{
  "$schema": "./content-catalog.schema.json",
  "catalog_version": "2.0.0",
  "generated_at": "2026-07-27",
  "scope": "deployable-domain-catalog",
  "controlled_vocabularies": {
    "primary_types": [
      "research",
      "case-study",
      "guide",
      "lab",
      "tool",
      "platform",
      "documentation",
      "reference-entity",
      "generated-reference",
      "article",
      "redirect",
      "mirror",
      "contribution",
      "index",
      "profile",
      "policy"
    ],
    "primary_domains": [
      "threat-intelligence",
      "detection-engineering",
      "threat-hunting",
      "incident-response",
      "malware-analysis",
      "identity-security",
      "offensive-research",
      "cloud-security",
      "security-governance",
      "open-source-intelligence",
      "vulnerability-research",
      "ai-security",
      "application-security",
      "network-security",
      "platform-documentation",
      "professional-profile",
      "site-governance"
    ],
    "audiences": [
      "cti-analyst",
      "detection-engineer",
      "threat-hunter",
      "security-engineer",
      "security-leader",
      "platform-operator",
      "developer",
      "general"
    ],
    "statuses": [
      "released",
      "maintained",
      "current-development",
      "experimental",
      "superseded",
      "archived",
      "submitted",
      "accepted"
    ],
    "lifecycles": [
      "maintained",
      "stable-reference",
      "current-development",
      "preserved",
      "historical",
      "currentness-unknown",
      "superseded",
      "archived"
    ],
    "maturity": [
      "production",
      "stable",
      "beta",
      "experimental",
      "historical",
      "reference"
    ],
    "evidence_levels": [
      "source-backed",
      "lab-validated",
      "release-evidence",
      "externally-accepted",
      "illustrative",
      "unverified"
    ],
    "collection_tiers": [
      "core",
      "reference",
      "archive"
    ]
  },
  "canonical_policy": {
    "identity": "One catalogue item represents one public artefact. Its stable ID is independent of display category, and its canonical URL is unique.",
    "medium_and_local_mirrors": "A locally hosted companion or export is typed as mirror and records the Medium publication as source_url. The 1200km archive URL is the preferred stable URL when it contains durable local context or assets; otherwise the external publication remains canonical. Duplicate source links are not emitted as second items.",
    "versioned_material": "Version-specific pages remain public only with an explicit version or applies_to boundary. Superseded material requires an archive reason and a visible historical or archive notice.",
    "redirects": "Legacy URLs are aliases, not independent catalogue items. They remain noindex redirects to the maintained canonical identity."
  },
  "declared_collections": [
    {
      "id": "collection:adversarygraph-docs",
      "name": "AdversaryGraph Documentation",
      "canonical_prefix": "https://1200km.com/adversarygraph-docs/",
      "sitemap_url": "https://1200km.com/adversarygraph-docs/sitemap.xml",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "collection_tier": "reference",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs"
    },
    {
      "id": "collection:cti-analyst-field-manual",
      "name": "CTI Analyst Field Manual",
      "canonical_prefix": "https://1200km.com/cti-analyst-field-manual/",
      "sitemap_url": "https://1200km.com/cti-analyst-field-manual/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "current CTI analyst practice",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual"
    },
    {
      "id": "collection:israel-government-threat-actors-cti",
      "name": "Israel Government Threat Actors CTI",
      "canonical_prefix": "https://1200km.com/israel-government-threat-actors-cti/",
      "sitemap_url": "https://1200km.com/israel-government-threat-actors-cti/sitemap.xml",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "public-source regional threat research",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti"
    },
    {
      "id": "collection:anomaly-detection-atlas",
      "name": "Anomaly Detection Atlas",
      "canonical_prefix": "https://1200km.com/anomaly-detection-atlas/",
      "sitemap_url": "https://1200km.com/anomaly-detection-atlas/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "current anomaly-detection practice",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas"
    },
    {
      "id": "collection:insider-threat-detection",
      "name": "Insider Threat Detection Engineering Guide",
      "canonical_prefix": "https://1200km.com/insider-threat-detection/",
      "sitemap_url": "https://1200km.com/insider-threat-detection/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "current insider-threat detection practice",
      "source_url": "https://github.com/anpa1200/insider-threat-detection"
    },
    {
      "id": "collection:operation-desert-hydra",
      "name": "Operation Desert Hydra",
      "canonical_prefix": "https://1200km.com/operation-desert-hydra/",
      "sitemap_url": "https://1200km.com/operation-desert-hydra/sitemap.xml",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "collection_tier": "core",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra"
    },
    {
      "id": "collection:opencti-intelligent-shield",
      "name": "OpenCTI Intelligent Shield",
      "canonical_prefix": "https://1200km.com/opencti-intelligent-shield/",
      "sitemap_url": "https://1200km.com/opencti-intelligent-shield/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "OpenCTI deployment and enrichment workflows",
      "source_url": "https://github.com/anpa1200/opencti-intelligent-shield"
    },
    {
      "id": "collection:cti-as-code",
      "name": "CTI as Code",
      "canonical_prefix": "https://1200km.com/CTI_as_a_Code/",
      "sitemap_url": "https://1200km.com/CTI_as_a_Code/sitemap.xml",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "collection_tier": "reference",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code"
    },
    {
      "id": "collection:customer-driven-ai-cti",
      "name": "Customer-Driven AI CTI Project",
      "canonical_prefix": "https://1200km.com/customer-driven-ai-cti-project/",
      "sitemap_url": "https://1200km.com/customer-driven-ai-cti-project/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project"
    },
    {
      "id": "collection:medium-export",
      "name": "1200km Article Archive",
      "canonical_prefix": "https://1200km.com/articles/",
      "sitemap_url": "https://1200km.com/articles/sitemap.xml",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "lifecycle": "currentness-unknown",
      "maturity": "reference",
      "evidence_level": "unverified",
      "collection_tier": "archive",
      "applies_to": "canonical local article pages with original publication URLs retained as provenance",
      "source_url": "https://github.com/anpa1200/medium-blog-navigation"
    }
  ],
  "aliases": [
    {
      "alias_url": "https://1200km.com/threatmapper/",
      "canonical_url": "https://1200km.com/adversarygraph/",
      "status": "superseded",
      "reason": "Historical product route retained as a redirect to AdversaryGraph."
    },
    {
      "alias_url": "https://1200km.com/threatmapper-docs/",
      "canonical_url": "https://1200km.com/adversarygraph-docs/",
      "status": "superseded",
      "prefix": true,
      "reason": "Historical documentation tree retained as noindex redirects to AdversaryGraph documentation."
    },
    {
      "alias_url": "https://1200km.com/threatmapper.html",
      "canonical_url": "https://1200km.com/adversarygraph/",
      "status": "superseded",
      "reason": "ThreatMapper is the historical product name replaced by AdversaryGraph."
    },
    {
      "alias_url": "https://1200km.com/threatmapper-web.html",
      "canonical_url": "https://1200km.com/adversarygraph-web-guide.html",
      "status": "superseded",
      "reason": "Historical public-workspace URL retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/threatmapper-web-guide.html",
      "canonical_url": "https://1200km.com/adversarygraph-web-guide.html",
      "status": "superseded",
      "reason": "Historical guide URL retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/articles/threatmapper-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform.html",
      "canonical_url": "https://1200km.com/articles/adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "status": "superseded",
      "reason": "Historical article slug retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/articles/threatmapper-v2-self-hosted-ai-cti-platform.html",
      "canonical_url": "https://1200km.com/articles/adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "status": "superseded",
      "reason": "Historical article slug retained as a redirect."
    }
  ],
  "inventory": {
    "item_count": 1725,
    "indexable_count": 1711,
    "external_count": 14,
    "by_primary_type": {
      "article": 179,
      "case-study": 47,
      "contribution": 1,
      "documentation": 168,
      "generated-reference": 713,
      "guide": 167,
      "index": 9,
      "lab": 49,
      "mirror": 3,
      "platform": 1,
      "policy": 2,
      "profile": 2,
      "reference-entity": 175,
      "research": 198,
      "tool": 11
    },
    "by_primary_domain": {
      "ai-security": 13,
      "application-security": 16,
      "cloud-security": 16,
      "detection-engineering": 72,
      "identity-security": 130,
      "incident-response": 1,
      "malware-analysis": 23,
      "network-security": 23,
      "offensive-research": 61,
      "open-source-intelligence": 4,
      "platform-documentation": 86,
      "professional-profile": 2,
      "security-governance": 1,
      "site-governance": 12,
      "threat-hunting": 4,
      "threat-intelligence": 1259,
      "vulnerability-research": 2
    },
    "by_status": {
      "archived": 4,
      "current-development": 3,
      "maintained": 1531,
      "released": 186,
      "superseded": 1
    },
    "by_lifecycle": {
      "archived": 4,
      "current-development": 3,
      "currentness-unknown": 73,
      "historical": 5,
      "maintained": 126,
      "preserved": 87,
      "stable-reference": 1426,
      "superseded": 1
    },
    "by_evidence_level": {
      "externally-accepted": 1,
      "illustrative": 11,
      "lab-validated": 54,
      "release-evidence": 87,
      "source-backed": 1391,
      "unverified": 181
    },
    "by_collection_tier": {
      "archive": 163,
      "core": 59,
      "reference": 1503
    }
  },
  "items": [
    {
      "id": "site:home",
      "title": "Threat intelligence that turns into detection.",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "1200km current public portfolio",
      "canonical_url": "https://1200km.com/",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Security research portfolio by Andrey Pautov: CTI-to-detection…",
      "tags": [
        "detection-engineering",
        "index",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:about.html",
      "title": "Andrey Pautov",
      "primary_type": "profile",
      "primary_domain": "professional-profile",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current professional profile",
      "canonical_url": "https://1200km.com/about.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Andrey Pautov — CTI-to-detection practitioner. Adversary profiling, ATT&CK mapping, malware analysis, and AI-assisted security…",
      "tags": [
        "ai-security",
        "malware-analysis",
        "mitre-attack",
        "profile",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/about.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:adversarygraph-docs",
      "title": "CTI-to-detection workbench for teams that need evidence, not guesswork",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "CTI-to-detection workbench for teams that need evidence, not guesswork. Commercial…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:ai-analysis:chat-assistant",
      "title": "AI Chat Assistant",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/ai-analysis/chat-assistant/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AI Chat Assistant. Every technique in the detail panel has an embedded AI chat. This is not a generic chatbot — it is a threat intelligence…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "embedded-security",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:ai-analysis:domains",
      "title": "Working with All Three ATT&CK Domains",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/ai-analysis/domains/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Working with All Three ATT&CK Domains. Working with all three ATT&CK domains — Enterprise, Mobile, and ICS",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:ai-analysis:overview",
      "title": "AI Analysis",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/ai-analysis/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AI Analysis. This is the core feature. Upload a threat report, paste raw text, or submit log / PCAP-derived telemetry and AdversaryGraph extracts…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "detection-engineering",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:analyze",
      "title": "Analysis API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/analyze/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Analysis API. Submit a Report",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:compare",
      "title": "Compare API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/compare/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Compare API. Jaccard similarity ranking against ATT&CK groups and campaigns.",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:export",
      "title": "Export API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/export/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Export API. Analysis PDF",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:layers",
      "title": "Layers API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/layers/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Layers API. Manage named Navigator layers stored in DB 2.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:overview",
      "title": "REST API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "REST API. AdversaryGraph exposes a full REST API. Drive the entire workflow programmatically — headless analysis, batch comparisons, layer management.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:sync",
      "title": "Sync API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/sync/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Sync API. Manage ATT&CK data versioning.",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:apt-library:overview",
      "title": "ATT&CK Group Library",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/apt-library/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "ATT&CK Group Library. The ATT&CK Group Library gives you a searchable, browsable view of threat groups and named campaigns in the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:architecture",
      "title": "Architecture Diagrams",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/architecture/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Architecture Diagrams. AdversaryGraph is a self-hosted CTI-to-detection platform. The architecture is intentionally modular: the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:attack-data-model",
      "title": "ATT&CK and STIX Data Model",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/attack-data-model/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "ATT&CK and STIX Data Model. AdversaryGraph stores ATT&CK and ATLAS data in two layers:",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:attack-simulation",
      "title": "Attack Simulation",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/attack-simulation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Attack Simulation. Attack Simulation is the AdversaryGraph v5 detection-validation workspace. It",
      "tags": [
        "adversarygraph",
        "documentation",
        "offensive-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:authentication-and-users",
      "title": "Authentication And Users",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/authentication-and-users/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Authentication And Users. The historical v5.5 release introduced enterprise access controls for controlled self-hosted",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:capabilities",
      "title": "Platform Capabilities",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/capabilities/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Platform Capabilities. AdversaryGraph is a self-hosted CTI-to-detection platform. It connects reports, IOCs, malware behavior, threat…",
      "tags": [
        "adversarygraph",
        "documentation",
        "malware-analysis",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:case-studies-v6",
      "title": "AdversaryGraph v6 Reproducible Case Studies",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "6",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/case-studies-v6/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": null,
      "summary": "These cases use fictional repository inputs. They demonstrate implemented",
      "tags": [
        "adversarygraph",
        "case-study",
        "detection-engineering",
        "malware-analysis",
        "mitre-attack",
        "platform-documentation",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:adversarygraph-docs:case-studies-validation",
      "title": "Case Studies And Validation Examples",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/case-studies-validation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Case Studies And Validation Examples. These examples show how to validate AdversaryGraph workflows using screenshots…",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:commercial-trust",
      "title": "Commercial Trust",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/commercial-trust/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Commercial Trust. AdversaryGraph is being shaped as a commercial-grade, self-hosted CTI-to-detection workbench. This page gives reviewers…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:campaigns",
      "title": "Mode 2 — Campaigns (DB 1)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/campaigns/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Mode 2 — Campaigns (DB 1). Switch to Campaigns (DB 1) and click Compare vs Campaigns. This ranks named operations from the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:group-vs-group",
      "title": "Group vs Group",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/group-vs-group/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Group vs Group. The Group vs Group page lets you compare up to 6 APT groups simultaneously, rather than comparing your own TTP layer against…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:groups",
      "title": "Mode 1 — Groups (DB 1)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/groups/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Mode 1 — Groups (DB 1). With techniques selected in Navigator (or injected from an AI analysis), navigate to Compare, select Groups…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:overview",
      "title": "Group & Campaign Similarity Deep-Dive",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Group & Campaign Similarity Deep-Dive. AdversaryGraph compares a selected technique set with known ATT&CK group and…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:reports",
      "title": "Mode 3 — Reports (DB 2)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/reports/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Mode 3 — Reports (DB 2). Switch to Reports (DB 2). The left panel lists every AI analysis you have ever run. Click any report to…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:atomic-red-team",
      "title": "AdversaryGraph vs Atomic Red Team",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/atomic-red-team/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs Atomic Red Team. Atomic Red Team provides small, focused tests mapped to MITRE ATT&CK techniques. It is…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "offensive-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:attack-navigator",
      "title": "AdversaryGraph vs ATT&CK Navigator",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/attack-navigator/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs ATT&CK Navigator. MITRE ATT&CK Navigator is the standard matrix/layer visualization tool for ATT&CK…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:malware-sandboxes",
      "title": "AdversaryGraph vs Malware Sandboxes",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/malware-sandboxes/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs Malware Sandboxes. Malware sandboxes such as Cuckoo, CAPE, ANY.RUN, and Joe Sandbox focus on malware…",
      "tags": [
        "adversarygraph",
        "documentation",
        "malware-analysis",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:misp",
      "title": "AdversaryGraph vs MISP",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/misp/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs MISP. MISP is a threat intelligence sharing platform centered on events, attributes, galaxies, taxonomies…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:opencti",
      "title": "AdversaryGraph vs OpenCTI",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/opencti/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs OpenCTI. OpenCTI is a full cyber threat intelligence platform built around a knowledge graph, entities…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:overview",
      "title": "Comparison Overview",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Comparison Overview. AdversaryGraph is not positioned as a replacement for mature CTI, sharing, ATT&CK visualization, emulation, or…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:cve-cvss-intelligence",
      "title": "CVE Library",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/cve-cvss-intelligence/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "CVE Library. AdversaryGraph stores vulnerability intelligence as first-class data so analysts can review strict relationships between:",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:evaluation",
      "title": "Evaluation and Analyst Validation",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/evaluation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Evaluation and Analyst Validation. AdversaryGraph output is a first-pass structured analysis, not a substitute for analyst…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:full-flow",
      "title": "Get Started: Full Deployment Flow",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/full-flow/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Get Started: Full Deployment Flow. This page covers the complete first-run path for the self-hosted AdversaryGraph…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:functionality-parity",
      "title": "Platform Scope",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/functionality-parity/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Platform Scope. This documentation describes the self-hosted AdversaryGraph platform.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:generating-reports",
      "title": "Generating PDF Reports",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/generating-reports/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Generating PDF Reports. Generating PDF Reports — download from analysis results bar",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:getting-started",
      "title": "Setup (10 Minutes)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/getting-started/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Setup (10 Minutes). Prerequisites",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:intro",
      "title": "AdversaryGraph",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/intro/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph. Current source release: v6.5.0; published tag: v6.0.0 · Project Hub · Commercial Trust · Architecture · Platform Guide ·…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:malware-analysis",
      "title": "Malware Analysis",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/malware-analysis/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Malware Analysis. Introduced in v4.0 and available in current v5.0, Malware Analysis",
      "tags": [
        "adversarygraph",
        "documentation",
        "malware-analysis",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:import-export",
      "title": "Import & Export",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/import-export/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Import & Export. Import an Existing Layer",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:layers",
      "title": "Saving and Loading Named Layers",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/layers/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Saving and Loading Named Layers. Once you have built a TTP layer — through AI analysis, manual selection, or an APT campaign…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:overview",
      "title": "ATT&CK Matrix Workspace",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "ATT&CK Matrix Workspace. The matrix is the central workspace for exploring ATT&CK, selecting techniques manually, overlaying group…",
      "tags": [
        "adversarygraph",
        "documentation",
        "identity-security",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:ttp-details",
      "title": "TTP Detail Panel",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/ttp-details/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "TTP Detail Panel. Every technique ID displayed anywhere in AdversaryGraph is clickable. Clicking one opens a slide-in detail panel on the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:observability-security-validation",
      "title": "Observability, Security Scanning, And Validation Examples",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/observability-security-validation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Observability, Security Scanning, And Validation Examples. AdversaryGraph includes operator-facing…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:operations:intelligence-pipeline",
      "title": "Intelligence Pipeline",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/operations/intelligence-pipeline/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Intelligence Pipeline. AdversaryGraph includes an analyst-controlled collection, enrichment, and detection",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:operations:operations-overview",
      "title": "Operational Intelligence Workbench",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/operations/operations-overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Operational Intelligence Workbench. AdversaryGraph adds persistent operational workflows beyond ATT&CK exploration.",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:platform-guide",
      "title": "AdversaryGraph Platform Guide",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/platform-guide/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph Platform Guide. Current v5 platform documentation. AdversaryGraph is an analyst-assistance",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:release-readiness-v6",
      "title": "AdversaryGraph v6 Release Readiness",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "6",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/release-readiness-v6/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": null,
      "summary": "AdversaryGraph v6.0.0 is production-oriented for a controlled self-hosted",
      "tags": [
        "adversarygraph",
        "detection-engineering",
        "documentation",
        "malware-analysis",
        "mitre-attack",
        "platform-documentation",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:adversarygraph-docs:roadmap",
      "title": "Roadmap",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/roadmap/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Roadmap. Current source release: AdversaryGraph v6.5.0; published tag: v6.0.0.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:security",
      "title": "Security and Deployment",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/security/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Security and Deployment. Self-Hosted Deployment Security",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:tips",
      "title": "Tips for Analysts",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/tips/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Tips for Analysts. Calibrate your confidence threshold. Treat < 50% confidence as noise until you validate it manually. The LLM is trying…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:two-databases",
      "title": "Two Databases: Actor Profiles and Your Report Library",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/two-databases/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Two Databases: Actor Profiles and Your Report Library. AdversaryGraph maintains two separate databases…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases",
      "title": "AdversaryGraph Use Cases",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph Use Cases. This page organizes AdversaryGraph workflows into three levels:",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-detection-content-from-intel",
      "title": "Defense: Create Detection Content From CTI",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-detection-content-from-intel/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Create Detection Content From CTI. Practical security guidance with scope, evidence, and validation…",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-executive-risk-coverage-report",
      "title": "Defense: Executive Risk And Coverage Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-executive-risk-coverage-report/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Executive Risk And Coverage Report. Practical security guidance with scope, evidence, and validation…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-ioc-enrichment-pipeline",
      "title": "Defense: Build IOC Enrichment Pipeline",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-ioc-enrichment-pipeline/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Build IOC Enrichment Pipeline. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-mitre-coverage-baseline",
      "title": "Defense: Build MITRE Coverage Baseline",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-mitre-coverage-baseline/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Build MITRE Coverage Baseline. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-sector-detection-roadmap",
      "title": "Defense: Create Sector-Based Detection Roadmap",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-sector-detection-roadmap/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Create Sector-Based Detection Roadmap. Practical security guidance with scope, evidence, and…",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-build-sector-brief",
      "title": "Build A Sector Threat Brief",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-build-sector-brief/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Build A Sector Threat Brief. Build Sector Threat Brief workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-compare-incident-to-actors",
      "title": "Compare Incident TTPs To Actors",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-compare-incident-to-actors/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Compare Incident TTPs To Actors. Compare Incident TTPs to Actors workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-compare-two-reports",
      "title": "Compare Two Reports",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-compare-two-reports/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Compare Two Reports. Compare Two Reports workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-enrich-actor-iocs",
      "title": "Enrich Actor IOCs",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-enrich-actor-iocs/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Enrich Actor IOCs. Enrich Actor IOCs workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-import-misp-json",
      "title": "Import MISP JSON",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-import-misp-json/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Import MISP JSON. Import MISP JSON workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-map-report-to-attack",
      "title": "Map A Report To ATT&CK",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-map-report-to-attack/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Map A Report To ATT&CK. Map Report to ATT&CK workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-pull-taxii-stix",
      "title": "Pull TAXII Or Import STIX",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-pull-taxii-stix/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Pull TAXII Or Import STIX. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-review-coverage-gap",
      "title": "Review One Coverage Gap",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-review-coverage-gap/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Review One Coverage Gap. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-sync-yara-sigma",
      "title": "Sync YARA And Sigma Feeds",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-sync-yara-sigma/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Sync YARA And Sigma Feeds. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "detection-engineering",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-use-local-llm",
      "title": "Use A Local LLM For Private Reports",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-use-local-llm/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Use A Local LLM For Private Reports. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-apt-campaign-cluster",
      "title": "Investigation: Cluster Multiple APT Reports",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-apt-campaign-cluster/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Cluster Multiple APT Reports. Practical security guidance with scope, evidence, and validation…",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-cloud-incident",
      "title": "Investigation: Cloud And Kubernetes Incident",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-cloud-incident/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Cloud And Kubernetes Incident. Practical security guidance with scope, evidence, and validation…",
      "tags": [
        "adversarygraph",
        "case-study",
        "cloud-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-malware-family",
      "title": "Investigation: Malware Family Behavior Mapping",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-malware-family/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Malware Family Behavior Mapping. Practical security guidance with scope, evidence, and…",
      "tags": [
        "adversarygraph",
        "case-study",
        "malware-analysis",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-ransomware-intrusion",
      "title": "Investigation: From Log To Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-ransomware-intrusion/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: From Log To Report. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-third-party-report-validation",
      "title": "Investigation: Validate A Third-Party CTI Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-third-party-report-validation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Validate A Third-Party CTI Report. Practical security guidance with scope, evidence, and…",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-add-custom-ioc-feed",
      "title": "Add A Custom IOC Feed",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-add-custom-ioc-feed/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Add A Custom IOC Feed. Add Custom IOC Feed workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-check-an-ioc",
      "title": "Check One IOC",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-check-an-ioc/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Check One IOC. Check One IOC workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-export-pdf-report",
      "title": "Export A PDF Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-export-pdf-report/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Export A PDF Report. Export PDF Report workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-import-navigator-layer",
      "title": "Import A Navigator Layer",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-import-navigator-layer/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Import A Navigator Layer. Import Navigator Layer workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-open-actor-profile",
      "title": "Open One Actor Profile",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-open-actor-profile/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Open One Actor Profile. Open Actor Profile workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-open-troubleshooting",
      "title": "Open Troubleshooting For An Error",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-open-troubleshooting/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Open Troubleshooting For An Error. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-run-selftest",
      "title": "Run Deployment Selftest",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-run-selftest/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Run Deployment Selftest. Run Deployment Selftest workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-search-ioc-library",
      "title": "Search The IOC Library",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-search-ioc-library/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Search The IOC Library. Search IOC Library workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-show-actor-on-matrix",
      "title": "Show Actor TTPs On The Matrix",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-show-actor-on-matrix/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Show Actor TTPs On The Matrix. Show Actor TTPs on Matrix workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-sync-threatfox",
      "title": "Sync ThreatFox IOCs",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-sync-threatfox/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Sync ThreatFox IOCs. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:visual-guide",
      "title": "AdversaryGraph Visual Guide",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/visual-guide/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph Visual Guide. This guide shows the current AdversaryGraph platform, not only the older",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-web-guide.html",
      "title": "Threat Matrix",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "Threat Matrix public ATT&CK workspace",
      "canonical_url": "https://1200km.com/adversarygraph-web-guide.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Guide to Threat Matrix: browser-native ATT&CK matrices, group library, TTP overlap scoring, group comparison, coverage…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/adversarygraph-web-guide.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph",
      "title": "AdversaryGraph",
      "primary_type": "platform",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "platform-operator"
      ],
      "status": "released",
      "maturity": "production",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-20",
      "summary": "AdversaryGraph v6.5.0 is the current merged, CI-validated source release of the self-hosted CTI-to-detection platform for…",
      "tags": [
        "adversarygraph",
        "detection-engineering",
        "platform",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "version": "6.5.0",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph:full-version-feature-guides.html",
      "title": "AdversaryGraph Full-Version Guide — 31 Modules and Use Cases",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "platform-operator",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph v6.5.0 merged, CI-validated source release; latest published immutable GitHub release v6.0.0",
      "canonical_url": "https://1200km.com/adversarygraph/full-version-feature-guides.html",
      "published_at": "2026-07-23",
      "updated_at": "2026-07-25",
      "summary": "Detailed single-column guide to all 31 governed AdversaryGraph workspaces with prerequisites, step-by-step workflows, outputs, worked use cases, acceptance evidence, screenshots, and explicit source-versus-published release boundaries.",
      "tags": [
        "adversarygraph",
        "case-studies",
        "detection-engineering",
        "guide",
        "platform-operations",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/adversarygraph/full-version-feature-guides.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph:use-cases.html",
      "title": "Use Cases for AI-Assisted CTI, Malware Analysis, ATT&CK Mapping, IOC Investigation, and Detection Handoff",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph analyst workflows",
      "canonical_url": "https://1200km.com/adversarygraph/use-cases.html",
      "published_at": null,
      "updated_at": "2026-07-17",
      "summary": "Use Cases for AI-Assisted CTI, Malware Analysis…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "malware-analysis",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/adversarygraph/use-cases.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-offensive.html",
      "title": "AI in Offensive Security",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized AI-assisted offensive-security testing",
      "canonical_url": "https://1200km.com/ai-offensive.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "AI-driven offensive security by Andrey Pautov: HexStrike AI, MCP orchestration, autonomous attack chains…",
      "tags": [
        "ai-security",
        "offensive-research",
        "offensive-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-offensive.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-vs-defense",
      "title": "Old Defense vs New-Age Attacks",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-vs-defense/",
      "published_at": null,
      "updated_at": null,
      "summary": "AI demolished the skill barrier that was an implicit cybersecurity defense for 20 years. A practitioner's guide for SOC analysts and CTI teams.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-vs-defense/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:anomaly-detection-atlas",
      "title": "Understand deviation. Measure observable change.",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "A vendor-neutral reference for statistical anomaly types and security log sources.",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:attack-activity-log-source-catalog",
      "title": "Suspicious and Malicious Activity by MITRE ATT&CK",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/attack-activity-log-source-catalog/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This catalog describes observable suspicious and malicious activity aligned to the current MITRE ATT&CK Enterprise tactics and techniques. Each activity links directly to the vendor-neutral log sources that can report it.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:attack-basic-detection-rule-catalog",
      "title": "Basic Detection Rules by MITRE ATT&CK TTP",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/attack-basic-detection-rule-catalog/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This catalog provides vendor-neutral algorithmic logic for basic deterministic detection rules mapped to MITRE ATT&CK Enterprise techniques and sub-techniques. Rules use signatures, fixed thresholds, allowlists, denylists, state changes, and bounded-window correlations. They do not depend on learned baselines or statistical anomaly models.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:attack-statistical-anomaly-mapping",
      "title": "Suspicious and Malicious Activity Explained by Statistical Anomalies",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/attack-statistical-anomaly-mapping/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This catalog explains how observable suspicious and malicious activity can manifest as statistical anomalies. It connects ATT&CK-aligned activity to the reference population, expected behavior, measurable deviation, applicable statistical anomaly types, and supporting log sources.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:security-log-source-taxonomy",
      "title": "Vendor-Neutral Security Log Source Taxonomy",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/security-log-source-taxonomy/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This document catalogs security-relevant log and telemetry source types without mapping them to vendors, detection rules, anomalies, or threat frameworks. Each entry describes what the source records and the kinds of activity it can report.",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:statistical-anomaly-taxonomy",
      "title": "Statistical Anomaly Taxonomy",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/statistical-anomaly-taxonomy/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This document lists statistically relevant anomaly types without tying them to any specific application domain. An anomaly is an observation, group of observations, relationship, sequence, or distributional state that deviates meaningfully from an appropriate reference model.",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles",
      "title": "Security research articles, available locally.",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "current local article index",
      "canonical_url": "https://1200km.com/articles/",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": null,
      "updated_at": "2026-07-29",
      "summary": "Read the complete local 1200km archive of security research articles, guides, labs, and case studies.",
      "tags": [
        "index",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:adversarygraph-from-log-to-report-ioc-investigation.html",
      "title": "From Log to Report: Using AdversaryGraph to Turn Firewall and EDR Noise Into a CTI Investigation",
      "primary_type": "case-study",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "AdversaryGraph log-to-report investigation workflow using synthetic telemetry",
      "canonical_url": "https://1200km.com/articles/adversarygraph-from-log-to-report-ioc-investigation.html",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": "2026-06-27",
      "updated_at": "2026-06-27",
      "summary": "From Log to Report: Using AdversaryGraph to Turn Firewall…",
      "tags": [
        "adversarygraph",
        "article",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "title": "Historical: AdversaryGraph v4 Capability Map",
      "primary_type": "mirror",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer"
      ],
      "status": "superseded",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "version": "AdversaryGraph v4",
      "applies_to": "historical AdversaryGraph v4 capability map",
      "canonical_url": "https://1200km.com/articles/adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "source_url": "https://medium.com/@1200km/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "published_at": "2026-06-19",
      "updated_at": "2026-06-27",
      "summary": "Historical, version-specific AdversaryGraph v4 capability map. The…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "archive_reason": "Preserved as a version-specific historical article; it does not describe the current stable release.",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "superseded"
    },
    {
      "id": "site:articles:read",
      "title": "Article Archive",
      "primary_type": "index",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "canonical local article pages with original publication URLs retained as provenance",
      "canonical_url": "https://1200km.com/articles/read/",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": null,
      "updated_at": "2026-07-25",
      "summary": "Article Archive. Full local Docusaurus archive of exported Medium articles by Andrey Pautov.",
      "tags": [
        "index",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2024:2024-10-17-wifi-cracking-with-aircrack-ng-d51cf98c789f",
      "title": "WiFi cracking with Aircrack-ng",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-17-wifi-cracking-with-aircrack-ng-d51cf98c789f/",
      "source_url": "https://medium.com/@1200km/wifi-cracking-with-aircrack-ng-d51cf98c789f",
      "published_at": "2024-10-17",
      "updated_at": "2024-10-17",
      "summary": "WiFi cracking with Aircrack-ng. In this article, I am going to explain how you can crack a WiFi network using Aircrack-ng and the PPG — Personal Pass.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/wifi-cracking-with-aircrack-ng-d51cf98c789f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-20-accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7",
      "title": "Accessing Remote Desktops: A Beginner’s Guide to RDP Cracking with Crowbar and PPG tools",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-20-accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7/",
      "source_url": "https://medium.com/@1200km/accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7",
      "published_at": "2024-10-20",
      "updated_at": "2024-10-20",
      "summary": "Accessing Remote Desktops: A Beginner’s Guide to RDP Cracking with Crowbar and PPG tools. Master the Techniques: Unveiling the Power of Crowbar and PPG to.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-20-personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c",
      "title": "Personal Pass Generator (PPG): The Ultimate Tool for Custom Password Lists",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-20-personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c/",
      "source_url": "https://medium.com/@1200km/personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c",
      "published_at": "2024-10-20",
      "updated_at": "2024-10-20",
      "summary": "Personal Pass Generator (PPG): The Ultimate Tool for Custom Password Lists. Hello, my name is Andrey Pautov, and today I’m excited to introduce you to my.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-21-exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602",
      "title": "Exploiting FTP Vulnerabilities for Effective Penetration Testing",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-21-exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602/",
      "source_url": "https://medium.com/@1200km/exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602",
      "published_at": "2024-10-21",
      "updated_at": "2024-10-21",
      "summary": "Exploiting FTP Vulnerabilities for Effective Penetration Testing. In this guide, we will explore common vulnerabilities in the File Transfer Protocol (FTP).",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-22-cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09",
      "title": "Cracking Telnet: Exploring Weaknesses and Exploitation Techniques",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-22-cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09/",
      "source_url": "https://medium.com/@1200km/cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09",
      "published_at": "2024-10-22",
      "updated_at": "2024-10-22",
      "summary": "Cracking Telnet: Exploring Weaknesses and Exploitation Techniques. In this article, I will walk you through the process of cracking a Telnet service.",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-23-cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee",
      "title": "Cracking RTSP Security: A Comprehensive Guide to Using the RTSP Brute Force Tool",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-23-cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee/",
      "source_url": "https://medium.com/@1200km/cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee",
      "published_at": "2024-10-23",
      "updated_at": "2024-10-23",
      "summary": "Cracking RTSP Security: A Comprehensive Guide to Using the RTSP Brute Force Tool. This article introduces a powerful tool designed for the RTSP Brute Force",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-23-cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b",
      "title": "Cracking SSH with Metasploit: A Step-by-Step Guide to Exploiting Weak Credentials",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-23-cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b/",
      "source_url": "https://medium.com/@1200km/cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b",
      "published_at": "2024-10-23",
      "updated_at": "2024-10-23",
      "summary": "Cracking SSH with Metasploit: A Step-by-Step Guide to Exploiting Weak Credentials. In this article, I will walk you through the process of cracking SSH using.",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-24-cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0",
      "title": "Cracking Web Interfaces with Burp Suite: A Comprehensive Tutorial",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-24-cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0/",
      "source_url": "https://medium.com/@1200km/cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0",
      "published_at": "2024-10-24",
      "updated_at": "2024-10-24",
      "summary": "Cracking Web Interfaces with Burp Suite: A Comprehensive Tutorial. In this guide, I will detail how to use Burp Suite, a popular web security tool, to.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-24-shodan-guide-how-you-can-find-everything-640f47f41bbe",
      "title": "Shodan , guide how you can find everything!",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-24-shodan-guide-how-you-can-find-everything-640f47f41bbe/",
      "source_url": "https://medium.com/@1200km/shodan-guide-how-you-can-find-everything-640f47f41bbe",
      "published_at": "2024-10-24",
      "updated_at": "2024-10-24",
      "summary": "Shodan , guide how you can find everything!. In this guide, we’ll explore how to navigate Shodan, understand the information it provides, and",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/shodan-guide-how-you-can-find-everything-640f47f41bbe",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-26-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 1",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-26-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0",
      "published_at": "2024-10-26",
      "updated_at": "2024-10-26",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 1. This comprehensive post will delve into the powerful network.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-27-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 2",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-27-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c",
      "published_at": "2024-10-27",
      "updated_at": "2024-10-27",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 2. This a second part of comprehensive Medium post will delve into.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 3",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 3. This a third part of comprehensive Medium post will delve into.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4",
      "title": "Office file (DOC, DOCX, PPT…) Password cracking. Guide with real life examples!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4/",
      "source_url": "https://medium.com/@1200km/office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "Office file (DOC, DOCX, PPT…) Password cracking. Guide with real life examples!. Unlock the secrets of Office file password cracking with our in-depth guide..",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4",
      "title": "PDF file Password cracking. Guide with real life examples!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4/",
      "source_url": "https://medium.com/@1200km/pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "PDF file Password cracking. Guide with real life examples!. Unlock the secrets of PDF file password cracking with our in-depth guide. Learn the tools.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897",
      "title": "ZIP file Password cracking. Guide with real life examples!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897/",
      "source_url": "https://medium.com/@1200km/zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "ZIP file Password cracking. Guide with real life examples!. Unlock the secrets of ZIP file password cracking with our in-depth guide. Learn the tools.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-29-passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd",
      "title": "Passwords cracking.ZIP, PDF, WEB, RDP, SSH, Cameras…",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-29-passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd/",
      "source_url": "https://medium.com/@1200km/passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd",
      "published_at": "2024-10-29",
      "updated_at": "2024-10-29",
      "summary": "Passwords cracking.ZIP, PDF, WEB, RDP, SSH, Cameras…. Dive into the art of password cracking with our guide that covers everything from brute force to.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-30-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 4. Scripts",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-30-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f",
      "published_at": "2024-10-30",
      "updated_at": "2024-10-30",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 4. Scripts. This a third part of comprehensive Medium post will.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-01-mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1",
      "title": "Mastering Hydra: The Ultimate Guide to Network Logon Cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-01-mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1/",
      "source_url": "https://medium.com/@1200km/mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1",
      "published_at": "2024-11-01",
      "updated_at": "2024-11-01",
      "summary": "Mastering Hydra: The Ultimate Guide to Network Logon Cracking. Unlocking the Gates of Network Security: An In-Depth Exploration into Mastering Hydra for.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-03-breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8",
      "title": "Breaking the Code: How to Use Hashcat for Effective Password Cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-03-breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8/",
      "source_url": "https://medium.com/@1200km/breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8",
      "published_at": "2024-11-03",
      "updated_at": "2024-11-03",
      "summary": "Breaking the Code: How to Use Hashcat for Effective Password Cracking. Your step-by-step guide to mastering Hashcat, from setting it up on your system to.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-04-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83",
      "title": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 1. (basic, wizard)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-04-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83/",
      "source_url": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83",
      "published_at": "2024-11-04",
      "updated_at": "2024-11-04",
      "summary": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 1. (basic, wizard). Learn how SQLMap transforms the landscape of database security by.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-05-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53",
      "title": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 2. (Advanced, custom setup)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-05-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53/",
      "source_url": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53",
      "published_at": "2024-11-05",
      "updated_at": "2024-11-05",
      "summary": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 2. (Advanced, custom setup). Learn how SQLMap transforms the landscape of database security by.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-06-owasp-amass-project-guide-94bd55521f91",
      "title": "OWASP Amass Project guide",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-06-owasp-amass-project-guide-94bd55521f91/",
      "source_url": "https://medium.com/@1200km/owasp-amass-project-guide-94bd55521f91",
      "published_at": "2024-11-06",
      "updated_at": "2024-11-06",
      "summary": "OWASP Amass Project guide. In-depth Attack Surface Mapping and Asset Discovery.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/owasp-amass-project-guide-94bd55521f91",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-07-sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712",
      "title": "Sublist3r. Your Essential Tool for Subdomain Enumeration",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-07-sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712/",
      "source_url": "https://medium.com/@1200km/sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712",
      "published_at": "2024-11-07",
      "updated_at": "2024-11-07",
      "summary": "Sublist3r. Your Essential Tool for Subdomain Enumeration. Uncovering Subdomains for Enhanced Reconnaissance: A Comprehensive Guide to Using Sublist3r for.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-07-theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3",
      "title": "theHarvester: Your Essential Tool for OSINT and Reconnaissance in Cybersecurity",
      "primary_type": "article",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-07-theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3/",
      "source_url": "https://medium.com/@1200km/theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3",
      "published_at": "2024-11-07",
      "updated_at": "2024-11-07",
      "summary": "theHarvester: Your Essential Tool for OSINT and Reconnaissance in Cybersecurity. Learn how to leverage theHarvester to gather emails, subdomains, IPs, and.",
      "tags": [
        "ai-security",
        "article",
        "open-source-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-09-mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394",
      "title": "Mastering the Basics: Essential CLI Tools for Reconnaissance in Penetration Testing",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-09-mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394/",
      "source_url": "https://medium.com/@1200km/mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394",
      "published_at": "2024-11-09",
      "updated_at": "2024-11-09",
      "summary": "Mastering the Basics: Essential CLI Tools for Reconnaissance in Penetration Testing. A Comprehensive Guide to Command Line Tools for Network Exploration: How.",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-censys-for-enhanced-cybersecurity-insight-533df14794bd",
      "title": "Censys for Enhanced Cybersecurity Insight",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-censys-for-enhanced-cybersecurity-insight-533df14794bd/",
      "source_url": "https://medium.com/@1200km/censys-for-enhanced-cybersecurity-insight-533df14794bd",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Censys for Enhanced Cybersecurity Insight. A professional guide to understanding and utilizing Censys for advanced digital threat intelligence.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/censys-for-enhanced-cybersecurity-insight-533df14794bd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b",
      "title": "Mastering DirBuster: A Strategic Approach to Uncovering Hidden Web Assets",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b/",
      "source_url": "https://medium.com/@1200km/mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Mastering DirBuster: A Strategic Approach to Uncovering Hidden Web Assets. A comprehensive guide to using DirBuster for uncovering hidden directories and.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411",
      "title": "Unlocking Web Intelligence: A Deep Dive into WhatWeb",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411/",
      "source_url": "https://medium.com/@1200km/unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Unlocking Web Intelligence: A Deep Dive into WhatWeb. Explore how WhatWeb deciphers the technologies powering websites, enhancing security and reconnaissance.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399",
      "title": "Web Applications Penetretion Testing. Stage 1: Reconnaissance",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399/",
      "source_url": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Web Applications Penetretion Testing. Stage 1: Reconnaissance. Unveil the first steps in securing web applications by exploring the essential techniques and.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-11-mastering-burp-suite-vulnerability-scanner-019ed82c8bac",
      "title": "Mastering Burp Suite Vulnerability Scanner",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-11-mastering-burp-suite-vulnerability-scanner-019ed82c8bac/",
      "source_url": "https://medium.com/@1200km/mastering-burp-suite-vulnerability-scanner-019ed82c8bac",
      "published_at": "2024-11-11",
      "updated_at": "2024-11-11",
      "summary": "Mastering Burp Suite Vulnerability Scanner. From configuration to result analysis, discover how to leverage Burp Suite’s automatic scanner for faster and.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-burp-suite-vulnerability-scanner-019ed82c8bac",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-12-nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21",
      "title": "Nikto: Uncovering Web Server Vulnerabilities with an Open-Source Scanner",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-12-nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21/",
      "source_url": "https://medium.com/@1200km/nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21",
      "published_at": "2024-11-12",
      "updated_at": "2024-11-12",
      "summary": "Nikto: Uncovering Web Server Vulnerabilities with an Open-Source Scanner. A Guide to Using Nikto for Identifying Security Flaws and Misconfigurations in Web.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-12-owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b",
      "title": "OWASP ZAP: A Comprehensive Guide to Web Application Security Testing",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-12-owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b/",
      "source_url": "https://medium.com/@1200km/owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b",
      "published_at": "2024-11-12",
      "updated_at": "2024-11-12",
      "summary": "OWASP ZAP: A Comprehensive Guide to Web Application Security Testing. Using OWASP ZAP for Identifying and Mitigating Web Application Vulnerabilities",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-13-web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130",
      "title": "Web Applications Penetretion Testing. Stage 2: Scanning and Vulnerability Assessment",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-13-web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130/",
      "source_url": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130",
      "published_at": "2024-11-13",
      "updated_at": "2024-11-13",
      "summary": "Web Applications Penetretion Testing. Stage 2: Scanning and Vulnerability Assessment. Identifying Weaknesses: Mastering the Art of Scanning and Vulnerability.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-15-2john-9bb0bd44ed64",
      "title": "2John",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-15-2john-9bb0bd44ed64/",
      "source_url": "https://medium.com/@1200km/2john-9bb0bd44ed64",
      "published_at": "2024-11-15",
      "updated_at": "2024-11-15",
      "summary": "2John. Full list of tools",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/2john-9bb0bd44ed64",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-15-john-the-ripper-hash-formats-f2ec958acaf8",
      "title": "John The Ripper Hash Formats",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-15-john-the-ripper-hash-formats-f2ec958acaf8/",
      "source_url": "https://medium.com/@1200km/john-the-ripper-hash-formats-f2ec958acaf8",
      "published_at": "2024-11-15",
      "updated_at": "2024-11-15",
      "summary": "John The Ripper Hash Formats. Reference",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/john-the-ripper-hash-formats-f2ec958acaf8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-15-mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71",
      "title": "Mastering John the Ripper: A Complete Guide to Password Cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-15-mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71/",
      "source_url": "https://medium.com/@1200km/mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71",
      "published_at": "2024-11-15",
      "updated_at": "2024-11-15",
      "summary": "Mastering John the Ripper: A Complete Guide to Password Cracking. Unlock the power of John the Ripper, from basic setups to advanced password recovery.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-16-the-basic-toolkit-for-penetration-testing-303da9234d82",
      "title": "The Basic Toolkit for Penetration Testing",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-16-the-basic-toolkit-for-penetration-testing-303da9234d82/",
      "source_url": "https://medium.com/@1200km/the-basic-toolkit-for-penetration-testing-303da9234d82",
      "published_at": "2024-11-16",
      "updated_at": "2024-11-16",
      "summary": "The Basic Toolkit for Penetration Testing. Unlocking Vulnerabilities: A Comprehensive Guide to Essential Tools for Pen Testing",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-basic-toolkit-for-penetration-testing-303da9234d82",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-17-the-ultimate-guide-to-metasploit-part-1-43c8573487df",
      "title": "The Ultimate Guide to Metasploit. Part 1.",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-17-the-ultimate-guide-to-metasploit-part-1-43c8573487df/",
      "source_url": "https://medium.com/@1200km/the-ultimate-guide-to-metasploit-part-1-43c8573487df",
      "published_at": "2024-11-17",
      "updated_at": "2024-11-17",
      "summary": "The Ultimate Guide to Metasploit. Part 1.. A Complete Guide to Exploiting Vulnerabilities and Strengthening Security with Metasploit",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-ultimate-guide-to-metasploit-part-1-43c8573487df",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-18-metasploit-modules-guide-auxiliary-1821db1712f0",
      "title": "Metasploit modules guide. Auxiliary",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-18-metasploit-modules-guide-auxiliary-1821db1712f0/",
      "source_url": "https://medium.com/@1200km/metasploit-modules-guide-auxiliary-1821db1712f0",
      "published_at": "2024-11-18",
      "updated_at": "2024-11-18",
