AI threat visibility
Adversary behavior, mapped to MITRE ATT&CK.
Every signal classified by an ensemble of detection models — surfaced against a live tactic-by-technique matrix.
Techniques observed (24h)
Active threat actors
Model precision
False positive rate
MITRE ATT&CK · Enterprise
Technique heat map
Cell intensity reflects observation count in the last 24 hours.
Initial Access
Execution
Persistence
Privilege Esc.
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
Anomaly timeline
Behavioral drift signal
AI classification stream
Model verdicts
Spear-phish (0.97)
phish-bert-v9 → exec-mailbox-04
Lateral · Pass-the-Hash (0.92)
graph-anomaly-3 → win-bld-srv-12
Data exfil signal (0.81)
egress-llm-2 → vpc-eu-w-2
Insider drift (0.74)
ueba-core-7 → user · k.fischer
Cobalt-Strike beacon (0.99)
malware-cnn-5 → fin-db-prod-04
DNS tunneling (0.88)
dns-tx-rnn → edge-pop-sgp
Privilege escalation attempt (0.85)
iam-gpt-1 → svc-account-build
Threat actor tracker
Adversary clusters
Actor
STORM-1098
Likely state-aligned · EE
92
Confidence
28
TTPs
14m ago
Seen
Actor
INK-MIRAGE
Cybercrime collective
78
Confidence
19
TTPs
2h ago
Seen
Actor
VELVET-OWL
Insider-adjacent broker
64
Confidence
12
TTPs
9m ago
Seen
Actor
CITRINE-04
Ransomware affiliate
88
Confidence
24
TTPs
37m ago
Seen