Skip to main content

Roadmap

Current release package: AdversaryGraph v6.0.0.

AdversaryGraph is functional and actively developed. The roadmap below separates what is already shipped from the next hardening and collaboration work.

Recently Shipped

v6.0.0 — Operational Evidence And Controlled Self-Hosted Readiness

  • Added a repeatable release gate covering metadata, Compose, frontend, backend, browser, dependency, SAST, and secret checks.
  • Added current sanitized screenshot evidence with reproducible capture steps and SHA-256 checksums.
  • Added fictional local case studies and deployment go/no-go criteria.
  • Corrected v5.1-v5.4 release history against the repository changelog.
  • Documented backup, rollback, validation, and production-claim boundaries.

v5.9.1 — JA3/JA4+ Network Fingerprint IOC Workflows

  • Added JA3, JA3S, JA4, JA4S, JA4H, JA4L, JA4LS, JA4X, JA4SSH, and JA4T IOC types.
  • Extracted labeled JA3/JA4+ fingerprints from uploaded report text.
  • Normalized network fingerprints during IOC import and preserved raw context.
  • Added network fingerprint filtering and labels in IOC Library.
  • Added network fingerprint context to IOC Detail and IOC node detail pages.
  • Included network fingerprints in IOC Investigation pivots and scoring.

v5.9.0 — EMB3D And Threat Radar Asset Workflows

  • Added EMB3D backend service, API route, frontend page, and documentation for embedded-device threat model assessment workflows.
  • Added unified product, component, dependency, and asset modeling support for cross-module exposure analysis.
  • Expanded Threat Radar with full asset-inventory import templates, product-security example datasets, and a dedicated asset review page.
  • Extended Asset Surface and Threat Radar workflows for product, component, dependency, and exposure triage.

v5.8.0 — Threat Radar Product-Security CTI

  • Added Threat Radar product-security CTI early warning with scored signals, claims, evidence, case graphs, and sanitized legal-sensitive metadata.
  • Added product/component/dependency exposure mapping, watchlists, workflow queues, and generated PSIRT, Threat Hunt, IR, Detection, and report outputs.
  • Added Threat Radar route tests and documentation for the workflow.

v5.7.0 — Research Collection And Linked Report Review

  • Added Reports / Research collection with TTP, IOC, CVE, threat actor, sector, and infrastructure tag buckets.
  • Added linked report review pages that preserve source text and connect entities back to Navigator, IOC Library, CVE Library, and ATT&CK Group Library.
  • Added research upload with optional Parse with AI and store-only staging.
  • Added a research analysis guide for embedded, hardware, firmware, and edge device research workflows.

v5.6.0 — Statistics And Evidence-to-Detection Hardening

  • Expanded Statistics with tag analytics across IOC, CVE, TTP, actor/group, report, sector, and cross-dataset views.
  • Added risk, confidence, region, sector, type, source, telemetry source, TLP, attack-vector, malware-family, freeform IOC tag, and relationship-confidence widgets.
  • Hardened statistics query execution so one failed widget does not suppress later widgets.

v5.5.0 — Enterprise Access Controls

  • Expanded RBAC roles for viewer, analyst, threat intelligence, detection engineering, incident response, audit, security administration, service account, and full admin workflows.
  • Per-user permission overrides layered on role defaults.
  • Session inventory, session expiry, self-service revoke-all, and admin session revocation.
  • MFA workflow support for local users.
  • Authentication audit history covering login, failed login, MFA, logout, user changes, password resets, session revocation, exports, feed sync, SIEM forwarding, and uploads.
  • Trusted proxy SSO metadata for OIDC/SAML-aware reverse-proxy deployments.

v5.4.0 — Observability, Security Scanning, And Commercial Trust

  • Authenticated Observability dashboard with API health, request metrics, recent traces, redacted log tail, top routes, and Prometheus-compatible metrics.
  • Backend SAST coverage, dependency/security scanning guidance, and local make security-scan workflow.
  • Screenshot-backed validation examples for Attack Simulation, CVE correlation, authentication/admin, malware analysis, and operator readiness.
  • Commercial trust, architecture, and comparison documentation for reviewer and buyer evaluation.