      "summary": "Metasploit modules guide. Auxiliary. Complete Explanation of Auxiliary Mode in Metasploit",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/metasploit-modules-guide-auxiliary-1821db1712f0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-20-how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3",
      "title": "How to Create a Vulnerable Windows Virtual Machine for Pentesting Training with scripts!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-20-how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3/",
      "source_url": "https://medium.com/@1200km/how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3",
      "published_at": "2024-11-20",
      "updated_at": "2024-11-20",
      "summary": "How to Create a Vulnerable Windows Virtual Machine for Pentesting Training with scripts!. Building Your Cybersecurity Playground: Step-by-Step Guide to.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-24-title-metasploit-modules-guide-exploit-73eecb50e3c3",
      "title": "Title Metasploit modules guide. Exploit",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-24-title-metasploit-modules-guide-exploit-73eecb50e3c3/",
      "source_url": "https://medium.com/@1200km/title-metasploit-modules-guide-exploit-73eecb50e3c3",
      "published_at": "2024-11-24",
      "updated_at": "2024-11-24",
      "summary": "Title Metasploit modules guide. Exploit. Complete Explanation of Exploit Mode in Metasploit",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/title-metasploit-modules-guide-exploit-73eecb50e3c3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-02-24-soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476",
      "title": "SOC Tier 1: The Complete Onboarding Guide to Security Monitoring and Incident Response",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-02-24-soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476/",
      "source_url": "https://medium.com/@1200km/soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476",
      "published_at": "2025-02-24",
      "updated_at": "2025-02-24",
      "summary": "SOC Tier 1: The Complete Onboarding Guide to Security Monitoring and Incident Response. Part 1.",
      "tags": [
        "article",
        "incident-response",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-14-authenticator-exe-dearsteeler-0c1d69767939",
      "title": "Authenticator.exe/DearSteeler",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-14-authenticator-exe-dearsteeler-0c1d69767939/",
      "source_url": "https://medium.com/@1200km/authenticator-exe-dearsteeler-0c1d69767939",
      "published_at": "2025-03-14",
      "updated_at": "2025-03-14",
      "summary": "Authenticator.exe/DearSteeler. Malware research report",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/authenticator-exe-dearsteeler-0c1d69767939",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-24-spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295",
      "title": "SPW AW25 — PO.010 SMS.exe.exe (AgentTesla)",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-24-spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295/",
      "source_url": "https://medium.com/@1200km/spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295",
      "published_at": "2025-03-24",
      "updated_at": "2025-03-24",
      "summary": "SPW AW25 — PO.010 SMS.exe.exe (AgentTesla). Malware research report",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-29-static-malware-analysis-strings-analysis-e876640cfdb0",
      "title": "Static Malware Analysis. Strings analysis.",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-29-static-malware-analysis-strings-analysis-e876640cfdb0/",
      "source_url": "https://medium.com/@1200km/static-malware-analysis-strings-analysis-e876640cfdb0",
      "published_at": "2025-03-29",
      "updated_at": "2025-03-29",
      "summary": "Static Malware Analysis. Strings analysis.. Understanding Strings",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/static-malware-analysis-strings-analysis-e876640cfdb0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-30-static-malware-analysis-obfuscation-51de3992065d",
      "title": "Static Malware Analysis . Obfuscation.",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-30-static-malware-analysis-obfuscation-51de3992065d/",
      "source_url": "https://medium.com/@1200km/static-malware-analysis-obfuscation-51de3992065d",
      "published_at": "2025-03-30",
      "updated_at": "2025-03-30",
      "summary": "Static Malware Analysis . Obfuscation.. Understanding Code Obfuscation in Malware",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/static-malware-analysis-obfuscation-51de3992065d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-04-01-static-malware-analysis-file-fingerprinting-3ddf9bdd7864",
      "title": "Static Malware Analysis. File Fingerprinting",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-04-01-static-malware-analysis-file-fingerprinting-3ddf9bdd7864/",
      "source_url": "https://medium.com/@1200km/static-malware-analysis-file-fingerprinting-3ddf9bdd7864",
      "published_at": "2025-04-01",
      "updated_at": "2025-04-01",
      "summary": "Static Malware Analysis. File Fingerprinting. Understanding File Signatures, Hash, Digital Signatures",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/static-malware-analysis-file-fingerprinting-3ddf9bdd7864",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-04-17-deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87",
      "title": "Deep Dive: Automating Static Malware Analysis with Three Python Tools",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-04-17-deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87/",
      "source_url": "https://medium.com/@1200km/deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87",
      "published_at": "2025-04-17",
      "updated_at": "2025-04-17",
      "summary": "Deep Dive: Automating Static Malware Analysis with Three Python Tools. Static malware analysis involves multiple stages, each revealing different facets of a.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-06-17-tools-by-mitre-att-and-ck-guide-77c4d947ba36",
      "title": "Tools by MITRE ATT&CK Guide",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-06-17-tools-by-mitre-att-and-ck-guide-77c4d947ba36/",
      "source_url": "https://medium.com/@1200km/tools-by-mitre-att-and-ck-guide-77c4d947ba36",
      "published_at": "2025-06-17",
      "updated_at": "2025-06-17",
      "summary": "Tools by MITRE ATT&CK Guide. Reconnecense",
      "tags": [
        "article",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/tools-by-mitre-att-and-ck-guide-77c4d947ba36",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-08-fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f",
      "title": "Fluent Bit on AWS-EKS: Centralized Kubernetes Log Shipping to XPLG",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-08-fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f/",
      "source_url": "https://medium.com/@1200km/fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f",
      "published_at": "2025-07-08",
      "updated_at": "2025-07-08",
      "summary": "Fluent Bit on AWS-EKS: Centralized Kubernetes Log Shipping to XPLG. Deploy Fluent Bit as a DaemonSet with full metadata enrichment, RBAC, and HTTP output to.",
      "tags": [
        "article",
        "cloud-security",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-09-threat-hunting-with-the-pyramid-of-pain-8add3cedb380",
      "title": "Threat Hunting with the Pyramid of Pain",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-09-threat-hunting-with-the-pyramid-of-pain-8add3cedb380/",
      "source_url": "https://medium.com/@1200km/threat-hunting-with-the-pyramid-of-pain-8add3cedb380",
      "published_at": "2025-07-09",
      "updated_at": "2025-07-09",
      "summary": "Threat Hunting with the Pyramid of Pain. A practical guide to using threat indicators that actually hurt your attackers, based on David J. Bianco’s model..",
      "tags": [
        "article",
        "threat-hunting"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/threat-hunting-with-the-pyramid-of-pain-8add3cedb380",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-11-fluentbit-on-kubernetes-demonset-deployment-13c3915113ba",
      "title": "FluentBit on Kubernetes DemonSet Deployment.",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-11-fluentbit-on-kubernetes-demonset-deployment-13c3915113ba/",
      "source_url": "https://medium.com/@1200km/fluentbit-on-kubernetes-demonset-deployment-13c3915113ba",
      "published_at": "2025-07-11",
      "updated_at": "2025-07-11",
      "summary": "FluentBit on Kubernetes DemonSet Deployment.. Cluster-wide log collection using Fluent Bit on every node",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/fluentbit-on-kubernetes-demonset-deployment-13c3915113ba",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-11-sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b",
      "title": "Sending EKS Control Plane Logs via AWS Lambda",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-11-sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b/",
      "source_url": "https://medium.com/@1200km/sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b",
      "published_at": "2025-07-11",
      "updated_at": "2025-07-11",
      "summary": "Sending EKS Control Plane Logs via AWS Lambda. A step-by-step guide to forwarding Amazon EKS control plane logs to SIEM/LogCOllector/XPLG using a lightweight.",
      "tags": [
        "article",
        "cloud-security",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-20-cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54",
      "title": "Cyberattacks on 4G/LTE Telecom Networks: Threat Mapping and Defense",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-20-cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54/",
      "source_url": "https://medium.com/@1200km/cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54",
      "published_at": "2025-07-20",
      "updated_at": "2025-07-20",
      "summary": "Cyberattacks on 4G/LTE Telecom Networks: Threat Mapping and Defense. This research provides an in-depth analysis of cyber threats targeting LTE telecom core.",
      "tags": [
        "article",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-20-cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df",
      "title": "Cyberattacks on 5G Telecom Networks: Threat Mapping and Defense",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-20-cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df/",
      "source_url": "https://medium.com/@1200km/cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df",
      "published_at": "2025-07-20",
      "updated_at": "2025-07-20",
      "summary": "Cyberattacks on 5G Telecom Networks: Threat Mapping and Defense. This research provides an in-depth analysis of cyber threats targeting 5G telecom core.",
      "tags": [
        "article",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-25-information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c",
      "title": "Information Security Awareness: Principles and Best Practices for Employees",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-25-information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c/",
      "source_url": "https://medium.com/@1200km/information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c",
      "published_at": "2025-07-25",
      "updated_at": "2025-07-25",
      "summary": "Information Security Awareness: Principles and Best Practices for Employees. What Is Information Security and Why Does It Matter",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-25-phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511",
      "title": "Phishing Email Awareness: Protecting Employees and Organizations",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-25-phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511/",
      "source_url": "https://medium.com/@1200km/phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511",
      "published_at": "2025-07-25",
      "updated_at": "2025-07-25",
      "summary": "Phishing Email Awareness: Protecting Employees and Organizations. What is Email Phishing and Why It’s Dangerous",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-27-quick-start-server-hardening-checklist-all-open-source-08e9887b9faa",
      "title": "Quick‑Start Server Hardening Checklist (all open‑source)",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-27-quick-start-server-hardening-checklist-all-open-source-08e9887b9faa/",
      "source_url": "https://medium.com/@1200km/quick-start-server-hardening-checklist-all-open-source-08e9887b9faa",
      "published_at": "2025-07-27",
      "updated_at": "2025-07-27",
      "summary": "Quick‑Start Server Hardening Checklist (all open‑source). ISO 27001-Based Server Hardening Plan",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/quick-start-server-hardening-checklist-all-open-source-08e9887b9faa",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-08-01-the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25",
      "title": "The 20x Employee: A Strategic Framework for Unlocking Hyper-Productivity with Artificial…",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-08-01-the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25/",
      "source_url": "https://medium.com/@1200km/the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25",
      "published_at": "2025-08-01",
      "updated_at": "2025-08-01",
      "summary": "The 20x Employee: A Strategic Framework for Unlocking Hyper-Productivity with Artificial…. A Strategic Blueprint for Augmenting Human Talent with Generative.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-08-31-from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83",
      "title": "From Bugs to Breaches: Learning Secure Coding Through the OWASP Top 10",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-08-31-from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83/",
      "source_url": "https://medium.com/@1200km/from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83",
      "published_at": "2025-08-31",
      "updated_at": "2025-08-31",
      "summary": "From Bugs to Breaches: Learning Secure Coding Through the OWASP Top 10. Practical scenarios that show how small developer mistakes lead to big security.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-13-villager-the-ai-powered-penetration-testing-framework-8df10532e265",
      "title": "Villager: The AI-Powered Penetration Testing Framework",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-13-villager-the-ai-powered-penetration-testing-framework-8df10532e265/",
      "source_url": "https://medium.com/@1200km/villager-the-ai-powered-penetration-testing-framework-8df10532e265",
      "published_at": "2025-10-13",
      "updated_at": "2025-10-13",
      "summary": "Villager: The AI-Powered Penetration Testing Framework. How “Villager,” a DeepSeek-driven framework from China’s Cyberspike collective, automates.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/villager-the-ai-powered-penetration-testing-framework-8df10532e265",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-14-the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3",
      "title": "The Invisible Pipeline: Defending CI/CD from Targeted Attacks",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-14-the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3/",
      "source_url": "https://medium.com/@1200km/the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3",
      "published_at": "2025-10-14",
      "updated_at": "2025-10-14",
      "summary": "The Invisible Pipeline: Defending CI/CD from Targeted Attacks. How adversaries weaponize build systems — and the concrete tools & controls you can use to.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-18-automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a",
      "title": "Automating a Safe DVWA Lab with Ansible: Build a Reproducible Vulnerable Environment for Training…",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-18-automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a/",
      "source_url": "https://medium.com/@1200km/automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a",
      "published_at": "2025-10-18",
      "updated_at": "2025-10-18",
      "summary": "Automating a Safe DVWA Lab with Ansible: Build a Reproducible Vulnerable Environment for Training…. How to deploy Damn Vulnerable Web App in minutes inside.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-19-augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5",
      "title": "Augmenting Digital Forensics with AI: How ChatGPT Transforms Investigation Workflows",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-19-augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5/",
      "source_url": "https://medium.com/@1200km/augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5",
      "published_at": "2025-10-19",
      "updated_at": "2025-10-19",
      "summary": "Augmenting Digital Forensics with AI: How ChatGPT Transforms Investigation Workflows. From evidence triage to report generation — applying large language.",
      "tags": [
        "ai-security",
        "article",
        "incident-response"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-20-meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085",
      "title": "Meet syscheck_beauty: a colorful Linux system report with deep storage insights (and exportable…",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-20-meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085/",
      "source_url": "https://medium.com/@1200km/meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085",
      "published_at": "2025-10-20",
      "updated_at": "2025-10-20",
      "summary": "Meet syscheck_beauty: a colorful Linux system report with deep storage insights (and exportable…. TL;DR: I built a single-file Python tool that prints a.",
      "tags": [
        "ai-security",
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-01-the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9",
      "title": "The Atomic Standard: A Practitioner’s Compendium for Single-Event Threat Detection",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-01-the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9/",
      "source_url": "https://medium.com/@1200km/the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9",
      "published_at": "2025-11-01",
      "updated_at": "2025-11-01",
      "summary": "The Atomic Standard: A Practitioner’s Compendium for Single-Event Threat Detection. Part 1: The Theoretical Foundation of Atomic Detection",
      "tags": [
        "article",
        "detection-engineering",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-02-deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8",
      "title": "Deploying Fluent Bit as a Windows Service for Centralized Log Forwarding",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-02-deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8/",
      "source_url": "https://medium.com/@1200km/deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8",
      "published_at": "2025-11-02",
      "updated_at": "2025-11-02",
      "summary": "Deploying Fluent Bit as a Windows Service for Centralized Log Forwarding. A step-by-step guide to collecting Windows Event Logs and securely shipping them to.",
      "tags": [
        "article",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-07-cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1",
      "title": "Cloud-Native Security Threats, Attacks, and Detection Strategies",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-07-cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1/",
      "source_url": "https://medium.com/@1200km/cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1",
      "published_at": "2025-11-07",
      "updated_at": "2025-11-07",
      "summary": "Cloud-Native Security Threats, Attacks, and Detection Strategies. Securing Cloud‑Native Environments — A Comprehensive Guide to Kubernetes Threats, Detection.",
      "tags": [
        "article",
        "cloud-security",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-23-spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f",
      "title": "SpiderFoot Deep Dive: Installation, Scans, and Practical Use Cases",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-23-spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f/",
      "source_url": "https://medium.com/@1200km/spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f",
      "published_at": "2025-11-23",
      "updated_at": "2025-11-23",
      "summary": "SpiderFoot Deep Dive: Installation, Scans, and Practical Use Cases. How to run SpiderFoot, pick the right modules, interpret results, and use it responsibly.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-24-reinventing-recon-nmap-meets-chatgpt-e2acb6130be5",
      "title": "Reinventing Recon: Nmap Meets ChatGPT",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-24-reinventing-recon-nmap-meets-chatgpt-e2acb6130be5/",
      "source_url": "https://medium.com/@1200km/reinventing-recon-nmap-meets-chatgpt-e2acb6130be5",
      "published_at": "2025-11-24",
      "updated_at": "2025-11-24",
      "summary": "Reinventing Recon: Nmap Meets ChatGPT. How I leveled up penetration tests by pairing classic tools (NMAP) with LLMs like ChatGPT.",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/reinventing-recon-nmap-meets-chatgpt-e2acb6130be5",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-25-getting-more-from-burp-suite-with-llms-fdd03cec343d",
      "title": "Getting More from Burp Suite with LLMs",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-25-getting-more-from-burp-suite-with-llms-fdd03cec343d/",
      "source_url": "https://medium.com/@1200km/getting-more-from-burp-suite-with-llms-fdd03cec343d",
      "published_at": "2025-11-25",
      "updated_at": "2025-11-25",
      "summary": "Getting More from Burp Suite with LLMs. How ChatGPT Accelerates Scan Analysis, Prioritization and Mitigation. Practical workflow and prompt recipes for.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/getting-more-from-burp-suite-with-llms-fdd03cec343d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-26-enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139",
      "title": "Enhancing Penetration Testing with HackerAI: Step-by-Step Guide (Metasploitable Lab)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-26-enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139/",
      "source_url": "https://medium.com/@1200km/enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139",
      "published_at": "2025-11-26",
      "updated_at": "2025-11-26",
      "summary": "Enhancing Penetration Testing with HackerAI: Step-by-Step Guide (Metasploitable Lab). Learn how to integrate AI into every phase of the penetration testing.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-01-single-event-detection-rules-in-cybersecurity-aa7498f665bd",
      "title": "Single-Event Detection Rules in Cybersecurity",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-01-single-event-detection-rules-in-cybersecurity-aa7498f665bd/",
      "source_url": "https://medium.com/@1200km/single-event-detection-rules-in-cybersecurity-aa7498f665bd",
      "published_at": "2025-12-01",
      "updated_at": "2025-12-01",
      "summary": "Single-Event Detection Rules in Cybersecurity. Introduction",
      "tags": [
        "article",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/single-event-detection-rules-in-cybersecurity-aa7498f665bd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-02-correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb",
      "title": "Correlation-Based Detection Rules in Cybersecurity: From Atomic Events to Behavioral Insight",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-02-correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb/",
      "source_url": "https://medium.com/@1200km/correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb",
      "published_at": "2025-12-02",
      "updated_at": "2025-12-02",
      "summary": "Correlation-Based Detection Rules in Cybersecurity: From Atomic Events to Behavioral Insight. A comprehensive exploration of multi-event analytics, temporal.",
      "tags": [
        "article",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-12-protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6",
      "title": "Protocol-Level Network Threat Hunting: A Wireshark-Centric Guide",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-12-protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6/",
      "source_url": "https://medium.com/@1200km/protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6",
      "published_at": "2025-12-12",
      "updated_at": "2025-12-12",
      "summary": "Protocol-Level Network Threat Hunting: A Wireshark-Centric Guide. Uncovering Stealthy Attacks Through IOCs, Anomaly Detection, and Practical Playbooks",
      "tags": [
        "article",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-14-endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113",
      "title": "Endpoint Threat Hunting: Proactive Detection on Windows, Linux, and macOS",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-14-endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113/",
      "source_url": "https://medium.com/@1200km/endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113",
      "published_at": "2025-12-14",
      "updated_at": "2025-12-14",
      "summary": "Endpoint Threat Hunting: Proactive Detection on Windows, Linux, and macOS. Uncovering Advanced Compromises Through Telemetry, Artifacts, MITRE ATT&CK.",
      "tags": [
        "article",
        "detection-engineering",
        "mitre-attack",
        "threat-hunting"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-18-hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949",
      "title": "HexStrike AI: Install, Configure, and Run MCP with Gemini, OpenAI, Cursor, Llama",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-18-hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949/",
      "source_url": "https://medium.com/@1200km/hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949",
      "published_at": "2025-12-18",
      "updated_at": "2025-12-18",
      "summary": "HexStrike AI: Install, Configure, and Run MCP with Gemini, OpenAI, Cursor, Llama. A practical, end-to-end guide to installing HexStrike AI, wiring it as an.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-21-ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde",
      "title": "AI-Driven Pentesting at Home: Using HexStrike-AI for Full Network Discovery and Exploitation",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-21-ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde/",
      "source_url": "https://medium.com/@1200km/ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde",
      "published_at": "2025-12-21",
      "updated_at": "2025-12-21",
      "summary": "AI-Driven Pentesting at Home: Using HexStrike-AI for Full Network Discovery and Exploitation. How I Used Gemini + HexStrike-AI on Kali Linux to Scan.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-22-ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040",
      "title": "AI-Driven Web Application Pentesting with HexStrike-AI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-22-ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040/",
      "source_url": "https://medium.com/@1200km/ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040",
      "published_at": "2025-12-22",
      "updated_at": "2025-12-22",
      "summary": "AI-Driven Web Application Pentesting with HexStrike-AI. A Practical, End-to-End Guide to Modern Web Application Penetration Testing Using LLM-Orchestrated.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-23-integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e",
      "title": "Integrating Shodan with HexStrike-AI Using Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-23-integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e/",
      "source_url": "https://medium.com/@1200km/integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e",
      "published_at": "2025-12-23",
      "updated_at": "2025-12-23",
      "summary": "Integrating Shodan with HexStrike-AI Using Gemini-CLI. A Practical Guide to AI-Driven External Reconnaissance and Vulnerability Analysis",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-24-ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4",
      "title": "AI-Driven Wireless Penetration Testing. One Promt WIFI cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-24-ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4/",
      "source_url": "https://medium.com/@1200km/ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4",
      "published_at": "2025-12-24",
      "updated_at": "2025-12-24",
      "summary": "AI-Driven Wireless Penetration Testing. One Promt WIFI cracking. Using Aircrack-ng with HexStrike-AI and Gemini-CLI",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-25-ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc",
      "title": "AI-Driven ZIP Password Recovery with HexStrike-AI and Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-25-ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc/",
      "source_url": "https://medium.com/@1200km/ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc",
      "published_at": "2025-12-25",
      "updated_at": "2025-12-25",
      "summary": "AI-Driven ZIP Password Recovery with HexStrike-AI and Gemini-CLI. From Encrypted Archive to Flag Using LLM-Orchestrated Tooling",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-25-hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae",
      "title": "HexStrike-AI: A Force Multiplier for Red Teams — and a Dangerous Shift in the Threat Landscape",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-25-hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae/",
      "source_url": "https://medium.com/@1200km/hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae",
      "published_at": "2025-12-25",
      "updated_at": "2025-12-25",
      "summary": "HexStrike-AI: A Force Multiplier for Red Teams — and a Dangerous Shift in the Threat Landscape. Why AI-Orchestrated Pentesting Is a Force Multiplier for Red.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-26-hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b",
      "title": "HexStrike + Gemini vs. HackerAI: “Ops Copilot” vs. “Chatbot with Tools”",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-26-hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b/",
      "source_url": "https://medium.com/@1200km/hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b",
      "published_at": "2025-12-26",
      "updated_at": "2025-12-26",
      "summary": "HexStrike + Gemini vs. HackerAI: “Ops Copilot” vs. “Chatbot with Tools”. A practical lab comparison: Why orchestration quality beats raw model IQ in.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-29-ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d",
      "title": "AI-Driven Office Documents Password Recovery with HexStrike-AI and Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-29-ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d/",
      "source_url": "https://medium.com/@1200km/ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d",
      "published_at": "2025-12-29",
      "updated_at": "2025-12-29",
      "summary": "AI-Driven Office Documents Password Recovery with HexStrike-AI and Gemini-CLI. From Encrypted Document to Readable Content Using LLM-Orchestrated Tooling",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-29-ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91",
      "title": "AI-Driven PDF Password Recovery with HexStrike-AI and Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-29-ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91/",
      "source_url": "https://medium.com/@1200km/ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91",
      "published_at": "2025-12-29",
      "updated_at": "2025-12-29",
      "summary": "AI-Driven PDF Password Recovery with HexStrike-AI and Gemini-CLI. From Encrypted Document to Readable Content Using LLM-Orchestrated Tooling",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-31-hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596",
      "title": "HexStrike MCP Orchestration with Ollama: Ubuntu Host, Kali VM, SSH Bridging, and Performance…",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-31-hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596/",
      "source_url": "https://medium.com/@1200km/hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596",
      "published_at": "2025-12-31",
      "updated_at": "2025-12-31",
      "summary": "HexStrike MCP Orchestration with Ollama: Ubuntu Host, Kali VM, SSH Bridging, and Performance…. How to wire Ubuntu (Ollama) to Kali (HexStrike) with MCP over.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2026:2026-01-02-burp-suite-mcp-gemini-cli-c1229edfe092",
      "title": "Burp Suite MCP + Gemini CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-02-burp-suite-mcp-gemini-cli-c1229edfe092/",
      "source_url": "https://medium.com/@1200km/burp-suite-mcp-gemini-cli-c1229edfe092",
      "published_at": "2026-01-02",
      "updated_at": "2026-01-02",
      "summary": "Burp Suite MCP + Gemini CLI. Connect Burp Suite to Gemini CLI using Model Context Protocol (MCP) and Turn Burp into an AI-callable toolset and accelerate.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/burp-suite-mcp-gemini-cli-c1229edfe092",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-03-hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f",
      "title": "HexStrike+OpenAI Codex. AI-Driven Exploitation of Metasploitable.",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-03-hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f/",
      "source_url": "https://medium.com/@1200km/hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f",
      "published_at": "2026-01-03",
      "updated_at": "2026-01-03",
      "summary": "HexStrike+OpenAI Codex. AI-Driven Exploitation of Metasploitable.. How I Used an LLM-Orchestrated Toolchain to Enumerate and Exploit a Deliberately.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-04-hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b",
      "title": "HexStrike + Gemini. AI-Assisted SSH Credential Brute-Force",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-04-hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b/",
      "source_url": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b",
      "published_at": "2026-01-04",
      "updated_at": "2026-01-04",
      "summary": "HexStrike + Gemini. AI-Assisted SSH Credential Brute-Force. From Service Validation → Dependency Fixes → Findings → Defensive Takeaways",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-05-building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c",
      "title": "Building an Extremely Vulnerable Windows 10 Lab: A Step-by-Step Guide (Bonus :Full PT with…",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-05-building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c/",
      "source_url": "https://medium.com/@1200km/building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c",
      "published_at": "2026-01-05",
      "updated_at": "2026-01-05",
      "summary": "Building an Extremely Vulnerable Windows 10 Lab: A Step-by-Step Guide (Bonus :Full PT with…. Hands-on guide to creating an intentionally insecure Windows 10.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-05-hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4",
      "title": "HexStrike + Gemini. AI-Assisted SMB Exposure Credential Brute-Force",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-05-hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4/",
      "source_url": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4",
      "published_at": "2026-01-05",
      "updated_at": "2026-01-05",
      "summary": "HexStrike + Gemini. AI-Assisted SMB Exposure Credential Brute-Force. From Toolchain Failures → Service Fingerprinting → Authentication Findings → Share Risk",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-06-building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b",
      "title": "Building an Extremely Vulnerable Ubuntu 24.04 Server Lab (Bonus: Full PT with Hexstrike)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-06-building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b/",
      "source_url": "https://medium.com/@1200km/building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b",
      "published_at": "2026-01-06",
      "updated_at": "2026-01-06",
      "summary": "Building an Extremely Vulnerable Ubuntu 24.04 Server Lab (Bonus: Full PT with Hexstrike). A Step-by-Step Guide: Hands-on guide to creating an intentionally.",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-08-hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7",
      "title": "HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-08-hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7/",
      "source_url": "https://medium.com/@1200km/hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7",
      "published_at": "2026-01-08",
      "updated_at": "2026-01-08",
      "summary": "HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough). A real end-to-end lab engagement: recon → credential discovery →.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-11-hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30",
      "title": "HexStrike + Cursor for OSINT: From One Email to a Full Exposure Map",
      "primary_type": "article",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-11-hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30/",
      "source_url": "https://medium.com/@1200km/hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30",
      "published_at": "2026-01-11",
      "updated_at": "2026-01-11",
      "summary": "HexStrike + Cursor for OSINT: From One Email to a Full Exposure Map. Why OSINT is harder than “hack the box,” what an AI-assisted workflow looks like in.",
      "tags": [
        "ai-security",
        "article",
        "open-source-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-15-building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe",
      "title": "Building a USB Rubber Ducky with Arduino Leonardo with Cursor.",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-15-building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe/",
      "source_url": "https://medium.com/@1200km/building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe",
      "published_at": "2026-01-15",
      "updated_at": "2026-01-15",
      "summary": "Building a USB Rubber Ducky with Arduino Leonardo with Cursor.. Integrating Cursor AI into your hardware hacking workflow is a game-changer. From Human.",
      "tags": [
        "ai-security",
        "application-security",
        "article",
        "embedded-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-16-hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845",
      "title": "Hacker Tool Development Workflow: Android Rubber Ducky Payloads in Cursor AI",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-16-hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845/",
      "source_url": "https://medium.com/@1200km/hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845",
      "published_at": "2026-01-16",
      "updated_at": "2026-01-16",
      "summary": "Hacker Tool Development Workflow: Android Rubber Ducky Payloads in Cursor AI. From plain-English prompts to reliable HID flows — validated with emulator.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-17-the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071",
      "title": "The One-Prompt PT Lab: Autonomous Android Security Research with Cursor AI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-17-the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071/",
      "source_url": "https://medium.com/@1200km/the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071",
      "published_at": "2026-01-17",
      "updated_at": "2026-01-17",
      "summary": "The One-Prompt PT Lab: Autonomous Android Security Research with Cursor AI. From Bare Directory to Full Exploitation: A Case Study on OWASP UnCrackable L1",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-19-the-ai-revolution-in-offensive-security-31e44704d51a",
      "title": "The AI Revolution in Offensive Security",
      "primary_type": "article",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-19-the-ai-revolution-in-offensive-security-31e44704d51a/",
      "source_url": "https://medium.com/@1200km/the-ai-revolution-in-offensive-security-31e44704d51a",
      "published_at": "2026-01-19",
      "updated_at": "2026-01-19",
      "summary": "The AI Revolution in Offensive Security. Practical Hands-On Guide to AI-Accelerated Offensive Security: Burp Suite, Nmap, OSINT, Exploitation, and End-to-End.",
      "tags": [
        "ai-security",
        "article",
        "offensive-security",
        "open-source-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-ai-revolution-in-offensive-security-31e44704d51a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-23-deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc",
      "title": "Deploy a Complete Active Directory PenTest Lab in One Prompt with Cursor AI",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-23-deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc/",
      "source_url": "https://medium.com/@1200km/deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc",
      "published_at": "2026-01-23",
      "updated_at": "2026-01-23",
      "summary": "Deploy a Complete Active Directory PenTest Lab in One Prompt with Cursor AI. How I automated the deployment of a complex AD lab environment using AI assistance",
      "tags": [
        "ai-security",
        "article",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-24-active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d",
      "title": "Active Directory Lab for PenTest. Manual Deployment Guide",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-24-active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d/",
      "source_url": "https://medium.com/@1200km/active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d",
      "published_at": "2026-01-24",
      "updated_at": "2026-01-24",
      "summary": "Active Directory Lab for PenTest. Manual Deployment Guide. This guide is a manual, step-by-step deployment of a GOAD-Mini Active Directory environment on.",
      "tags": [
        "article",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-25-hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191",
      "title": "Hi! Two of my articles have been in pending status for the past few days.",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-25-hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191/",
      "source_url": "https://medium.com/@1200km/hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191",
      "published_at": "2026-01-25",
      "updated_at": "2026-01-25",
      "summary": "Hi! Two of my articles have been in pending status for the past few days.. Hi! Two of my articles have been in pending status for the past few days.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-26-active-directory-penetration-testing-745cfb31d7d3",
      "title": "Active Directory Penetration Testing",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-26-active-directory-penetration-testing-745cfb31d7d3/",
      "source_url": "https://medium.com/@1200km/active-directory-penetration-testing-745cfb31d7d3",
      "published_at": "2026-01-26",
      "updated_at": "2026-01-26",
      "summary": "Active Directory Penetration Testing. A Deep Dive into GOAD-Mini Lab Assessment. Step-by-step guide.",
      "tags": [
        "article",
        "identity-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/active-directory-penetration-testing-745cfb31d7d3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-27-ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7",
      "title": "AI-Driven Black Box Active Directory Penetration Testing",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-27-ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7/",
      "source_url": "https://medium.com/@1200km/ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7",
      "published_at": "2026-01-27",
      "updated_at": "2026-01-27",
      "summary": "AI-Driven Black Box Active Directory Penetration Testing. Fully Automated AD Discovery and Exploitation with Cursor AI and HexStrike-ai MCP. From IP to Full.",
      "tags": [
        "ai-security",
        "article",
        "identity-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-28-adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d",
      "title": "ADCS ESC8 Attack: Certificate-Based Domain Compromise — Complete Guide",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-28-adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d/",
      "source_url": "https://medium.com/@1200km/adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d",
      "published_at": "2026-01-28",
      "updated_at": "2026-01-28",
      "summary": "ADCS ESC8 Attack: Certificate-Based Domain Compromise — Complete Guide. Abstract",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-29-building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff",
      "title": "Building a Vulnerable GCP Pentest Lab with Terraform",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-29-building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff/",
      "source_url": "https://medium.com/@1200km/building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff",
      "published_at": "2026-01-29",
      "updated_at": "2026-01-29",
      "summary": "Building a Vulnerable GCP Pentest Lab with Terraform. A complete, step-by-step guide to deploying intentionally misconfigured cloud resources for hands-on.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-29-cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58",
      "title": "Cursor + Hexstrike. Fully Automated ADCS ESC8 Attack",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-29-cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58/",
      "source_url": "https://medium.com/@1200km/cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58",
      "published_at": "2026-01-29",
      "updated_at": "2026-01-29",
      "summary": "Cursor + Hexstrike. Fully Automated ADCS ESC8 Attack. One-Prompt Domain Compromise",
      "tags": [
        "article",
        "offensive-research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-31-a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd",
      "title": "A Complete Cloud Penetration Testing Walkthrough",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-31-a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd/",
      "source_url": "https://medium.com/@1200km/a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd",
      "published_at": "2026-01-31",
      "updated_at": "2026-01-31",
      "summary": "A Complete Cloud Penetration Testing Walkthrough. How I Discovered Critical Vulnerabilities in a Cloud Environment Using Basic Tools and Methodical Testing",
      "tags": [
        "article",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-31-ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258",
      "title": "AI-Assisted Web and Cloud Penetration Testing with Cursor + MCP HexStrike and Burp Suite MCP.",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-31-ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258/",
      "source_url": "https://medium.com/@1200km/ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258",
      "published_at": "2026-01-31",
      "updated_at": "2026-01-31",
      "summary": "AI-Assisted Web and Cloud Penetration Testing with Cursor + MCP HexStrike and Burp Suite MCP.. A Complete Guide to Modern AI-Powered Security Testing. From.",
      "tags": [
        "ai-security",
        "article",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-02-building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91",
      "title": "Building a Vulnerable Kubernetes Lab: A Complete Guide to 25 Critical Security Issues",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-02-building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91/",
      "source_url": "https://medium.com/@1200km/building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91",
      "published_at": "2026-02-02",
      "updated_at": "2026-02-02",
      "summary": "Building a Vulnerable Kubernetes Lab: A Complete Guide to 25 Critical Security Issues. Learn Kubernetes security by building a comprehensive penetration.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-03-black-box-kubernetes-penetration-testing-playbook-56350b178af4",
      "title": "Black-Box Kubernetes Penetration Testing Playbook",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-03-black-box-kubernetes-penetration-testing-playbook-56350b178af4/",
      "source_url": "https://medium.com/@1200km/black-box-kubernetes-penetration-testing-playbook-56350b178af4",
      "published_at": "2026-02-03",
      "updated_at": "2026-02-03",
      "summary": "Black-Box Kubernetes Penetration Testing Playbook. A Manual, End-to-End Walkthrough from First Signal to Cluster Takeover",
      "tags": [
        "article",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/black-box-kubernetes-penetration-testing-playbook-56350b178af4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-04-my-lab-82d780962213",
      "title": "My lab:",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-04-my-lab-82d780962213/",
      "source_url": "https://medium.com/@1200km/my-lab-82d780962213",
      "published_at": "2026-02-04",
      "updated_at": "2026-02-04",
      "summary": "My lab:. Building a vulnerable Kubernetes lab",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/my-lab-82d780962213",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-04-one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e",
      "title": "One-Prompt AI-Powered Black-Box Kubernetes Penetration Test",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-04-one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e/",
      "source_url": "https://medium.com/@1200km/one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e",
      "published_at": "2026-02-04",
      "updated_at": "2026-02-04",
      "summary": "One-Prompt AI-Powered Black-Box Kubernetes Penetration Test. How Cursor + HexStrike MCP Automatically Discovers and Exploits Vulnerabilities. From single.",
      "tags": [
        "ai-security",
        "article",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-05-warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19",
      "title": "⚠️ WARNING: I Just Built Real Malware by using just human language prompts!",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-05-warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19/",
      "source_url": "https://medium.com/@1200km/warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19",
      "published_at": "2026-02-05",
      "updated_at": "2026-02-05",
      "summary": "⚠️ WARNING: I Just Built Real Malware by using just human language prompts!. A Complete Walkthrough: From “I Want to Build Malware” to Fully Functional.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-06-welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503",
      "title": "Welcome to the New Era: When a Teenager Can Crash Your Company in Minutes",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-06-welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503/",
      "source_url": "https://medium.com/@1200km/welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503",
      "published_at": "2026-02-06",
      "updated_at": "2026-02-06",
      "summary": "Welcome to the New Era: When a Teenager Can Crash Your Company in Minutes. An Urgent Message for CISOs and C-Level Executives. The threat landscape has.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-09-gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d",
      "title": "GCP Penetration Testing: A Step-by-Step Attack Guide",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-09-gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d/",
      "source_url": "https://medium.com/@1200km/gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d",
      "published_at": "2026-02-09",
      "updated_at": "2026-02-09",
      "summary": "GCP Penetration Testing: A Step-by-Step Attack Guide. A practical GCP lab case study: overprivileged identities, leaked creds, weak controls — and how it all.",
      "tags": [
        "article",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-11-kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80",
      "title": "Kubernetes Logging and Monitoring: Complete Guide",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-11-kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80/",
      "source_url": "https://medium.com/@1200km/kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80",
      "published_at": "2026-02-11",
      "updated_at": "2026-02-11",
      "summary": "Kubernetes Logging and Monitoring: Complete Guide. A comprehensive reference for every major log type in Kubernetes: what it is, what you can monitor with.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-13-build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e",
      "title": "Build a Vulnerable IIS SharePoint Lab with Fluent Bit: Complete Deployment Guide",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-13-build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e/",
      "source_url": "https://medium.com/@1200km/build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e",
      "published_at": "2026-02-13",
      "updated_at": "2026-02-13",
      "summary": "Build a Vulnerable IIS SharePoint Lab with Fluent Bit: Complete Deployment Guide. A full step-by-step guide with all scripts to deploy a vulnerable.",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-19-the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca",
      "title": "The Complete Guide to AI-Driven Penetration Testing: Cursor, MCP, and the Modern PT Workflow",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-19-the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca/",
      "source_url": "https://medium.com/@1200km/the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca",
      "published_at": "2026-02-19",
      "updated_at": "2026-02-19",
      "summary": "The Complete Guide to AI-Driven Penetration Testing: Cursor, MCP, and the Modern PT Workflow. A comprehensive, step-by-step guide to running penetration.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-21-one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de",
      "title": "One Tool to Rule Them All: File Metadata & Static Analysis for Malware Analysts and SOC Teams",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-21-one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de/",
      "source_url": "https://medium.com/@1200km/one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de",
      "published_at": "2026-02-21",
      "updated_at": "2026-02-21",
      "summary": "One Tool to Rule Them All: File Metadata & Static Analysis for Malware Analysts and SOC Teams. Extract hashes, PE/ELF/Mach-O metadata, strings, YARA hits.",
      "tags": [
        "article",
        "detection-engineering",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-26-a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868",
      "title": "A Practical Guide to String Analyzer: Extract and Analyze Strings from Binaries (Without the…",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-26-a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868/",
      "source_url": "https://medium.com/@1200km/a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868",
      "published_at": "2026-02-26",
      "updated_at": "2026-02-26",
      "summary": "A Practical Guide to String Analyzer: Extract and Analyze Strings from Binaries (Without the…. Turn executables, memory dumps, and disk images into.",
      "tags": [
        "article",
        "network-security",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-26-pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3",
      "title": "PE Import Analyzer: A Practical Guide for Malware Analysts and Reverse Engineers",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-26-pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3/",
      "source_url": "https://medium.com/@1200km/pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3",
      "published_at": "2026-02-26",
      "updated_at": "2026-02-26",
      "summary": "PE Import Analyzer: A Practical Guide for Malware Analysts and Reverse Engineers. How to quickly understand what a Windows executable does — before you run it.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-28-unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b",
      "title": "Unpacker: A Practical Guide to Modular Malware Packer Detection and Unpacking",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-28-unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b/",
      "source_url": "https://medium.com/@1200km/unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b",
      "published_at": "2026-02-28",
      "updated_at": "2026-02-28",
      "summary": "Unpacker: A Practical Guide to Modular Malware Packer Detection and Unpacking. Extract and validate unpacked PE/ELF samples with real examples — and prove it.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-01-basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8",
      "title": "Basic Static Malware Analysis: From Triage to Unpacking — Explained and Automated",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-01-basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8/",
      "source_url": "https://medium.com/@1200km/basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8",
      "published_at": "2026-03-01",
      "updated_at": "2026-03-01",
      "summary": "Basic Static Malware Analysis: From Triage to Unpacking — Explained and Automated. What static malware analysis is, why each step matters, and how to run the.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-06-cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8",
      "title": "CTI Research: Handala Hack Group (aka Handala Hack Team)",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-06-cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8/",
      "source_url": "https://medium.com/@1200km/cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8",
      "published_at": "2026-03-06",
      "updated_at": "2026-03-06",
      "summary": "CTI Research: Handala Hack Group (aka Handala Hack Team). Evidence-Labeled Threat Intelligence Assessment and SOC Defensive Guidance (December 2023 to March.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-07-cti-research-sandworm-apt44-649332e8af44",
      "title": "CTI Research: Sandworm / APT44",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-07-cti-research-sandworm-apt44-649332e8af44/",
      "source_url": "https://medium.com/@1200km/cti-research-sandworm-apt44-649332e8af44",
      "published_at": "2026-03-07",
      "updated_at": "2026-03-07",
      "summary": "CTI Research: Sandworm / APT44. Evidence-Labeled Threat Intelligence Assessment and SOC Defensive Guidance (2009 — March 2026)",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-sandworm-apt44-649332e8af44",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-09-cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061",
      "title": "CTI Research: MuddyWater/Seedworm (Mango Sandstorm)",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-09-cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061/",
      "source_url": "https://medium.com/@1200km/cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061",
      "published_at": "2026-03-09",
      "updated_at": "2026-03-09",
      "summary": "CTI Research: MuddyWater/Seedworm (Mango Sandstorm). Evidence-Labeled Threat Intelligence Assessment and SOC Defensive Guidance (2017 — March 2026)",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-11-building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59",
      "title": "Building a Dockerized AI-Powered Host Vulnerability Assessment Tool",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-11-building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59/",
      "source_url": "https://medium.com/@1200km/building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59",
      "published_at": "2026-03-11",
      "updated_at": "2026-03-11",
      "summary": "Building a Dockerized AI-Powered Host Vulnerability Assessment Tool. How I automated security auditing with Claude, Python, and Docker — and what it found on.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-13-building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e",
      "title": "Building a Vulnerable Cloud Pentest Lab with Terraform",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-13-building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e/",
      "source_url": "https://medium.com/@1200km/building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e",
      "published_at": "2026-03-13",
      "updated_at": "2026-03-13",
      "summary": "Building a Vulnerable Cloud Pentest Lab with Terraform. A complete, step-by-step guide to deploying intentionally misconfigured cloud resources for hands-on.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-14-ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a",
      "title": "AI-Powered Malware Debugger That Explains Every Function It Sees",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-14-ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a/",
      "source_url": "https://medium.com/@1200km/ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a",
      "published_at": "2026-03-14",
      "updated_at": "2026-03-14",
      "summary": "AI-Powered Malware Debugger That Explains Every Function It Sees. How I combined Claude AI, Frida, Capstone, and a suite of static analysis engines into a.",
      "tags": [
        "ai-security",
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-14-stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84",
      "title": "StratusAI: I Built an AI-Powered Cloud Security Scanner for AWS and GCP — Here’s Everything",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-14-stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84/",
      "source_url": "https://medium.com/@1200km/stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84",
      "published_at": "2026-03-14",
      "updated_at": "2026-03-14",
      "summary": "StratusAI: I Built an AI-Powered Cloud Security Scanner for AWS and GCP — Here’s Everything. A complete engineering walkthrough of building, testing, and.",
      "tags": [
        "ai-security",
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-16-navigate-my-blog-all-articles-by-topic-ffd800ef5480",
      "title": "Navigate My Blog: All Articles by Topic",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-16-navigate-my-blog-all-articles-by-topic-ffd800ef5480/",
      "source_url": "https://medium.com/@1200km/navigate-my-blog-all-articles-by-topic-ffd800ef5480",
      "published_at": "2026-03-16",
      "updated_at": "2026-03-16",
      "summary": "Navigate My Blog: All Articles by Topic. A single entry point to 100+ articles on offensive security, AI-driven pentesting, red team, labs, and defense. Use.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/navigate-my-blog-all-articles-by-topic-ffd800ef5480",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-19-att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101",
      "title": "ATT&CK as a Working Tool: Theory and Hands-On Practical Usage",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-19-att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101/",
      "source_url": "https://medium.com/@1200km/att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101",
      "published_at": "2026-03-19",
      "updated_at": "2026-03-19",
      "summary": "ATT&CK as a Working Tool: Theory and Hands-On Practical Usage. A practitioner’s guide for CTI analysts, detection engineers, and threat hunters",
      "tags": [
        "article",
        "detection-engineering",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-20-attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced",
      "title": "Attribution Methodology: How to Build, Defend, and Challenge a Threat Actor Attribution",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-20-attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced/",
      "source_url": "https://medium.com/@1200km/attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced",
      "published_at": "2026-03-20",
      "updated_at": "2026-03-20",
      "summary": "Attribution Methodology: How to Build, Defend, and Challenge a Threat Actor Attribution. A practitioner’s guide for CTI analysts — from evidence collection.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-21-infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c",
      "title": "Infrastructure Pivoting: How CTI Analysts Expand From a Single IOC to a Full Attacker Network",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-21-infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c/",
      "source_url": "https://medium.com/@1200km/infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c",
      "published_at": "2026-03-21",
      "updated_at": "2026-03-21",
      "summary": "Infrastructure Pivoting: How CTI Analysts Expand From a Single IOC to a Full Attacker Network. The field manual for tracing attacker infrastructure — from.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-24-cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456",
      "title": "CVSS v4.0: The Practical Field Guide for Vulnerability Management",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-24-cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456/",
      "source_url": "https://medium.com/@1200km/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456",
      "published_at": "2026-03-24",
      "updated_at": "2026-03-24",
      "summary": "CVSS v4.0: The Practical Field Guide for Vulnerability Management. From a number that nobody trusts to a tool that changes how you work",
      "tags": [
        "application-security",
        "article",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-30-android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12",
      "title": "Android APK Analysis Tool: AI-Powered Static Malware Analysis in Your Terminal",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-30-android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12/",
      "source_url": "https://medium.com/@1200km/android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12",
      "published_at": "2026-03-30",
      "updated_at": "2026-03-30",
      "summary": "Android APK Analysis Tool: AI-Powered Static Malware Analysis in Your Terminal. A practical guide to analyzing Android applications with Claude, OpenAI.",
      "tags": [
        "ai-security",
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-30-android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d",
      "title": "Android Malware Analysis: A Practical Guide for Security Analysts",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-30-android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d/",
      "source_url": "https://medium.com/@1200km/android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d",
      "published_at": "2026-03-30",
      "updated_at": "2026-03-30",
      "summary": "Android Malware Analysis: A Practical Guide for Security Analysts. From APK unpacking to behavioral analysis — with three real-world malware case studies and.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-06-building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622",
      "title": "Building an Android App Analysis Lab on Ubuntu: A Practical Setup Guide",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-06-building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622/",
      "source_url": "https://medium.com/@1200km/building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622",
      "published_at": "2026-04-06",
      "updated_at": "2026-04-06",
      "summary": "Building an Android App Analysis Lab on Ubuntu: A Practical Setup Guide. A practical step-by-step guide to building an Android malware analysis and security.",
      "tags": [
        "article",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-07-android-emulation-and-virtualisation-2f6b33fcc4aa",
      "title": "Android Emulation & Virtualisation",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-07-android-emulation-and-virtualisation-2f6b33fcc4aa/",
      "source_url": "https://medium.com/@1200km/android-emulation-and-virtualisation-2f6b33fcc4aa",
      "published_at": "2026-04-07",
      "updated_at": "2026-04-07",
      "summary": "Android Emulation & Virtualisation. Complete Research Lab Guide. From Zero to a Fully Instrumented Android Research Environment",
      "tags": [
        "article",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-emulation-and-virtualisation-2f6b33fcc4aa",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-08-android-apk-vulnerability-research-complete-guide-a8fcae0f4849",
      "title": "Android APK Vulnerability Research Complete Guide",
      "primary_type": "article",
      "primary_domain": "vulnerability-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-08-android-apk-vulnerability-research-complete-guide-a8fcae0f4849/",
      "source_url": "https://medium.com/@1200km/android-apk-vulnerability-research-complete-guide-a8fcae0f4849",
      "published_at": "2026-04-08",
      "updated_at": "2026-04-08",
      "summary": "Android APK Vulnerability Research Complete Guide. Practical, end-to-end APK analysis for red teamers, bug hunters, and defenders.",
      "tags": [
        "article",
        "offensive-security",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-apk-vulnerability-research-complete-guide-a8fcae0f4849",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-08-deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415",
      "title": "Deliberately Vulnerable Android App Covering Every OWASP Mobile Top 10 Class",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-08-deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415/",
      "source_url": "https://medium.com/@1200km/deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415",
      "published_at": "2026-04-08",
      "updated_at": "2026-04-08",
      "summary": "Deliberately Vulnerable Android App Covering Every OWASP Mobile Top 10 Class. A hands-on reference for mobile security researchers, bug bounty hunters, and.",
      "tags": [
        "article",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-12-ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9",
      "title": "AI in Offensive Operations: How Threat Actors Use Artificial Intelligence",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-12-ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9/",
      "source_url": "https://medium.com/@1200km/ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9",
      "published_at": "2026-04-12",
      "updated_at": "2026-04-12",
      "summary": "AI in Offensive Operations: How Threat Actors Use Artificial Intelligence. A CTI assessment of documented malicious and dual-use AI activity through April.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-14-from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426",
      "title": "From Threat Intelligence to Detection: A Practitioner’s Guide",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-14-from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426/",
      "source_url": "https://medium.com/@1200km/from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426",
      "published_at": "2026-04-14",
