AdversaryGraph
Current release package: v6.0.0 · v6 Readiness · v6 Case Studies · Project Hub · Commercial Trust · Architecture · Platform Guide · Attack Simulation · Capabilities · Authentication · GitHub
AdversaryGraph is an AI-assisted CTI-to-detection workbench for mapping threat reports, IOC context, malware-analysis evidence, and operational telemetry to MITRE ATT&CK / ATLAS. It helps analysts compare TTP overlap with known groups and campaigns, identify detection gaps, enrich observables, organize investigations, and export analyst-ready outputs.
The v6.0 release package includes the complete v5 capability line—Attack Simulation, SIEM validation, CVE correlation, enterprise access controls, observability, Evidence-to-Detection Graph reasoning, statistics, research collection, Threat Radar, EMB3D, and JA3/JA4+ network fingerprints—plus a reproducible release gate, current screenshot evidence, fictional local case studies, deployment acceptance criteria, and rollback guidance.
AdversaryGraph does not perform definitive attribution or final malware verdicts. TTP overlap, Jaccard similarity, IOC enrichment, generated detections, AI summaries, and malware-analysis output are analytical signals for hypothesis generation, prioritization, and further investigation.

Start Here
- Open the Project Hub
- Read the commercial trust package
- Review architecture diagrams
- Review case studies and validation examples
- Compare AdversaryGraph with related tools
- Read the current platform guide
- Review all platform capabilities
- Review authentication and enterprise access
- Review Attack Simulation and SIEM validation
- Review observability and security validation
- Review the Malware Analysis workspace
- Follow the full deployment flow
Full Self-Hosted Platform
Use Docker for private AI-assisted report analysis, provider-configured LLM extraction, stored reports, campaign comparison, IOC enrichment, feed management, malware-analysis workflows, Attack Simulation lab telemetry, SIEM forwarding, API access, PDF exports, and scheduled ATT&CK/ATLAS synchronization.
AdversaryGraph is self-hosted. In Docker mode, report content is sent only to the LLM provider configured by the operator. For fully private analysis, use a local or private LLM gateway.
ATT&CK Data Provenance
AdversaryGraph uses official MITRE ATT&CK STIX bundles. The active domain, version, and generated/synchronized timestamp are shown in the relevant UI. Counts depend on the selected domain and release.
Validation and Limitations
LLM-generated mappings may contain false positives, false negatives, or ambiguous technique assignments. Analysts must validate mappings against source evidence, procedure descriptions, telemetry requirements, and ATT&CK definitions. See Evaluation and Analyst Validation.