Skip to main content
AdversaryGraph v6.0.0

CTI-to-detection workbench for teams that need evidence, not guesswork

Self-hosted platform for ATT&CK/ATLAS mapping, IOC and CVE intelligence, malware-analysis triage, asset attack-surface review, Attack Simulation, SIEM validation, observability, and analyst-ready outputs.

Built for controlled deployments, private analysis, and detection-engineering handoff. AI assists the workflow; analysts validate the evidence.

Commercial Trust Snapshot

AdversaryGraph is source-available and self-hosted. The current focus is production hardening: clear boundaries, documented validation, screenshot-backed workflows, secure deployment guidance, and compatibility with established CTI and detection tools.

Self-hosted

Docker deployment with operator-controlled storage, provider keys, and database.

Evidence-first

AI mapping, actor similarity, CVE links, and malware summaries are reviewable signals, not final proof.

Security-scanned

CI covers tests, lint, SAST, dependency audit, Docker build, container scan, and secret scan.

Observable

Runtime health, request traces, route metrics, redacted log tail, and Prometheus output.

Start Here

  1. Read the commercial trust and boundary page
  2. Review architecture diagrams and deployment posture
  3. Check screenshot-backed validation examples
  4. Compare fit against OpenCTI, MISP, ATT&CK Navigator, Atomic Red Team, and sandboxes
  5. Clone the repository, configure `.env`, start Docker, and run selftest
  6. Sync ATT&CK/ATLAS, analyze a report or IOC, validate evidence, and export outputs

Self-Hosted Platform

AdversaryGraph Docker is the supported full platform: private AI-assisted extraction, stored analyses, enterprise access controls, APIs, PDF reports, IOC enrichment, CVE Library, STIX/TAXII/MISP workflows, YARA/Sigma sync, malware-analysis handoff, attack simulation, and scheduled reference synchronization.

Report content is sent only to the LLM provider configured by the operator. For fully private analysis, use a local or private OpenAI-compatible gateway. Native authentication can protect the workspace with RBAC roles, per-user permissions, session controls, MFA workflow support, audit history, and trusted proxy SSO metadata.

Follow the complete clone-to-feed-sync flow →
v6.0

Current Release Focus

AdversaryGraph v6.0 packages the complete v5 capability line for controlled self-hosted production with a repeatable release gate, corrected history, current visual evidence, fictional local case studies, deployment go/no-go criteria, and an explicit rollback path.

Where It Fits

AdversaryGraph complements established tools instead of trying to replace them. It sits between intelligence intake and detection engineering.

Before CTI Systems

Extract, review, enrich, and normalize report evidence before pushing selected outputs into an OpenCTI or MISP-centered workflow.

OpenCTI comparison →

Around ATT&CK Layers

Build layers from evidence, actors, reports, assets, malware findings, and validation telemetry, then export Navigator-compatible artifacts.

Navigator comparison →

Before Detection Deployment

Review telemetry readiness, validate lab or source-shaped events, forward to SIEM, and record detection gaps before operational rollout.

Atomic Red Team comparison →

After Malware Analysis

Turn sandbox/static findings into ATT&CK context, IOCs, CVE links, actor/report comparison, and case-ready outputs.

Sandbox comparison →

Documentation Areas

v6 Release Readiness

Run the release gate, review deployment go/no-go criteria, verify backup and rollback preparation, and preserve the controlled self-hosted production boundary.

Read more →

v6 Case Studies

Reproduce evidence-to-detection, asset exposure, and controlled Attack Simulation acceptance workflows with fictional repository data.

Read more →

Commercial Trust

Review implemented capabilities, boundaries, validation evidence, deployment posture, and commercial-readiness checklist.

Read more →

Architecture Diagrams

Understand runtime services, data flow, ATT&CK/CVE/IOC correlations, Attack Simulation, Malware Analysis, and observability boundaries.

Read more →

Case Studies And Validation

Walk through screenshot-backed validation examples for logs-to-report, SIEM validation, CVE correlation, auth/admin, and malware analysis.

Read more →

Comparison Pages

Compare AdversaryGraph with OpenCTI, MISP, ATT&CK Navigator, Atomic Red Team, and malware sandboxes using practical fit criteria.

Read more →

Full Deployment Flow

Clone the repository, configure secrets, start Docker, verify selftest, sync ATT&CK/ATLAS, and connect IOC/rule/enrichment feeds.

Read more →

Attack Simulation

Run TTP-first validation workflows, inspect real lab telemetry, forward events to SIEM collectors, and use AI-assisted kill-chain drills for detection engineering.

Read more →

Malware Analysis

Analyze Windows samples through the MalwareGraph-backed workflow: static triage, strings, unpacking, decompilation, debug workspaces, AI summaries, and gated dynamic analysis.

Read more →

Asset Attack Surface

Upload asset inventories, normalize exposure, score risk, map likely ATT&CK techniques, and create attack-surface cases for validation and prioritization.

Read more →

CVE Library

Sync NVD and CISA KEV, enrich CVSS fields, and review strict CVE-to-APT/TTP/IOC evidence links without treating vulnerability data as attribution.

Read more →

Authentication And Users

Enable native login, bootstrap named administrators, manage RBAC permissions, sessions, MFA workflow state, audit history, and trusted proxy SSO metadata.

Read more →

Observability And Validation

Review API health, request traces, redacted log tails, Prometheus metrics, security scanning, and validation examples.

Read more →

Platform Capabilities

Review the full capability map: AI analysis, actor intelligence, IOC/CVE libraries, enrichment, feeds, STIX/TAXII/MISP, attack simulation, malware analysis, exports, and APIs.

Read more →

AI-Assisted Mapping

Ingest PDF, DOCX, TXT, or pasted reports through the LLM provider configured by the operator, then review evidence-backed ATT&CK mapping candidates.

Read more →

ATT&CK And ATLAS Navigator

Explore Enterprise, Mobile, ICS, and ATLAS matrices, build layers, review technique context, and plan coverage.

Read more →

Group, Campaign, And Report Similarity

Use TTP overlap for hypothesis generation, prioritization, report comparison, and gap analysis. Similarity is not attribution.

Read more →

Operations, Security, And Validation

Operate the self-hosted platform with selftests, troubleshooting, evaluation guidance, API access, and deployment hardening.

Read more →