      "updated_at": "2026-04-14",
      "summary": "From Threat Intelligence to Detection: A Practitioner’s Guide. Building atomic, collection, correlational, TTP-based, and anomaly detection rules from real.",
      "tags": [
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-04-18-what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12",
      "title": "What AI-Assisted Offensive Work Actually Means for Your Detection Program: A Practitioner’s…",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-18-what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12/",
      "source_url": "https://medium.com/@1200km/what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12",
      "published_at": "2026-04-18",
      "updated_at": "2026-04-18",
      "summary": "What AI-Assisted Offensive Work Actually Means for Your Detection Program: A Practitioner’s…. What the public record supports, what it does not, and how to.",
      "tags": [
        "ai-security",
        "article",
        "detection-engineering",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-20-malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12",
      "title": "Malicious Activity as a Statistical Signal: A Detection Engineering Analysis of Anomaly-Based…",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-20-malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12/",
      "source_url": "https://medium.com/@1200km/malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12",
      "published_at": "2026-04-20",
      "updated_at": "2026-04-20",
      "summary": "Malicious Activity as a Statistical Signal: A Detection Engineering Analysis of Anomaly-Based…. An evidence-based examination of the hypothesis that.",
      "tags": [
        "article",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-04-22-detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82",
      "title": "Detecting Malicious Insider Activity: A Technical Detection Engineering Guide",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-22-detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82/",
      "source_url": "https://medium.com/@1200km/detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82",
      "published_at": "2026-04-22",
      "updated_at": "2026-04-22",
      "summary": "Detecting Malicious Insider Activity: A Technical Detection Engineering Guide. Detection logic, case evidence from 14 documented incidents, and a four-phase.",
      "tags": [
        "article",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-04-25-cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87",
      "title": "CTI Research: Kubernetes & Cloud-Native Threat Landscape",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-25-cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87/",
      "source_url": "https://medium.com/@1200km/cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87",
      "published_at": "2026-04-25",
      "updated_at": "2026-04-25",
      "summary": "CTI Research: Kubernetes & Cloud-Native Threat Landscape. Technical Kill Chain Analysis, Detection Engineering, and Defensive Architecture (2023 — Q2 2026)",
      "tags": [
        "article",
        "cloud-security",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-28-vulnerable-ai-lab-3747e96314dd",
      "title": "Vulnerable AI Lab",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-28-vulnerable-ai-lab-3747e96314dd/",
      "source_url": "https://medium.com/@1200km/vulnerable-ai-lab-3747e96314dd",
      "published_at": "2026-04-28",
      "updated_at": "2026-04-28",
      "summary": "Vulnerable AI Lab. Technical Guide for Usage, Attack Testing, Scenario Authoring, and Vulnerability Module Development",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/vulnerable-ai-lab-3747e96314dd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-29-ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86",
      "title": "AI Offensive Security: Practical Attacks Against LLM Agents",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-29-ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86/",
      "source_url": "https://medium.com/@1200km/ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86",
      "published_at": "2026-04-29",
      "updated_at": "2026-04-29",
      "summary": "AI Offensive Security: Practical Attacks Against LLM Agents. Red-Team and AppSec Practitioner Guide",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-02-apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6",
      "title": "APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-02-apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6/",
      "source_url": "https://medium.com/@1200km/apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6",
      "published_at": "2026-05-02",
      "updated_at": "2026-05-02",
      "summary": "APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise. Threat Intelligence Report | Operation DragonRx",
      "tags": [
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c",
      "title": "Lab Architecture — Operation DragonRx",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c/",
      "source_url": "https://medium.com/@1200km/lab-architecture-operation-dragonrx-38602f432e5c",
      "published_at": "2026-05-02",
      "updated_at": "2026-05-02",
      "summary": "Lab Architecture — Operation DragonRx. Part of the Operation DragonRx series · Overview · Lab Architecture · Attack Playbook · DFIR Walkthrough",
      "tags": [
        "ai-security",
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/lab-architecture-operation-dragonrx-38602f432e5c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-04-attack-playbook-operation-dragonrx-91339316f0df",
      "title": "Attack Playbook — Operation DragonRx",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-04-attack-playbook-operation-dragonrx-91339316f0df/",
      "source_url": "https://medium.com/@1200km/attack-playbook-operation-dragonrx-91339316f0df",
      "published_at": "2026-05-04",
      "updated_at": "2026-05-04",
      "summary": "Attack Playbook — Operation DragonRx. Phase-by-Phase Attack Guide: Exact Commands Against the Deployed Lab",
      "tags": [
        "ai-security",
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/attack-playbook-operation-dragonrx-91339316f0df",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-08-manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc",
      "title": "Manual CTI vs. AI-Assisted CTI: A Step-by-Step Clock Comparison",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-08-manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc/",
      "source_url": "https://medium.com/@1200km/manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc",
      "published_at": "2026-05-08",
      "updated_at": "2026-05-08",
      "summary": "Manual CTI vs. AI-Assisted CTI: A Step-by-Step Clock Comparison. Which steps compress, which do not, and what you risk if you do not understand the difference.",
      "tags": [
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-09-cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979",
      "title": "CTI Kill Chain: An Analyst Guide With Real-World Evidence",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-09-cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979/",
      "source_url": "https://medium.com/@1200km/cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979",
      "published_at": "2026-05-09",
      "updated_at": "2026-05-09",
      "summary": "CTI Kill Chain: An Analyst Guide With Real-World Evidence. Mapping adversary behavior from preparation to impact without overstating the evidence",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-09-cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31",
      "title": "CTI-Led Defensive Strategy for a Cellular Provider (Case Study)",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-09-cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31/",
      "source_url": "https://medium.com/@1200km/cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31",
      "published_at": "2026-05-09",
      "updated_at": "2026-05-09",
      "summary": "CTI-Led Defensive Strategy for a Cellular Provider (Case Study). A full end-to-end practitioner guide for telecom core, cloud-native operations, SOC/NOC.",
      "tags": [
        "article",
        "cloud-security",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-10-applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b",
      "title": "Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-10-applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b/",
      "source_url": "https://medium.com/@1200km/applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b",
      "published_at": "2026-05-10",
      "updated_at": "2026-05-10",
      "summary": "Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide. Estimative language, evidence discipline, and analytic integrity for cyber.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-11-customer-driven-ai-cti-project-template-part-1-foundations-745861507d03",
      "title": "Customer-Driven AI CTI Project Template. Part 1: Foundations",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-11-customer-driven-ai-cti-project-template-part-1-foundations-745861507d03/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-1-foundations-745861507d03",
      "published_at": "2026-05-11",
      "updated_at": "2026-05-11",
      "summary": "Customer-Driven AI CTI Project Template. Part 1: Foundations. From pure CTI to hands-on detection engineering with strict validation gates",
      "tags": [
        "ai-security",
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-1-foundations-745861507d03",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-12-customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59",
      "title": "Customer-Driven AI CTI Project Template. Part 2A: Phase-by-Phase Execution Guide",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-12-customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59",
      "published_at": "2026-05-12",
      "updated_at": "2026-05-12",
      "summary": "Customer-Driven AI CTI Project Template. Part 2A: Phase-by-Phase Execution Guide. From pure CTI to hands-on detection engineering with strict validation gates.",
      "tags": [
        "ai-security",
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-12-customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943",
      "title": "Customer-Driven AI CTI Project Template :Part 2B: Reference Toolkit",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-12-customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943",
      "published_at": "2026-05-12",
      "updated_at": "2026-05-12",
      "summary": "Customer-Driven AI CTI Project Template :Part 2B: Reference Toolkit. From pure CTI to hands-on detection engineering with strict validation gates",
      "tags": [
        "ai-security",
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-13-customer-driven-ai-cti-project-c0db3cdc1830",
      "title": "Customer-Driven AI CTI Project",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-13-customer-driven-ai-cti-project-c0db3cdc1830/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-c0db3cdc1830",
      "published_at": "2026-05-13",
      "updated_at": "2026-05-13",
      "summary": "Customer-Driven AI CTI Project. Full Workflow Quick Reference",
      "tags": [
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-c0db3cdc1830",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-18-cti-analyst-field-manual-complete-reference-ef2a370bb21f",
      "title": "CTI Analyst Field Manual — Complete Reference",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-18-cti-analyst-field-manual-complete-reference-ef2a370bb21f/",
      "source_url": "https://medium.com/@1200km/cti-analyst-field-manual-complete-reference-ef2a370bb21f",
      "published_at": "2026-05-18",
      "updated_at": "2026-05-18",
      "summary": "CTI Analyst Field Manual — Complete Reference. A practitioner field manual for cyber threat intelligence: from collection requirements to production detection.",
      "tags": [
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-analyst-field-manual-complete-reference-ef2a370bb21f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-05-21-the-intelligent-shield-opencti-057c9b4b9394",
      "title": "The Intelligent Shield. OpenCTI",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-21-the-intelligent-shield-opencti-057c9b4b9394/",
      "source_url": "https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394",
      "published_at": "2026-05-21",
      "updated_at": "2026-05-21",
      "summary": "The Intelligent Shield. OpenCTI. In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-22-one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c",
      "title": "One place for my cybersecurity projects, guides, articles, labs, tools, and research workflows",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-22-one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c/",
      "source_url": "https://medium.com/@1200km/one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c",
      "published_at": "2026-05-22",
      "updated_at": "2026-05-22",
      "summary": "One place for my cybersecurity projects, guides, articles, labs, tools, and research workflows. Andrey Pautov - CTI, Detection Engineering & Security Research",
      "tags": [
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-23-operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0",
      "title": "Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-23-operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0/",
      "source_url": "https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0",
      "published_at": "2026-05-23",
      "updated_at": "2026-05-23",
      "summary": "Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana. Most threat actor writeups stop too early. They describe the group, list ATT&CK.",
      "tags": [
        "ai-security",
        "article",
        "mitre-attack",
        "offensive-research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-05-29-cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46",
      "title": "CTI as a Code: Complete Step-by-Step Methodology",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-29-cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46/",
      "source_url": "https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46",
      "published_at": "2026-05-29",
      "updated_at": "2026-05-29",
      "summary": "CTI as a Code: Complete Step-by-Step Methodology. The evidence problem.An analyst writes “the adversary used T1078” in a report. Six months later nobody can.",
      "tags": [
        "article",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-30-cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f",
      "title": "CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-30-cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f/",
      "source_url": "https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f",
      "published_at": "2026-05-30",
      "updated_at": "2026-05-30",
      "summary": "CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma. All organizations, names, and data are fictional. This is training assignment A01 from.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-06-07-adversarygraph-i-built-a-self-hosted-ai-threat-intelligence-platform-here-s-how-to-use-it-0aa7673e6bd8",
      "title": "AdversaryGraph: I Built a Self-Hosted AI Threat Intelligence Platform — Here’s How to Use It",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-07-adversarygraph-i-built-a-self-hosted-ai-threat-intelligence-platform-here-s-how-to-use-it-0aa7673e6bd8/",
      "source_url": "https://infosecwriteups.com/threatmapper-i-built-a-self-hosted-ai-threat-intelligence-platform-heres-how-to-use-it-0aa7673e6bd8",
      "published_at": "2026-06-07",
      "updated_at": "2026-06-07",
      "summary": "AdversaryGraph: I Built a Self-Hosted AI Threat Intelligence Platform — Here’s How to Use It. GitHub - anpa1200/threatmapper: AI-powered MITRE ATT&CK threat.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/threatmapper-i-built-a-self-hosted-ai-threat-intelligence-platform-heres-how-to-use-it-0aa7673e6bd8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-16-adversarygraph-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65",
      "title": "AdversaryGraph v2.0: I Built a Self-Hosted AI Threat Intelligence Platform",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "2.0",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-16-adversarygraph-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65/",
      "source_url": "https://infosecwriteups.com/threatmapper-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65",
      "published_at": "2026-06-16",
      "updated_at": "2026-06-16",
      "summary": "AdversaryGraph v2.0: I Built a Self-Hosted AI Threat Intelligence Platform. A report is not enough. A PDF from a vendor, an incident response write-up, a.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "incident-response",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/threatmapper-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-19-adversarygraph-usecases-820d03c3a7ab",
      "title": "AdversaryGraph Usecases",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-19-adversarygraph-usecases-820d03c3a7ab/",
      "source_url": "https://medium.com/@1200km/adversarygraph-usecases-820d03c3a7ab",
      "published_at": "2026-06-19",
      "updated_at": "2026-06-19",
      "summary": "AdversaryGraph Usecases. AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adversarygraph-usecases-820d03c3a7ab",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-06-19-adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "title": "AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "2.5",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-19-adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e/",
      "source_url": "https://infosecwriteups.com/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "published_at": "2026-06-19",
      "updated_at": "2026-06-19",
      "summary": "AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map. This release marks an important transition for the project: the tool now has.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-21-from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "title": "From Log to Report: Using AdversaryGraph!",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-21-from-log-to-report-using-adversarygraph-eff2e1d8f2cd/",
      "source_url": "https://medium.com/@1200km/from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "published_at": "2026-06-21",
      "updated_at": "2026-06-21",
      "summary": "From Log to Report: Using AdversaryGraph!. The harder problem is turning scattered technical evidence into a defensible investigation",
      "tags": [
        "adversarygraph",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-06-26-adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platfo-8dfbf1db2c9e",
      "title": "AdversaryGraph v4.0: I Added a Full Malware Analysis Workbench to My Self-Hosted CTI Platform",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "4.0",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-26-adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platfo-8dfbf1db2c9e/",
      "source_url": "https://infosecwriteups.com/adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platform-8dfbf1db2c9e",
      "published_at": "2026-06-26",
      "updated_at": "2026-06-26",
      "summary": "AdversaryGraph v4.0: I Added a Full Malware Analysis Workbench to My Self-Hosted CTI Platform. You upload a sample to one tool for hash reputation. You open.",
      "tags": [
        "adversarygraph",
        "article",
        "malware-analysis",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platform-8dfbf1db2c9e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-29-adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39",
      "title": "AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "5.0",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-29-adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39/",
      "source_url": "https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39",
      "published_at": "2026-06-29",
      "updated_at": "2026-06-29",
      "summary": "AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation. How can a security team move from threat intelligence to detection.",
      "tags": [
        "adversarygraph",
        "article",
        "detection-engineering",
        "offensive-security",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-07-03-comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmwa-8a151f8d5f1b",
      "title": "Comprehensive Cyber Intelligence Research: Attacks Against Embedded Systems, Hardware, Firmware…",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-03-comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmwa-8a151f8d5f1b/",
      "source_url": "https://infosecwriteups.com/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "published_at": "2026-07-03",
      "updated_at": "2026-07-03",
      "summary": "Comprehensive Cyber Intelligence Research: Attacks Against Embedded Systems, Hardware, Firmware…. 2. Post-compromise persistence is the real risk, not only.",
      "tags": [
        "application-security",
        "article",
        "embedded-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-07-07-when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-curso-55eea06b69bd",
      "title": "When AI Coding Agents Say Yes Too Easily: Testing Suspicious Cybersecurity Prompts in Cursor",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-07-when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-curso-55eea06b69bd/",
      "source_url": "https://medium.com/@1200km/when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-cursor-55eea06b69bd",
      "published_at": "2026-07-07",
      "updated_at": "2026-07-07",
      "summary": "When AI Coding Agents Say Yes Too Easily: Testing Suspicious Cybersecurity Prompts in Cursor. I ran a small test inside Cursor to compare how different AI.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-cursor-55eea06b69bd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-07-11-newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "title": "Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-11-newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556/",
      "source_url": "https://infosecwriteups.com/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "published_at": "2026-07-11",
      "updated_at": "2026-07-11",
      "summary": "Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry. 7. Technique 4: Weak-Signal Aggregation and Risk-Based Alerting",
      "tags": [
        "article",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code",
      "title": "CTI as a Code",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Version-controlled CTI methodology, evidence-traced analysis, and deployable detections. Docker Compose lab stack and 8 structured training assignments.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:architecture",
      "title": "Architecture",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/architecture/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Design principles",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:celltronx-proactive-case-study",
      "title": "CTI as a Code in Practice: Proactive Assessment — CelltronX Telecom",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/celltronx-proactive-case-study/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "A complete walkthrough of the proactive methodology applied to a real training scenario: MuddyWater targeting Israeli telecom, five attack scenarios, a detection backlog, and five Sigma rules ready for deployment.",
      "tags": [
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:cti-as-a-code-methodology",
      "title": "CTI as a Code: Complete Step-by-Step Methodology",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/cti-as-a-code-methodology/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Version-controlled threat intelligence — from first call to deployed Sigma rule.",
      "tags": [
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/ecosystem/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:intake-form",
      "title": "Investigation Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intake-form/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "CTI Lab — Reactive investigation intake checklist",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:intake-fullcycle",
      "title": "Full-Cycle CTI Program Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intake-fullcycle/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "CTI Lab — Full-cycle CTI program design intake checklist",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:intake-proactive",
      "title": "Proactive Assessment Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intake-proactive/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "CTI Lab — Proactive threat assessment intake checklist",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:integrations:opencti-thehive",
      "title": "OpenCTI → TheHive Integration",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/integrations/opencti-thehive/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "This integration enables two workflows:",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:integrations:threat-feeds",
      "title": "Threat Feeds and Data Sources",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/integrations/threat-feeds/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Populate the lab with real threat intelligence by connecting external feeds. See the ecosystem for how feeds fit into the overall lab stack.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:intro",
      "title": "CTI as a Code",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intro/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "A full Linux Cyber Threat Intelligence lab and structured CTI methodology framework, running on Docker Compose.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:lifetech-pharma-case-study",
      "title": "Case Study: CTI as a Code in Practice — LifeTech Pharma",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/lifetech-pharma-case-study/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Complete published case study of the PROJ-2024-001 LifeTech Pharma investigation — dual entry points, DCSync, 381 MB formula exfiltration, and a 10-day Sysmon gap.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:methodology",
      "title": "CTI as a Code — Methodology",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/methodology/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Version-controlled, template-driven threat intelligence. Every claim traces to evidence. Every detection traces to a technique. Every commit is an audit record. This page is the tool reference and quick-step overview.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:prerequisites",
      "title": "Prerequisites",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/prerequisites/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Requirements for running the CTI as a Code lab on a single Linux host. Once these are met, follow the Quick Start to bring up all services.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:proactive-walkthrough",
      "title": "CTI as a Code in Practice: Proactive Threat Assessment — CelltronX Telecom",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/proactive-walkthrough/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "A complete walkthrough of the proactive methodology: how four intelligence triggers, a contractor supply chain threat, and an INCD compliance gap become a sprint-ready detection backlog.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:quick-start",
      "title": "Quick Start",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/quick-start/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Get the full lab running in under 10 minutes. See Prerequisites before starting if this is your first run.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:reactive-walkthrough",
      "title": "CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/reactive-walkthrough/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:services:elastic-siem",
      "title": "Elastic SIEM",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/elastic-siem/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "The Elastic SIEM layer consists of Elasticsearch (shared with the other services), Kibana, and optionally Logstash for log ingestion.",
      "tags": [
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:services:elasticsearch",
      "title": "Elasticsearch",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/elasticsearch/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Elasticsearch 8.x acts as the shared data store for every service in the lab stack: OpenCTI, TheHive, Cortex, and Kibana SIEM.",
      "tags": [
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:services:opencti",
      "title": "OpenCTI",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/opencti/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "OpenCTI is the core threat intelligence platform. It stores STIX2 objects (threat actors, attack patterns, malware, campaigns, IOCs) and provides a graph-based investigation interface.",
      "tags": [
        "lab",
        "malware-analysis",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:services:thehive-cortex",
      "title": "TheHive 5 + Cortex",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/thehive-cortex/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "TheHive is the incident response case management system. Cortex is the companion automated enrichment engine that runs analyzers against observables.",
      "tags": [
        "incident-response",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:setup:cortex-setup",
      "title": "Cortex Setup and TheHive Integration",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/cortex-setup/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Create Cortex admin",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:setup:first-run",
      "title": "First-Run Checklist",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/first-run/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Run through this list after docker compose up -d and ./scripts/setup.sh complete successfully.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:setup:opencti-setup",
      "title": "OpenCTI First-Run Setup",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/opencti-setup/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Initial configuration",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:setup:thehive-setup",
      "title": "TheHive First-Run Setup",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/thehive-setup/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Create organisation and admin",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training",
      "title": "Training Assignments",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Eight structured CTI assignments covering the full analyst skill set across four operational modes. Every assignment contains a project brief (assignment.md), distributed analytical files demonstrating the step-by-step methodology, synthetic evidence data, and a worked solution (solution.md).",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:emulation-ndsa",
      "title": "A08 — Adversary Emulation (Gov): NDSA INCD Section 8",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/emulation-ndsa/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode NDSA · PROJ-2026-008",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:emulation-techpay",
      "title": "A04 — Adversary Emulation: TechPay (Operation Desert Cipher)",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/emulation-techpay/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode TechPay FinTech · PROJ-2024-004",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:full-cycle-ndsa",
      "title": "A07 — Full CTI Cycle (Gov): NDSA CTI Program",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/full-cycle-ndsa/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode NDSA · PROJ-2025-007",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:full-cycle-techpay",
      "title": "A03 — Full CTI Cycle: TechPay FinTech",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/full-cycle-techpay/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode TechPay Israel Ltd. · PROJ-2024-003",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:proactive-celltronx",
      "title": "A02 — Proactive CTI: CelltronX Telecom",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/proactive-celltronx/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode CelltronX Telecom · PROJ-2024-002",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:proactive-govid2",
      "title": "A06 — Proactive CTI (Gov): GovID 2.0 Pre-Launch",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/proactive-govid2/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode NDSA GovID 2.0 · PROJ-2025-006",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:reactive-lifetech",
      "title": "A01 — Reactive IR: LifeTech Pharma",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/reactive-lifetech/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode LifeTech Pharma · PROJ-2024-001",
      "tags": [
        "incident-response",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:training:reactive-ndsa",
      "title": "A05 — Reactive IR (Gov): NDSA Biometric Breach",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/reactive-ndsa/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Mode National Digital Services Authority (NDSA) · PROJ-2025-005",
      "tags": [
        "incident-response",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:workflows:fullcycle-program",
      "title": "Full-Cycle CTI Program — Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/fullcycle-program/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Building a CTI program that doesn't exist yet — or rebuilding one that failed — starts here.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:workflows:ioc-triage",
      "title": "IOC Triage Workflow",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/ioc-triage/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "This workflow covers the end-to-end process of receiving a suspicious indicator, enriching it, correlating it with known threat intel, and producing a finished intelligence product. It is a core step in both the reactive investigation and proactive assessment workflows.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:workflows:proactive-assessment",
      "title": "Proactive Assessment — Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/proactive-assessment/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "Start here, before you open any advisory, before you run any query.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:workflows:reactive-investigation",
      "title": "Reactive Investigation — Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/reactive-investigation/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "This is the step most analysts skip. It is the most important step.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti_as_a_code:workflows:threat-actor-research",
      "title": "Threat Actor Research Workflow",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/threat-actor-research/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": null,
      "summary": "A structured approach to building a threat actor profile using the lab — from open-source collection to a finished STIX-structured intelligence product in OpenCTI. This workflow follows the proactive assessment intake and feeds directly into IOC triage and detection engineering.",
      "tags": [
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual",
      "title": "CTI Analyst Field Manual",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Professional CTI tradecraft manual: from collection requirements to evidence discipline, attribution, infrastructure pivoting, and detection-ready outputs. 80+ pages across 10 modules.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:actor-profile-template",
      "title": "Actor Profile Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/actor-profile-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:actor-update-workflow",
      "title": "Actor Update Workflow",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/actor-update-workflow/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:apt41-dragonrx",
      "title": "APT41 / Operation DragonRx",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/apt41-dragonrx/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:handala",
      "title": "Handala / Void Manticore Research Method",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/handala/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:muddywater-seedworm",
      "title": "MuddyWater / Seedworm",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/muddywater-seedworm/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:ai-cti-control-matrix",
      "title": "AI CTI Control Matrix",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/ai-cti-control-matrix/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Control matrix for AI-assisted CTI: which analytical tasks are suitable for LLM acceleration, which require human validation, and how to manage AI-introduced bias.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:ai-quality-gates",
      "title": "AI Quality Gates",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/ai-quality-gates/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:hallucination-control",
      "title": "Hallucination Control",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/hallucination-control/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Practical hallucination control for CTI analysts using AI tools — validation checkpoints, authoritative source grounding, and techniques for catching AI fabrications.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:manual-vs-ai-assisted-cti",
      "title": "Manual vs AI-Assisted CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/manual-vs-ai-assisted-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:prompt-library",
      "title": "Prompt Library",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/prompt-library/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:safe-llm-research-workflow",
      "title": "Safe LLM Research Workflow",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/safe-llm-research-workflow/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Safe LLM research workflow for CTI analysts — how to use AI tools like Claude without hallucination risk, with validation gates and source attribution requirements.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:alternative-hypotheses",
      "title": "Alternative Hypotheses",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/alternative-hypotheses/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Structured analytic techniques for CTI: how to generate, test, and eliminate alternative hypotheses to avoid confirmation bias in threat assessments.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:analyst-checklist",
      "title": "Analyst Checklist",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/analyst-checklist/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:assumptions-and-gaps",
      "title": "Assumptions and Gaps",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/assumptions-and-gaps/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:contradiction-handling",
      "title": "Contradiction Handling",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/contradiction-handling/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:estimative-language",
      "title": "Estimative Language",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/estimative-language/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Using estimative language in CTI analysis: probability words, confidence levels, Sherman Kent scale, and how to avoid ambiguous assertions in finished intelligence.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:sherman-kent-for-cti",
      "title": "Sherman Kent for CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/sherman-kent-for-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:attribution-methodology",
      "title": "Attribution Methodology",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/attribution-methodology/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "CTI attribution methodology: how to build structured group and campaign similarity hypotheses from TTPs, infrastructure, targeting, and victimology without overreaching.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:attribution-worked-example",
      "title": "Attribution Worked Example",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/attribution-worked-example/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:confidence-vs-probability",
      "title": "Confidence vs Probability",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/confidence-vs-probability/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:evidence-strength-ladder",
      "title": "Evidence Strength Ladder",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/evidence-strength-ladder/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:false-flag-analysis",
      "title": "False Flag Analysis",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/false-flag-analysis/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "How to identify and analyze false flag operations in CTI — when to consider deception, how to weight conflicting indicators, and how to hedge assessments.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:confidence-language",
      "title": "Confidence Language",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/confidence-language/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Standardized confidence language for CTI reporting — probabilistic and estimative language, confidence tiers, and how to communicate uncertainty to consumers.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:evidence-labels",
      "title": "Evidence Labels",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/evidence-labels/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "CTI evidence labeling system: how to tag claims with source quality, confidence tier, and evidence type to maintain analytic rigor across investigations.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:finished-intelligence-vs-research-notes",
      "title": "Finished Intelligence vs Research Notes",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/finished-intelligence-vs-research-notes/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:intelligence-cycle",
      "title": "Intelligence Cycle",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/intelligence-cycle/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "The intelligence cycle for CTI: direction, collection, processing, analysis, dissemination, and feedback — applied to practitioner workflows.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:pir-sir-eei",
      "title": "PIR, SIR, and EEI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/pir-sir-eei/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "How to define Priority Intelligence Requirements (PIR), Specific Intelligence Requirements (SIR), and Essential Elements of Information (EEI) for CTI programs.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:source-reliability",
      "title": "Source Reliability",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/source-reliability/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Practical model for rating source reliability and information credibility using Admiralty scale and evidence labels — without pretending ratings are absolute.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:what-is-cti",
      "title": "What Is CTI?",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/what-is-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Defines cyber threat intelligence as an analytic discipline — covering the difference between IOCs, threat feeds, finished intelligence, and decision-supporting CTI.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:detection-backlog",
      "title": "Detection Backlog",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/detection-backlog/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "How to build and manage a structured CTI detection backlog — prioritizing TTP-based detections, assigning detection readiness levels, and tracking coverage gaps.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:detection-readiness-levels",
      "title": "Detection Readiness Levels",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/detection-readiness-levels/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:hunting-hypothesis-template",
      "title": "Hunting Hypothesis Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/hunting-hypothesis-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Template and methodology for writing threat hunting hypotheses from CTI — actor-anchored, behavior-anchored, and anomaly-anchored hypothesis formats.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:intelligence-to-detection",
      "title": "Intelligence to Detection",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/intelligence-to-detection/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Converting CTI claims into telemetry requirements, detection hypotheses, KQL/Sigma rules, and SOC handoff packages — the complete CTI-to-detection workflow.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:sigma-kql-spl-examples",
      "title": "Sigma, KQL, and SPL Examples",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/sigma-kql-spl-examples/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:soc-handoff",
      "title": "SOC Handoff",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/soc-handoff/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "How to hand off CTI findings to SOC teams: structured handoff note format, telemetry requirements, detection readiness levels, and triage guidance.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:telemetry-requirements",
      "title": "Telemetry Requirements",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/telemetry-requirements/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ecosystem/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:fact-correlation",
      "title": "Cross-Project Fact Correlation",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/fact-correlation/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:attck-mapping-mistakes",
      "title": "ATT&CK Mapping Mistakes",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/attck-mapping-mistakes/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "The most common ATT&CK mapping mistakes CTI analysts make — over-tagging, under-tagging, confusing sub-techniques, and how to calibrate mappings correctly.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:cyber-kill-chain",
      "title": "Cyber Kill Chain",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/cyber-kill-chain/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:diamond-model",
      "title": "Diamond Model",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/diamond-model/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "identity-security",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:mitre-attack-as-working-tool",
      "title": "MITRE ATT&CK as a Working Tool",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/mitre-attack-as-working-tool/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "How to use MITRE ATT&CK as a working CTI tool — technique mapping, gap analysis, detection prioritization, and common analyst mistakes to avoid.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:pyramid-of-pain",
      "title": "Pyramid of Pain",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/pyramid-of-pain/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "David Bianco's Pyramid of Pain applied to CTI practice: how indicator type affects adversary disruption cost and how to prioritize TTP-based detection over IOCs.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:governance:cross-project-correlation-register",
      "title": "Cross-Project Correlation Register",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/governance/cross-project-correlation-register/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:asn-hosting-pivots",
      "title": "ASN and Hosting Pivots",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/asn-hosting-pivots/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:certificates",
      "title": "Certificates",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/certificates/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:infrastructure-pivoting-worked-case",
      "title": "Infrastructure Pivoting Worked Case",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/infrastructure-pivoting-worked-case/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:passive-dns",
      "title": "Passive DNS",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/passive-dns/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Using passive DNS data for infrastructure pivoting in CTI investigations: querying historical resolution records, identifying actor infrastructure clusters, and pivot techniques.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:pivoting-limitations",
      "title": "Pivoting Limitations",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/pivoting-limitations/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:single-ioc-to-network",
      "title": "Single IOC to Network",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/single-ioc-to-network/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Step-by-step workflow for expanding a single IOC into a full infrastructure cluster using WHOIS, passive DNS, certificate transparency, and ASN pivoting.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:intro",
      "title": "CTI Analyst Field Manual",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/intro/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "A practical CTI tradecraft handbook for analysts — covering source reliability, analytic discipline, ATT&CK mapping, TTP-to-detection workflow, and AI-assisted CTI methodology.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:limitations",
      "title": "Known Limitations",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/limitations/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Honest assessment of what the CTI Analyst Field Manual covers, what it doesn't, and how to apply its tradecraft with appropriate calibration.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:references:authoritative-bibliography",
      "title": "Authoritative Bibliography",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/references/authoritative-bibliography/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:references:medium-source-index",
      "title": "Medium Source Index",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/references/medium-source-index/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:review:publication-grade-review",
      "title": "Publication-Grade Review Backlog",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/review/publication-grade-review/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:role-based-reading-paths",
      "title": "Role-Based Reading Paths",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/role-based-reading-paths/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Reading guide for the CTI Analyst Field Manual by role: CTI analyst, SOC analyst, detection engineer, and threat hunter — with recommended page sequences.",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:cellular-provider-case-study",
      "title": "Cellular Provider Case Study",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/cellular-provider-case-study/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:israel-public-sector-notes",
      "title": "Israel Public-Sector Notes",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/israel-public-sector-notes/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:telecom-4g-threats",
      "title": "Telecom 4G Threats",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/telecom-4g-threats/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:telecom-5g-threats",
      "title": "Telecom 5G Threats",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/telecom-5g-threats/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:actor-profile-template",
      "title": "Actor Profile Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/actor-profile-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:collection-gap-register",
      "title": "Collection Gap Register",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/collection-gap-register/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:detection-backlog-item",
      "title": "Detection Backlog Item",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/detection-backlog-item/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:evidence-register-template",
      "title": "Evidence Register Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/evidence-register-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:executive-summary",
      "title": "Executive Summary Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/executive-summary/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:finished-intel-report-template",
      "title": "Finished Intelligence Report Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/finished-intel-report-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:hunting-hypothesis-template",
      "title": "Hunting Hypothesis Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/hunting-hypothesis-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:infrastructure-pivot-log",
      "title": "Infrastructure Pivot Log",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/infrastructure-pivot-log/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:soc-handoff-note",
      "title": "SOC Handoff Note",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/soc-handoff-note/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:source-register-template",
      "title": "Source Register Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/source-register-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:validation:ci-validation-evidence",
      "title": "CI Validation Evidence",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/validation/ci-validation-evidence/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:validation:link-check-report",
      "title": "Link-Check Report",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/validation/link-check-report/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:actor-research",
      "title": "Worked Examples: Actor Research",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/actor-research/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:ai-assisted-cti",
      "title": "Worked Examples: AI-Assisted CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/ai-assisted-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:analytic-discipline",
      "title": "Worked Examples: Analytic Discipline",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/analytic-discipline/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:attribution",
      "title": "Worked Examples: Attribution",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/attribution/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:cti-foundations",
      "title": "Worked Examples: CTI Foundations",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/cti-foundations/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:cti-to-detection",
      "title": "Worked Examples: CTI to Detection",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/cti-to-detection/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:frameworks",
      "title": "Worked Examples: Frameworks",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/frameworks/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:infrastructure-pivoting",
      "title": "Worked Examples: Infrastructure Pivoting",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/infrastructure-pivoting/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:sector-cti",
      "title": "Worked Examples: Sector CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/sector-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cti.html",
      "title": "Selected Security Research",
      "primary_type": "index",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current threat-intelligence research index",
      "canonical_url": "https://1200km.com/cti.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "CTI research by Andrey Pautov: actor profiles, ATT&CK-mapped analysis, TTP overlap scoring, detection…",
      "tags": [
        "detection-engineering",
        "index",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cti.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project",
      "title": "Customer-Driven AI CTI Project",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Docusaurus site for the Customer-Driven AI CTI Project methodology.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs",
      "title": "Customer-Driven AI CTI Project",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Docusaurus documentation site for a customer-driven, AI-assisted cyber threat intelligence project methodology.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/ecosystem/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "How the Customer-Driven AI CTI Project connects to the broader 1200km.com ecosystem: CTI Field Manual, actor profiles, AdversaryGraph, and detection repositories.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:fact-correlation",
      "title": "Cross-Project Fact Correlation",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/fact-correlation/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:infographics",
      "title": "Published Article Index",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/infographics/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Index of published Medium article series with source links.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:complete-template",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/complete-template/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Single-file version of the complete Customer-Driven AI CTI Project Template.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:foundations",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/foundations/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Analytic standards, governance, scoring, roles, artifacts, and detection readiness foundations.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:phase-by-phase-execution-guide",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/phase-by-phase-execution-guide/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Phase 0 through Phase 14 execution guide for CTI-to-detection delivery.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:reference-toolkit",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/reference-toolkit/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "AI workflows, LLM task cards, quality gates, registers, worked example, and delivery package.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package",
      "title": "Practitioner Package",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Synthetic sample artifacts for running the Customer-Driven AI CTI Project workflow.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:complete-worked-case",
      "title": "Complete Worked Case: Cloud Identity to Backup Deletion",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/complete-worked-case/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Full synthetic PIR-to-detection-to-pilot-to-executive-report case.",
      "tags": [
        "ai-security",
        "cloud-security",
        "guide",
        "identity-security",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:detection-artifacts",
      "title": "Detection Artifacts",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/detection-artifacts/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Sigma Rule",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:fake-customer-scenario",
      "title": "Fake Customer Scenario",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/fake-customer-scenario/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "The LifeTech Pharma fake customer scenario: PIRs, threat landscape, organizational context, and intelligence requirements used throughout the customer-driven CTI worked case.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:gate-evidence-packs",
      "title": "Gate Evidence Packs",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/gate-evidence-packs/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Gate evidence packs for the customer-driven CTI project: analyst-validated evidence and confidence ratings at each methodology phase gate.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:replay-example",
      "title": "Replay Example",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/replay-example/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "The replay example uses the synthetic dataset in examples/datasets/cloudidentityevents.csv.",
      "tags": [
        "ai-security",
        "cloud-security",
        "guide",
        "identity-security",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:sample-registers",
      "title": "Sample Registers",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/sample-registers/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "The sample registers are provided as CSV files under examples/registers/.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:workflow-output-screenshots",
      "title": "Workflow Output Screenshots",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/workflow-output-screenshots/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "These SVG screenshots are synthetic workflow outputs generated for the worked case.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:changelog",
      "title": "Changelog",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/changelog/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "v1.0.0 - 2026-05-13",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:deprecated",
      "title": "Deprecated Sections",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/deprecated/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "No sections are deprecated in v1.0.0.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:roadmap",
      "title": "Roadmap",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/roadmap/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "v1.1 - Validation and Schemas",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:versioning",
      "title": "Versioning",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/versioning/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Current release: v1.0.0",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:published-articles",
      "title": "Published Articles",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/published-articles/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Canonical Medium links for the Customer-Driven AI CTI Project article series.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:artifact-contracts",
      "title": "Artifact Contracts",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/artifact-contracts/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "Artifact contracts define the minimum fields expected for reusable project outputs.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:attack-mappings",
      "title": "ATT&CK and D3FEND Mappings",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/attack-mappings/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "ATT&CK mapping standard for the customer-driven CTI methodology: technique selection criteria, evidence validation, and how mappings connect to customer deliverables.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:normative-language",
      "title": "Normative Language",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/normative-language/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "This project uses requirement keywords to make the methodology standard-like and auditable.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:schemas-and-validation",
      "title": "Schemas and Validation",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/schemas-and-validation/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "The Practitioner Package includes machine-readable examples and validation checks.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:workflow:full-workflow-quick-reference",
      "title": "Customer-Driven AI CTI Project: Full Workflow Quick Reference",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/workflow/full-workflow-quick-reference/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": null,
      "summary": "End-to-end quick reference for the Customer-Driven AI CTI Project workflow.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cv.html",
      "title": "Andrey Pautov",
      "primary_type": "profile",
      "primary_domain": "professional-profile",
      "audience": [
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current public CV",
      "canonical_url": "https://1200km.com/cv.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "CV of Andrey Pautov: CTI-to-detection practitioner. Adversary profiling, ATT&CK mapping, IOC investigation, malware analysis…",
      "tags": [
        "malware-analysis",
        "mitre-attack",
        "profile",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cv.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge",
      "title": "Cybersecurity Knowledge Base and Practitioner Field Guides",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "security-leader",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "the maintained 1200km Cyber Knowledge collection and its ten source-reviewed practitioner field guides",
      "canonical_url": "https://1200km.com/cyber-knowledge/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "Cyber Knowledge. A syllabus-style reference hub covering CTI, red team, blue team, vulnerability research, malware analysis, secure code, DFIR, cloud, GRC…",
      "tags": [
        "cloud-security",
        "malware-analysis",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:ai-security.html",
      "title": "AI Security",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer",
        "security-leader",
        "detection-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AI application and model security, RAG integrity, prompt injection, agent and MCP authorization, model supply-chain assurance, adversarial testing, monitoring, incident response, governance, and secure AI delivery",
      "canonical_url": "https://1200km.com/cyber-knowledge/ai-security.html",
      "published_at": "2026-07-28",
      "updated_at": "2026-07-28",
      "summary": "A 14-module practitioner guide to securing AI systems end to end: threat modeling, RAG and retrieval integrity, model supply chain, prompt injection, agents…",
      "tags": [
        "ai-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/ai-security.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:attack-matrix.html",
      "title": "MITRE ATT&CK Knowledge Mesh",
      "primary_type": "tool",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "MITRE ATT&CK Enterprise 19.1 technique exploration and governed cross-domain Cyber Knowledge discovery",
      "canonical_url": "https://1200km.com/cyber-knowledge/attack-matrix.html",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Explore ATT&CK Enterprise techniques, defensive relationships, threat groups, and linked 1200km Cyber Knowledge learning routes.",
      "tags": [
        "mitre-attack",
        "threat-intelligence",
        "tool"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/attack-matrix.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:blue-team.html",
      "title": "Blue Team & Defensive Security",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "security operations, telemetry engineering, detection development, threat hunting, investigation, incident response, validation, and controlled AI assistance",
      "canonical_url": "https://1200km.com/cyber-knowledge/blue-team.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Blue Team field guide covering SOC operations, telemetry, detection engineering, threat hunting, cloud defense, incident response, AI, and validation.",
      "tags": [
        "ai-security",
        "cloud-security",
        "detection-engineering",
        "incident-response",
        "research",
        "threat-hunting"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/blue-team.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:cloud-security.html",
      "title": "Cloud Security",
      "primary_type": "guide",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "developer",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "multi-cloud governance, shared responsibility, landing zones, human and workload identity, network and data protection, infrastructure delivery, containers, Kubernetes, detection, posture and exposure management, incident response, SaaS, suppliers, and cloud AI systems",
      "canonical_url": "https://1200km.com/cyber-knowledge/cloud-security.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Cloud-security guide covering shared responsibility, IAM, networks, data, IaC, containers, Kubernetes, detection, incident response, SaaS, and AI.",
      "tags": [
        "ai-security",
        "cloud-security",
        "detection-engineering",
        "identity-security",
        "incident-response",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/cloud-security.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:cti.html",
      "title": "Cyber Threat Intelligence (CTI)",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI foundations, analysis, sharing, hunting, and detection practice",
      "canonical_url": "https://1200km.com/cyber-knowledge/cti.html",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "Source-linked CTI field guide covering intelligence requirements, collection, analysis, ATT&CK, actor research, sharing, hunting, and detection.",
      "tags": [
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/cti.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:dfir.html",
      "title": "Digital Forensics & Incident Response (DFIR)",
      "primary_type": "guide",
      "primary_domain": "incident-response",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "incident preparation, declaration, triage, evidence preservation, endpoint, disk, memory, network, cloud, identity and malware investigation, containment, recovery, reporting, post-incident learning, and controlled AI assistance",
      "canonical_url": "https://1200km.com/cyber-knowledge/dfir.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "DFIR field guide covering readiness, triage, evidence integrity, endpoint, memory, network, cloud, identity, containment, recovery, reporting, and AI.",
      "tags": [
        "ai-security",
        "cloud-security",
        "identity-security",
        "incident-response",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/dfir.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:editorial-policy",
