AdversaryGraph v2.5 · Practical Workflows

Use Cases for AI-Assisted CTI, ATT&CK Mapping, and IOC Enrichment

Twenty-six analyst workflows showing how AdversaryGraph supports report analysis, actor comparison, sector intelligence, IOC enrichment, STIX/TAXII/MISP exchange, Sigma/YARA and sandbox context, detection handoff, and deployment validation.

Use Case Library

These are practical ways to use the tool in CTI, SOC, incident response, malware analysis, detection engineering, and platform validation work.

1. Map a new threat report to ATT&CK

Flow: Upload PDF/DOCX/TXT or paste text, run AI Analysis, review evidence, accept TTPs, and inject them into Navigator.

Output: Technique list, evidence, confidence, review status, layer, JSON, and PDF.

AI AnalysisATT&CK

2. Build a client-facing CTI briefing

Flow: Analyze a report, validate TTPs, compare actors, add IOCs, and export a PDF.

Output: Evidence-backed briefing with actor context and detection priorities.

PDFBriefing

3. Compare an incident to APT groups

Flow: Extract TTPs, run group comparison, inspect Jaccard overlap, and open actor pages.

Output: Ranked actor hypotheses, not definitive attribution.

ActorsSimilarity

4. Compare multiple reports

Flow: Store report analyses, compare shared TTPs, tactics, IOCs, and actor links.

Output: Relatedness view with shared and distinct behavior.

ReportsOverlap

5. Turn CTI into a detection backlog

Flow: Accept validated TTPs, review tactic coverage, inspect guidance, and export evidence.

Output: Prioritized detection engineering candidates.

DetectionBacklog

6. Create ATT&CK Navigator layers

Flow: Select TTPs manually, import layers, inject AI findings, or load actor TTPs.

Output: Navigator-compatible JSON and matrix visualization.

NavigatorLayer

7. Review detection coverage gaps

Flow: Load TTPs, inspect tactic distribution, compare against actor or campaign profiles.

Output: Missing technique areas and priority gaps.

CoverageGap Analysis

8. Track actor relevance by sector

Flow: Filter by sector, region, technology, and activity window in Sector Intel.

Output: Relevant actor ranking and matrix-ready TTPs.

Sector IntelPriority

9. Build a sector-specific threat model

Flow: Combine sector filters, actor profiles, relevant TTPs, and evidence cards.

Output: Customer-specific threat model and ATT&CK behavior map.

Threat ModelCustomer

10. Enrich actor profiles with IOCs

Flow: Open actor IOCs, sync ThreatFox or custom feeds, and export CSV.

Output: Actor-linked observables with source and last-seen context.

IOCActors

11. Maintain a central IOC Library

Flow: Search by indicator, description, malware, campaign, actor, type, source, or last seen.

Output: Central observable library with enrichment actions.

IOC LibrarySearch

12. Enrich an IOC with VirusTotal

Flow: Query an IP, domain, URL, or hash and review reputation, tags, rules, relationships, actors, and TTPs.

Output: Structured enrichment with pivots to matrix and actor pages.

VirusTotalEnrichment

13. Pull OTX, Malpedia, and ThreatFox context

Flow: Configure keys, sync sources, and enrich actor, malware, and IOC records.

Output: Source-backed external intelligence with timestamps.

OTXMalpediaThreatFox

14. Import custom private feeds

Flow: Add JSON, CSV, or TXT feeds and keep customer intelligence in the external DB.

Output: Private observables separated from public reference data.

Custom FeedPrivate DB

15. Import and export STIX/TAXII

Flow: Export STIX indicators, import STIX files, or pull TAXII collection objects.

Output: Structured CTI exchange with compatible platforms.

STIXTAXII

16. Connect MISP JSON exports

Flow: Provide a MISP JSON export URL or gateway URL and sync it as a source.

Output: MISP-backed IOC records for search and enrichment.

MISPJSON

17. Sync Sigma and YARA rule feeds

Flow: Add rule feeds and review detection-rule matches in enrichment context.

Output: Detection context for IOCs, malware families, and techniques.

SigmaYARA

18. Enrich malware behavior from sandboxes

Flow: Sync sandbox behavior sources and connect observed behavior to malware, IOCs, and TTPs.

Output: Runtime evidence for behavior and technique mapping.

SandboxBehavior

19. Extract IOCs from uploaded reports

Flow: Analyze a report, extract observables, map them to actors or malware, and store them.

Output: Report-derived IOC records with source context.

ExtractionReports

20. Analyze DFIR report examples

Flow: Open DFIR Examples, inspect source-linked TTPs and actors, then use the report for AI analysis.

Output: Practice dataset for validation and demos.

DFIRExamples

21. Compare two APT groups

Flow: Select groups, inspect shared and different techniques, and review the combined matrix.

Output: Group-to-group behavior comparison.

Group vs GroupAPT

22. Track ATT&CK changes over time

Flow: Track actor changes, sync references, and compare stored data to current ATT&CK.

Output: Visible actor and technique updates.

SyncChange Tracking

23. Use local or private LLMs

Flow: Configure a local/private LLM gateway and choose it during analysis.

Output: Private extraction with operator-controlled model routing.

Local LLMPrivacy

24. Build a repeatable CTI pipeline

Flow: Track intake, analysis, review states, actor hypotheses, IOC enrichment, and detection candidates.

Output: Auditable CTI-to-detection workflow.

PipelineOperations

25. Validate deployment readiness

Flow: Run selftest, fix popup errors, recheck, and open troubleshooting when needed.

Output: Clear API, DB, ATT&CK, ATLAS, and enrichment readiness status.

SelftestTroubleshooting

26. Prepare release or maintainer evidence

Flow: Combine release notes, selftest output, screenshots, sample data, API docs, and validation pages.

Output: Evidence package for publication, review, or stakeholder approval.

ReleaseValidation

Capability Map

CapabilityRelevant Use Cases
AI report extraction1, 2, 3, 4, 19, 20, 23, 24
ATT&CK Navigator and layers1, 5, 6, 7, 8, 9, 21
Actor and campaign comparison3, 4, 8, 9, 21, 22
Sector intelligence8, 9
IOC Library10, 11, 12, 14, 15, 16, 19
External enrichment12, 13, 17, 18
STIX/TAXII/MISP workflows15, 16
Detection engineering handoff5, 7, 17, 18, 24
Operations and pipeline2, 19, 24, 26
Deployment reliability23, 25, 26
Attribution note: AdversaryGraph shows TTP overlap and supporting evidence for analyst hypothesis generation. It does not make definitive attribution claims without corroborating evidence and analyst judgment.