Current source release v6.5.0 · merged, CI-validated, and ready for controlled self-hosting

AdversaryGraph

Current source release: v6.5.0, merged and CI-validated 25 July 2026. Latest published immutable release: v6.0.0, published . AdversaryGraph was formerly named ThreatMapper.

A self-hosted analyst workbench for turning reports, logs, IOCs, malware findings, asset inventories, and ATT&CK knowledge into mapped techniques, investigation context, detection gaps, validation scenarios, observability, and report-ready outputs.

160+ATT&CK groups in the public workspace
650+Enterprise techniques and sub-techniques
v6.5.0Validated source release with release gate, SOC access groups, asset assessment, Threat Hunting, RAG, and MCP
AdversaryGraph Discover dashboard with module launchers
Privacy boundary. The public workspace is for exploration. Do not upload confidential customer data, internal reports, classified material, malware samples, or private indicators to public pages. Use the self-hosted Docker deployment for private analysis and operator-controlled LLM routing.

Unified RAG And MCP — v6.5 Source Release

These capabilities are included in the merged, CI-validated AdversaryGraph v6.5.0 source release. They are absent from the historical v6.0.0 tag; immutable v6.5 release publication is still pending.

RAG and MCP v6.5 source guide

Governed Hybrid Retrieval

Search 12 indexed source types: ATT&CK techniques, groups, and campaigns; actor intelligence; IOCs; CVEs; analysis reports; knowledge; threat signals; threat hunts; evidence nodes; and assets. Exact matching and PostgreSQL full-text search are the default. Operators can optionally add embeddings through a private model endpoint and pgvector.

Business profilesEntity citationsPrivate embeddings

Constrained Analyst Assistance

Grounded answers cite indexed evidence. Navigator output remains a checksum-bound proposal that is persisted as an expiring advisory record and requires analyst confirmation; it does not save or apply a named layer automatically. The stdio-only MCP server exposes exactly four tools: search_intelligence, ask_intelligence, get_indexed_entity, and propose_navigator_layer.

No MCP mutationNo MCP reindexNo MCP confirmation
Authorization boundary. RAG status uses read. Profile listing, search, entity and provider reads, assistance, and proposal confirmation use run_analysis. Profile administration uses manage_intel; reindexing and index-run review use manage_feeds. MCP inherits the deployment API token, authorization, and data visibility boundaries.

Built For Analysts Who Need Evidence, Not Just Text

AdversaryGraph connects CTI extraction, IOC enrichment, ATT&CK mapping, malware analysis, asset exposure, attack simulation, and detection validation into one workflow.

1

Ingest

Reports, logs, IOCs, malware findings, asset inventory, or feed data.

2

Map

Extract ATT&CK candidates with evidence and analyst review gates.

3

Enrich

Pivot through IOC sources, actor context, campaigns, sectors, and references.

4

Validate

Review detection gaps, run lab simulations, and forward telemetry to SIEM.

5

Report

Export investigation summaries, matrices, layers, and analyst handoff output.

Commercial Trust Package

AdversaryGraph now documents the evidence reviewers and buyers need: architecture, validation examples, security scanning, enterprise access guidance, public roadmap, and comparisons with established CTI and detection tools.

Trust docs

Architecture

Runtime, evidence model, correlation model, Attack Simulation, Malware Analysis, and observability diagrams.

Architecture diagrams

Validation

Screenshot-backed case studies for logs-to-report, SIEM validation, CVE correlation, auth/admin, and malware analysis.

Validation examples

Roadmap

Public plan covering work after the v6.5 source boundary, Windows telemetry direction, broader simulation coverage, and integrations.

Roadmap

Comparisons

Clear fit against OpenCTI, MISP, ATT&CK Navigator, Atomic Red Team, and malware sandboxes.

Compare tools

Capabilities

The platform is organized around real analyst tasks, not a single visualization.

Capability docs

AI-Assisted ATT&CK Mapping

Analyze reports and telemetry with Claude, OpenAI, Gemini, MiniMax, or local OpenAI-compatible providers. Keep extracted TTPs tied to evidence and confidence.

PDF/DOCX/TXTEvidence-backed TTPsAnalyst review

Explore Enterprise, Mobile, ICS, and ATLAS matrices. Compare selected TTPs against groups, campaigns, reports, and saved layers.

ATT&CK layersTTP overlapGap review

IOC Investigation

Pivot on IPs, domains, URLs, hashes, and observables. Combine reputation, DNS, graph relationships, source conflicts, and ATT&CK leads.

ThreatFoxVirusTotalurlscanOTX

Malware Analysis Module

Use the MalwareGraph-backed workflow for Windows sample triage: hashes, PE metadata, strings, unpacking, decompilation views, debug workspaces, and AI summaries.