      "title": "Editorial and Source Policy",
      "primary_type": "policy",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "Cyber Knowledge source selection, review, corrections, versioning, and AI-assistance boundaries",
      "canonical_url": "https://1200km.com/cyber-knowledge/editorial-policy/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-28",
      "summary": "How 1200km Cyber Knowledge selects sources, reviews claims, records versions, handles AI assistance, and corrects factual issues.",
      "tags": [
        "ai-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/editorial-policy/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:glossary",
      "title": "Cyber Knowledge Glossary",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "defined terms extracted from the maintained Cyber Knowledge field guides",
      "canonical_url": "https://1200km.com/cyber-knowledge/glossary/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "A source-linked glossary of cybersecurity terminology consolidated from the ten 1200km practitioner field guides.",
      "tags": [
        "network-security",
        "research",
        "security-research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/glossary/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:grc.html",
      "title": "Governance, Risk & Compliance (GRC)",
      "primary_type": "guide",
      "primary_domain": "security-governance",
      "audience": [
        "security-leader",
        "security-engineer",
        "developer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "cybersecurity governance, organizational context, scenario-based risk assessment and treatment, security frameworks, policies, controls, evidence, audit and assurance, legal and contractual obligations, third-party and software supply-chain risk, privacy, resilience, metrics, cloud and product governance, and controlled AI-assisted GRC",
      "canonical_url": "https://1200km.com/cyber-knowledge/grc.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Cybersecurity GRC guide covering governance, scenario-based risk, NIST CSF 2.0, controls, audit evidence, suppliers, privacy, resilience, and AI.",
      "tags": [
        "ai-security",
        "research",
        "security-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/grc.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:malware-analysis.html",
      "title": "Malware Analysis & Reverse Engineering",
      "primary_type": "guide",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer",
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized malware triage, reverse engineering, behavior analysis, detection development, threat-intelligence enrichment, and incident-response handoff",
      "canonical_url": "https://1200km.com/cyber-knowledge/malware-analysis.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Malware-analysis and reverse-engineering guide covering safe triage, disassembly, debugging, unpacking, memory, Android, YARA, AI, and defensive handoff.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "malware-analysis",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/malware-analysis.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:osint.html",
      "title": "OSINT & Reconnaissance",
      "primary_type": "guide",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized and ethical open-source collection, investigator OPSEC, intelligence requirements, search and archives, DNS, RDAP, certificate transparency, internet exposure, web and API reconnaissance, organization research, public code and cloud artifacts, media verification, threat-infrastructure pivoting, automation, AI assistance, external attack-surface monitoring, evidence preservation, and reporting",
      "canonical_url": "https://1200km.com/cyber-knowledge/osint.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "A 14-module OSINT field guide to ethical collection, infrastructure discovery, media verification, threat research, AI assistance, evidence, and reporting.",
      "tags": [
        "ai-security",
        "open-source-intelligence",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/osint.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:red-team.html",
      "title": "Red Team & Offensive Security",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized offensive-security testing, adversary emulation, laboratories, and defensive validation",
      "canonical_url": "https://1200km.com/cyber-knowledge/red-team.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "A 14-module red-team field guide covering authorization, recon, web, cloud, identity, clients, AI/MCP, labs, validation, evidence, and reporting.",
      "tags": [
        "ai-security",
        "cloud-security",
        "identity-security",
        "offensive-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/red-team.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:secure-code.html",
      "title": "Secure Code & Application Security",
      "primary_type": "guide",
      "primary_domain": "application-security",
      "audience": [
        "developer",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "secure software design, implementation, verification, supply-chain assurance, AI application security, release, and remediation",
      "canonical_url": "https://1200km.com/cyber-knowledge/secure-code.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Application-security guide covering threat modeling, identity, authorization, APIs, cryptography, supply chains, testing, AI systems, and remediation.",
      "tags": [
        "ai-security",
        "identity-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/secure-code.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:sources",
      "title": "Cyber Knowledge Source Index",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "external sources referenced by the maintained Cyber Knowledge field guides",
      "canonical_url": "https://1200km.com/cyber-knowledge/sources/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "Authoritative, first-party, research, and practitioner sources referenced across the 1200km Cyber Knowledge field guides.",
      "tags": [
        "research",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/sources/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:vulnerability-research.html",
      "title": "Vulnerability Research & Exploit Development",
      "primary_type": "guide",
      "primary_domain": "vulnerability-research",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized vulnerability research, exploitability validation, coordinated disclosure, and remediation verification",
      "canonical_url": "https://1200km.com/cyber-knowledge/vulnerability-research.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Vulnerability-research guide covering safe labs, static and dynamic analysis, fuzzing, exploitability, coordinated disclosure, remediation, and AI.",
      "tags": [
        "ai-security",
        "malware-analysis",
        "offensive-security",
        "research",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/vulnerability-research.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:embedded-systems-hardware-firmware",
      "title": "Embedded Systems, Hardware, Firmware",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "embedded, hardware, and firmware threat research companion",
      "canonical_url": "https://1200km.com/embedded-systems-hardware-firmware/",
      "published_at": "2026-07-03",
      "updated_at": "2026-07-03",
      "summary": "Source-verified CTI research on embedded systems, edge appliances, BMC, UEFI…",
      "tags": [
        "application-security",
        "embedded-security",
        "research",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "source_url": "https://medium.com/@1200km/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://medium.com/@1200km/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:external-validation.html",
      "title": "Public evidence for the 1200km security research ecosystem.",
      "primary_type": "contribution",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "externally-accepted",
      "applies_to": "accepted and open external contribution evidence, kept separate",
      "canonical_url": "https://1200km.com/external-validation.html",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Evidence-backed validation for 1200km: accepted upstream contributions, separately tracked open…",
      "tags": [
        "research",
        "security-research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/external-validation.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:guides.html",
      "title": "Security Research Library",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current guide index",
      "canonical_url": "https://1200km.com/guides.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Security guides by Andrey Pautov: CTI tradecraft, ATT&CK mapping, detection engineering, anomaly…",
      "tags": [
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/guides.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:hexstrike-ai-guide",
      "title": "HexStrike AI Penetration Testing Orchestrator",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/Hexstrike-AI-guide/",
      "published_at": null,
      "updated_at": null,
      "summary": "HexStrike AI — bridge LLMs to 150+ security tools via MCP for authorized lab assessment, evidence collection, troubleshooting, and reporting.",
      "tags": [
        "ai-security",
        "guide",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/Hexstrike-AI-guide/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:hexstrike.html",
      "title": "HexStrike",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized offensive-security testing",
      "canonical_url": "https://1200km.com/hexstrike.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "HexStrike by Andrey Pautov: AI-assisted pentesting, privilege escalation, lateral movement, credential theft, post-exploitation…",
      "tags": [
        "ai-security",
        "offensive-research",
        "offensive-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/hexstrike.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection",
      "title": "Insider Threat Detection",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Detection logic, 14 documented cases, telemetry requirements, and a four-phase implementation programme for detecting malicious insider activity.",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies",
      "title": "3. Documented Case Studies",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Case studies overview",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:barile",
      "title": "3.14 Juliana Barile — Former New York Credit Union Employee (2021)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/barile/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category New York credit union",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:desjardins",
      "title": "3.11 Desjardins Group — Employee Data Theft (2017–2019)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/desjardins/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Desjardins Group (Canada)",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:duronio",
      "title": "3.3 Roger Duronio — UBS Systems Administrator (2002)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/duronio/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category UBS PaineWebber",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:kvashuk",
      "title": "3.10 Volodymyr Kvashuk — Microsoft Software Engineer (2018–2019)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/kvashuk/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Microsoft",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:levandowski",
      "title": "3.4 Anthony Levandowski — Waymo Engineer (2016)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/levandowski/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Waymo (Alphabet) → Otto → Uber",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:manning",
      "title": "3.1 Chelsea Manning — US Army Intelligence Analyst (2010)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/manning/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category US Army",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:ramesh",
      "title": "3.5 Sudhish Kasaba Ramesh — Cisco Engineer (2018)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/ramesh/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Cisco Systems",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:ruiz",
      "title": "3.8 Reyes Daniel Ruiz — Yahoo Software Engineer (2018)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/ruiz/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Yahoo",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:sharp",
      "title": "3.9 Nickolas Sharp — Ubiquiti Developer (2020–2021)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/sharp/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Ubiquiti Networks",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:skelton",
      "title": "3.7 Andrew Skelton — Morrisons Internal Auditor (2014)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/skelton/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Morrisons (UK supermarket)",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:snowden",
      "title": "3.2 Edward Snowden — NSA Contractor (2013)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/snowden/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category NSA / Booz Allen Hamilton",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:tesla",
      "title": "3.12 Tesla — Departing Employee Data Leak (2023)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/tesla/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Tesla",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:twitter",
      "title": "3.13 Twitter — Saudi Arabia State-Sponsored Insider Espionage (2015)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/twitter/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category Twitter",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:zheng",
      "title": "3.6 Xiaoqing Zheng — GE Aviation Engineer (2019 indictment)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/zheng/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Category General Electric Aviation",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:conclusion",
      "title": "9. Conclusion and Coverage Gaps",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/conclusion/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Conclusion",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods",
      "title": "4. Detection Methods",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Detection methods overview",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:behavioural-heuristics",
      "title": "4.2 Behavioural Heuristics",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/behavioural-heuristics/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Behavioural heuristics",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:covering-tracks",
      "title": "4.7 Covering-Tracks Detection",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/covering-tracks/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Covering tracks",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:deterministic-rules",
      "title": "4.1 Deterministic Rules",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/deterministic-rules/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Deterministic rules",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:exfiltration-paths",
      "title": "4.4 Exfiltration Path Coverage",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/exfiltration-paths/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Exfiltration paths",
      "tags": [
        "ai-security",
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:identity-privilege",
      "title": "4.3 Identity and Privilege Anomalies",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/identity-privilege/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Identity and privilege",
      "tags": [
        "detection-engineering",
        "guide",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:sabotage-signals",
      "title": "4.5 Sabotage Signals",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/sabotage-signals/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Sabotage signals",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:ueba-anomaly",
      "title": "4.6 UEBA and Anomaly Models",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/ueba-anomaly/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "UEBA and anomaly models",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:implementation",
      "title": "8. Implementation Guidance",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/implementation/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Implementation guidance",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:intro",
      "title": "Detecting Malicious Insider Activity: A Technical Detection Engineering Guide",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/intro/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "For ATT&CK mapping, coverage-gap analysis, and detection-backlog handoff across this research, use the AdversaryGraph AI CTI workbench.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:legal-privacy",
      "title": "7. Legal and Privacy Constraints",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/legal-privacy/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Legal and privacy",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:priority-matrix",
      "title": "5. Detection Priority Matrix",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/priority-matrix/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Priority matrix",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:references",
      "title": "10. References",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/references/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "The following primary sources are cited in this guide. For DOJ criminal matters, press releases and criminal complaints are cited; where the original filing URL has changed, the relevant DOJ press office page is provided as an entry point.",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:required-telemetry",
      "title": "6. Required Telemetry",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/required-telemetry/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Required telemetry",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:taxonomy",
      "title": "2. Insider Threat Taxonomy and Kill Chain",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/taxonomy/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Taxonomy overview",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:insider-threat-detection:docs:why-harder",
      "title": "1. Why Insider Detection Is Structurally Harder",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/why-harder/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": null,
      "summary": "Structural differences diagram",
      "tags": [
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti",
      "title": "Israel Government Threat Actors CTI",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This documentation organizes public-source threat intelligence for defensive use by Israeli government and public-sector defenders.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors",
      "title": "Actor Index",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This index is the entry point for actor-centric navigation. Use the Field Manual Actor Profile Template and Attribution Methodology when editing actor claims. Each actor links to its profile and to the generated cross-reference workbench that joins actor pages to TTPs, IOC references, malware/tool references, hunts, detections, and surfaces.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:agrius",
      "title": "Agrius",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/agrius/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Agrius is an Iran-aligned destructive threat actor targeting Israeli organizations with wiper malware disguised as ransomware, operating through the BlackShadow and Moneybird personas.",
      "tags": [
        "agrius",
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:apt35",
      "title": "Magic Hound / APT35",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/apt35/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Magic Hound (APT35) is an IRGC-IO-attributed cyber espionage group targeting academics, journalists, diplomats, and Israeli government entities through persona-based spearphishing and credential theft.",
      "tags": [
        "apt35",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:apt39",
      "title": "APT39",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/apt39/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "apt39",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:apt42",
      "title": "APT42",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/apt42/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "APT42 is an IRGC-IO-attributed surveillance cluster targeting journalists, civil society, government officials, and foreign policy researchers via persona-based social engineering and credential theft.",
      "tags": [
        "apt42",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:arid-viper",
      "title": "APT-C-23 / Arid Viper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/arid-viper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "APT-C-23 (Arid Viper) is a Hamas-affiliated mobile threat actor deploying Android spyware (AridSpy) against Israeli military, Palestinian civil society, and Egyptian political targets.",
      "tags": [
        "arid-viper",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:cotton-sandstorm",
      "title": "Cotton Sandstorm",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/cotton-sandstorm/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Cotton Sandstorm (Emennet Pasargad / ASA) is an IRGC-affiliated influence operations actor combining intrusion, data theft, and media messaging campaigns targeting Israel and Western audiences.",
      "tags": [
        "cotton-sandstorm",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:cyber-toufan",
      "title": "Cyber Toufan",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/cyber-toufan/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Cyber Toufan emerged in October 2023 conducting data theft and wiper operations against Israeli organizations, claiming 100+ victims following Hamas's October 7 attack.",
      "tags": [
        "cyber-toufan",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:cyberav3ngers",
      "title": "CyberAv3ngers",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/cyberav3ngers/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "CyberAv3ngers is the public persona of the IRGC Cyber-Electronic Command's Shahid Kaveh Group, targeting ICS/SCADA and OT systems including water treatment facilities and PLCs.",
      "tags": [
        "cyberav3ngers",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:darkbit",
      "title": "DarkBit",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/darkbit/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "darkbit",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:handala",
      "title": "Void Manticore / Handala",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/handala/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Void Manticore (Handala Hack) is a MOIS-linked destructive actor targeting Israeli organizations through data theft, wiper deployment, and Telegram-amplified influence operations since October 2023.",
      "tags": [
        "detection-engineering",
        "handala",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:imperial-kitten",
      "title": "Imperial Kitten",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/imperial-kitten/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "detection-engineering",
        "imperial-kitten",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:lebanese-cedar",
      "title": "Lebanese Cedar",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/lebanese-cedar/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Lebanese Cedar (Volatile Cedar) is a Hezbollah-affiliated espionage group with multi-year persistent access to telecom, defense, media, and education organizations in the Middle East and Europe.",
      "tags": [
        "detection-engineering",
        "lebanese-cedar",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:lyceum",
      "title": "Lyceum",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/lyceum/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "detection-engineering",
        "lyceum",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:muddywater",
      "title": "MuddyWater",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/muddywater/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "MuddyWater is a MOIS-attributed Iranian cyber espionage group explicitly designated by CISA advisory AA22-055A, active since 2017 targeting Israeli government, defense, and critical infrastructure.",
      "tags": [
        "detection-engineering",
        "muddywater",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:oilrig",
      "title": "OilRig",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/oilrig/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "OilRig (APT34) is one of Iran's most prolific espionage groups, active since 2014 targeting Middle Eastern government, energy, telecom, and financial sectors with custom backdoors and cloud-service C2.",
      "tags": [
        "cloud-security",
        "detection-engineering",
        "oilrig",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:pioneer-kitten",
      "title": "Pioneer Kitten",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/pioneer-kitten/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "detection-engineering",
        "pioneer-kitten",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:scarred-manticore",
      "title": "Scarred Manticore",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/scarred-manticore/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "detection-engineering",
        "research",
        "scarred-manticore",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:ta402",
      "title": "TA402",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/ta402/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "TA402 (Molerats/Gaza Cybergang) is a Palestinian-aligned espionage group active since 2012 targeting Palestinian Authority, Israeli government, and regional diplomatic entities with the IronWind implant.",
      "tags": [
        "detection-engineering",
        "research",
        "ta402",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:unc1860",
      "title": "UNC1860",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/unc1860/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Repository Navigation",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence",
        "unc1860"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:unc3890",
      "title": "UNC3890",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/unc3890/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "UNC3890 is an Iran-linked cluster targeting Israeli shipping, aviation, healthcare, and government organizations via watering hole attacks and credential harvesting, documented by Mandiant in 2022.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence",
        "unc3890"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:wirte",
      "title": "WIRTE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/wirte/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "WIRTE is a Hamas-affiliated threat actor that evolved from espionage to destructive operations, deploying the SameCoin wiper against Israeli financial institutions and hospitals in 2024.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence",
        "wirte"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:connected-tips",
      "title": "Connected TIPs And CTI Feeds",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/connected-tips/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This framework now has a feed-intake layer for open-source/free CTI updates.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:customer-environment-use",
      "title": "Customer Environment Use",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/customer-environment-use/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page explains how to use the repository in a real SOC or consulting",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:backend-conversion-results",
      "title": "Backend Conversion Results",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/backend-conversion-results/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Sigma conversion was run locally with temporary sigma-cli backends for Splunk",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:detection-lifecycle",
      "title": "Detection Lifecycle",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/detection-lifecycle/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Detection engineering in this repository uses CTI as input, but production deployment requires engineering evidence. This lifecycle aligns with the Field Manual Intelligence to Detection method and the Customer project delivery gates.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:detection-status-dashboard",
      "title": "Detection Status Dashboard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/detection-status-dashboard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Generated from examples/registers/detection-backlog.csv,",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:drl-evidence-packs",
      "title": "DRL Evidence Packs",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/drl-evidence-packs/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page summarizes the current detection-readiness evidence packs. The packs",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:platform-field-mapping",
      "title": "Platform Field Mapping",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/platform-field-mapping/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page defines the minimum field mapping needed before a hunt starter can be",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:platform-query-variants",
      "title": "Platform Query Variants",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/platform-query-variants/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page tracks platform-specific query status. The goal is to separate",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:quality-gates",
      "title": "Quality Gates",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/quality-gates/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Quality gates prevent weak CTI from becoming weak detections.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:replay-datasets",
      "title": "Replay Datasets",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/replay-datasets/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "The repository includes small synthetic, lab-realistic replay datasets under",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:sigma-validation-results",
      "title": "Sigma Validation Results",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/sigma-validation-results/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Sigma semantic validation was run locally with sigma-cli against all rules in",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:soc-handoff-packet",
      "title": "SOC Handoff Packet",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/soc-handoff-packet/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This packet models the handoff a detection engineer would give to a SOC lead for",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:soc-triage-playbooks",
      "title": "SOC Triage Playbooks",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/soc-triage-playbooks/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "These playbooks define first-response actions for the repository's highest-risk",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/ecosystem/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:fact-correlation",
      "title": "Cross-Project Fact Correlation",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/fact-correlation/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Purpose",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:intelligence-updates",
      "title": "Intelligence Update Queue",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/intelligence-updates/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page summarizes the latest no-key public CTI feed pull. It is a review queue, not an automatic source of truth.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:israel-government-threat-model",
      "title": "Israel Government Threat Model",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/israel-government-threat-model/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Protected Mission",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:known-limitations",
      "title": "Known Limitations",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/known-limitations/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This repository is a public defensive CTI-to-detection research project. It is",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:malware-tool-intelligence",
      "title": "Malware And Tool Intelligence",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/malware-tool-intelligence/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page turns the repository's malware and tooling references into an analyst navigation layer: actor, tool, behavior, hash/IOC status, source, and detection notes.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:artifact-contracts",
      "title": "Artifact Contracts",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/artifact-contracts/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Artifact contracts define the minimum fields required for reusable CTI, hunting, and detection-engineering outputs.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:operating-standard",
      "title": "CTI-To-Detection Operating Standard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/operating-standard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This repository is not only an actor encyclopedia. It is designed to support threat hunting and CTI-based detection engineering for Israeli government, public-sector, municipal, critical infrastructure, telecom, defense-adjacent, and supplier environments.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:scoring-models",
      "title": "Scoring Models",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/scoring-models/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This project uses separate scores for source quality, claim quality, analyst confidence, threat priority, and detection readiness. These scores MUST NOT be collapsed into one generic risk number.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:source-freshness",
      "title": "Source Freshness",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/source-freshness/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Source freshness keeps public CTI from silently aging into stale assumptions.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:navigation:actor-workbench",
      "title": "Actor Navigation Workbench",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/navigation/actor-workbench/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Use this page as the click-through hub from an actor to its structured TTPs, IOC reference locations, malware/tool references, mapped hunts, mapped detections, and evidence records.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:navigation:surface-capability-matrix",
      "title": "Surface And Capability Matrix",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/navigation/surface-capability-matrix/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Use this page when the starting point is not an actor name. Pick the exposed surface or defender capability, then route to the relevant actors, hunts, detections, and telemetry fields.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:navigation:ttp-detection-matrix",
      "title": "TTP To Detection Matrix",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/navigation/ttp-detection-matrix/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Use this page when the starting point is a technique. For mapping discipline, use the Field Manual ATT&CK as a Working Tool. Each technique links back to relevant actors, mapped repository detections, mapped hunts, and MITRE ATT&CK.",
      "tags": [
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports",
      "title": "Report Index",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Use data/sources.csv as the authoritative machine-readable source register.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:actor-deep-research-prompts",
      "title": "Actor Deep Research Prompts",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/actor-deep-research-prompts/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "These prompts are designed for LLM-assisted deep research with web search enabled. They are intended to refresh actor profiles, source registers, tool pages, ATT&CK mappings, hunting hypotheses, and detection backlog items without weakening evidence discipline.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:additional-research-gemeni",
      "title": "Cyber Threat Intelligence Dossier: Iranian and Hamas-Aligned Operations Targeting Israeli and Allied Ecosystems (2023-2026)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/additional-research-gemeni/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page is an imported research-intake artifact. Treat it as a lead-generation and validation queue, not as authoritative repository assessment. Claims below must be checked against primary public sources before they are promoted into actor pages, evidence records, source records, detection logic, or tool-intelligence rows.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:andrey-medium-articles",
      "title": "Andrey Pautov Medium Articles",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/andrey-medium-articles/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page tracks articles from medium.com/@1200km that are relevant to this repository. These are treated as authored CTI or methodology sources. For production blocking, incident attribution, or executive claims, analysts SHOULD trace back to the primary sources cited inside each article.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:apt35-oilrig-israel-deep-research",
      "title": "Executive Summary",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/apt35-oilrig-israel-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page is an imported deep-research artifact. Treat it as lead-generation material until claims, citations, URLs, hashes, and detection logic are validated against primary public sources and repository evidence standards.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:apt39-arid-viper-unc3890-cyber-toufan-deep-research",
      "title": "APT39 (Chafer / Remix Kitten)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/apt39-arid-viper-unc3890-cyber-toufan-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page is an imported deep-research artifact. Treat it as lead-generation material until claims, citations, URLs, hashes, and detection logic are validated against primary public sources and repository evidence standards.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:ci-validation-evidence",
      "title": "CI Validation Evidence",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/ci-validation-evidence/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page records public GitHub Actions evidence for repository validation and",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:defensive-cti-threats-to-israeli-public-sector",
      "title": "Defensive CTI Research on Threats to Israeli Government and Public-Sector Environments",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/defensive-cti-threats-to-israeli-public-sector/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Status: Research synthesis.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:israel-critical-infrastructure-escalation",
      "title": "Defensive Cyber Threat Intelligence Report: Israeli Critical Infrastructure and Geopolitical Escalation (2024-2026)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/israel-critical-infrastructure-escalation/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Status: Research intake and defensive synthesis.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:muddywater-deep-research",
      "title": "1. Executive Summary",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/muddywater-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page is an imported deep-research artifact. Treat it as lead-generation material until claims, citations, URLs, hashes, and detection logic are validated against primary public sources and repository evidence standards.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:oilrig-magic-hound-deep-research",
      "title": "OilRig (APT34 / Helix Kitten / Earth Simnavaz etc)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/oilrig-magic-hound-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page is an imported deep-research artifact. Treat it as lead-generation material until claims, citations, URLs, hashes, and detection logic are validated against primary public sources and repository evidence standards.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:pioneer-kitten-deep-research",
      "title": "Pioneer Kitten (Fox Kitten, Lemon Sandstorm, UNC757) – Actor Deep Research",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/pioneer-kitten-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page is an imported deep-research artifact. Treat it as lead-generation material until claims, citations, URLs, hashes, and detection logic are validated against primary public sources and repository evidence standards.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:release-notes",
      "title": "Release Notes",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/release-notes/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page records repository maturity changes. It is intentionally explicit",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:research-intake-upgrade-summary",
      "title": "Research Intake Upgrade Summary",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/research-intake-upgrade-summary/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This page records how the newly imported deep-research reports were converted into practical repository improvements. It is intentionally conservative: imported LLM research is treated as an intake queue until every claim is validated against primary public reporting.",
      "tags": [
        "ai-security",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:resourses_research",
      "title": "Israel Government Threat Actors CTI: Evidentiary Foundation Intake",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/resourses_research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "TLPCLEAR.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:worked-cases",
      "title": "Worked Cases",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/worked-cases/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "These worked cases show how the repository expects analysts to move from public",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:source-rating",
      "title": "Source Rating",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/source-rating/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "The repository uses a six-level source reliability scale adapted from the NATO Admiralty Code (STANAG 2511). The full scale is defined in the Scoring Models page; this page provides quick-reference examples for the most common levels.",
      "tags": [
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:threat-hunting:hunt-workflow",
      "title": "Threat Hunting Workflow",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/threat-hunting/hunt-workflow/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "Threat hunts in this repository begin with a PIR and end with one of four outcomes:",
      "tags": [
        "detection-engineering",
        "research",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools",
      "title": "Malicious Tools Index",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This index links to one defensive page per malware family, implant, web shell, backdoor, wiper, or dual-use tool tracked in data/tool-intelligence.csv.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:antak-aspxspy",
      "title": "ANTAK / ASPXSPY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/antak-aspxspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:apostle",
      "title": "Apostle",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/apostle/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:aridspy",
      "title": "AridSpy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/aridspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ashtag",
      "title": "AshTag",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ashtag/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:aspxspy",
      "title": "ASPXSpy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/aspxspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bfg-agonizer",
      "title": "BFG Agonizer",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bfg-agonizer/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bibi-bibi-wiper-lineage",
      "title": "BiBi / BiBi Wiper lineage",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bibi-bibi-wiper-lineage/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bitsadmin",
      "title": "BITSAdmin",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bitsadmin/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:blackbeard",
      "title": "BlackBeard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/blackbeard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:blackshadow",
      "title": "BlackShadow",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/blackshadow/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bondupdater",
      "title": "BONDUPDATER",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bondupdater/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bugsleep",
      "title": "BugSleep",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bugsleep/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:cadelspy",
      "title": "Cadelspy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/cadelspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:caterpillar-webshell",
      "title": "Caterpillar WebShell",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/caterpillar-webshell/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:certutil",
      "title": "certutil",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/certutil/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:charmpower",
      "title": "CharmPower",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/charmpower/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:chimneysweep",
      "title": "CHIMNEYSWEEP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/chimneysweep/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:connectwise",
      "title": "ConnectWise",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/connectwise/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:crackmapexec",
      "title": "CrackMapExec",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/crackmapexec/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:cryptoslay",
      "title": "CRYPTOSLAY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/cryptoslay/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:cyber-toufan-supplier-access-playbook",
      "title": "Cyber Toufan supplier-access playbook",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/cyber-toufan-supplier-access-playbook/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:danbot",
      "title": "DanBot",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/danbot/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:darkbit-ransomware",
      "title": "DarkBit ransomware",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/darkbit-ransomware/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:dchspy",
      "title": "DCHSpy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/dchspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:deadwood",
      "title": "DEADWOOD",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/deadwood/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:desert-scorpion",
      "title": "Desert Scorpion",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/desert-scorpion/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:dindoor",
      "title": "Dindoor",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/dindoor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:dnssystem",
      "title": "DnsSystem",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/dnssystem/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:downpaper",
      "title": "DownPaper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/downpaper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:empire",
      "title": "Empire",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/empire/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:explosive-rat",
      "title": "Explosive RAT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/explosive-rat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:fakeset",
      "title": "Fakeset",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/fakeset/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:fooder-muddyviper",
      "title": "Fooder / MuddyViper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/fooder-muddyviper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:frozencell",
      "title": "FrozenCell",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/frozencell/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:frp-plink",
      "title": "FRP / Plink",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/frp-plink/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ftp",
      "title": "ftp",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ftp/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:handala-linked-destructive-installer-chains",
      "title": "Handala-linked destructive installer chains",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/handala-linked-destructive-installer-chains/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:helminth",
      "title": "Helminth",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/helminth/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:imaploader",
      "title": "IMAPLoader",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/imaploader/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:impacket",
      "title": "Impacket",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/impacket/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:iocontrol",
      "title": "IOControl",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/iocontrol/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ipconfig",
      "title": "ipconfig",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ipconfig/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ipsec-helper",
      "title": "IPsec Helper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ipsec-helper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ironwind",
      "title": "IronWind",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ironwind/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:isminjector",
      "title": "ISMInjector",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/isminjector/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:kevin",
      "title": "Kevin",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/kevin/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:koadic",
      "title": "Koadic",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/koadic/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:lazagne",
      "title": "LaZagne",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/lazagne/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:liontail",
      "title": "Liontail",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/liontail/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:lp-notes",
      "title": "LP-Notes",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/lp-notes/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mango",
      "title": "Mango",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mango/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mechaflounder",
      "title": "MechaFlounder",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mechaflounder/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:micropsia",
      "title": "Micropsia",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/micropsia/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:milan",
      "title": "Milan",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/milan/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mimikatz-sqlmap-havij",
      "title": "Mimikatz / SQLMap / Havij",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mimikatz-sqlmap-havij/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mimikatz",
      "title": "Mimikatz",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mimikatz/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:moneybird",
      "title": "Moneybird",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/moneybird/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mori",
      "title": "Mori",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mori/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:multilayer-wiper",
      "title": "MultiLayer Wiper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/multilayer-wiper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:nbtscan",
      "title": "NBTscan",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/nbtscan/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:net",
      "title": "Net",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/net/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:netsh",
      "title": "netsh",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/netsh/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:netstat",
      "title": "netstat",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/netstat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ngrok-ligolo",
      "title": "NGROK / Ligolo",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ngrok-ligolo/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ngrok",
      "title": "ngrok",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ngrok/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:nicecurl",
      "title": "NICECURL",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/nicecurl/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:odagent",
      "title": "ODAgent",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/odagent/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:oilbooster",
      "title": "OilBooster",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/oilbooster/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:oilcheck",
      "title": "OilCheck",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/oilcheck/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:oopsie",
      "title": "OopsIE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/oopsie/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:out1",
      "title": "Out1",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/out1/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:phenakite",
      "title": "Phenakite",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/phenakite/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ping",
      "title": "Ping",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ping/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:pipesnoop",
      "title": "PipeSnoop",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/pipesnoop/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:poshc2",
      "title": "PoshC2",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/poshc2/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerexchange",
      "title": "PowerExchange",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerexchange/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerless",
      "title": "PowerLess",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerless/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerpost",
      "title": "POWERPOST",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerpost/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powersploit",
      "title": "PowerSploit",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powersploit/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerstats",
      "title": "POWERSTATS",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerstats/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powgoop",
      "title": "PowGoop",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powgoop/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powruner",
      "title": "POWRUNER",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powruner/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:psexec",
      "title": "PsExec",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/psexec/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:pupy",
      "title": "Pupy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/pupy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:pwdump",
      "title": "pwdump",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/pwdump/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:quadagent",
      "title": "QUADAGENT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/quadagent/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rawdisk",
      "title": "RawDisk",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rawdisk/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rclone",
      "title": "Rclone",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rclone/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rdat",
      "title": "RDAT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rdat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:redalertapk",
      "title": "RedAlert.apk",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/redalertapk/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:reg",
      "title": "Reg",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/reg/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:remexi",
      "title": "Remexi",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/remexi/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:remote-monitoring-and-management-tools",
      "title": "Remote Monitoring and Management tools",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/remote-monitoring-and-management-tools/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:remoteutilities",
      "title": "RemoteUtilities",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/remoteutilities/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rgdoor",
      "title": "RGDoor",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rgdoor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:roadsweep",
      "title": "ROADSWEEP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/roadsweep/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rustywater",
      "title": "RustyWater",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rustywater/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:saitama",
      "title": "Saitama",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/saitama/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:samecoin",
      "title": "SameCoin",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/samecoin/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:samplecheck5000",
      "title": "SampleCheck5000",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/samplecheck5000/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sasheyaway",
      "title": "SASHEYAWAY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sasheyaway/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:seasharpee",
      "title": "SEASHARPEE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/seasharpee/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:shark",
      "title": "Shark",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/shark/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sharpstats",
      "title": "SHARPSTATS",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sharpstats/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sidetwist",
      "title": "SideTwist",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sidetwist/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:small-sieve",
      "title": "Small Sieve",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/small-sieve/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:solar",
      "title": "Solar",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/solar/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:spyc23",
      "title": "SpyC23",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/spyc23/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:standardkeyboard",
      "title": "StandardKeyboard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/standardkeyboard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:starwhale",
      "title": "STARWHALE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/starwhale/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:stayshante",
      "title": "STAYSHANTE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/stayshante/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sugarush-sugardump",
      "title": "SUGARUSH / SUGARDUMP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sugarush-sugardump/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:systeminfo",
      "title": "Systeminfo",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/systeminfo/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:tamecat",
      "title": "TAMECAT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/tamecat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:tasklist",
      "title": "Tasklist",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/tasklist/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templedoor",
      "title": "TEMPLEDOOR",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templedoor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templedrop",
      "title": "TEMPLEDROP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templedrop/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templelock",
      "title": "TEMPLELOCK",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templelock/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templeplay",
      "title": "TEMPLEPLAY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templeplay/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:tsundere-botnet",
      "title": "Tsundere Botnet",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/tsundere-botnet/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:unitronics-vision-plc-webhmi",
      "title": "Unitronics Vision PLC Web/HMI",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/unitronics-vision-plc-webhmi/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:virogreen",
      "title": "VIROGREEN",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/virogreen/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:wezrat",
      "title": "WezRat",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/wezrat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:windows-credential-editor",
      "title": "Windows Credential Editor",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/windows-credential-editor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:zerocleare",
      "title": "ZeroCleare",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/zerocleare/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "This is a defensive tool-intelligence page. It is intended for analyst navigation, source review, and hunt planning. It is not a malware-analysis report and does not contain sample code or binaries.",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:virustotal-enrichment",
      "title": "VirusTotal Malware Enrichment",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/virustotal-enrichment/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": null,
      "summary": "VirusTotal is connected as an optional enrichment source for reviewed malware and",
      "tags": [
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr",
      "title": "ITDR",
      "primary_type": "research",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR. Protocols, attack techniques, detection engineering, and simulations for identity-centric security.",
      "tags": [
        "detection-engineering",
        "identity-security",
        "mitre-attack",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:acl-abuse",
      "title": "Acl Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/acl-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Acl Abuse. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/acl-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:adminsdholder-abuse",
      "title": "AdminSDHolder Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/adminsdholder-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AdminSDHolder Abuse. AdminSDHolder persistence — backdoor ACLs on the AdminSDHolder template propagate to all protected groups via SDProp.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/adminsdholder-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:asrep-roasting",
      "title": "AS-REP Roasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/asrep-roasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AS-REP Roasting. AS-REP Roasting — targeting accounts with pre-authentication disabled to obtain crackable TGT material.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/asrep-roasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:constrained-delegation",
      "title": "Constrained Delegation Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/constrained-delegation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Constrained Delegation Abuse. Constrained Kerberos delegation abuse — S4U2Self + S4U2Proxy to impersonate any user to specific…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/constrained-delegation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:dcshadow",
      "title": "DCShadow",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/dcshadow/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "DCShadow. DCShadow — rogue domain controller injection to push malicious AD changes without generating standard event logs.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/dcshadow/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:dcsync",
      "title": "Dcsync",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/dcsync/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Dcsync. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/dcsync/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:golden-ticket",
      "title": "Golden Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/golden-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Golden Ticket. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/golden-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:kerberoasting",
      "title": "Kerberoasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/kerberoasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kerberoasting. Kerberoasting — requesting Kerberos service tickets for SPN accounts and cracking them offline.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/kerberoasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:pass-the-hash",
      "title": "Pass-the-Hash (PtH)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-hash/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Pass-the-Hash (PtH). Pass-the-Hash — authenticating with an NTLM hash instead of a plaintext password.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-hash/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:pass-the-ticket",
      "title": "Pass The Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Pass The Ticket. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:rbcd",
      "title": "Resource-Based Constrained Delegation (RBCD) Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/rbcd/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Resource-Based Constrained Delegation (RBCD) Abuse. RBCD abuse — write…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/rbcd/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:sid-history-abuse",
      "title": "Sid History Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/sid-history-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Sid History Abuse. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/sid-history-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:silver-ticket",
      "title": "Silver Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/silver-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Silver Ticket. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/silver-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:skeleton-key",
      "title": "Skeleton Key",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/skeleton-key/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Skeleton Key. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/skeleton-key/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:unconstrained-delegation",
      "title": "Unconstrained Delegation Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/unconstrained-delegation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Unconstrained Delegation Abuse. Unconstrained Kerberos delegation — a service can impersonate any user to any service…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/unconstrained-delegation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:adcs-certificates:certificate-theft",
      "title": "Certificate Theft",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/certificate-theft/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Certificate Theft. Stealing certificates and private keys from Windows certificate stores, disk, and memory.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/certificate-theft/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:adcs-certificates:esc1-template-abuse",
      "title": "ESC1 — Certificate Template Privilege Escalation",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc1-template-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ESC1 — Certificate Template Privilege Escalation. ESC1 — abusing misconfigured ADCS templates to request…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc1-template-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:adcs-certificates:esc4-esc8",
