVEs with CISA KEV and EPSS context, and sector crosshairs. Everything is an analytic view of public claims — not proof of attacks, attribution, or causation.

How the Intelligence Lab panels work

The lab correlates canonical claim records over a selectable analysis window anchored to the latest observation. Panels include provider-asserted group relationships, a repeat-victim radar, contested and multi-group claims, an attack-playbook matrix with MITRE ATT&CK technique definitions and attribution, most-exploited CVEs with CISA KEV and EPSS context, and sector crosshairs.

Enrichment sources are labeled and bounded: ATT&CK, KEV, EPSS, and threat-intel aggregates provide defensive context around the claims, and enrichment never verifies a claim or adds corroboration. Every panel is an analytic view of public claims — not proof of attacks, attribution, or causation.

Example: reading this page correctly

Example reading: a CVE ranked high in the most-exploited panel with a KEV listing and high EPSS score is well-supported context for patch prioritization. The supported statement is about the CVE's ecosystem prominence — not that any specific claimed victim was compromised through it.

Frequently asked questions

Where do the MITRE ATT&CK techniques come from?
From provider-published group playbook data mapped to ATT&CK technique identifiers, with definitions and attribution from the official ATT&CK knowledge base. A technique in a group's matrix is a reported association, not per-incident forensics.
What is the repeat-victim radar?
A panel surfacing organizations named in more than one observed claim within the analysis window — across groups or repeatedly by one group — as candidates for closer study via the case file.
Do the CVE rankings mean my organization is at risk?
They describe which vulnerabilities appear most in reported ransomware context, with KEV and EPSS as defensive prioritization signals. The tracker computes no organization-level risk scores.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.