Static triageDebugger UIAI summary

Asset Attack Surface Mapping

Upload inventories, normalize exposed assets, score risk, propose likely entry points, and map asset-driven ATT&CK candidates for validation.

CMDB/scanner inputRisk matrixSaved cases

Attack Simulation And SIEM Validation

Select TTPs, run approved lab scenarios, view target-side logs, forward telemetry to a SIEM, and generate coherent AI-assisted attack-chain drills.

Lab scopedTarget-side logsSIEM forwarding

Observability And Security Validation

Review API health, request traces, route metrics, redacted logs, Prometheus output, SAST, dependency audit, secret scan, and container scan coverage.

MetricsSASTValidation

Enterprise Access Controls

Protect private deployments with native login, expanded RBAC, per-user permissions, session revocation, MFA workflow support, audit history, and trusted proxy SSO metadata.

Access controlsRBACSessionsAudit

Feeds And Pipeline

Sync ATT&CK, ATLAS, ThreatFox, Malpedia, OTX, OpenCTI, STIX/TAXII, MISP JSON, custom IOC feeds, Sigma/YARA, and sandbox behavior sources.

OpenCTIMISPSTIX/TAXII

Investigation Reports

Turn selected evidence, IOCs, actor context, technique mappings, similarity analysis, and validation notes into analyst-ready reports.

PDF outputEvidence chainHandoff

Self-Hosted Deployment

Run the full platform locally or in controlled infrastructure with Docker, private LLM gateways, local data stores, API workflows, and startup self-tests.

DockerAPIPrivate analysis

Screenshot-Backed Proof

Current v6 captures use sanitized, deterministic API fixtures for reproducibility; older captures document historical product surfaces. They demonstrate UI behavior, not external deployment or detection-efficacy claims.

Full platform guide
AdversaryGraph ATT&CK Navigator matrix
ATT&CK Navigator matrix Review techniques, build layers, overlay actor context, and move selected TTPs into comparisons and reports.Click screenshot to enlarge
AdversaryGraph AI Analysis page
AI-assisted report analysis Extract ATT&CK candidates from report text and preserve evidence for analyst validation.Click screenshot to enlarge
AdversaryGraph IOC Investigation page
IOC Investigation Pivot from one observable into reputation, relationships, graph context, and TTP leads.Click screenshot to enlarge
AdversaryGraph Malware Analysis dashboard
Malware Analysis module Static triage, hash checks, unpacking, decompilation/debug views, AI summaries, and gated runtime analysis.Click screenshot to enlarge
AdversaryGraph Attack Simulation chain graph
Historical v5 screenshot — Attack Simulation Coherent multi-phase kill-chain graph with telemetry sources, event counts, detection goals, and SIEM delivery. The workflow remains in the v6.5 source release.Click screenshot to enlarge
AdversaryGraph SIEM forwarding configuration
SIEM forwarding Send selected target-side telemetry to HTTP collectors with routing, payload format, and authentication controls.Click screenshot to enlarge

Public Proof And Validation

Links that verify the project, release, documentation, and platform surface.

Who It Is For

AdversaryGraph is practical infrastructure for teams that need repeatable CTI-to-detection work.

CTI Analysts

Map reports, compare actors, track campaigns, pivot on IOCs, and prepare evidence-backed intelligence products.

Detection Engineers

Turn ATT&CK mappings into validation plans, SIEM telemetry tests, parser checks, and detection backlog items.

Malware Analysts

Connect sample triage, strings, imports, behaviors, and family leads back to ATT&CK and IOC workflows.

SOC And IR Teams

Move from raw logs and suspicious artifacts to enriched context, matrix views, actor hypotheses, and reports.

Bug Reports, Feature Requests, And Feedback

Send a bug report, feature request, or short note with hardened client-side validation. Text is sanitized before it is copied, opened as a direct email draft, or opened as a GitHub issue that triggers repository notifications. Screenshots are validated locally and are not uploaded by this static page.

GitHub notifications

Use AdversaryGraph As Your CTI-to-Detection Workbench

Start with the public workspace, then deploy the self-hosted version when you need private reports, local IOC feeds, configured LLM providers, malware-analysis workflows, and SIEM validation.

AdversaryGraph Discover dashboard with module launchers full-size preview Discover dashboardClick anywhere to close AdversaryGraph ATT&CK Navigator matrix full-size preview ATT&CK Navigator matrixClick anywhere to close AdversaryGraph AI Analysis page full-size preview AI-assisted report analysisClick anywhere to close AdversaryGraph IOC Investigation page full-size preview IOC InvestigationClick anywhere to close AdversaryGraph Malware Analysis dashboard full-size preview Malware Analysis moduleClick anywhere to close AdversaryGraph Attack Simulation chain graph full-size preview Historical v5 Attack Simulation chain-graph screenshotClick anywhere to close AdversaryGraph SIEM forwarding configuration full-size preview SIEM forwarding configurationClick anywhere to close