      "title": "ESC4–ESC8 — CA-Level and ACL Attacks",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc4-esc8/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ESC4–ESC8 — CA-Level and ACL Attacks. ADCS ESC4 (template ACL), ESC6 (CA flag), ESC7 (CA ACL), ESC8 (NTLM relay to CA).",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc4-esc8/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:cross-platform:credential-stuffing",
      "title": "Credential Stuffing",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/cross-platform/credential-stuffing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Credential Stuffing. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/cross-platform/credential-stuffing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:cross-platform:hybrid-attack-chains",
      "title": "Hybrid Attack Chains",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/cross-platform/hybrid-attack-chains/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Hybrid Attack Chains. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/cross-platform/hybrid-attack-chains/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:cross-platform:mfa-bypass-techniques",
      "title": "Mfa Bypass Techniques",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/cross-platform/mfa-bypass-techniques/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Mfa Bypass Techniques. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/cross-platform/mfa-bypass-techniques/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:aitm-phishing",
      "title": "AiTM Phishing (Adversary-in-the-Middle)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/aitm-phishing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AiTM Phishing (Adversary-in-the-Middle). AiTM reverse-proxy phishing bypasses MFA by relaying credentials and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/aitm-phishing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:conditional-access-bypass",
      "title": "Conditional Access Bypass",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/conditional-access-bypass/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Conditional Access Bypass. Techniques for bypassing Entra ID Conditional Access policies — legacy auth, CAP gaps, device compliance…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/conditional-access-bypass/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:device-code-phishing",
      "title": "Device Code Phishing",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/device-code-phishing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Device Code Phishing. OAuth2 Device Authorization Grant abused to steal tokens — no credentials captured, no MFA bypass needed.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/device-code-phishing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:golden-saml",
      "title": "Golden SAML",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/golden-saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Golden SAML. Golden SAML — forging SAML assertions using a stolen IdP signing key to authenticate as any user.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/golden-saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:illicit-consent-grant",
      "title": "Illicit Consent Grant",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/illicit-consent-grant/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Illicit Consent Grant. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/illicit-consent-grant/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:managed-identity-abuse",
      "title": "Managed Identity Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/managed-identity-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Managed Identity Abuse. Azure managed identity abuse — IMDS token theft from compromised VMs, containers, and serverless workloads.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/managed-identity-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:mfa-fatigue",
      "title": "Mfa Fatigue",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/mfa-fatigue/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Mfa Fatigue. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/mfa-fatigue/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:oauth-token-theft",
      "title": "Oauth Token Theft",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/oauth-token-theft/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Oauth Token Theft. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/oauth-token-theft/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:pass-the-prt",
      "title": "Pass The Prt",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/pass-the-prt/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Pass The Prt. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/pass-the-prt/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:scim-abuse",
      "title": "SCIM Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/scim-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SCIM Abuse. SCIM provisioning token theft and abuse — unauthorized user provisioning, group manipulation, and account takeover via SCIM API.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/scim-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:service-principal-abuse",
      "title": "Service Principal Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/service-principal-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Service Principal Abuse. Service principal and app registration abuse in Entra ID — credential theft, over-privileged SPs, and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/service-principal-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:api-token-abuse",
      "title": "API Token Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/api-token-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "API Token Abuse. API token theft and abuse in SaaS platforms — GitHub PATs, Slack tokens, Salesforce API keys, and CI/CD secrets.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/api-token-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:oauth-app-abuse",
      "title": "OAuth App Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/oauth-app-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OAuth App Abuse. OAuth application abuse — malicious app consent, over-privileged third-party apps, and persistent access without credentials.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/oauth-app-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:session-hijacking",
      "title": "Session Hijacking",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/session-hijacking/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Session Hijacking. Web session cookie theft and hijacking for SaaS applications — infostealer malware, XSS, and cookie replay.",
      "tags": [
        "documentation",
        "identity-security",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/session-hijacking/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:shadow-admin",
      "title": "Shadow Admin",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/shadow-admin/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Shadow Admin. Shadow admins in SaaS — accounts with administrative capabilities through indirect role paths, bypassing formal admin lists.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/shadow-admin/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-acl-abuse",
      "title": "Detecting Acl Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-acl-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Acl Abuse. Scaffold — detection rules for Acl Abuse.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-acl-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-asrep-roasting",
      "title": "Detecting Asrep Roasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-asrep-roasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Asrep Roasting. Scaffold — detection rules for Asrep Roasting.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-asrep-roasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-dcsync",
      "title": "Detecting Dcsync",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-dcsync/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Dcsync. Scaffold — detection rules for Dcsync.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-dcsync/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-golden-ticket",
      "title": "Detecting Golden Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-golden-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Golden Ticket. Scaffold — detection rules for Golden Ticket.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-golden-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-kerberoasting",
      "title": "Detecting Kerberoasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-kerberoasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Kerberoasting. Detection rules for Kerberoasting — Event 4769, RC4 ticket requests, bulk SPN queries.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-kerberoasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-pass-the-hash",
      "title": "Detecting Pass The Hash",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-hash/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Pass The Hash. Scaffold — detection rules for Pass The Hash.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-hash/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-pass-the-ticket",
      "title": "Detecting Pass The Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Pass The Ticket. Scaffold — detection rules for Pass The Ticket.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:adcs-detection:detect-certificate-attacks",
      "title": "Detecting ADCS / Certificate Attacks",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/adcs-detection/detect-certificate-attacks/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting ADCS / Certificate Attacks. Detection rules for ESC1, certificate enrollment abuse, and certificate-based…",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/adcs-detection/detect-certificate-attacks/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-device-code-phishing",
      "title": "Detecting Device Code Phishing",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-device-code-phishing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Device Code Phishing. Scaffold — detection rules for Device Code Phishing in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-device-code-phishing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-golden-saml",
      "title": "Detecting Golden Saml",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-golden-saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Golden Saml. Scaffold — detection rules for Golden Saml in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-golden-saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-mfa-fatigue",
      "title": "Detecting Mfa Fatigue",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-mfa-fatigue/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Mfa Fatigue. Scaffold — detection rules for Mfa Fatigue in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-mfa-fatigue/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-oauth-abuse",
      "title": "Detecting Oauth Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-oauth-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Oauth Abuse. Scaffold — detection rules for Oauth Abuse in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-oauth-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:detection-framework",
      "title": "Detection Framework",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/detection-framework/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detection Framework. ITDR detection engineering framework — telemetry requirements, DRL levels, rule structure, and validation methodology.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/detection-framework/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:identity-as-perimeter",
      "title": "Identity as the New Perimeter",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/identity-as-perimeter/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity as the New Perimeter. Why identity replaced the network perimeter as the primary security boundary, and what this…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/identity-as-perimeter/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:identity-attack-surface",
      "title": "Identity Attack Surface",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/identity-attack-surface/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity Attack Surface. Taxonomy of the identity attack surface across on-premises, cloud, and hybrid environments — credential…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/identity-attack-surface/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:identity-frameworks",
      "title": "Identity Frameworks & Standards",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/identity-frameworks/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity Frameworks & Standards. Key frameworks for identity security — NIST IAM, MITRE ATT&CK, CIS Controls, and how they…",
      "tags": [
        "documentation",
        "identity-security",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/identity-frameworks/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:what-is-identity",
      "title": "What is Identity?",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/what-is-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "What is Identity?. Core identity concepts — principals, authentication, authorization, credentials, and the identity lifecycle.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/what-is-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:what-is-itdr",
      "title": "What is ITDR?",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/what-is-itdr/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "What is ITDR?. Identity Threat Detection and Response — definition, scope, lifecycle, and how it differs from SIEM/EDR.",
      "tags": [
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/what-is-itdr/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:iga:iga-overview",
      "title": "Identity Governance & Administration (IGA)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/iga/iga-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity Governance & Administration (IGA). IGA discipline and vendors — SailPoint, Saviynt, Omada, One Identity —…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/iga/iga-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:intro",
      "title": "ITDR — Identity Threat Detection & Response",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/intro/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR — Identity Threat Detection & Response. Overview of the ITDR handbook — what it covers, how to use it, and…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/intro/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:itdr-vendors:itdr-vendor-landscape",
      "title": "ITDR Vendor Landscape",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/itdr-vendors/itdr-vendor-landscape/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR Vendor Landscape. Major ITDR vendors — Palo Alto Networks, CrowdStrike, Microsoft, Silverfort, Semperis, Permiso, Veza, Astrix…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/itdr-vendors/itdr-vendor-landscape/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:labs:lab-ad-setup",
      "title": "Active Directory Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-ad-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory Lab Setup. Build an AD lab with Domain Controller, workstation, ADCS, vulnerable configurations, and logging.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-ad-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-architecture",
      "title": "Lab Architecture",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-architecture/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Lab Architecture. ITDR lab environment design — topology, components, tooling, and what each lab enables.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-architecture/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-entra-setup",
      "title": "Entra ID Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-entra-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra ID Lab Setup. Set up an Entra ID lab tenant for cloud identity attack simulation — OAuth, device code, Golden SAML.",
      "tags": [
        "cloud-security",
        "identity-security",
        "lab",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-entra-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-linux-setup",
      "title": "Linux Identity Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-linux-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux Identity Lab Setup. Set up a Linux lab with AD integration via SSSD, PAM, Kerberos, and sudo for identity attack practice.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-linux-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-okta-setup",
      "title": "Okta Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-okta-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta Lab Setup. Set up an Okta developer org for MFA fatigue and admin console attack simulation.",
      "tags": [
        "identity-security",
        "lab",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-okta-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:mfa:mfa-technologies",
      "title": "MFA Technologies",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/mfa/mfa-technologies/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "MFA Technologies. Complete MFA taxonomy — TOTP, HOTP, push MFA, smart cards, FIDO2, passkeys, biometrics, SMS, email OTP — with phishing…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/mfa/mfa-technologies/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:pam:pam-overview",
      "title": "Privileged Access Management (PAM)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/pam/pam-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Privileged Access Management (PAM). PAM discipline and vendors — CyberArk, BeyondTrust, Delinea, One Identity, Wallix —…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/pam/pam-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ad-overview",
      "title": "Active Directory — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory — Overview. Active Directory DS architecture, domains, forests, trusts, and security boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ad-trusts",
      "title": "Active Directory Trusts",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-trusts/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory Trusts. AD trust types, transitivity, SID filtering, and trust-based attack paths.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-trusts/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:adcs",
      "title": "Active Directory Certificate Services (ADCS)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/adcs/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory Certificate Services (ADCS). ADCS architecture, certificate templates, enrollment permissions…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/adcs/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:group-policy",
      "title": "Group Policy",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/group-policy/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Group Policy. Group Policy Objects — structure, application order, security settings, and how attackers abuse GPO for persistence and lateral…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/group-policy/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:kerberos",
      "title": "Kerberos Protocol",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/kerberos/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kerberos Protocol. Kerberos v5 internals — AS, TGS, ticket structure, encryption types, and delegation models.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/kerberos/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ldap",
      "title": "LDAP in Active Directory",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ldap/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "LDAP in Active Directory. LDAP protocol in AD — queries, ACLs, anonymous bind, LDAPS, and how attackers use LDAP for enumeration and…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ldap/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ntlm",
      "title": "NTLM Authentication",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ntlm/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "NTLM Authentication. NTLM challenge-response internals, NTLMv1 vs NTLMv2, relay attacks, and why NTLM persists in modern environments.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ntlm/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:spnego-gssapi",
      "title": "SPNEGO & GSSAPI",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/spnego-gssapi/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SPNEGO & GSSAPI. SPNEGO auth negotiation and GSSAPI security API — how Windows chooses Kerberos vs NTLM, and the attack implications.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/spnego-gssapi/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:aws-cognito",
      "title": "AWS Cognito",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-cognito/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS Cognito. AWS Cognito — User Pools, Identity Pools, and security considerations.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-cognito/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:aws-iam-overview",
      "title": "AWS IAM — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-iam-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS IAM — Overview. AWS IAM — principals, policies, roles, permission boundaries, and the IAM attack surface.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-iam-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:aws-sts",
      "title": "AWS Security Token Service (STS)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-sts/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS Security Token Service (STS). STS AssumeRole flows, cross-account access, IMDS token theft, and role chaining attacks.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-sts/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:iam-identity-center",
      "title": "AWS IAM Identity Center",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/iam-identity-center/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS IAM Identity Center. AWS IAM Identity Center (SSO) — permission sets, account assignment, federated IdP integration, and attack…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/iam-identity-center/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:auth0",
      "title": "Auth0 (Okta Customer Identity Cloud)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/auth0/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Auth0 (Okta Customer Identity Cloud). Auth0 / Okta Customer Identity Cloud — CIAM platform, tenant architecture, and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/auth0/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:duo-security",
      "title": "Duo Security (Cisco)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/duo-security/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Duo Security (Cisco). Duo Security — MFA and zero-trust access platform, authentication proxy, and integration patterns.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/duo-security/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:jumpcloud",
      "title": "JumpCloud",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/jumpcloud/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "JumpCloud. JumpCloud — cloud directory service replacing AD, SSO, device management, and security considerations.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/jumpcloud/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:onelogin",
      "title": "OneLogin",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/onelogin/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OneLogin. OneLogin — cloud IdP, SSO, MFA, and Trusted Experience Platform.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/onelogin/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:ping-identity",
      "title": "Ping Identity",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/ping-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Ping Identity. Ping Identity — PingOne, PingFederate, PingAccess, and the Ping Identity platform.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/ping-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:conditional-access",
      "title": "Conditional Access",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/conditional-access/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Conditional Access. Entra ID Conditional Access — signals, policy structure, grant controls, and bypass techniques.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/conditional-access/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:entra-connect-sync",
      "title": "Entra Connect Sync (AD Connect)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-connect-sync/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra Connect Sync (AD Connect). Entra Connect Sync — sync modes, architecture, the sync account's dangerous privileges, and…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-connect-sync/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:entra-overview",
      "title": "Entra ID (Azure AD) — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra ID (Azure AD) — Overview. Microsoft Entra ID architecture — tenants, directory objects, authentication protocols, and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:identity-protection",
      "title": "Entra ID Identity Protection",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/identity-protection/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra ID Identity Protection. Entra ID Identity Protection — risk detection types, risk levels, risk-based Conditional Access…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/identity-protection/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:oauth2",
      "title": "OAuth 2.0",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/oauth2/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OAuth 2.0. OAuth 2.0 grant types, token types, scopes, and how each flow is abused in identity attacks.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/oauth2/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:oidc",
      "title": "OpenID Connect (OIDC)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/oidc/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OpenID Connect (OIDC). OpenID Connect — ID tokens, claims, discovery, and how OIDC federation is abused.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/oidc/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:pim",
      "title": "Privileged Identity Management (PIM)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/pim/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Privileged Identity Management (PIM). Entra ID PIM — JIT privilege, approval workflows, and how PIM is bypassed or abused.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/pim/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:saml",
      "title": "SAML 2.0",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SAML 2.0. SAML 2.0 protocol — SP/IdP roles, assertion structure, bindings, and Golden SAML attack surface.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:ws-federation",
      "title": "WS-Federation",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/ws-federation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "WS-Federation. WS-Federation protocol — passive requestor profile, STS tokens, and how it relates to SAML and modern federation.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/ws-federation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:gcp-iam",
      "title": "Google Cloud IAM",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/gcp-iam/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Google Cloud IAM. Google Cloud IAM — principals, roles, policy bindings, service accounts, and the GCP attack surface.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/gcp-iam/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:gws-overview",
      "title": "Google Workspace — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Google Workspace — Overview. Google Workspace identity architecture — Cloud Identity, Admin SDK, OAuth2 scopes, and Super Admin…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:gws-saml-oidc",
      "title": "Google Workspace SAML & OIDC",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-saml-oidc/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Google Workspace SAML & OIDC. Google Workspace as IdP (SAML) and as SP (third-party IdP federation), and OIDC for GCP/API access.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-saml-oidc/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:workload-identity-federation",
      "title": "Workload Identity Federation",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/workload-identity-federation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Workload Identity Federation. Google Workload Identity Federation and Workforce Identity Federation — federated access without…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/workload-identity-federation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:kubernetes:k8s-rbac",
      "title": "Kubernetes RBAC",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-rbac/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kubernetes RBAC. Kubernetes RBAC — roles, bindings, cluster-admin escalation paths, and audit logging.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-rbac/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:kubernetes:k8s-service-accounts",
      "title": "Kubernetes Service Accounts",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-service-accounts/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kubernetes Service Accounts. Kubernetes service accounts — token mounting, OIDC federation, projected volumes, and the attack…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-service-accounts/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:kubernetes:spiffe-spire",
      "title": "SPIFFE & SPIRE",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/kubernetes/spiffe-spire/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SPIFFE & SPIRE. SPIFFE workload identity standard and SPIRE implementation — SVIDs, trust bundles, and zero-trust workload auth.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/kubernetes/spiffe-spire/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-kerberos",
      "title": "Kerberos on Linux",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-kerberos/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kerberos on Linux. Kerberos credential caches on Linux, ccache theft, and keytab abuse.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-kerberos/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-pam",
      "title": "Linux PAM",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-pam/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux PAM. Pluggable Authentication Modules — stack structure, modules, and security configuration.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-pam/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-sssd",
      "title": "Linux SSSD",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sssd/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux SSSD. SSSD — connecting Linux to Active Directory, Kerberos authentication, and group policy via realm.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sssd/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-sudo",
      "title": "Linux sudo & Privilege",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sudo/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux sudo & Privilege. sudo configuration, sudoers file, common misconfigurations, and privilege escalation via sudo.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sudo/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:network-auth:radius",
      "title": "RADIUS",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/network-auth/radius/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "RADIUS. RADIUS protocol — authentication, authorization, accounting, and how it is used for network access control.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/network-auth/radius/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:network-auth:tacacs-plus",
      "title": "TACACS+",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/network-auth/tacacs-plus/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "TACACS+. TACACS+ vs RADIUS, use for network device authentication, and command authorization.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/network-auth/tacacs-plus/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-mfa",
      "title": "Okta MFA",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-mfa/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta MFA. Okta MFA factors, authenticator types, enrollment policies, and push bombing attack surface.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-mfa/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-overview",
      "title": "Okta — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta — Overview. Okta architecture, org types, identity protocols supported, and key security features.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-policies",
      "title": "Okta Policies & Network Zones",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-policies/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta Policies & Network Zones. Okta sign-on, MFA, and password policies — structure, precedence, and security gaps.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-policies/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-scim",
      "title": "Okta SCIM Provisioning",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-scim/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta SCIM Provisioning. SCIM 2.0 protocol in Okta — provisioning flows, attribute mapping, and security considerations.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-scim/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:open-source-directories:389ds",
      "title": "389 Directory Server",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/open-source-directories/389ds/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "389 Directory Server. 389 Directory Server — the LDAP engine behind FreeIPA and Red Hat Directory Server.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/open-source-directories/389ds/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:open-source-directories:freeipa",
      "title": "FreeIPA",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/open-source-directories/freeipa/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "FreeIPA. FreeIPA — integrated Linux identity management (LDAP + Kerberos + DNS + CA) and its attack surface.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/open-source-directories/freeipa/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:open-source-directories:openldap",
      "title": "OpenLDAP",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/open-source-directories/openldap/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OpenLDAP. OpenLDAP — architecture, schema, replication, security configuration, and attack surface.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/open-source-directories/openldap/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:fido2-webauthn",
      "title": "FIDO2 & WebAuthn",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/fido2-webauthn/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "FIDO2 & WebAuthn. FIDO2 and WebAuthn — passwordless authentication, phishing resistance, authenticator types, and enterprise deployment.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/fido2-webauthn/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:passkeys",
      "title": "Passkeys",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/passkeys/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Passkeys. Passkeys — synced FIDO2 credentials, platform implementations, enterprise considerations, and security model.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/passkeys/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:pki-overview",
      "title": "PKI Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/pki-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "PKI Overview. Public Key Infrastructure — CAs, trust chains, certificate lifecycle, and PKI in enterprise identity.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/pki-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:smart-cards",
      "title": "Smart Cards & Hardware Tokens",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/smart-cards/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Smart Cards & Hardware Tokens. Smart card authentication, PIV standard, YubiKey, FIDO2, and the limits of hardware-based…",
      "tags": [
        "documentation",
        "embedded-security",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/smart-cards/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:x509-certificates",
      "title": "X.509 Certificates",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/x509-certificates/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "X.509 Certificates. X.509 certificate structure, encoding formats, validation, and common certificate attack paths.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/x509-certificates/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:roadmap",
      "title": "ITDR Professional Roadmap",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/roadmap/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR Professional Roadmap. Complete learning path from identity fundamentals to professional-level ITDR — protocols, attack…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/roadmap/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:saas-platforms:github-identity",
      "title": "GitHub Identity Security",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/saas-platforms/github-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "GitHub Identity Security. GitHub identity attack surface — org admin compromise, PAT abuse, Actions secrets exfiltration, and supply…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/saas-platforms/github-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:saas-platforms:m365-identity",
      "title": "Microsoft 365 Identity",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/saas-platforms/m365-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Microsoft 365 Identity. M365 identity security — authentication, attack surface, and detection in Exchange, Teams, SharePoint, and the…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/saas-platforms/m365-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:certificate-escalation",
      "title": "Scenario: Certificate Escalation",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/certificate-escalation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Certificate Escalation. Scaffold — full attack-defense simulation for Certificate Escalation.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/certificate-escalation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:cloud-identity-takeover",
      "title": "Scenario: Cloud Identity Takeover",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/cloud-identity-takeover/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Cloud Identity Takeover. Scaffold — full attack-defense simulation for Cloud Identity Takeover.",
      "tags": [
        "cloud-security",
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/cloud-identity-takeover/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:domain-compromise-chain",
      "title": "Scenario: Domain Compromise Chain",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/domain-compromise-chain/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Domain Compromise Chain. Full AD compromise simulation — Kerberoasting → Pass-the-Hash → DCSync → Golden Ticket…",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/domain-compromise-chain/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:hybrid-golden-saml",
      "title": "Scenario: Hybrid Golden Saml",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/hybrid-golden-saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Hybrid Golden Saml. Scaffold — full attack-defense simulation for Hybrid Golden Saml.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/hybrid-golden-saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:simulation-framework",
      "title": "Attack–Defense Simulation Framework",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/simulation-framework/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Attack–Defense Simulation Framework. How ITDR simulations are structured — scenario format, lab prerequisites, attacker…",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/simulation-framework/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:labs.html",
      "title": "Lab Work",
      "primary_type": "index",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "lab-validated",
      "applies_to": "authorized security lab index",
      "canonical_url": "https://1200km.com/labs.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Security labs by Andrey Pautov: APT41 simulation, vulnerable AD and cloud infrastructure, Android malware analysis, Sliver C2, and…",
      "tags": [
        "cloud-security",
        "index",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/labs.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:newest-detection-engineering-techniques",
      "title": "Newest Detection Engineering Techniques",
      "primary_type": "mirror",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current detection-engineering research companion",
      "canonical_url": "https://1200km.com/newest-detection-engineering-techniques/",
      "published_at": "2026-07-11",
      "updated_at": "2026-07-11",
      "summary": "1200km ecosystem page for the Medium article Newest Detection Engineering…",
      "tags": [
        "detection-engineering",
        "research"
      ],
      "featured": true,
      "indexable": true,
      "source_url": "https://medium.com/@1200km/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://medium.com/@1200km/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:opencti-intelligent-shield",
      "title": "The Intelligent Shield — OpenCTI AI CTI Platform Guide",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "OpenCTI deployment and enrichment workflows",
      "canonical_url": "https://1200km.com/opencti-intelligent-shield/",
      "source_url": "https://github.com/anpa1200/opencti-intelligent-shield",
      "published_at": null,
      "updated_at": null,
      "summary": "Deploying AI-driven enrichment in OpenCTI with Claude and STIX 2.1.",
      "tags": [
        "ai-security",
        "guide",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:opencti-intelligent-shield",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/opencti-intelligent-shield",
      "original_publication": "https://github.com/anpa1200/opencti-intelligent-shield",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:opencti-intelligent-shield:docs:intelligent-shield",
      "title": "The Intelligent Shield: Building an AI-Powered CTI Platform with OpenCTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "OpenCTI deployment and enrichment workflows",
      "canonical_url": "https://1200km.com/opencti-intelligent-shield/docs/intelligent-shield/",
      "source_url": "https://github.com/anpa1200/opencti-intelligent-shield",
      "published_at": null,
      "updated_at": null,
      "summary": "Practical OpenCTI AI CTI platform guide covering STIX 2.1 deployment, feeds, Claude AI enrichment, ATT&CK mapping, security hardening, and investigation workflows.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:opencti-intelligent-shield",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/opencti-intelligent-shield",
      "original_publication": "https://github.com/anpa1200/opencti-intelligent-shield",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra",
      "title": "Operation Desert Hydra",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "AI-assisted CTI pipeline: MuddyWater public sources → OpenCTI → 11 detection records → 14 PASS / 1 PARTIAL / 1 FAIL across 16 rule checks → Kibana.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:for-defenders",
      "title": "What Defenders Should Do Right Now",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/for-defenders/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Defender-focused summary of Operation Desert Hydra: prioritized detection recommendations for organizations exposed to MuddyWater/Seedworm targeting Israeli infrastructure.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:intro",
      "title": "Why MuddyWater?",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/intro/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Operation Desert Hydra is a complete CTI-to-detection pipeline for MuddyWater/Seedworm — from source gathering and OpenCTI ingestion to KQL/Sigma rules validated in a live Kibana lab.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:limitations",
      "title": "Limitations",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/limitations/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Scope and limitations of Operation Desert Hydra: what the pipeline covers, where analyst judgment is required, and how to extend the methodology to other actors.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-1-source-gathering",
      "title": "Phase 1: Source Gathering",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-1-source-gathering/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Phase 1 of the Desert Hydra CTI pipeline: source selection, Admiralty reliability rating, and structured intake of MuddyWater/Seedworm public reporting.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-2-procedure-dataset",
      "title": "Phase 2: Procedure Dataset",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-2-procedure-dataset/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Phase 2: extracting and normalizing MuddyWater procedure-level ATT&CK technique data from rated sources into a structured dataset for detection development.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-3-opencti",
      "title": "Phase 3: OpenCTI Knowledge Graph",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-3-opencti/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Phase 3: importing the MuddyWater procedure dataset into OpenCTI as STIX 2.1 objects — structured threat intelligence ready for downstream detection and hunting.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-4-detection-atlas",
      "title": "Phase 4: Detection Atlas",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-4-detection-atlas/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Phase 4: translating MuddyWater ATT&CK techniques into telemetry requirements, hunting hypotheses, detection readiness levels, and Sigma/KQL rule candidates.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-5-results",
      "title": "Phase 5: Validation Results Summary",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-5-results/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Operation Desert Hydra validation results: 14 PASS / 1 PARTIAL / 1 FAIL against a live Kibana lab with Sysmon and Winlogbeat — full per-technique breakdown.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-5-validation-lab",
      "title": "Phase 5: Validation Lab",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-5-validation-lab/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "The Desert Hydra validation lab: Kibana, Elasticsearch, Sysmon, and Winlogbeat setup for end-to-end detection rule testing against MuddyWater/Seedworm TTPs.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-6-coverage-matrix",
      "title": "Phase 6: Coverage Matrix",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-6-coverage-matrix/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Phase 6 ATT&CK coverage matrix: all Desert Hydra detections mapped to MITRE technique IDs with detection readiness levels and validated/gap status.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:pipeline",
      "title": "The Pipeline",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/pipeline/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "The six-phase Operation Desert Hydra pipeline: source collection, procedure dataset, OpenCTI structuring, detection atlas, lab validation, and ATT&CK coverage matrix.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:production-scars",
      "title": "Production Scars",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/production-scars/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "Lessons learned and production scars from the Desert Hydra CTI-to-detection pipeline — real problems encountered, how they were resolved, and what to watch for.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:operation-desert-hydra:docs:reproduce",
      "title": "Reproduce It Yourself",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/reproduce/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": null,
      "summary": "How to reproduce Operation Desert Hydra: prerequisites, environment setup, step-by-step execution guide, and expected outputs at each phase.",
      "tags": [
        "case-study",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:privacy.html",
      "title": "Privacy and Data Handling",
      "primary_type": "policy",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "1200km public-site data handling",
      "canonical_url": "https://1200km.com/privacy.html",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Privacy, analytics, local search, browser storage, and public-demo data-handling information for…",
      "tags": [
        "ai-security",
        "policy",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/privacy.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:projects.html",
      "title": "1200km projects, packages, research, and external submissions.",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current public project registry",
      "canonical_url": "https://1200km.com/projects.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Project inventory for the 1200km security research ecosystem: AdversaryGraph, MalwareGraph…",
      "tags": [
        "adversarygraph",
        "index",
        "malware-analysis"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/projects.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:pt-tools.html",
      "title": "PT Tools & Techniques",
      "primary_type": "index",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized penetration-testing tools",
      "canonical_url": "https://1200km.com/pt-tools.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Security assessment tools by Andrey Pautov: RTSP testing, password tooling, StratusAI, AuditAI, Nmap…",
      "tags": [
        "offensive-research",
        "security-research",
        "tool"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/pt-tools.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:search.html",
      "title": "Search 1200km research",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "1200km public content catalogue",
      "canonical_url": "https://1200km.com/search.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Search the complete 1200km security research ecosystem: AdversaryGraph, threat actors, ATT&CK techniques, CTI…",
      "tags": [
        "adversarygraph",
        "index",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/search.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix",
      "title": "Threat Matrix — AdversaryGraph Light",
      "primary_type": "tool",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph Light public web workspace; browser-only ATT&CK exploration with full-version module gates",
      "canonical_url": "https://1200km.com/threat-matrix/",
      "published_at": null,
      "updated_at": "2026-07-23",
      "summary": "Threat Matrix is the public light web version of AdversaryGraph: browser-only…",
      "tags": [
        "adversarygraph",
        "threat-intelligence",
        "tool"
      ],
      "featured": true,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/threat-matrix/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:threat-matrix:actors:g0001",
      "title": "Axiom",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0001/",
      "source_url": "https://attack.mitre.org/groups/G0001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Axiom actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0001",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0002",
      "title": "Moafee",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0002/",
      "source_url": "https://attack.mitre.org/groups/G0002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Moafee actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0002",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0003",
      "title": "Cleaver",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0003/",
      "source_url": "https://attack.mitre.org/groups/G0003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cleaver actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0003",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0004",
      "title": "Ke3chang",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0004/",
      "source_url": "https://attack.mitre.org/groups/G0004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ke3chang actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0004",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0005",
      "title": "APT12",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0005/",
      "source_url": "https://attack.mitre.org/groups/G0005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT12 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0005",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0006",
      "title": "APT1",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0006/",
      "source_url": "https://attack.mitre.org/groups/G0006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT1 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0006",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0007",
      "title": "APT28",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0007/",
      "source_url": "https://attack.mitre.org/groups/G0007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT28 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0007",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0008",
      "title": "Carbanak",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0008/",
      "source_url": "https://attack.mitre.org/groups/G0008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Carbanak actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0008",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0009",
      "title": "Deep Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0009/",
      "source_url": "https://attack.mitre.org/groups/G0009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Deep Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0009",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0010",
      "title": "Turla",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0010/",
      "source_url": "https://attack.mitre.org/groups/G0010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Turla actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0010",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0011",
      "title": "PittyTiger",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0011/",
      "source_url": "https://attack.mitre.org/groups/G0011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PittyTiger actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0011",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0012",
      "title": "Darkhotel",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0012/",
      "source_url": "https://attack.mitre.org/groups/G0012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Darkhotel actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0012",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0013",
      "title": "APT30",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0013/",
      "source_url": "https://attack.mitre.org/groups/G0013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT30 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0013",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0016",
      "title": "APT29",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0016/",
      "source_url": "https://attack.mitre.org/groups/G0016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT29 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0016",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0017",
      "title": "DragonOK",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0017/",
      "source_url": "https://attack.mitre.org/groups/G0017/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DragonOK actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "ai-security",
        "g0017",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0018",
      "title": "admin@338",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0018/",
      "source_url": "https://attack.mitre.org/groups/G0018/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "admin@338 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0018",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0019",
      "title": "Naikon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0019/",
      "source_url": "https://attack.mitre.org/groups/G0019/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Naikon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0019",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0019/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0020",
      "title": "Equation",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0020/",
      "source_url": "https://attack.mitre.org/groups/G0020/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Equation actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0020",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0020/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0021",
      "title": "Molerats",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0021/",
      "source_url": "https://attack.mitre.org/groups/G0021/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Molerats actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0021",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0021/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0022",
      "title": "APT3",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0022/",
      "source_url": "https://attack.mitre.org/groups/G0022/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT3 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0022",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0022/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0023",
      "title": "APT16",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0023/",
      "source_url": "https://attack.mitre.org/groups/G0023/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT16 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0023",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0023/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0024",
      "title": "Putter Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0024/",
      "source_url": "https://attack.mitre.org/groups/G0024/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Putter Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0024",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0024/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0025",
      "title": "APT17",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0025/",
      "source_url": "https://attack.mitre.org/groups/G0025/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT17 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0025",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0025/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0026",
      "title": "APT18",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0026/",
      "source_url": "https://attack.mitre.org/groups/G0026/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT18 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0026",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0026/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0027",
      "title": "Threat Group-3390",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0027/",
      "source_url": "https://attack.mitre.org/groups/G0027/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Threat Group-3390 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0027",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0027/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0028",
      "title": "Threat Group-1314",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0028/",
      "source_url": "https://attack.mitre.org/groups/G0028/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Threat Group-1314 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0028",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0028/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0029",
      "title": "Scarlet Mimic",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0029/",
      "source_url": "https://attack.mitre.org/groups/G0029/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scarlet Mimic actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0029",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0029/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0030",
      "title": "Lotus Blossom",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0030/",
      "source_url": "https://attack.mitre.org/groups/G0030/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lotus Blossom actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0030",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0030/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0032",
      "title": "Lazarus Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0032/",
      "source_url": "https://attack.mitre.org/groups/G0032/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lazarus Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0032",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0032/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0033",
      "title": "Poseidon Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0033/",
      "source_url": "https://attack.mitre.org/groups/G0033/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Poseidon Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0033",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0033/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0034",
      "title": "Sandworm Team",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0034/",
      "source_url": "https://attack.mitre.org/groups/G0034/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sandworm Team actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0034",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0034/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0035",
      "title": "Dragonfly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0035/",
      "source_url": "https://attack.mitre.org/groups/G0035/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dragonfly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "ai-security",
        "g0035",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0035/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0036",
      "title": "GCMAN",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0036/",
      "source_url": "https://attack.mitre.org/groups/G0036/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GCMAN actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0036",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0036/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0037",
      "title": "FIN6",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0037/",
      "source_url": "https://attack.mitre.org/groups/G0037/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN6 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0037",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0037/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0038",
      "title": "Stealth Falcon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0038/",
      "source_url": "https://attack.mitre.org/groups/G0038/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Stealth Falcon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0038",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0038/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0039",
      "title": "Suckfly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0039/",
      "source_url": "https://attack.mitre.org/groups/G0039/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Suckfly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0039",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0039/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0040",
      "title": "Patchwork",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0040/",
      "source_url": "https://attack.mitre.org/groups/G0040/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Patchwork actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0040",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0040/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0041",
      "title": "Strider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0041/",
      "source_url": "https://attack.mitre.org/groups/G0041/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Strider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0041",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0041/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0043",
      "title": "Group5",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0043/",
      "source_url": "https://attack.mitre.org/groups/G0043/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Group5 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0043",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0043/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0044",
      "title": "Winnti Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0044/",
      "source_url": "https://attack.mitre.org/groups/G0044/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Winnti Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0044",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0044/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0045",
      "title": "menuPass",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0045/",
      "source_url": "https://attack.mitre.org/groups/G0045/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "menuPass actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0045",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0045/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0046",
      "title": "FIN7",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0046/",
      "source_url": "https://attack.mitre.org/groups/G0046/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN7 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0046",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0046/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0047",
      "title": "Gamaredon Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0047/",
      "source_url": "https://attack.mitre.org/groups/G0047/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gamaredon Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0047",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0047/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0048",
      "title": "RTM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0048/",
      "source_url": "https://attack.mitre.org/groups/G0048/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "RTM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0048",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0048/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0049",
      "title": "OilRig",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0049/",
      "source_url": "https://attack.mitre.org/groups/G0049/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "OilRig actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0049",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0049/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0050",
      "title": "APT32",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0050/",
      "source_url": "https://attack.mitre.org/groups/G0050/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT32 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0050",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0050/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0051",
      "title": "FIN10",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0051/",
      "source_url": "https://attack.mitre.org/groups/G0051/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN10 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0051",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0051/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0052",
      "title": "CopyKittens",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0052/",
      "source_url": "https://attack.mitre.org/groups/G0052/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "CopyKittens actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0052",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0052/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0053",
      "title": "FIN5",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0053/",
      "source_url": "https://attack.mitre.org/groups/G0053/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN5 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0053",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0053/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0054",
      "title": "Sowbug",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0054/",
      "source_url": "https://attack.mitre.org/groups/G0054/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sowbug actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0054",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0054/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0055",
      "title": "NEODYMIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0055/",
      "source_url": "https://attack.mitre.org/groups/G0055/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "NEODYMIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0055",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0055/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0056",
      "title": "PROMETHIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0056/",
      "source_url": "https://attack.mitre.org/groups/G0056/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PROMETHIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0056",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0056/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0059",
      "title": "Magic Hound",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0059/",
