Full Deployment Flow
Clone the repository, configure secrets, start Docker, verify selftest, sync ATT&CK/ATLAS, and connect IOC/rule/enrichment feeds.
Read more →
AI-assisted CTI-to-detection workbench for ATT&CK mapping, group and campaign similarity, detection-gap analysis, and analyst-ready outputs.
AdversaryGraph assists analysts but does not replace analyst validation. TTP overlap is an investigation lead, not attribution proof.
AdversaryGraph Docker is the supported full platform: private AI-assisted extraction, stored analyses, APIs, PDF reports, IOC enrichment, STIX/TAXII/MISP workflows, YARA/Sigma sync, sandbox behavior, and scheduled reference synchronization.
Report content is sent only to the LLM provider configured by the operator. For fully private analysis, use a local or private OpenAI-compatible gateway.
Follow the complete clone-to-feed-sync flow →Clone the repository, configure secrets, start Docker, verify selftest, sync ATT&CK/ATLAS, and connect IOC/rule/enrichment feeds.
Read more →Review the full capability map: AI analysis, actor intelligence, IOC Library, enrichment, feeds, STIX/TAXII/MISP, YARA/Sigma, sandbox behavior, exports, and APIs.
Read more →Ingest PDF, DOCX, TXT, or pasted reports through the LLM provider configured by the operator, then review evidence-backed ATT&CK mapping candidates.
Read more →Explore Enterprise, Mobile, ICS, and ATLAS matrices, build layers, review technique context, and plan coverage.
Read more →Use TTP overlap for hypothesis generation, prioritization, report comparison, and gap analysis. Similarity is not attribution.
Read more →Operate the self-hosted platform with selftests, troubleshooting, evaluation guidance, API access, and deployment hardening.
Read more →