v5.3.0 — Authentication And User Operations

  • Native username/password login, expanded RBAC, per-user permissions, session inventory/revocation, MFA workflow state, trusted proxy SSO metadata, bootstrap admin setup, and admin user-management workflows.
  • Local authentication setup guide reachable from the running app and login page.

v5.1.0 — Telemetry Fidelity And CVE Correlation

  • Source-correct telemetry policy for Attack Simulation.
  • Raw ATT&CK/STIX preservation and normalized query tables.
  • CVE Library with NVD/CISA KEV sync, CVSS/CWE/CPE fields, and strict APT/TTP/IOC/CVE evidence links.

v5.0.0 — Attack Simulation And SIEM Validation

  • TTP-first Attack Simulation workflow with ATT&CK matrix selection.
  • Per-technique simulation pages with scenario description, telemetry source, event structure, and detection focus.
  • Real-time attacked-server log view for lab web telemetry.
  • SIEM forwarding with saved non-secret destinations and source-format controls.
  • AI Attack Assistant for coherent, multi-phase detection drills.
  • Named kill-chain scenarios, attack-chain graph, and explain-attack view.
  • Screenshot-backed documentation and Medium release article.

v4.1.0 — Asset Attack Surface Mapping

  • Asset inventory upload and normalization from CSV, JSON, CMDB exports, cloud lists, scanner output, and hostname/IP lists.
  • AI-assisted attack-surface explanation, likely entry points, ATT&CK candidate mapping, validation gaps, and saved asset cases.
  • White Navigator layer for asset-inventory-based TTP candidates.

v4.0.0 — Malware Analysis Workspace

  • MalwareGraph-backed static triage, IOC extraction, hash feed checks, string analysis, unpacking workflow, decompilation/debug IDE, and controlled dynamic-analysis preparation.
  • AI-assisted function summaries, behavior summaries, validation gaps, and malware-analysis reporting.