      "source_url": "https://attack.mitre.org/groups/G0059/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Magic Hound actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0059",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0059/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0060",
      "title": "BRONZE BUTLER",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0060/",
      "source_url": "https://attack.mitre.org/groups/G0060/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BRONZE BUTLER actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0060",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0060/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0061",
      "title": "FIN8",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0061/",
      "source_url": "https://attack.mitre.org/groups/G0061/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN8 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0061",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0061/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0062",
      "title": "TA459",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0062/",
      "source_url": "https://attack.mitre.org/groups/G0062/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA459 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0062",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0062/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0063",
      "title": "BlackOasis",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0063/",
      "source_url": "https://attack.mitre.org/groups/G0063/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BlackOasis actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0063",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0063/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0064",
      "title": "APT33",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0064/",
      "source_url": "https://attack.mitre.org/groups/G0064/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT33 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0064",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0064/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0065",
      "title": "Leviathan",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0065/",
      "source_url": "https://attack.mitre.org/groups/G0065/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Leviathan actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0065",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0065/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0066",
      "title": "Elderwood",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0066/",
      "source_url": "https://attack.mitre.org/groups/G0066/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Elderwood actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0066",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0066/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0067",
      "title": "APT37",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0067/",
      "source_url": "https://attack.mitre.org/groups/G0067/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT37 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0067",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0067/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0068",
      "title": "PLATINUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0068/",
      "source_url": "https://attack.mitre.org/groups/G0068/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PLATINUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0068",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0068/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0069",
      "title": "MuddyWater",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0069/",
      "source_url": "https://attack.mitre.org/groups/G0069/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "MuddyWater actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0069",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0069/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0070",
      "title": "Dark Caracal",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0070/",
      "source_url": "https://attack.mitre.org/groups/G0070/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dark Caracal actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0070",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0070/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0071",
      "title": "Orangeworm",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0071/",
      "source_url": "https://attack.mitre.org/groups/G0071/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Orangeworm actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0071",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0071/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0073",
      "title": "APT19",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0073/",
      "source_url": "https://attack.mitre.org/groups/G0073/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT19 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0073",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0073/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0075",
      "title": "Rancor",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0075/",
      "source_url": "https://attack.mitre.org/groups/G0075/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rancor actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0075",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0075/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0076",
      "title": "Thrip",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0076/",
      "source_url": "https://attack.mitre.org/groups/G0076/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Thrip actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0076",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0076/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0077",
      "title": "Leafminer",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0077/",
      "source_url": "https://attack.mitre.org/groups/G0077/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Leafminer actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0077",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0077/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0078",
      "title": "Gorgon Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0078/",
      "source_url": "https://attack.mitre.org/groups/G0078/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gorgon Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0078",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0078/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0079",
      "title": "DarkHydrus",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0079/",
      "source_url": "https://attack.mitre.org/groups/G0079/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DarkHydrus actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0079",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0079/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0080",
      "title": "Cobalt Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0080/",
      "source_url": "https://attack.mitre.org/groups/G0080/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cobalt Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0080",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0080/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0081",
      "title": "Tropic Trooper",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0081/",
      "source_url": "https://attack.mitre.org/groups/G0081/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Tropic Trooper actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0081",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0081/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0082",
      "title": "APT38",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0082/",
      "source_url": "https://attack.mitre.org/groups/G0082/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT38 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0082",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0082/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0083",
      "title": "SilverTerrier",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0083/",
      "source_url": "https://attack.mitre.org/groups/G0083/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SilverTerrier actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0083",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0083/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0084",
      "title": "Gallmaker",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0084/",
      "source_url": "https://attack.mitre.org/groups/G0084/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gallmaker actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0084",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0084/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0085",
      "title": "FIN4",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0085/",
      "source_url": "https://attack.mitre.org/groups/G0085/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN4 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0085",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0085/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0087",
      "title": "APT39",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0087/",
      "source_url": "https://attack.mitre.org/groups/G0087/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT39 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0087",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0087/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0088",
      "title": "TEMP.Veles",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0088/",
      "source_url": "https://attack.mitre.org/groups/G0088/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TEMP.Veles actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0088",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0088/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0089",
      "title": "The White Company",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0089/",
      "source_url": "https://attack.mitre.org/groups/G0089/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "The White Company actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0089",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0089/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0090",
      "title": "WIRTE",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0090/",
      "source_url": "https://attack.mitre.org/groups/G0090/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "WIRTE actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0090",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0090/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0091",
      "title": "Silence",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0091/",
      "source_url": "https://attack.mitre.org/groups/G0091/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Silence actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0091",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0091/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0092",
      "title": "TA505",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0092/",
      "source_url": "https://attack.mitre.org/groups/G0092/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA505 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0092",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0092/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0093",
      "title": "GALLIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0093/",
      "source_url": "https://attack.mitre.org/groups/G0093/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GALLIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0093",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0093/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0094",
      "title": "Kimsuky",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0094/",
      "source_url": "https://attack.mitre.org/groups/G0094/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Kimsuky actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0094",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0094/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0095",
      "title": "Machete",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0095/",
      "source_url": "https://attack.mitre.org/groups/G0095/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Machete actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0095",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0095/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0096",
      "title": "APT41",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0096/",
      "source_url": "https://attack.mitre.org/groups/G0096/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT41 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0096",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0096/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0097",
      "title": "Bouncing Golf",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0097/",
      "source_url": "https://attack.mitre.org/groups/G0097/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bouncing Golf actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0097",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0097/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0098",
      "title": "BlackTech",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0098/",
      "source_url": "https://attack.mitre.org/groups/G0098/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BlackTech actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0098",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0098/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0099",
      "title": "APT-C-36",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0099/",
      "source_url": "https://attack.mitre.org/groups/G0099/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT-C-36 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0099",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0099/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0100",
      "title": "Inception",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0100/",
      "source_url": "https://attack.mitre.org/groups/G0100/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Inception actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0100",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0100/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0102",
      "title": "Wizard Spider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0102/",
      "source_url": "https://attack.mitre.org/groups/G0102/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Wizard Spider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0102",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0102/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0103",
      "title": "Mofang",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0103/",
      "source_url": "https://attack.mitre.org/groups/G0103/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mofang actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0103",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0103/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0105",
      "title": "DarkVishnya",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0105/",
      "source_url": "https://attack.mitre.org/groups/G0105/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DarkVishnya actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0105",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0105/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0106",
      "title": "Rocke",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0106/",
      "source_url": "https://attack.mitre.org/groups/G0106/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rocke actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0106",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0106/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0107",
      "title": "Whitefly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0107/",
      "source_url": "https://attack.mitre.org/groups/G0107/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Whitefly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0107",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0107/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0108",
      "title": "Blue Mockingbird",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0108/",
      "source_url": "https://attack.mitre.org/groups/G0108/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Blue Mockingbird actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0108",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0108/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0112",
      "title": "Windshift",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0112/",
      "source_url": "https://attack.mitre.org/groups/G0112/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windshift actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0112",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0112/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0114",
      "title": "Chimera",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0114/",
      "source_url": "https://attack.mitre.org/groups/G0114/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Chimera actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0114",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0114/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0115",
      "title": "GOLD SOUTHFIELD",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0115/",
      "source_url": "https://attack.mitre.org/groups/G0115/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GOLD SOUTHFIELD actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0115",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0115/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0117",
      "title": "Fox Kitten",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0117/",
      "source_url": "https://attack.mitre.org/groups/G0117/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Fox Kitten actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0117",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0117/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0119",
      "title": "Indrik Spider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0119/",
      "source_url": "https://attack.mitre.org/groups/G0119/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Indrik Spider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0119",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0119/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0120",
      "title": "Evilnum",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0120/",
      "source_url": "https://attack.mitre.org/groups/G0120/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Evilnum actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0120",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0120/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0121",
      "title": "Sidewinder",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0121/",
      "source_url": "https://attack.mitre.org/groups/G0121/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sidewinder actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0121",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0121/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0122",
      "title": "Silent Librarian",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0122/",
      "source_url": "https://attack.mitre.org/groups/G0122/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Silent Librarian actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0122",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0122/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0123",
      "title": "Volatile Cedar",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0123/",
      "source_url": "https://attack.mitre.org/groups/G0123/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Volatile Cedar actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0123",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0123/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0124",
      "title": "Windigo",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0124/",
      "source_url": "https://attack.mitre.org/groups/G0124/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windigo actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0124",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0124/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0125",
      "title": "HAFNIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0125/",
      "source_url": "https://attack.mitre.org/groups/G0125/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "HAFNIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0125",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0125/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0126",
      "title": "Higaisa",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0126/",
      "source_url": "https://attack.mitre.org/groups/G0126/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Higaisa actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0126",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0126/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0127",
      "title": "TA551",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0127/",
      "source_url": "https://attack.mitre.org/groups/G0127/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA551 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0127",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0127/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0128",
      "title": "ZIRCONIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0128/",
      "source_url": "https://attack.mitre.org/groups/G0128/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ZIRCONIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0128",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0128/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0129",
      "title": "Mustang Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0129/",
      "source_url": "https://attack.mitre.org/groups/G0129/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mustang Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0129",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0129/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0130",
      "title": "Ajax Security Team",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0130/",
      "source_url": "https://attack.mitre.org/groups/G0130/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ajax Security Team actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting…",
      "tags": [
        "g0130",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0130/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0131",
      "title": "Tonto Team",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0131/",
      "source_url": "https://attack.mitre.org/groups/G0131/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Tonto Team actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0131",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0131/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0133",
      "title": "Nomadic Octopus",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0133/",
      "source_url": "https://attack.mitre.org/groups/G0133/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Nomadic Octopus actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0133",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0133/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0134",
      "title": "Transparent Tribe",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0134/",
      "source_url": "https://attack.mitre.org/groups/G0134/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Transparent Tribe actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0134",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0134/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0135",
      "title": "BackdoorDiplomacy",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0135/",
      "source_url": "https://attack.mitre.org/groups/G0135/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BackdoorDiplomacy actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0135",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0135/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0136",
      "title": "IndigoZebra",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0136/",
      "source_url": "https://attack.mitre.org/groups/G0136/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "IndigoZebra actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0136",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0136/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0137",
      "title": "Ferocious Kitten",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0137/",
      "source_url": "https://attack.mitre.org/groups/G0137/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ferocious Kitten actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0137",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0137/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0138",
      "title": "Andariel",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0138/",
      "source_url": "https://attack.mitre.org/groups/G0138/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Andariel actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0138",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0138/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0139",
      "title": "TeamTNT",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0139/",
      "source_url": "https://attack.mitre.org/groups/G0139/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TeamTNT actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0139",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0139/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0140",
      "title": "LazyScripter",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0140/",
      "source_url": "https://attack.mitre.org/groups/G0140/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LazyScripter actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0140",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0140/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0142",
      "title": "Confucius",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0142/",
      "source_url": "https://attack.mitre.org/groups/G0142/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Confucius actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0142",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0142/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0143",
      "title": "Aquatic Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0143/",
      "source_url": "https://attack.mitre.org/groups/G0143/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Aquatic Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0143",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0143/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1001",
      "title": "HEXANE",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1001/",
      "source_url": "https://attack.mitre.org/groups/G1001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "HEXANE actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1001",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1002",
      "title": "BITTER",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1002/",
      "source_url": "https://attack.mitre.org/groups/G1002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BITTER actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1002",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1003",
      "title": "Ember Bear",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1003/",
      "source_url": "https://attack.mitre.org/groups/G1003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ember Bear actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1003",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1004",
      "title": "LAPSUS$",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1004/",
      "source_url": "https://attack.mitre.org/groups/G1004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LAPSUS$ actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1004",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1005",
      "title": "POLONIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1005/",
      "source_url": "https://attack.mitre.org/groups/G1005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "POLONIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1005",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1006",
      "title": "Earth Lusca",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1006/",
      "source_url": "https://attack.mitre.org/groups/G1006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Earth Lusca actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1006",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1007",
      "title": "Aoqin Dragon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1007/",
      "source_url": "https://attack.mitre.org/groups/G1007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Aoqin Dragon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "ai-security",
        "g1007",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1008",
      "title": "SideCopy",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1008/",
      "source_url": "https://attack.mitre.org/groups/G1008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SideCopy actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1008",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1009",
      "title": "Moses Staff",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1009/",
      "source_url": "https://attack.mitre.org/groups/G1009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Moses Staff actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1009",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1011",
      "title": "EXOTIC LILY",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1011/",
      "source_url": "https://attack.mitre.org/groups/G1011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "EXOTIC LILY actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1011",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1012",
      "title": "CURIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1012/",
      "source_url": "https://attack.mitre.org/groups/G1012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "CURIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1012",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1013",
      "title": "Metador",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1013/",
      "source_url": "https://attack.mitre.org/groups/G1013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Metador actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1013",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1014",
      "title": "LuminousMoth",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1014/",
      "source_url": "https://attack.mitre.org/groups/G1014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LuminousMoth actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1014",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1015",
      "title": "Scattered Spider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1015/",
      "source_url": "https://attack.mitre.org/groups/G1015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scattered Spider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1015",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1016",
      "title": "FIN13",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1016/",
      "source_url": "https://attack.mitre.org/groups/G1016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN13 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1016",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1017",
      "title": "Volt Typhoon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1017/",
      "source_url": "https://attack.mitre.org/groups/G1017/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Volt Typhoon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1017",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1018",
      "title": "TA2541",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1018/",
      "source_url": "https://attack.mitre.org/groups/G1018/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA2541 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1018",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1019",
      "title": "MoustachedBouncer",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1019/",
      "source_url": "https://attack.mitre.org/groups/G1019/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "MoustachedBouncer actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1019",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1019/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1020",
      "title": "Mustard Tempest",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1020/",
      "source_url": "https://attack.mitre.org/groups/G1020/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mustard Tempest actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1020",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1020/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1021",
      "title": "Cinnamon Tempest",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1021/",
      "source_url": "https://attack.mitre.org/groups/G1021/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cinnamon Tempest actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1021",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1021/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1022",
      "title": "ToddyCat",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1022/",
      "source_url": "https://attack.mitre.org/groups/G1022/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ToddyCat actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1022",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1022/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1023",
      "title": "APT5",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1023/",
      "source_url": "https://attack.mitre.org/groups/G1023/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT5 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1023",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1023/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1024",
      "title": "Akira",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1024/",
      "source_url": "https://attack.mitre.org/groups/G1024/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Akira actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1024",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1024/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1026",
      "title": "Malteiro",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1026/",
      "source_url": "https://attack.mitre.org/groups/G1026/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malteiro actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1026",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1026/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1028",
      "title": "APT-C-23",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1028/",
      "source_url": "https://attack.mitre.org/groups/G1028/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT-C-23 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1028",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1028/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1030",
      "title": "Agrius",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1030/",
      "source_url": "https://attack.mitre.org/groups/G1030/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Agrius actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1030",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1030/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1031",
      "title": "Saint Bear",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1031/",
      "source_url": "https://attack.mitre.org/groups/G1031/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Saint Bear actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1031",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1031/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1032",
      "title": "INC Ransom",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1032/",
      "source_url": "https://attack.mitre.org/groups/G1032/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "INC Ransom actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1032",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1032/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1033",
      "title": "Star Blizzard",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1033/",
      "source_url": "https://attack.mitre.org/groups/G1033/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Star Blizzard actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1033",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1033/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1034",
      "title": "Daggerfly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1034/",
      "source_url": "https://attack.mitre.org/groups/G1034/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Daggerfly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1034",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1034/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1035",
      "title": "Winter Vivern",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1035/",
      "source_url": "https://attack.mitre.org/groups/G1035/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Winter Vivern actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1035",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1035/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1036",
      "title": "Moonstone Sleet",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1036/",
      "source_url": "https://attack.mitre.org/groups/G1036/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Moonstone Sleet actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1036",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1036/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1037",
      "title": "TA577",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1037/",
      "source_url": "https://attack.mitre.org/groups/G1037/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA577 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1037",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1037/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1038",
      "title": "TA578",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1038/",
      "source_url": "https://attack.mitre.org/groups/G1038/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA578 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1038",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1038/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1039",
      "title": "RedCurl",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1039/",
      "source_url": "https://attack.mitre.org/groups/G1039/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "RedCurl actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1039",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1039/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1040",
      "title": "Play",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1040/",
      "source_url": "https://attack.mitre.org/groups/G1040/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Play actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1040",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1040/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1041",
      "title": "Sea Turtle",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1041/",
      "source_url": "https://attack.mitre.org/groups/G1041/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Sea Turtle (G1041): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1041",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1041/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1042",
      "title": "RedEcho",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1042/",
      "source_url": "https://attack.mitre.org/groups/G1042/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "RedEcho (G1042): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1042",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1042/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1043",
      "title": "BlackByte",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1043/",
      "source_url": "https://attack.mitre.org/groups/G1043/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "BlackByte (G1043): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1043",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1043/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1044",
      "title": "APT42",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1044/",
      "source_url": "https://attack.mitre.org/groups/G1044/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "APT42 (G1044): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1044",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1044/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1045",
      "title": "Salt Typhoon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1045/",
      "source_url": "https://attack.mitre.org/groups/G1045/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Salt Typhoon (G1045): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1045",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1045/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1046",
      "title": "Storm-1811",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1046/",
      "source_url": "https://attack.mitre.org/groups/G1046/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Storm-1811 (G1046): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1046",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1046/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1047",
      "title": "Velvet Ant",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1047/",
      "source_url": "https://attack.mitre.org/groups/G1047/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Velvet Ant (G1047): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1047",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1047/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1048",
      "title": "UNC3886",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1048/",
      "source_url": "https://attack.mitre.org/groups/G1048/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "UNC3886 (G1048): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1048",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1048/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1049",
      "title": "AppleJeus",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1049/",
      "source_url": "https://attack.mitre.org/groups/G1049/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "AppleJeus (G1049): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1049",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1049/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1050",
      "title": "Water Galura",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1050/",
      "source_url": "https://attack.mitre.org/groups/G1050/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Water Galura (G1050): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1050",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1050/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1051",
      "title": "Medusa Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1051/",
      "source_url": "https://attack.mitre.org/groups/G1051/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Medusa Group (G1051): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1051",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1051/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1052",
      "title": "Contagious Interview",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1052/",
      "source_url": "https://attack.mitre.org/groups/G1052/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Contagious Interview (G1052): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1052",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1052/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1053",
      "title": "Storm-0501",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1053/",
      "source_url": "https://attack.mitre.org/groups/G1053/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Storm-0501 (G1053): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1053",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1053/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1054",
      "title": "MirrorFace",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1054/",
      "source_url": "https://attack.mitre.org/groups/G1054/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "MirrorFace (G1054): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1054",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1054/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1055",
      "title": "VOID MANTICORE",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1055/",
      "source_url": "https://attack.mitre.org/groups/G1055/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "VOID MANTICORE (G1055): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1055",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1055/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001.001",
      "title": "Junk Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001.001/",
      "source_url": "https://attack.mitre.org/techniques/T1001/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1001.001 Junk Data: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001.002",
      "title": "Steganography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001.002/",
      "source_url": "https://attack.mitre.org/techniques/T1001/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1001.002 Steganography: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001.003",
      "title": "Protocol or Service Impersonation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001.003/",
      "source_url": "https://attack.mitre.org/techniques/T1001/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1001.003 Protocol or Service Impersonation: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001",
      "title": "Data Obfuscation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001/",
      "source_url": "https://attack.mitre.org/techniques/T1001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1001 Data Obfuscation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.001",
      "title": "LSASS Memory",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.001/",
      "source_url": "https://attack.mitre.org/techniques/T1003/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.001 LSASS Memory: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.002",
      "title": "Security Account Manager",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.002/",
      "source_url": "https://attack.mitre.org/techniques/T1003/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.002 Security Account Manager: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.003",
      "title": "NTDS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.003/",
      "source_url": "https://attack.mitre.org/techniques/T1003/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.003 NTDS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.004",
      "title": "LSA Secrets",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.004/",
      "source_url": "https://attack.mitre.org/techniques/T1003/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.004 LSA Secrets: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.005",
      "title": "Cached Domain Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.005/",
      "source_url": "https://attack.mitre.org/techniques/T1003/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.005 Cached Domain Credentials: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.006",
      "title": "DCSync",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.006/",
      "source_url": "https://attack.mitre.org/techniques/T1003/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.006 DCSync: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.007",
      "title": "Proc Filesystem",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.007/",
      "source_url": "https://attack.mitre.org/techniques/T1003/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.007 Proc Filesystem: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.008",
      "title": "/etc/passwd and /etc/shadow",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.008/",
      "source_url": "https://attack.mitre.org/techniques/T1003/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003.008 /etc/passwd and /etc/shadow: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003",
      "title": "OS Credential Dumping",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003/",
      "source_url": "https://attack.mitre.org/techniques/T1003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1003 OS Credential Dumping: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1005",
      "title": "Data from Local System",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1005/",
      "source_url": "https://attack.mitre.org/techniques/T1005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1005 Data from Local System: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1006",
      "title": "Direct Volume Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1006/",
      "source_url": "https://attack.mitre.org/techniques/T1006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1006 Direct Volume Access: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1007",
      "title": "System Service Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1007/",
      "source_url": "https://attack.mitre.org/techniques/T1007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1007 System Service Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1008",
      "title": "Fallback Channels",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1008/",
      "source_url": "https://attack.mitre.org/techniques/T1008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1008 Fallback Channels: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1010",
      "title": "Application Window Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1010/",
      "source_url": "https://attack.mitre.org/techniques/T1010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1010 Application Window Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1011.001",
      "title": "Exfiltration Over Bluetooth",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1011.001/",
      "source_url": "https://attack.mitre.org/techniques/T1011/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1011.001 Exfiltration Over Bluetooth: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1011.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1011/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1011",
      "title": "Exfiltration Over Other Network Medium",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1011/",
      "source_url": "https://attack.mitre.org/techniques/T1011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1011 Exfiltration Over Other Network Medium: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1012",
      "title": "Query Registry",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1012/",
      "source_url": "https://attack.mitre.org/techniques/T1012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1012 Query Registry: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1014",
      "title": "Rootkit",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1014/",
      "source_url": "https://attack.mitre.org/techniques/T1014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1014 Rootkit: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1016.001",
      "title": "Internet Connection Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1016.001/",
      "source_url": "https://attack.mitre.org/techniques/T1016/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1016.001 Internet Connection Discovery: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1016.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1016/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1016.002",
      "title": "Wi-Fi Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1016.002/",
      "source_url": "https://attack.mitre.org/techniques/T1016/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1016.002 Wi-Fi Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1016.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1016/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1016",
      "title": "System Network Configuration Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1016/",
      "source_url": "https://attack.mitre.org/techniques/T1016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1016 System Network Configuration Discovery: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1016",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1018",
      "title": "Remote System Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1018/",
      "source_url": "https://attack.mitre.org/techniques/T1018/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1018 Remote System Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1018",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1020.001",
      "title": "Traffic Duplication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1020.001/",
      "source_url": "https://attack.mitre.org/techniques/T1020/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1020.001 Traffic Duplication: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1020.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1020/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1020",
      "title": "Automated Exfiltration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1020/",
      "source_url": "https://attack.mitre.org/techniques/T1020/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1020 Automated Exfiltration: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1020",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1020/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.001",
      "title": "Remote Desktop Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.001/",
      "source_url": "https://attack.mitre.org/techniques/T1021/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.001 Remote Desktop Protocol: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.002",
      "title": "SMB/Windows Admin Shares",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.002/",
      "source_url": "https://attack.mitre.org/techniques/T1021/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.002 SMB/Windows Admin Shares: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.003",
      "title": "Distributed Component Object Model",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.003/",
      "source_url": "https://attack.mitre.org/techniques/T1021/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.003 Distributed Component Object Model: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.004",
      "title": "SSH",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.004/",
      "source_url": "https://attack.mitre.org/techniques/T1021/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.004 SSH: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.005",
      "title": "VNC",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.005/",
      "source_url": "https://attack.mitre.org/techniques/T1021/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.005 VNC: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.006",
      "title": "Windows Remote Management",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.006/",
      "source_url": "https://attack.mitre.org/techniques/T1021/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.006 Windows Remote Management: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.007",
      "title": "Cloud Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.007/",
      "source_url": "https://attack.mitre.org/techniques/T1021/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.007 Cloud Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1021.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.008",
      "title": "Direct Cloud VM Connections",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.008/",
      "source_url": "https://attack.mitre.org/techniques/T1021/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021.008 Direct Cloud VM Connections: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1021.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021",
      "title": "Remote Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021/",
      "source_url": "https://attack.mitre.org/techniques/T1021/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1021 Remote Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1025",
      "title": "Data from Removable Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1025/",
      "source_url": "https://attack.mitre.org/techniques/T1025/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1025 Data from Removable Media: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1025",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1025/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.001",
      "title": "Binary Padding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.001/",
      "source_url": "https://attack.mitre.org/techniques/T1027/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.001 Binary Padding: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.002",
      "title": "Software Packing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.002/",
      "source_url": "https://attack.mitre.org/techniques/T1027/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.002 Software Packing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.003",
      "title": "Steganography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.003/",
      "source_url": "https://attack.mitre.org/techniques/T1027/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.003 Steganography: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.004",
      "title": "Compile After Delivery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.004/",
      "source_url": "https://attack.mitre.org/techniques/T1027/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.004 Compile After Delivery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.005",
      "title": "Indicator Removal from Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.005/",
      "source_url": "https://attack.mitre.org/techniques/T1027/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.005 Indicator Removal from Tools: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.006",
      "title": "HTML Smuggling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.006/",
      "source_url": "https://attack.mitre.org/techniques/T1027/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.006 HTML Smuggling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.007",
      "title": "Dynamic API Resolution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.007/",
      "source_url": "https://attack.mitre.org/techniques/T1027/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.007 Dynamic API Resolution: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.008",
      "title": "Stripped Payloads",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.008/",
      "source_url": "https://attack.mitre.org/techniques/T1027/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.008 Stripped Payloads: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.009",
      "title": "Embedded Payloads",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.009/",
      "source_url": "https://attack.mitre.org/techniques/T1027/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.009 Embedded Payloads: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1027.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.010",
      "title": "Command Obfuscation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.010/",
      "source_url": "https://attack.mitre.org/techniques/T1027/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.010 Command Obfuscation: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.011",
      "title": "Fileless Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.011/",
      "source_url": "https://attack.mitre.org/techniques/T1027/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.011 Fileless Storage: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1027.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.012",
      "title": "LNK Icon Smuggling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.012/",
      "source_url": "https://attack.mitre.org/techniques/T1027/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.012 LNK Icon Smuggling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.013",
      "title": "Encrypted/Encoded File",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.013/",
      "source_url": "https://attack.mitre.org/techniques/T1027/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.013 Encrypted/Encoded File: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.014",
      "title": "Polymorphic Code",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.014/",
      "source_url": "https://attack.mitre.org/techniques/T1027/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027.014 Polymorphic Code: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.015",
      "title": "Compression",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.015/",
      "source_url": "https://attack.mitre.org/techniques/T1027/015/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.015 Compression: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.016",
      "title": "Junk Code Insertion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.016/",
      "source_url": "https://attack.mitre.org/techniques/T1027/016/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.016 Junk Code Insertion: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.016",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.017",
      "title": "SVG Smuggling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.017/",
      "source_url": "https://attack.mitre.org/techniques/T1027/017/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.017 SVG Smuggling: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.017",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.018",
      "title": "Invisible Unicode",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.018/",
      "source_url": "https://attack.mitre.org/techniques/T1027/018/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.018 Invisible Unicode: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.018",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027",
      "title": "Obfuscated Files or Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027/",
      "source_url": "https://attack.mitre.org/techniques/T1027/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1027 Obfuscated Files or Information: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1029",
      "title": "Scheduled Transfer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1029/",
      "source_url": "https://attack.mitre.org/techniques/T1029/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1029 Scheduled Transfer: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1029",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1029/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1030",
      "title": "Data Transfer Size Limits",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1030/",
      "source_url": "https://attack.mitre.org/techniques/T1030/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1030 Data Transfer Size Limits: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1030",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1030/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1033",
      "title": "System Owner/User Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1033/",
      "source_url": "https://attack.mitre.org/techniques/T1033/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1033 System Owner/User Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1033",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1033/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.001",
      "title": "Invalid Code Signature",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.001/",
      "source_url": "https://attack.mitre.org/techniques/T1036/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.001 Invalid Code Signature: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.002",
      "title": "Right-to-Left Override",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.002/",
      "source_url": "https://attack.mitre.org/techniques/T1036/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.002 Right-to-Left Override: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.003",
      "title": "Rename System Utilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.003/",
      "source_url": "https://attack.mitre.org/techniques/T1036/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.003 Rename System Utilities: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.004",
      "title": "Masquerade Task or Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.004/",
      "source_url": "https://attack.mitre.org/techniques/T1036/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.004 Masquerade Task or Service: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.005",
      "title": "Match Legitimate Name or Location",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.005/",
      "source_url": "https://attack.mitre.org/techniques/T1036/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.005 Match Legitimate Name or Location: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.006",
      "title": "Space after Filename",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.006/",
      "source_url": "https://attack.mitre.org/techniques/T1036/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.006 Space after Filename: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.007",
      "title": "Double File Extension",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.007/",
      "source_url": "https://attack.mitre.org/techniques/T1036/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.007 Double File Extension: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.008",
      "title": "Masquerade File Type",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.008/",
      "source_url": "https://attack.mitre.org/techniques/T1036/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.008 Masquerade File Type: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.009",
      "title": "Break Process Trees",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.009/",
      "source_url": "https://attack.mitre.org/techniques/T1036/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.009 Break Process Trees: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.010",
      "title": "Masquerade Account Name",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.010/",
      "source_url": "https://attack.mitre.org/techniques/T1036/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036.010 Masquerade Account Name: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.011",
      "title": "Overwrite Process Arguments",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.011/",
      "source_url": "https://attack.mitre.org/techniques/T1036/011/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1036.011 Overwrite Process Arguments: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.012",
      "title": "Browser Fingerprint",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.012/",
      "source_url": "https://attack.mitre.org/techniques/T1036/012/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1036.012 Browser Fingerprint: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036",
      "title": "Masquerading",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036/",
      "source_url": "https://attack.mitre.org/techniques/T1036/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1036 Masquerading: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.001",
      "title": "Logon Script (Windows)",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.001/",
      "source_url": "https://attack.mitre.org/techniques/T1037/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1037.001 Logon Script (Windows): description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.002",
      "title": "Login Hook",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.002/",
      "source_url": "https://attack.mitre.org/techniques/T1037/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1037.002 Login Hook: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.003",
      "title": "Network Logon Script",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.003/",
      "source_url": "https://attack.mitre.org/techniques/T1037/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1037.003 Network Logon Script: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.004",
      "title": "RC Scripts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.004/",
      "source_url": "https://attack.mitre.org/techniques/T1037/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1037.004 RC Scripts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.005",
      "title": "Startup Items",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.005/",
      "source_url": "https://attack.mitre.org/techniques/T1037/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1037.005 Startup Items: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037",
      "title": "Boot or Logon Initialization Scripts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037/",
      "source_url": "https://attack.mitre.org/techniques/T1037/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1037 Boot or Logon Initialization Scripts: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1039",
      "title": "Data from Network Shared Drive",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1039/",
      "source_url": "https://attack.mitre.org/techniques/T1039/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1039 Data from Network Shared Drive: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1039",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1039/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1040",
      "title": "Network Sniffing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1040/",
      "source_url": "https://attack.mitre.org/techniques/T1040/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1040 Network Sniffing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1040",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1040/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1041",
      "title": "Exfiltration Over C2 Channel",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1041/",
      "source_url": "https://attack.mitre.org/techniques/T1041/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1041 Exfiltration Over C2 Channel: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1041",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1041/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1046",
      "title": "Network Service Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1046/",
      "source_url": "https://attack.mitre.org/techniques/T1046/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1046 Network Service Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1046",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1046/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1047",
      "title": "Windows Management Instrumentation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1047/",
      "source_url": "https://attack.mitre.org/techniques/T1047/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1047 Windows Management Instrumentation: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1047",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1047/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048.001",
      "title": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048.001/",
      "source_url": "https://attack.mitre.org/techniques/T1048/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1048.001 Exfiltration Over Symmetric Encrypted…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048.002",
      "title": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048.002/",
      "source_url": "https://attack.mitre.org/techniques/T1048/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1048.002 Exfiltration Over Asymmetric…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048.003",
      "title": "Exfiltration Over Unencrypted Non-C2 Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048.003/",
      "source_url": "https://attack.mitre.org/techniques/T1048/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048",
      "title": "Exfiltration Over Alternative Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048/",
      "source_url": "https://attack.mitre.org/techniques/T1048/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1048 Exfiltration Over Alternative Protocol: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1049",
      "title": "System Network Connections Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1049/",
      "source_url": "https://attack.mitre.org/techniques/T1049/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1049 System Network Connections Discovery: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1049",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1049/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1052.001",
      "title": "Exfiltration over USB",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1052.001/",
      "source_url": "https://attack.mitre.org/techniques/T1052/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1052.001 Exfiltration over USB: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1052.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1052/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1052",
      "title": "Exfiltration Over Physical Medium",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1052/",
      "source_url": "https://attack.mitre.org/techniques/T1052/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1052 Exfiltration Over Physical Medium: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1052",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1052/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.002",
      "title": "At",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.002/",
      "source_url": "https://attack.mitre.org/techniques/T1053/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1053.002 At: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.003",
      "title": "Cron",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.003/",
      "source_url": "https://attack.mitre.org/techniques/T1053/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1053.003 Cron: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.005",
      "title": "Scheduled Task",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.005/",
      "source_url": "https://attack.mitre.org/techniques/T1053/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1053.005 Scheduled Task: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.006",
      "title": "Systemd Timers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.006/",
      "source_url": "https://attack.mitre.org/techniques/T1053/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1053.006 Systemd Timers: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.007",
      "title": "Container Orchestration Job",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.007/",
      "source_url": "https://attack.mitre.org/techniques/T1053/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1053.007 Container Orchestration Job: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1053.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053",
      "title": "Scheduled Task/Job",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053/",
      "source_url": "https://attack.mitre.org/techniques/T1053/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1053 Scheduled Task/Job: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.001",
      "title": "Dynamic-link Library Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.001/",
      "source_url": "https://attack.mitre.org/techniques/T1055/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.001 Dynamic-link Library Injection: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.002",
      "title": "Portable Executable Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.002/",
      "source_url": "https://attack.mitre.org/techniques/T1055/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.002 Portable Executable Injection: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.003",
      "title": "Thread Execution Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.003/",
      "source_url": "https://attack.mitre.org/techniques/T1055/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.003 Thread Execution Hijacking: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.004",
      "title": "Asynchronous Procedure Call",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.004/",
      "source_url": "https://attack.mitre.org/techniques/T1055/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.004 Asynchronous Procedure Call: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.005",
      "title": "Thread Local Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.005/",
      "source_url": "https://attack.mitre.org/techniques/T1055/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.005 Thread Local Storage: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1055.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.008",
      "title": "Ptrace System Calls",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.008/",
      "source_url": "https://attack.mitre.org/techniques/T1055/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.008 Ptrace System Calls: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.009",
      "title": "Proc Memory",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.009/",
      "source_url": "https://attack.mitre.org/techniques/T1055/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.009 Proc Memory: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.011",
      "title": "Extra Window Memory Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.011/",
      "source_url": "https://attack.mitre.org/techniques/T1055/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.011 Extra Window Memory Injection: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.012",
      "title": "Process Hollowing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.012/",
      "source_url": "https://attack.mitre.org/techniques/T1055/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.012 Process Hollowing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.013",
      "title": "Process Doppelgänging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.013/",
      "source_url": "https://attack.mitre.org/techniques/T1055/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.013 Process Doppelgänging: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.014",
      "title": "VDSO Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.014/",
      "source_url": "https://attack.mitre.org/techniques/T1055/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.014 VDSO Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.015",
      "title": "ListPlanting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.015/",
      "source_url": "https://attack.mitre.org/techniques/T1055/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055.015 ListPlanting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055",
      "title": "Process Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055/",
      "source_url": "https://attack.mitre.org/techniques/T1055/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1055 Process Injection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.001",
      "title": "Keylogging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.001/",
      "source_url": "https://attack.mitre.org/techniques/T1056/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1056.001 Keylogging: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.002",
      "title": "GUI Input Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.002/",
      "source_url": "https://attack.mitre.org/techniques/T1056/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1056.002 GUI Input Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.003",
      "title": "Web Portal Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.003/",
      "source_url": "https://attack.mitre.org/techniques/T1056/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1056.003 Web Portal Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.004",
      "title": "Credential API Hooking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.004/",
      "source_url": "https://attack.mitre.org/techniques/T1056/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1056.004 Credential API Hooking: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056",
      "title": "Input Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056/",
      "source_url": "https://attack.mitre.org/techniques/T1056/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1056 Input Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1057",
      "title": "Process Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1057/",
      "source_url": "https://attack.mitre.org/techniques/T1057/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1057 Process Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1057",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1057/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.001",
      "title": "PowerShell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.001/",
      "source_url": "https://attack.mitre.org/techniques/T1059/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.001 PowerShell: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.002",
      "title": "AppleScript",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.002/",
      "source_url": "https://attack.mitre.org/techniques/T1059/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.002 AppleScript: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.003",
      "title": "Windows Command Shell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.003/",
      "source_url": "https://attack.mitre.org/techniques/T1059/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.003 Windows Command Shell: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.004",
      "title": "Unix Shell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.004/",
      "source_url": "https://attack.mitre.org/techniques/T1059/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.004 Unix Shell: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.005",
      "title": "Visual Basic",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.005/",
      "source_url": "https://attack.mitre.org/techniques/T1059/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.005 Visual Basic: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.006",
      "title": "Python",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.006/",
      "source_url": "https://attack.mitre.org/techniques/T1059/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.006 Python: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.007",
      "title": "JavaScript",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.007/",
      "source_url": "https://attack.mitre.org/techniques/T1059/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.007 JavaScript: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.008",
      "title": "Network Device CLI",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.008/",
      "source_url": "https://attack.mitre.org/techniques/T1059/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.008 Network Device CLI: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.009",
      "title": "Cloud API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.009/",
      "source_url": "https://attack.mitre.org/techniques/T1059/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.009 Cloud API: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1059.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.010",
      "title": "AutoHotKey & AutoIT",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.010/",
      "source_url": "https://attack.mitre.org/techniques/T1059/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.010 AutoHotKey & AutoIT: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.011",
      "title": "Lua",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.011/",
      "source_url": "https://attack.mitre.org/techniques/T1059/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059.011 Lua: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.012",
      "title": "Hypervisor CLI",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.012/",
      "source_url": "https://attack.mitre.org/techniques/T1059/012/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1059.012 Hypervisor CLI: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.013",
      "title": "Container CLI/API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.013/",
      "source_url": "https://attack.mitre.org/techniques/T1059/013/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1059.013 Container CLI/API: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1059.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059",
      "title": "Command and Scripting Interpreter",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059/",
      "source_url": "https://attack.mitre.org/techniques/T1059/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1059 Command and Scripting Interpreter: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1068",
      "title": "Exploitation for Privilege Escalation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1068/",
      "source_url": "https://attack.mitre.org/techniques/T1068/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1068 Exploitation for Privilege Escalation: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1068",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1068/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069.001",
      "title": "Local Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069.001/",
      "source_url": "https://attack.mitre.org/techniques/T1069/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1069.001 Local Groups: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1069.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069.002",
      "title": "Domain Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069.002/",
      "source_url": "https://attack.mitre.org/techniques/T1069/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1069.002 Domain Groups: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1069.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069.003",
      "title": "Cloud Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069.003/",
      "source_url": "https://attack.mitre.org/techniques/T1069/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1069.003 Cloud Groups: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1069.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069",
      "title": "Permission Groups Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069/",
      "source_url": "https://attack.mitre.org/techniques/T1069/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1069 Permission Groups Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1069",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.001",
      "title": "Clear Windows Event Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.001/",
      "source_url": "https://attack.mitre.org/techniques/T1070/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.001 Clear Windows Event Logs: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.002",
      "title": "Clear Linux or Mac System Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.002/",
      "source_url": "https://attack.mitre.org/techniques/T1070/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.002 Clear Linux or Mac System Logs: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.003",
      "title": "Clear Command History",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.003/",
      "source_url": "https://attack.mitre.org/techniques/T1070/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.003 Clear Command History: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.004",
      "title": "File Deletion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.004/",
      "source_url": "https://attack.mitre.org/techniques/T1070/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.004 File Deletion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.005",
      "title": "Network Share Connection Removal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.005/",
      "source_url": "https://attack.mitre.org/techniques/T1070/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.005 Network Share Connection Removal: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.006",
      "title": "Timestomp",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.006/",
      "source_url": "https://attack.mitre.org/techniques/T1070/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.006 Timestomp: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.007",
      "title": "Clear Network Connection History and Configurations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.007/",
      "source_url": "https://attack.mitre.org/techniques/T1070/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.007 Clear Network Connection History and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.008",
      "title": "Clear Mailbox Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.008/",
      "source_url": "https://attack.mitre.org/techniques/T1070/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.008 Clear Mailbox Data: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.009",
      "title": "Clear Persistence",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.009/",
      "source_url": "https://attack.mitre.org/techniques/T1070/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.009 Clear Persistence: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.010",
      "title": "Relocate Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.010/",
      "source_url": "https://attack.mitre.org/techniques/T1070/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070.010 Relocate Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "mitre-attack",
        "t1070.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070",
      "title": "Indicator Removal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070/",
      "source_url": "https://attack.mitre.org/techniques/T1070/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1070 Indicator Removal: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.001",
      "title": "Web Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.001/",
      "source_url": "https://attack.mitre.org/techniques/T1071/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1071.001 Web Protocols: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.002",
      "title": "File Transfer Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.002/",
      "source_url": "https://attack.mitre.org/techniques/T1071/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1071.002 File Transfer Protocols: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.003",
      "title": "Mail Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.003/",
      "source_url": "https://attack.mitre.org/techniques/T1071/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1071.003 Mail Protocols: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.004",
      "title": "DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.004/",
      "source_url": "https://attack.mitre.org/techniques/T1071/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1071.004 DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.005",
      "title": "Publish/Subscribe Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.005/",
      "source_url": "https://attack.mitre.org/techniques/T1071/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1071.005 Publish/Subscribe Protocols: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071",
      "title": "Application Layer Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071/",
      "source_url": "https://attack.mitre.org/techniques/T1071/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1071 Application Layer Protocol: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1072",
      "title": "Software Deployment Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1072/",
      "source_url": "https://attack.mitre.org/techniques/T1072/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1072 Software Deployment Tools: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1072",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1072/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1074.001",
      "title": "Local Data Staging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1074.001/",
      "source_url": "https://attack.mitre.org/techniques/T1074/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1074.001 Local Data Staging: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1074.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1074/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1074.002",
      "title": "Remote Data Staging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1074.002/",
      "source_url": "https://attack.mitre.org/techniques/T1074/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1074.002 Remote Data Staging: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1074.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1074/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1074",
      "title": "Data Staged",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1074/",
      "source_url": "https://attack.mitre.org/techniques/T1074/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1074 Data Staged: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1074",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1074/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.001",
      "title": "Default Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.001/",
      "source_url": "https://attack.mitre.org/techniques/T1078/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1078.001 Default Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.002",
      "title": "Domain Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.002/",
      "source_url": "https://attack.mitre.org/techniques/T1078/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1078.002 Domain Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.003",
      "title": "Local Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.003/",
      "source_url": "https://attack.mitre.org/techniques/T1078/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1078.003 Local Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.004",
      "title": "Cloud Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.004/",
      "source_url": "https://attack.mitre.org/techniques/T1078/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1078.004 Cloud Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1078.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078",
      "title": "Valid Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078/",
      "source_url": "https://attack.mitre.org/techniques/T1078/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1078 Valid Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1080",
      "title": "Taint Shared Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1080/",
      "source_url": "https://attack.mitre.org/techniques/T1080/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1080 Taint Shared Content: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1080",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1080/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1082",
      "title": "System Information Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1082/",
      "source_url": "https://attack.mitre.org/techniques/T1082/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1082 System Information Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1082",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1082/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1083",
      "title": "File and Directory Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1083/",
      "source_url": "https://attack.mitre.org/techniques/T1083/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1083 File and Directory Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1083",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1083/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.001",
      "title": "Local Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.001/",
      "source_url": "https://attack.mitre.org/techniques/T1087/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1087.001 Local Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.002",
      "title": "Domain Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.002/",
      "source_url": "https://attack.mitre.org/techniques/T1087/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1087.002 Domain Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.003",
      "title": "Email Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.003/",
      "source_url": "https://attack.mitre.org/techniques/T1087/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1087.003 Email Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.004",
      "title": "Cloud Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.004/",
      "source_url": "https://attack.mitre.org/techniques/T1087/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1087.004 Cloud Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1087.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087",
      "title": "Account Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087/",
      "source_url": "https://attack.mitre.org/techniques/T1087/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1087 Account Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.001",
      "title": "Internal Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.001/",
      "source_url": "https://attack.mitre.org/techniques/T1090/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1090.001 Internal Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.002",
      "title": "External Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.002/",
      "source_url": "https://attack.mitre.org/techniques/T1090/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1090.002 External Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.003",
      "title": "Multi-hop Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.003/",
      "source_url": "https://attack.mitre.org/techniques/T1090/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1090.003 Multi-hop Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.004",
      "title": "Domain Fronting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.004/",
      "source_url": "https://attack.mitre.org/techniques/T1090/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1090.004 Domain Fronting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090",
      "title": "Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090/",
      "source_url": "https://attack.mitre.org/techniques/T1090/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1090 Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1091",
      "title": "Replication Through Removable Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1091/",
      "source_url": "https://attack.mitre.org/techniques/T1091/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1091 Replication Through Removable Media: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1091",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1091/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1092",
      "title": "Communication Through Removable Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1092/",
      "source_url": "https://attack.mitre.org/techniques/T1092/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1092 Communication Through Removable Media: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1092",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1092/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1095",
      "title": "Non-Application Layer Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1095/",
      "source_url": "https://attack.mitre.org/techniques/T1095/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1095 Non-Application Layer Protocol: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1095",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1095/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.001",
      "title": "Additional Cloud Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.001/",
      "source_url": "https://attack.mitre.org/techniques/T1098/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.001 Additional Cloud Credentials: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1098.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.002",
      "title": "Additional Email Delegate Permissions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.002/",
      "source_url": "https://attack.mitre.org/techniques/T1098/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.002 Additional Email Delegate Permissions: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.003",
      "title": "Additional Cloud Roles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.003/",
      "source_url": "https://attack.mitre.org/techniques/T1098/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.003 Additional Cloud Roles: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1098.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.004",
      "title": "SSH Authorized Keys",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.004/",
      "source_url": "https://attack.mitre.org/techniques/T1098/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.004 SSH Authorized Keys: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.005",
      "title": "Device Registration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.005/",
      "source_url": "https://attack.mitre.org/techniques/T1098/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.005 Device Registration: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.006",
      "title": "Additional Container Cluster Roles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.006/",
      "source_url": "https://attack.mitre.org/techniques/T1098/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.006 Additional Container Cluster Roles: description, detection logic, threat…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1098.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.007",
      "title": "Additional Local or Domain Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.007/",
      "source_url": "https://attack.mitre.org/techniques/T1098/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098.007 Additional Local or Domain Groups: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098",
      "title": "Account Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098/",
      "source_url": "https://attack.mitre.org/techniques/T1098/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1098 Account Manipulation: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102.001",
      "title": "Dead Drop Resolver",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102.001/",
      "source_url": "https://attack.mitre.org/techniques/T1102/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1102.001 Dead Drop Resolver: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102.002",
      "title": "Bidirectional Communication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102.002/",
      "source_url": "https://attack.mitre.org/techniques/T1102/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1102.002 Bidirectional Communication: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102.003",
      "title": "One-Way Communication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102.003/",
      "source_url": "https://attack.mitre.org/techniques/T1102/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1102.003 One-Way Communication: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102",
      "title": "Web Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102/",
      "source_url": "https://attack.mitre.org/techniques/T1102/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1102 Web Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1104",
      "title": "Multi-Stage Channels",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1104/",
      "source_url": "https://attack.mitre.org/techniques/T1104/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1104 Multi-Stage Channels: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1104",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1104/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1105",
      "title": "Ingress Tool Transfer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1105/",
      "source_url": "https://attack.mitre.org/techniques/T1105/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1105 Ingress Tool Transfer: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1105",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1105/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1106",
      "title": "Native API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1106/",
      "source_url": "https://attack.mitre.org/techniques/T1106/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1106 Native API: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1106",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1106/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.001",
      "title": "Password Guessing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.001/",
      "source_url": "https://attack.mitre.org/techniques/T1110/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1110.001 Password Guessing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.002",
      "title": "Password Cracking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.002/",
      "source_url": "https://attack.mitre.org/techniques/T1110/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1110.002 Password Cracking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.003",
      "title": "Password Spraying",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.003/",
      "source_url": "https://attack.mitre.org/techniques/T1110/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1110.003 Password Spraying: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.004",
      "title": "Credential Stuffing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.004/",
      "source_url": "https://attack.mitre.org/techniques/T1110/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1110.004 Credential Stuffing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110",
      "title": "Brute Force",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110/",
      "source_url": "https://attack.mitre.org/techniques/T1110/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1110 Brute Force: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1111",
      "title": "Multi-Factor Authentication Interception",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1111/",
      "source_url": "https://attack.mitre.org/techniques/T1111/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1111 Multi-Factor Authentication Interception: description, detection…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1111",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1111/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1112",
      "title": "Modify Registry",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1112/",
      "source_url": "https://attack.mitre.org/techniques/T1112/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1112 Modify Registry: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1112",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1112/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1113",
      "title": "Screen Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1113/",
      "source_url": "https://attack.mitre.org/techniques/T1113/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1113 Screen Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1113",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1113/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114.001",
      "title": "Local Email Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114.001/",
      "source_url": "https://attack.mitre.org/techniques/T1114/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1114.001 Local Email Collection: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114.002",
      "title": "Remote Email Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114.002/",
      "source_url": "https://attack.mitre.org/techniques/T1114/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1114.002 Remote Email Collection: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114.003",
      "title": "Email Forwarding Rule",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114.003/",
      "source_url": "https://attack.mitre.org/techniques/T1114/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1114.003 Email Forwarding Rule: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114",
      "title": "Email Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114/",
      "source_url": "https://attack.mitre.org/techniques/T1114/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1114 Email Collection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1115",
      "title": "Clipboard Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1115/",
      "source_url": "https://attack.mitre.org/techniques/T1115/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1115 Clipboard Data: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1115",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1115/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1119",
      "title": "Automated Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1119/",
      "source_url": "https://attack.mitre.org/techniques/T1119/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1119 Automated Collection: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1119",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1119/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1120",
      "title": "Peripheral Device Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1120/",
      "source_url": "https://attack.mitre.org/techniques/T1120/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1120 Peripheral Device Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1120",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1120/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1123",
      "title": "Audio Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1123/",
      "source_url": "https://attack.mitre.org/techniques/T1123/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1123 Audio Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1123",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1123/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1124",
      "title": "System Time Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1124/",
      "source_url": "https://attack.mitre.org/techniques/T1124/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1124 System Time Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1124",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1124/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1125",
      "title": "Video Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1125/",
      "source_url": "https://attack.mitre.org/techniques/T1125/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1125 Video Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1125",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1125/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127.001",
      "title": "MSBuild",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127.001/",
      "source_url": "https://attack.mitre.org/techniques/T1127/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1127.001 MSBuild: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127.002",
      "title": "ClickOnce",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127.002/",
      "source_url": "https://attack.mitre.org/techniques/T1127/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1127.002 ClickOnce: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127.003",
      "title": "JamPlus",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127.003/",
      "source_url": "https://attack.mitre.org/techniques/T1127/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1127.003 JamPlus: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127",
      "title": "Trusted Developer Utilities Proxy Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127/",
      "source_url": "https://attack.mitre.org/techniques/T1127/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1127 Trusted Developer Utilities Proxy Execution: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1129",
      "title": "Shared Modules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1129/",
      "source_url": "https://attack.mitre.org/techniques/T1129/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1129 Shared Modules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1129",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1129/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1132.001",
      "title": "Standard Encoding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1132.001/",
      "source_url": "https://attack.mitre.org/techniques/T1132/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1132.001 Standard Encoding: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1132.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1132/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1132.002",
      "title": "Non-Standard Encoding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1132.002/",
      "source_url": "https://attack.mitre.org/techniques/T1132/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1132.002 Non-Standard Encoding: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1132.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1132/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1132",
      "title": "Data Encoding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1132/",
      "source_url": "https://attack.mitre.org/techniques/T1132/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1132 Data Encoding: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1132",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1132/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1133",
      "title": "External Remote Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1133/",
      "source_url": "https://attack.mitre.org/techniques/T1133/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1133 External Remote Services: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1133",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1133/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.001",
      "title": "Token Impersonation/Theft",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.001/",
      "source_url": "https://attack.mitre.org/techniques/T1134/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1134.001 Token Impersonation/Theft: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.002",
      "title": "Create Process with Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.002/",
      "source_url": "https://attack.mitre.org/techniques/T1134/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1134.002 Create Process with Token: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.003",
      "title": "Make and Impersonate Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.003/",
      "source_url": "https://attack.mitre.org/techniques/T1134/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1134.003 Make and Impersonate Token: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.004",
      "title": "Parent PID Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.004/",
      "source_url": "https://attack.mitre.org/techniques/T1134/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1134.004 Parent PID Spoofing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.005",
      "title": "SID-History Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.005/",
      "source_url": "https://attack.mitre.org/techniques/T1134/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1134.005 SID-History Injection: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134",
      "title": "Access Token Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134/",
      "source_url": "https://attack.mitre.org/techniques/T1134/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1134 Access Token Manipulation: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1135",
      "title": "Network Share Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1135/",
      "source_url": "https://attack.mitre.org/techniques/T1135/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1135 Network Share Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1135",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1135/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136.001",
      "title": "Local Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136.001/",
      "source_url": "https://attack.mitre.org/techniques/T1136/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1136.001 Local Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1136.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136.002",
      "title": "Domain Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136.002/",
      "source_url": "https://attack.mitre.org/techniques/T1136/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1136.002 Domain Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1136.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136.003",
      "title": "Cloud Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136.003/",
      "source_url": "https://attack.mitre.org/techniques/T1136/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1136.003 Cloud Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1136.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136",
      "title": "Create Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136/",
      "source_url": "https://attack.mitre.org/techniques/T1136/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1136 Create Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1136",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.001",
      "title": "Office Template Macros",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.001/",
      "source_url": "https://attack.mitre.org/techniques/T1137/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137.001 Office Template Macros: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.002",
      "title": "Office Test",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.002/",
      "source_url": "https://attack.mitre.org/techniques/T1137/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137.002 Office Test: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.003",
      "title": "Outlook Forms",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.003/",
      "source_url": "https://attack.mitre.org/techniques/T1137/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137.003 Outlook Forms: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.004",
      "title": "Outlook Home Page",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.004/",
      "source_url": "https://attack.mitre.org/techniques/T1137/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137.004 Outlook Home Page: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.005",
      "title": "Outlook Rules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.005/",
      "source_url": "https://attack.mitre.org/techniques/T1137/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137.005 Outlook Rules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.006",
      "title": "Add-ins",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.006/",
      "source_url": "https://attack.mitre.org/techniques/T1137/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137.006 Add-ins: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137",
      "title": "Office Application Startup",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137/",
      "source_url": "https://attack.mitre.org/techniques/T1137/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1137 Office Application Startup: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1140",
      "title": "Deobfuscate/Decode Files or Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1140/",
      "source_url": "https://attack.mitre.org/techniques/T1140/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1140 Deobfuscate/Decode Files or Information: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1140",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1140/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1176.001",
      "title": "Browser Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1176.001/",
      "source_url": "https://attack.mitre.org/techniques/T1176/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1176.001 Browser Extensions: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1176.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1176/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1176.002",
      "title": "IDE Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1176.002/",
      "source_url": "https://attack.mitre.org/techniques/T1176/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1176.002 IDE Extensions: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1176.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1176/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1176",
      "title": "Browser Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1176/",
      "source_url": "https://attack.mitre.org/techniques/T1176/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1176 Browser Extensions: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1176",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1176/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1185",
      "title": "Browser Session Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1185/",
      "source_url": "https://attack.mitre.org/techniques/T1185/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1185 Browser Session Hijacking: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1185",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1185/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1187",
      "title": "Forced Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1187/",
      "source_url": "https://attack.mitre.org/techniques/T1187/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1187 Forced Authentication: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1187",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1187/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1189",
      "title": "Drive-by Compromise",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1189/",
      "source_url": "https://attack.mitre.org/techniques/T1189/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1189 Drive-by Compromise: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1189",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1189/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1190",
      "title": "Exploit Public-Facing Application",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1190/",
      "source_url": "https://attack.mitre.org/techniques/T1190/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1190 Exploit Public-Facing Application: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1190",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1190/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195.001",
      "title": "Compromise Software Dependencies and Development Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195.001/",
      "source_url": "https://attack.mitre.org/techniques/T1195/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1195.001 Compromise Software Dependencies and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1195.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195.002",
      "title": "Compromise Software Supply Chain",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195.002/",
      "source_url": "https://attack.mitre.org/techniques/T1195/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1195.002 Compromise Software Supply Chain: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1195.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195.003",
      "title": "Compromise Hardware Supply Chain",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195.003/",
      "source_url": "https://attack.mitre.org/techniques/T1195/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1195.003 Compromise Hardware Supply Chain: description, detection logic, threat actors…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1195.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195",
      "title": "Supply Chain Compromise",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195/",
      "source_url": "https://attack.mitre.org/techniques/T1195/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1195 Supply Chain Compromise: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1195",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1197",
      "title": "BITS Jobs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1197/",
      "source_url": "https://attack.mitre.org/techniques/T1197/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1197 BITS Jobs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1197",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1197/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1199",
      "title": "Trusted Relationship",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1199/",
      "source_url": "https://attack.mitre.org/techniques/T1199/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1199 Trusted Relationship: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1199",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1199/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1200",
      "title": "Hardware Additions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1200/",
      "source_url": "https://attack.mitre.org/techniques/T1200/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1200 Hardware Additions: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1200",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1200/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1201",
      "title": "Password Policy Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1201/",
      "source_url": "https://attack.mitre.org/techniques/T1201/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1201 Password Policy Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1201",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1201/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1202",
      "title": "Indirect Command Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1202/",
      "source_url": "https://attack.mitre.org/techniques/T1202/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1202 Indirect Command Execution: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1202",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1202/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1203",
      "title": "Exploitation for Client Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1203/",
      "source_url": "https://attack.mitre.org/techniques/T1203/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1203 Exploitation for Client Execution: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1203",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1203/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.001",
      "title": "Malicious Link",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.001/",
      "source_url": "https://attack.mitre.org/techniques/T1204/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1204.001 Malicious Link: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.002",
      "title": "Malicious File",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.002/",
      "source_url": "https://attack.mitre.org/techniques/T1204/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1204.002 Malicious File: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.003",
      "title": "Malicious Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.003/",
      "source_url": "https://attack.mitre.org/techniques/T1204/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1204.003 Malicious Image: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.004",
      "title": "Malicious Copy and Paste",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.004/",
      "source_url": "https://attack.mitre.org/techniques/T1204/004/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1204.004 Malicious Copy and Paste: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.005",
      "title": "Malicious Library",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.005/",
      "source_url": "https://attack.mitre.org/techniques/T1204/005/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1204.005 Malicious Library: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204",
      "title": "User Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204/",
      "source_url": "https://attack.mitre.org/techniques/T1204/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1204 User Execution: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1205.001",
      "title": "Port Knocking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1205.001/",
      "source_url": "https://attack.mitre.org/techniques/T1205/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1205.001 Port Knocking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1205.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1205/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1205.002",
      "title": "Socket Filters",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1205.002/",
      "source_url": "https://attack.mitre.org/techniques/T1205/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1205.002 Socket Filters: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1205.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1205/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1205",
      "title": "Traffic Signaling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1205/",
      "source_url": "https://attack.mitre.org/techniques/T1205/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1205 Traffic Signaling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1205",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1205/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1207",
      "title": "Rogue Domain Controller",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1207/",
      "source_url": "https://attack.mitre.org/techniques/T1207/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1207 Rogue Domain Controller: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1207",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1207/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1210",
      "title": "Exploitation of Remote Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1210/",
      "source_url": "https://attack.mitre.org/techniques/T1210/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1210 Exploitation of Remote Services: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1210",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1210/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1211",
      "title": "Exploitation for Defense Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1211/",
      "source_url": "https://attack.mitre.org/techniques/T1211/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1211 Exploitation for Defense Evasion: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1211",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1211/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1212",
      "title": "Exploitation for Credential Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1212/",
      "source_url": "https://attack.mitre.org/techniques/T1212/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1212 Exploitation for Credential Access: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1212",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1212/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.001",
      "title": "Confluence",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.001/",
      "source_url": "https://attack.mitre.org/techniques/T1213/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1213.001 Confluence: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.002",
      "title": "Sharepoint",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.002/",
      "source_url": "https://attack.mitre.org/techniques/T1213/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1213.002 Sharepoint: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.003",
      "title": "Code Repositories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.003/",
      "source_url": "https://attack.mitre.org/techniques/T1213/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1213.003 Code Repositories: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.004",
      "title": "Customer Relationship Management Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.004/",
      "source_url": "https://attack.mitre.org/techniques/T1213/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1213.004 Customer Relationship Management Software: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.005",
      "title": "Messaging Applications",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.005/",
      "source_url": "https://attack.mitre.org/techniques/T1213/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1213.005 Messaging Applications: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.006",
      "title": "Databases",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.006/",
      "source_url": "https://attack.mitre.org/techniques/T1213/006/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1213.006 Databases: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213",
      "title": "Data from Information Repositories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213/",
      "source_url": "https://attack.mitre.org/techniques/T1213/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1213 Data from Information Repositories: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1216.001",
      "title": "PubPrn",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1216.001/",
      "source_url": "https://attack.mitre.org/techniques/T1216/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1216.001 PubPrn: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1216.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1216/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1216.002",
      "title": "SyncAppvPublishingServer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1216.002/",
      "source_url": "https://attack.mitre.org/techniques/T1216/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1216.002 SyncAppvPublishingServer: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1216.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1216/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1216",
      "title": "System Script Proxy Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1216/",
      "source_url": "https://attack.mitre.org/techniques/T1216/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1216 System Script Proxy Execution: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1216",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1216/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1217",
      "title": "Browser Information Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1217/",
      "source_url": "https://attack.mitre.org/techniques/T1217/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1217 Browser Information Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1217",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1217/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.001",
      "title": "Compiled HTML File",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.001/",
      "source_url": "https://attack.mitre.org/techniques/T1218/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.001 Compiled HTML File: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.002",
      "title": "Control Panel",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.002/",
      "source_url": "https://attack.mitre.org/techniques/T1218/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.002 Control Panel: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.003",
      "title": "CMSTP",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.003/",
      "source_url": "https://attack.mitre.org/techniques/T1218/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.003 CMSTP: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.004",
      "title": "InstallUtil",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.004/",
      "source_url": "https://attack.mitre.org/techniques/T1218/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.004 InstallUtil: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.005",
      "title": "Mshta",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.005/",
      "source_url": "https://attack.mitre.org/techniques/T1218/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.005 Mshta: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.007",
      "title": "Msiexec",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.007/",
      "source_url": "https://attack.mitre.org/techniques/T1218/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.007 Msiexec: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.008",
      "title": "Odbcconf",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.008/",
      "source_url": "https://attack.mitre.org/techniques/T1218/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.008 Odbcconf: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.009",
      "title": "Regsvcs/Regasm",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.009/",
      "source_url": "https://attack.mitre.org/techniques/T1218/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.009 Regsvcs/Regasm: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.010",
      "title": "Regsvr32",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.010/",
      "source_url": "https://attack.mitre.org/techniques/T1218/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.010 Regsvr32: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.011",
      "title": "Rundll32",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.011/",
      "source_url": "https://attack.mitre.org/techniques/T1218/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.011 Rundll32: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.012",
      "title": "Verclsid",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.012/",
      "source_url": "https://attack.mitre.org/techniques/T1218/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.012 Verclsid: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.013",
      "title": "Mavinject",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.013/",
      "source_url": "https://attack.mitre.org/techniques/T1218/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.013 Mavinject: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.014",
      "title": "MMC",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.014/",
      "source_url": "https://attack.mitre.org/techniques/T1218/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.014 MMC: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.015",
      "title": "Electron Applications",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.015/",
      "source_url": "https://attack.mitre.org/techniques/T1218/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218.015 Electron Applications: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218",
      "title": "System Binary Proxy Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218/",
      "source_url": "https://attack.mitre.org/techniques/T1218/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1218 System Binary Proxy Execution: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219.001",
      "title": "IDE Tunneling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219.001/",
      "source_url": "https://attack.mitre.org/techniques/T1219/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1219.001 IDE Tunneling: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1219.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219.002",
      "title": "Remote Desktop Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219.002/",
      "source_url": "https://attack.mitre.org/techniques/T1219/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1219.002 Remote Desktop Software: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1219.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219.003",
      "title": "Remote Access Hardware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219.003/",
      "source_url": "https://attack.mitre.org/techniques/T1219/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1219.003 Remote Access Hardware: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1219.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219",
      "title": "Remote Access Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219/",
      "source_url": "https://attack.mitre.org/techniques/T1219/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1219 Remote Access Software: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1219",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1220",
      "title": "XSL Script Processing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1220/",