Version History From v2.5

VersionRelease ThemeWhat Changed
v6.0.0Operational evidence and controlled self-hosted readinessRepeatable release gate, current sanitized screenshot evidence, fictional local case studies, deployment go/no-go criteria, corrected release history, backup and rollback guidance
v5.9.1JA3/JA4+ network fingerprint IOC workflowsJA3/JA3S/JA4/JA4S/JA4H/JA4L/JA4LS/JA4X/JA4SSH/JA4T IOC types, report-text extraction, normalized import tagging, IOC Library filtering, IOC Detail context, IOC node detail support, and IOC Investigation pivots
v5.9.0EMB3D and Threat Radar asset workflowsEMB3D API/service/UI/documentation, unified product/component/dependency/asset modeling, full asset-inventory import templates, product-security sample datasets, and Threat Radar asset review pages
v5.8.0Threat Radar product-security CTIThreat Radar module, scored CVE/KEV/PoC/zero-day/supplier/package/hardware/customer/internal telemetry signals, product/component/dependency exposure mappings, case graph, sanitized legal-sensitive evidence handling, PSIRT/Hunt/IR/Detection queues, watchlists, and generated reports
v5.7.0Research collection and linked report reviewReports / Research collection page, linked report review with inline entity links, source-text preservation for AI analysis, store-only research upload, Parse with AI upload workflow, and research analysis guide
v5.6.0Statistics tag analyticsExpanded Statistics module with IOC/CVE/TTP/actor/report/sector/global tag widgets for risk, confidence, region, sector, type, source, telemetry, TLP, attack vector, malware family, and relationship-confidence analysis
v5.5.0Enterprise access controlsExpanded RBAC, per-user permissions, session inventory/revocation, MFA workflow support, audit history, trusted proxy SSO metadata, and Admin Panel updates
v5.4.0Observability and commercial trustRuntime observability dashboard, security scanning workflow, screenshot-backed validation examples, commercial trust package, architecture diagrams, and comparison pages
v5.3.0Authentication and user operationsNative login, initial viewer/analyst/admin roles, bootstrap admin flow, admin user-management, and auth documentation
v5.2.0QA hardeningReproducible tests, frontend audit cleanup, local lint/test/audit/build validation, and release metadata cleanup
v5.1.0Telemetry fidelity and CVE correlationSource-correct Attack Simulation telemetry policy, raw STIX preservation, CVE Library, CVSS/CWE/CPE fields, and strict APT/TTP/IOC/CVE evidence links
v5.0.0Attack Simulation and SIEM validationTTP-first simulation matrix, real lab telemetry, SIEM forwarding, AI kill-chain drills, scenario library, and attack-chain graph
v4.1.0Asset Attack Surface MappingAsset inventory ingestion, deterministic exposure scoring, ATT&CK candidates, saved asset cases, and white Navigator layers
v4.0.0Malware Analysis platform releaseFully documented MalwareGraph-backed module, clickable findings, debugger-style review, dynamic-analysis preparation, and AI feedback loops
v3.2.0MalwareGraph integration milestoneIntegrated Malware Analysis module documentation, standalone MalwareGraph positioning, static triage flow, and gated runtime-debug policy
v3.1.0From Log To Report workflowPublished log-to-report workflow with source-tagged IOCs/TTPs, graph pivots, actor-overlap review, AI summary, and final report generation
v3.0.0Investigation workbenchIOC Investigation, relationship graph pivoting, evidence ranking, saved sessions, AI log/PCAP analysis, and ATT&CK handoff
v2.7.0IOC Investigation workflowTiered enrichment pivots from one artifact, source status, TTP/actor leads, AI summary packaging, and local/external source collection
v2.6.0Telemetry triage and use casesAI-assisted log/PCAP analysis, richer Navigator layer handling, Discover launchers, and animated use-case documentation
v2.5.9Detection Studio improvementsDefault YARA/Sigma feed setup, YARA-L generation, and AI-assisted detection skeleton generation for Sigma, YARA, KQL, SPL, and EQL
v2.5.8IOC enrichment drill-downClickable IOC detail pages, source metadata, actor/TTP links, enrichment values, and raw JSON audit view
v2.5.7MiniMax provider supportMiniMax support across AI Analysis, Navigator AI chat, IOC-to-TTP fallback, Docker configuration, and self-test
v2.5.4IOC normalization and evidence priorityHash normalization, duplicate merge, explicit IOC-to-TTP priority model, and opt-in AI fallback
v2.5.0IOC Library and connector hardeningIOC Library, global observable search, VirusTotal enrichment, STIX/TAXII/MISP/custom feeds, YARA/Sigma feeds, sandbox behavior feeds, and IOC-to-TTP mapping

Current Hardening Sprint

  • Keep main, release tags, docs, screenshots, and public site text aligned.
  • Continue route-level tests for user-facing API workflows.
  • Keep dependency audit, container scan, and secret scan green in CI.
  • Improve reviewer evidence: screenshots, safety boundaries, architecture notes, validation pages, and reproducible demo data.
  • Close stale GitHub issues only after the code or documentation has been verified.

Planned Hardening Work

  • Windows Lab Agent planning for real Windows Event Log, Sysmon, Defender, PowerShell, registry, process, and ETW telemetry.
  • Broader Attack Simulation scenario coverage across web, identity, endpoint, cloud, proxy, DNS, and firewall telemetry.
  • More production-style event fixtures for Windows Event Log, Sysmon, EDR, WAF, NGINX/Apache, proxy, DNS, and firewall schemas.
  • Improved scenario scoring: expected detections, false-positive controls, coverage gaps, and missed-stage explanations.
  • Exportable detection engineering exercises for SOC training and purple-team validation.
  • Deeper integrations with OpenCTI, MISP, Sigma/YARA workflows, and SIEM forwarding profiles.

Longer-Term Direction

  • TAXII/STIX import from CTI platforms and commercial feeds.
  • Team collaboration with shared TTP layers and user namespacing.
  • Automatic tracked-actor change monitoring when ATT&CK releases new versions.
  • Native MITRE ATLAS ingestion adapter for the Docker platform.

Contributing

The project is source-available. Personal/private use is free; business or organizational use requires approval from Andrey Pautov.