      "source_url": "https://attack.mitre.org/techniques/T1220/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1220 XSL Script Processing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1220",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1220/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1221",
      "title": "Template Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1221/",
      "source_url": "https://attack.mitre.org/techniques/T1221/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1221 Template Injection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1221",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1221/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1222.001",
      "title": "Windows File and Directory Permissions Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1222.001/",
      "source_url": "https://attack.mitre.org/techniques/T1222/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1222.001 Windows File and Directory Permissions…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1222.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1222/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1222.002",
      "title": "Linux and Mac File and Directory Permissions Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1222.002/",
      "source_url": "https://attack.mitre.org/techniques/T1222/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1222.002 Linux and Mac File and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1222.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1222/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1222",
      "title": "File and Directory Permissions Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1222/",
      "source_url": "https://attack.mitre.org/techniques/T1222/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1222 File and Directory Permissions Modification: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1222",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1222/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1480.001",
      "title": "Environmental Keying",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1480.001/",
      "source_url": "https://attack.mitre.org/techniques/T1480/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1480.001 Environmental Keying: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1480.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1480/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1480.002",
      "title": "Mutual Exclusion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1480.002/",
      "source_url": "https://attack.mitre.org/techniques/T1480/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1480.002 Mutual Exclusion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1480.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1480/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1480",
      "title": "Execution Guardrails",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1480/",
      "source_url": "https://attack.mitre.org/techniques/T1480/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1480 Execution Guardrails: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1480",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1480/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1482",
      "title": "Domain Trust Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1482/",
      "source_url": "https://attack.mitre.org/techniques/T1482/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1482 Domain Trust Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1482",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1482/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1484.001",
      "title": "Group Policy Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1484.001/",
      "source_url": "https://attack.mitre.org/techniques/T1484/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1484.001 Group Policy Modification: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1484.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1484/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1484.002",
      "title": "Trust Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1484.002/",
      "source_url": "https://attack.mitre.org/techniques/T1484/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1484.002 Trust Modification: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1484.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1484/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1484",
      "title": "Domain or Tenant Policy Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1484/",
      "source_url": "https://attack.mitre.org/techniques/T1484/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1484 Domain or Tenant Policy Modification: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1484",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1484/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1485.001",
      "title": "Lifecycle-Triggered Deletion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1485.001/",
      "source_url": "https://attack.mitre.org/techniques/T1485/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1485.001 Lifecycle-Triggered Deletion: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1485.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1485/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1485",
      "title": "Data Destruction",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1485/",
      "source_url": "https://attack.mitre.org/techniques/T1485/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1485 Data Destruction: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1485",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1485/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1486",
      "title": "Data Encrypted for Impact",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1486/",
      "source_url": "https://attack.mitre.org/techniques/T1486/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1486 Data Encrypted for Impact: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1486",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1486/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1489",
      "title": "Service Stop",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1489/",
      "source_url": "https://attack.mitre.org/techniques/T1489/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1489 Service Stop: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1489",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1489/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1490",
      "title": "Inhibit System Recovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1490/",
      "source_url": "https://attack.mitre.org/techniques/T1490/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1490 Inhibit System Recovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1490",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1490/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1491.001",
      "title": "Internal Defacement",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1491.001/",
      "source_url": "https://attack.mitre.org/techniques/T1491/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1491.001 Internal Defacement: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1491.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1491/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1491.002",
      "title": "External Defacement",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1491.002/",
      "source_url": "https://attack.mitre.org/techniques/T1491/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1491.002 External Defacement: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1491.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1491/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1491",
      "title": "Defacement",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1491/",
      "source_url": "https://attack.mitre.org/techniques/T1491/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1491 Defacement: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1491",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1491/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1495",
      "title": "Firmware Corruption",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1495/",
      "source_url": "https://attack.mitre.org/techniques/T1495/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1495 Firmware Corruption: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1495",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1495/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.001",
      "title": "Compute Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.001/",
      "source_url": "https://attack.mitre.org/techniques/T1496/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1496.001 Compute Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.002",
      "title": "Bandwidth Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.002/",
      "source_url": "https://attack.mitre.org/techniques/T1496/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1496.002 Bandwidth Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.003",
      "title": "SMS Pumping",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.003/",
      "source_url": "https://attack.mitre.org/techniques/T1496/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1496.003 SMS Pumping: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.004",
      "title": "Cloud Service Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.004/",
      "source_url": "https://attack.mitre.org/techniques/T1496/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1496.004 Cloud Service Hijacking: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1496.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496",
      "title": "Resource Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496/",
      "source_url": "https://attack.mitre.org/techniques/T1496/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1496 Resource Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497.001",
      "title": "System Checks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497.001/",
      "source_url": "https://attack.mitre.org/techniques/T1497/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1497.001 System Checks: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1497.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497.002",
      "title": "User Activity Based Checks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497.002/",
      "source_url": "https://attack.mitre.org/techniques/T1497/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1497.002 User Activity Based Checks: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1497.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497.003",
      "title": "Time Based Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497.003/",
      "source_url": "https://attack.mitre.org/techniques/T1497/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1497.003 Time Based Evasion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1497.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497",
      "title": "Virtualization/Sandbox Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497/",
      "source_url": "https://attack.mitre.org/techniques/T1497/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1497 Virtualization/Sandbox Evasion: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "mitre-attack",
        "t1497",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1498.001",
      "title": "Direct Network Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1498.001/",
      "source_url": "https://attack.mitre.org/techniques/T1498/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1498.001 Direct Network Flood: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1498.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1498/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1498.002",
      "title": "Reflection Amplification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1498.002/",
      "source_url": "https://attack.mitre.org/techniques/T1498/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1498.002 Reflection Amplification: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1498.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1498/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1498",
      "title": "Network Denial of Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1498/",
      "source_url": "https://attack.mitre.org/techniques/T1498/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1498 Network Denial of Service: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1498",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1498/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.001",
      "title": "OS Exhaustion Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.001/",
      "source_url": "https://attack.mitre.org/techniques/T1499/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1499.001 OS Exhaustion Flood: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.002",
      "title": "Service Exhaustion Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.002/",
      "source_url": "https://attack.mitre.org/techniques/T1499/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1499.002 Service Exhaustion Flood: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.003",
      "title": "Application Exhaustion Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.003/",
      "source_url": "https://attack.mitre.org/techniques/T1499/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1499.003 Application Exhaustion Flood: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.004",
      "title": "Application or System Exploitation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.004/",
      "source_url": "https://attack.mitre.org/techniques/T1499/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1499.004 Application or System Exploitation: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1499.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499",
      "title": "Endpoint Denial of Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499/",
      "source_url": "https://attack.mitre.org/techniques/T1499/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1499 Endpoint Denial of Service: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.001",
      "title": "SQL Stored Procedures",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.001/",
      "source_url": "https://attack.mitre.org/techniques/T1505/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1505.001 SQL Stored Procedures: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.002",
      "title": "Transport Agent",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.002/",
      "source_url": "https://attack.mitre.org/techniques/T1505/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1505.002 Transport Agent: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.003",
      "title": "Web Shell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.003/",
      "source_url": "https://attack.mitre.org/techniques/T1505/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1505.003 Web Shell: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.004",
      "title": "IIS Components",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.004/",
      "source_url": "https://attack.mitre.org/techniques/T1505/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1505.004 IIS Components: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.005",
      "title": "Terminal Services DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.005/",
      "source_url": "https://attack.mitre.org/techniques/T1505/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1505.005 Terminal Services DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.006",
      "title": "vSphere Installation Bundles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.006/",
      "source_url": "https://attack.mitre.org/techniques/T1505/006/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1505.006 vSphere Installation Bundles: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505",
      "title": "Server Software Component",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505/",
      "source_url": "https://attack.mitre.org/techniques/T1505/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1505 Server Software Component: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1518.001",
      "title": "Security Software Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1518.001/",
      "source_url": "https://attack.mitre.org/techniques/T1518/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1518.001 Security Software Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1518.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1518/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1518.002",
      "title": "Backup Software Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1518.002/",
      "source_url": "https://attack.mitre.org/techniques/T1518/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1518.002 Backup Software Discovery: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1518.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1518/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1518",
      "title": "Software Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1518/",
      "source_url": "https://attack.mitre.org/techniques/T1518/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1518 Software Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1518",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1518/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1525",
      "title": "Implant Internal Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1525/",
      "source_url": "https://attack.mitre.org/techniques/T1525/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1525 Implant Internal Image: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1525",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1525/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1526",
      "title": "Cloud Service Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1526/",
      "source_url": "https://attack.mitre.org/techniques/T1526/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1526 Cloud Service Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1526",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1526/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1528",
      "title": "Steal Application Access Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1528/",
      "source_url": "https://attack.mitre.org/techniques/T1528/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1528 Steal Application Access Token: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1528",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1528/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1529",
      "title": "System Shutdown/Reboot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1529/",
      "source_url": "https://attack.mitre.org/techniques/T1529/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1529 System Shutdown/Reboot: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1529",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1529/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1530",
      "title": "Data from Cloud Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1530/",
      "source_url": "https://attack.mitre.org/techniques/T1530/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1530 Data from Cloud Storage: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "ai-security",
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1530",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1530/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1531",
      "title": "Account Access Removal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1531/",
      "source_url": "https://attack.mitre.org/techniques/T1531/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1531 Account Access Removal: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1531",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1531/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1534",
      "title": "Internal Spearphishing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1534/",
      "source_url": "https://attack.mitre.org/techniques/T1534/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1534 Internal Spearphishing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1534",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1534/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1535",
      "title": "Unused/Unsupported Cloud Regions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1535/",
      "source_url": "https://attack.mitre.org/techniques/T1535/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1535 Unused/Unsupported Cloud Regions: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1535",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1535/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1537",
      "title": "Transfer Data to Cloud Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1537/",
      "source_url": "https://attack.mitre.org/techniques/T1537/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1537 Transfer Data to Cloud Account: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1537",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1537/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1538",
      "title": "Cloud Service Dashboard",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1538/",
      "source_url": "https://attack.mitre.org/techniques/T1538/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1538 Cloud Service Dashboard: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1538",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1538/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1539",
      "title": "Steal Web Session Cookie",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1539/",
      "source_url": "https://attack.mitre.org/techniques/T1539/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1539 Steal Web Session Cookie: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1539",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1539/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.001",
      "title": "System Firmware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.001/",
      "source_url": "https://attack.mitre.org/techniques/T1542/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1542.001 System Firmware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1542.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.002",
      "title": "Component Firmware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.002/",
      "source_url": "https://attack.mitre.org/techniques/T1542/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1542.002 Component Firmware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1542.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.003",
      "title": "Bootkit",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.003/",
      "source_url": "https://attack.mitre.org/techniques/T1542/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1542.003 Bootkit: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.004",
      "title": "ROMMONkit",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.004/",
      "source_url": "https://attack.mitre.org/techniques/T1542/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1542.004 ROMMONkit: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.005",
      "title": "TFTP Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.005/",
      "source_url": "https://attack.mitre.org/techniques/T1542/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1542.005 TFTP Boot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542",
      "title": "Pre-OS Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542/",
      "source_url": "https://attack.mitre.org/techniques/T1542/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1542 Pre-OS Boot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.001",
      "title": "Launch Agent",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.001/",
      "source_url": "https://attack.mitre.org/techniques/T1543/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1543.001 Launch Agent: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.002",
      "title": "Systemd Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.002/",
      "source_url": "https://attack.mitre.org/techniques/T1543/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1543.002 Systemd Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.003",
      "title": "Windows Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.003/",
      "source_url": "https://attack.mitre.org/techniques/T1543/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1543.003 Windows Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.004",
      "title": "Launch Daemon",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.004/",
      "source_url": "https://attack.mitre.org/techniques/T1543/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1543.004 Launch Daemon: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.005",
      "title": "Container Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.005/",
      "source_url": "https://attack.mitre.org/techniques/T1543/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1543.005 Container Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1543.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543",
      "title": "Create or Modify System Process",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543/",
      "source_url": "https://attack.mitre.org/techniques/T1543/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1543 Create or Modify System Process: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.001",
      "title": "Change Default File Association",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.001/",
      "source_url": "https://attack.mitre.org/techniques/T1546/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.001 Change Default File Association: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.002",
      "title": "Screensaver",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.002/",
      "source_url": "https://attack.mitre.org/techniques/T1546/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.002 Screensaver: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.003",
      "title": "Windows Management Instrumentation Event Subscription",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.003/",
      "source_url": "https://attack.mitre.org/techniques/T1546/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.003 Windows Management Instrumentation…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.004",
      "title": "Unix Shell Configuration Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.004/",
      "source_url": "https://attack.mitre.org/techniques/T1546/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.004 Unix Shell Configuration Modification: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.005",
      "title": "Trap",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.005/",
      "source_url": "https://attack.mitre.org/techniques/T1546/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.005 Trap: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.006",
      "title": "LC_LOAD_DYLIB Addition",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.006/",
      "source_url": "https://attack.mitre.org/techniques/T1546/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.006 LC_LOAD_DYLIB Addition: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.007",
      "title": "Netsh Helper DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.007/",
      "source_url": "https://attack.mitre.org/techniques/T1546/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.007 Netsh Helper DLL: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.008",
      "title": "Accessibility Features",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.008/",
      "source_url": "https://attack.mitre.org/techniques/T1546/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.008 Accessibility Features: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.009",
      "title": "AppCert DLLs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.009/",
      "source_url": "https://attack.mitre.org/techniques/T1546/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.009 AppCert DLLs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.010",
      "title": "AppInit DLLs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.010/",
      "source_url": "https://attack.mitre.org/techniques/T1546/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.010 AppInit DLLs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.011",
      "title": "Application Shimming",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.011/",
      "source_url": "https://attack.mitre.org/techniques/T1546/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.011 Application Shimming: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.012",
      "title": "Image File Execution Options Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.012/",
      "source_url": "https://attack.mitre.org/techniques/T1546/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.012 Image File Execution Options Injection: description, detection…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.013",
      "title": "PowerShell Profile",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.013/",
      "source_url": "https://attack.mitre.org/techniques/T1546/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.013 PowerShell Profile: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.014",
      "title": "Emond",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.014/",
      "source_url": "https://attack.mitre.org/techniques/T1546/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.014 Emond: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.015",
      "title": "Component Object Model Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.015/",
      "source_url": "https://attack.mitre.org/techniques/T1546/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.015 Component Object Model Hijacking: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.016",
      "title": "Installer Packages",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.016/",
      "source_url": "https://attack.mitre.org/techniques/T1546/016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.016 Installer Packages: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.016",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.017",
      "title": "Udev Rules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.017/",
      "source_url": "https://attack.mitre.org/techniques/T1546/017/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546.017 Udev Rules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.017",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.018",
      "title": "Python Startup Hooks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.018/",
      "source_url": "https://attack.mitre.org/techniques/T1546/018/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1546.018 Python Startup Hooks: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.018",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546",
      "title": "Event Triggered Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546/",
      "source_url": "https://attack.mitre.org/techniques/T1546/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1546 Event Triggered Execution: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.001",
      "title": "Registry Run Keys / Startup Folder",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.001/",
      "source_url": "https://attack.mitre.org/techniques/T1547/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.001 Registry Run Keys / Startup Folder: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.002",
      "title": "Authentication Package",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.002/",
      "source_url": "https://attack.mitre.org/techniques/T1547/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.002 Authentication Package: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.003",
      "title": "Time Providers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.003/",
      "source_url": "https://attack.mitre.org/techniques/T1547/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.003 Time Providers: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.004",
      "title": "Winlogon Helper DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.004/",
      "source_url": "https://attack.mitre.org/techniques/T1547/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.004 Winlogon Helper DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.005",
      "title": "Security Support Provider",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.005/",
      "source_url": "https://attack.mitre.org/techniques/T1547/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.005 Security Support Provider: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.006",
      "title": "Kernel Modules and Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.006/",
      "source_url": "https://attack.mitre.org/techniques/T1547/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.006 Kernel Modules and Extensions: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.007",
      "title": "Re-opened Applications",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.007/",
      "source_url": "https://attack.mitre.org/techniques/T1547/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.007 Re-opened Applications: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.008",
      "title": "LSASS Driver",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.008/",
      "source_url": "https://attack.mitre.org/techniques/T1547/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.008 LSASS Driver: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.009",
      "title": "Shortcut Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.009/",
      "source_url": "https://attack.mitre.org/techniques/T1547/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.009 Shortcut Modification: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.010",
      "title": "Port Monitors",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.010/",
      "source_url": "https://attack.mitre.org/techniques/T1547/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.010 Port Monitors: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.012",
      "title": "Print Processors",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.012/",
      "source_url": "https://attack.mitre.org/techniques/T1547/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.012 Print Processors: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.013",
      "title": "XDG Autostart Entries",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.013/",
      "source_url": "https://attack.mitre.org/techniques/T1547/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.013 XDG Autostart Entries: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.014",
      "title": "Active Setup",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.014/",
      "source_url": "https://attack.mitre.org/techniques/T1547/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.014 Active Setup: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.015",
      "title": "Login Items",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.015/",
      "source_url": "https://attack.mitre.org/techniques/T1547/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547.015 Login Items: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547",
      "title": "Boot or Logon Autostart Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547/",
      "source_url": "https://attack.mitre.org/techniques/T1547/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1547 Boot or Logon Autostart Execution: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.001",
      "title": "Setuid and Setgid",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.001/",
      "source_url": "https://attack.mitre.org/techniques/T1548/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548.001 Setuid and Setgid: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.002",
      "title": "Bypass User Account Control",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.002/",
      "source_url": "https://attack.mitre.org/techniques/T1548/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548.002 Bypass User Account Control: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.003",
      "title": "Sudo and Sudo Caching",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.003/",
      "source_url": "https://attack.mitre.org/techniques/T1548/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548.003 Sudo and Sudo Caching: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.004",
      "title": "Elevated Execution with Prompt",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.004/",
      "source_url": "https://attack.mitre.org/techniques/T1548/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548.004 Elevated Execution with Prompt: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.005",
      "title": "Temporary Elevated Cloud Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.005/",
      "source_url": "https://attack.mitre.org/techniques/T1548/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548.005 Temporary Elevated Cloud Access: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1548.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.006",
      "title": "TCC Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.006/",
      "source_url": "https://attack.mitre.org/techniques/T1548/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548.006 TCC Manipulation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548",
      "title": "Abuse Elevation Control Mechanism",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548/",
      "source_url": "https://attack.mitre.org/techniques/T1548/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1548 Abuse Elevation Control Mechanism: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.001",
      "title": "Application Access Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.001/",
      "source_url": "https://attack.mitre.org/techniques/T1550/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1550.001 Application Access Token: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.002",
      "title": "Pass the Hash",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.002/",
      "source_url": "https://attack.mitre.org/techniques/T1550/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1550.002 Pass the Hash: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.003",
      "title": "Pass the Ticket",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.003/",
      "source_url": "https://attack.mitre.org/techniques/T1550/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1550.003 Pass the Ticket: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.004",
      "title": "Web Session Cookie",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.004/",
      "source_url": "https://attack.mitre.org/techniques/T1550/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1550.004 Web Session Cookie: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550",
      "title": "Use Alternate Authentication Material",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550/",
      "source_url": "https://attack.mitre.org/techniques/T1550/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1550 Use Alternate Authentication Material: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.001",
      "title": "Credentials In Files",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.001/",
      "source_url": "https://attack.mitre.org/techniques/T1552/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.001 Credentials In Files: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.002",
      "title": "Credentials in Registry",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.002/",
      "source_url": "https://attack.mitre.org/techniques/T1552/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.002 Credentials in Registry: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.003",
      "title": "Bash History",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.003/",
      "source_url": "https://attack.mitre.org/techniques/T1552/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.003 Bash History: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.004",
      "title": "Private Keys",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.004/",
      "source_url": "https://attack.mitre.org/techniques/T1552/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.004 Private Keys: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.005",
      "title": "Cloud Instance Metadata API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.005/",
      "source_url": "https://attack.mitre.org/techniques/T1552/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.005 Cloud Instance Metadata API: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1552.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.006",
      "title": "Group Policy Preferences",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.006/",
      "source_url": "https://attack.mitre.org/techniques/T1552/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.006 Group Policy Preferences: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.007",
      "title": "Container API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.007/",
      "source_url": "https://attack.mitre.org/techniques/T1552/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.007 Container API: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1552.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.008",
      "title": "Chat Messages",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.008/",
      "source_url": "https://attack.mitre.org/techniques/T1552/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552.008 Chat Messages: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552",
      "title": "Unsecured Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552/",
      "source_url": "https://attack.mitre.org/techniques/T1552/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1552 Unsecured Credentials: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.001",
      "title": "Gatekeeper Bypass",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.001/",
      "source_url": "https://attack.mitre.org/techniques/T1553/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553.001 Gatekeeper Bypass: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.002",
      "title": "Code Signing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.002/",
      "source_url": "https://attack.mitre.org/techniques/T1553/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553.002 Code Signing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.003",
      "title": "SIP and Trust Provider Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.003/",
      "source_url": "https://attack.mitre.org/techniques/T1553/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553.003 SIP and Trust Provider Hijacking: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.004",
      "title": "Install Root Certificate",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.004/",
      "source_url": "https://attack.mitre.org/techniques/T1553/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553.004 Install Root Certificate: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.005",
      "title": "Mark-of-the-Web Bypass",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.005/",
      "source_url": "https://attack.mitre.org/techniques/T1553/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553.005 Mark-of-the-Web Bypass: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.006",
      "title": "Code Signing Policy Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.006/",
      "source_url": "https://attack.mitre.org/techniques/T1553/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553.006 Code Signing Policy Modification: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553",
      "title": "Subvert Trust Controls",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553/",
      "source_url": "https://attack.mitre.org/techniques/T1553/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1553 Subvert Trust Controls: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1554",
      "title": "Compromise Host Software Binary",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1554/",
      "source_url": "https://attack.mitre.org/techniques/T1554/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1554 Compromise Host Software Binary: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1554",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1554/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.001",
      "title": "Keychain",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.001/",
      "source_url": "https://attack.mitre.org/techniques/T1555/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555.001 Keychain: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.002",
      "title": "Securityd Memory",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.002/",
      "source_url": "https://attack.mitre.org/techniques/T1555/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555.002 Securityd Memory: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.003",
      "title": "Credentials from Web Browsers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.003/",
      "source_url": "https://attack.mitre.org/techniques/T1555/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555.003 Credentials from Web Browsers: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.004",
      "title": "Windows Credential Manager",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.004/",
      "source_url": "https://attack.mitre.org/techniques/T1555/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555.004 Windows Credential Manager: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.005",
      "title": "Password Managers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.005/",
      "source_url": "https://attack.mitre.org/techniques/T1555/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555.005 Password Managers: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.006",
      "title": "Cloud Secrets Management Stores",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.006/",
      "source_url": "https://attack.mitre.org/techniques/T1555/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555.006 Cloud Secrets Management Stores: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1555.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555",
      "title": "Credentials from Password Stores",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555/",
      "source_url": "https://attack.mitre.org/techniques/T1555/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1555 Credentials from Password Stores: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.001",
      "title": "Domain Controller Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.001/",
      "source_url": "https://attack.mitre.org/techniques/T1556/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.001 Domain Controller Authentication: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.002",
      "title": "Password Filter DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.002/",
      "source_url": "https://attack.mitre.org/techniques/T1556/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.002 Password Filter DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.003",
      "title": "Pluggable Authentication Modules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.003/",
      "source_url": "https://attack.mitre.org/techniques/T1556/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.003 Pluggable Authentication Modules: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.004",
      "title": "Network Device Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.004/",
      "source_url": "https://attack.mitre.org/techniques/T1556/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.004 Network Device Authentication: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.005",
      "title": "Reversible Encryption",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.005/",
      "source_url": "https://attack.mitre.org/techniques/T1556/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.005 Reversible Encryption: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.006",
      "title": "Multi-Factor Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.006/",
      "source_url": "https://attack.mitre.org/techniques/T1556/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.006 Multi-Factor Authentication: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.007",
      "title": "Hybrid Identity",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.007/",
      "source_url": "https://attack.mitre.org/techniques/T1556/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.007 Hybrid Identity: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "identity-security",
        "mitre-attack",
        "t1556.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.008",
      "title": "Network Provider DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.008/",
      "source_url": "https://attack.mitre.org/techniques/T1556/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.008 Network Provider DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.009",
      "title": "Conditional Access Policies",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.009/",
      "source_url": "https://attack.mitre.org/techniques/T1556/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556.009 Conditional Access Policies: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556",
      "title": "Modify Authentication Process",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556/",
      "source_url": "https://attack.mitre.org/techniques/T1556/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1556 Modify Authentication Process: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.001",
      "title": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.001/",
      "source_url": "https://attack.mitre.org/techniques/T1557/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.002",
      "title": "ARP Cache Poisoning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.002/",
      "source_url": "https://attack.mitre.org/techniques/T1557/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1557.002 ARP Cache Poisoning: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.003",
      "title": "DHCP Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.003/",
      "source_url": "https://attack.mitre.org/techniques/T1557/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1557.003 DHCP Spoofing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.004",
      "title": "Evil Twin",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.004/",
      "source_url": "https://attack.mitre.org/techniques/T1557/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1557.004 Evil Twin: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557",
      "title": "Adversary-in-the-Middle",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557/",
      "source_url": "https://attack.mitre.org/techniques/T1557/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1557 Adversary-in-the-Middle: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.001",
      "title": "Golden Ticket",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.001/",
      "source_url": "https://attack.mitre.org/techniques/T1558/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1558.001 Golden Ticket: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.002",
      "title": "Silver Ticket",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.002/",
      "source_url": "https://attack.mitre.org/techniques/T1558/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1558.002 Silver Ticket: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.003",
      "title": "Kerberoasting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.003/",
      "source_url": "https://attack.mitre.org/techniques/T1558/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1558.003 Kerberoasting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.004",
      "title": "AS-REP Roasting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.004/",
      "source_url": "https://attack.mitre.org/techniques/T1558/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1558.004 AS-REP Roasting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.005",
      "title": "Ccache Files",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.005/",
      "source_url": "https://attack.mitre.org/techniques/T1558/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1558.005 Ccache Files: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558",
      "title": "Steal or Forge Kerberos Tickets",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558/",
      "source_url": "https://attack.mitre.org/techniques/T1558/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1558 Steal or Forge Kerberos Tickets: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "identity-security",
        "mitre-attack",
        "t1558",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559.001",
      "title": "Component Object Model",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559.001/",
      "source_url": "https://attack.mitre.org/techniques/T1559/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1559.001 Component Object Model: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559.002",
      "title": "Dynamic Data Exchange",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559.002/",
      "source_url": "https://attack.mitre.org/techniques/T1559/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1559.002 Dynamic Data Exchange: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559.003",
      "title": "XPC Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559.003/",
      "source_url": "https://attack.mitre.org/techniques/T1559/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1559.003 XPC Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559",
      "title": "Inter-Process Communication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559/",
      "source_url": "https://attack.mitre.org/techniques/T1559/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1559 Inter-Process Communication: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560.001",
      "title": "Archive via Utility",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560.001/",
      "source_url": "https://attack.mitre.org/techniques/T1560/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1560.001 Archive via Utility: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560.002",
      "title": "Archive via Library",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560.002/",
      "source_url": "https://attack.mitre.org/techniques/T1560/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1560.002 Archive via Library: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560.003",
      "title": "Archive via Custom Method",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560.003/",
      "source_url": "https://attack.mitre.org/techniques/T1560/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1560.003 Archive via Custom Method: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560",
      "title": "Archive Collected Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560/",
      "source_url": "https://attack.mitre.org/techniques/T1560/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1560 Archive Collected Data: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1561.001",
      "title": "Disk Content Wipe",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1561.001/",
      "source_url": "https://attack.mitre.org/techniques/T1561/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1561.001 Disk Content Wipe: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1561.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1561/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1561.002",
      "title": "Disk Structure Wipe",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1561.002/",
      "source_url": "https://attack.mitre.org/techniques/T1561/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1561.002 Disk Structure Wipe: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1561.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1561/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1561",
      "title": "Disk Wipe",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1561/",
      "source_url": "https://attack.mitre.org/techniques/T1561/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1561 Disk Wipe: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1561",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1561/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.001",
      "title": "Disable or Modify Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.001/",
      "source_url": "https://attack.mitre.org/techniques/T1562/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.001 Disable or Modify Tools: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.002",
      "title": "Disable Windows Event Logging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.002/",
      "source_url": "https://attack.mitre.org/techniques/T1562/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.002 Disable Windows Event Logging: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.003",
      "title": "Impair Command History Logging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.003/",
      "source_url": "https://attack.mitre.org/techniques/T1562/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.003 Impair Command History Logging: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.004",
      "title": "Disable or Modify System Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.004/",
      "source_url": "https://attack.mitre.org/techniques/T1562/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.004 Disable or Modify System Firewall: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.006",
      "title": "Indicator Blocking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.006/",
      "source_url": "https://attack.mitre.org/techniques/T1562/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.006 Indicator Blocking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.007",
      "title": "Disable or Modify Cloud Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.007/",
      "source_url": "https://attack.mitre.org/techniques/T1562/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.007 Disable or Modify Cloud Firewall: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1562.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.008",
      "title": "Disable or Modify Cloud Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.008/",
      "source_url": "https://attack.mitre.org/techniques/T1562/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.008 Disable or Modify Cloud Logs: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1562.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.009",
      "title": "Safe Mode Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.009/",
      "source_url": "https://attack.mitre.org/techniques/T1562/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.009 Safe Mode Boot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.010",
      "title": "Downgrade Attack",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.010/",
      "source_url": "https://attack.mitre.org/techniques/T1562/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.010 Downgrade Attack: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.011",
      "title": "Spoof Security Alerting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.011/",
      "source_url": "https://attack.mitre.org/techniques/T1562/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.011 Spoof Security Alerting: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.012",
      "title": "Disable or Modify Linux Audit System",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.012/",
      "source_url": "https://attack.mitre.org/techniques/T1562/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562.012 Disable or Modify Linux Audit System: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562",
      "title": "Impair Defenses",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562/",
      "source_url": "https://attack.mitre.org/techniques/T1562/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1562 Impair Defenses: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1563.001",
      "title": "SSH Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1563.001/",
      "source_url": "https://attack.mitre.org/techniques/T1563/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1563.001 SSH Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1563.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1563/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1563.002",
      "title": "RDP Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1563.002/",
      "source_url": "https://attack.mitre.org/techniques/T1563/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1563.002 RDP Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1563.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1563/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1563",
      "title": "Remote Service Session Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1563/",
      "source_url": "https://attack.mitre.org/techniques/T1563/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1563 Remote Service Session Hijacking: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1563",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1563/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.001",
      "title": "Hidden Files and Directories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.001/",
      "source_url": "https://attack.mitre.org/techniques/T1564/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.001 Hidden Files and Directories: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.002",
      "title": "Hidden Users",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.002/",
      "source_url": "https://attack.mitre.org/techniques/T1564/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.002 Hidden Users: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.003",
      "title": "Hidden Window",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.003/",
      "source_url": "https://attack.mitre.org/techniques/T1564/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.003 Hidden Window: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.004",
      "title": "NTFS File Attributes",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.004/",
      "source_url": "https://attack.mitre.org/techniques/T1564/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.004 NTFS File Attributes: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.005",
      "title": "Hidden File System",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.005/",
      "source_url": "https://attack.mitre.org/techniques/T1564/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.005 Hidden File System: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.006",
      "title": "Run Virtual Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.006/",
      "source_url": "https://attack.mitre.org/techniques/T1564/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.006 Run Virtual Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.007",
      "title": "VBA Stomping",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.007/",
      "source_url": "https://attack.mitre.org/techniques/T1564/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.007 VBA Stomping: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.008",
      "title": "Email Hiding Rules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.008/",
      "source_url": "https://attack.mitre.org/techniques/T1564/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.008 Email Hiding Rules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.009",
      "title": "Resource Forking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.009/",
      "source_url": "https://attack.mitre.org/techniques/T1564/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.009 Resource Forking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.010",
      "title": "Process Argument Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.010/",
      "source_url": "https://attack.mitre.org/techniques/T1564/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.010 Process Argument Spoofing: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.011",
      "title": "Ignore Process Interrupts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.011/",
      "source_url": "https://attack.mitre.org/techniques/T1564/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.011 Ignore Process Interrupts: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.012",
      "title": "File/Path Exclusions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.012/",
      "source_url": "https://attack.mitre.org/techniques/T1564/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564.012 File/Path Exclusions: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.013",
      "title": "Bind Mounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.013/",
      "source_url": "https://attack.mitre.org/techniques/T1564/013/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1564.013 Bind Mounts: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.014",
      "title": "Extended Attributes",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.014/",
      "source_url": "https://attack.mitre.org/techniques/T1564/014/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1564.014 Extended Attributes: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564",
      "title": "Hide Artifacts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564/",
      "source_url": "https://attack.mitre.org/techniques/T1564/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1564 Hide Artifacts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565.001",
      "title": "Stored Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565.001/",
      "source_url": "https://attack.mitre.org/techniques/T1565/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1565.001 Stored Data Manipulation: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565.002",
      "title": "Transmitted Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565.002/",
      "source_url": "https://attack.mitre.org/techniques/T1565/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1565.002 Transmitted Data Manipulation: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565.003",
      "title": "Runtime Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565.003/",
      "source_url": "https://attack.mitre.org/techniques/T1565/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1565.003 Runtime Data Manipulation: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565",
      "title": "Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565/",
      "source_url": "https://attack.mitre.org/techniques/T1565/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1565 Data Manipulation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.001",
      "title": "Spearphishing Attachment",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.001/",
      "source_url": "https://attack.mitre.org/techniques/T1566/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1566.001 Spearphishing Attachment: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.002",
      "title": "Spearphishing Link",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.002/",
      "source_url": "https://attack.mitre.org/techniques/T1566/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1566.002 Spearphishing Link: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.003",
      "title": "Spearphishing via Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.003/",
      "source_url": "https://attack.mitre.org/techniques/T1566/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1566.003 Spearphishing via Service: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.004",
      "title": "Spearphishing Voice",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.004/",
      "source_url": "https://attack.mitre.org/techniques/T1566/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1566.004 Spearphishing Voice: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566",
      "title": "Phishing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566/",
      "source_url": "https://attack.mitre.org/techniques/T1566/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1566 Phishing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.001",
      "title": "Exfiltration to Code Repository",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.001/",
      "source_url": "https://attack.mitre.org/techniques/T1567/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1567.001 Exfiltration to Code Repository: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1567.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.002",
      "title": "Exfiltration to Cloud Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.002/",
      "source_url": "https://attack.mitre.org/techniques/T1567/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1567.002 Exfiltration to Cloud Storage: description, detection logic, threat actors, correlated…",
      "tags": [
        "ai-security",
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1567.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.003",
      "title": "Exfiltration to Text Storage Sites",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.003/",
      "source_url": "https://attack.mitre.org/techniques/T1567/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1567.003 Exfiltration to Text Storage Sites: description, detection logic, threat…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1567.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.004",
      "title": "Exfiltration Over Webhook",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.004/",
      "source_url": "https://attack.mitre.org/techniques/T1567/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1567.004 Exfiltration Over Webhook: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1567.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567",
      "title": "Exfiltration Over Web Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567/",
      "source_url": "https://attack.mitre.org/techniques/T1567/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1567 Exfiltration Over Web Service: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1567",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568.001",
      "title": "Fast Flux DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568.001/",
      "source_url": "https://attack.mitre.org/techniques/T1568/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1568.001 Fast Flux DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568.002",
      "title": "Domain Generation Algorithms",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568.002/",
      "source_url": "https://attack.mitre.org/techniques/T1568/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1568.002 Domain Generation Algorithms: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568.003",
      "title": "DNS Calculation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568.003/",
      "source_url": "https://attack.mitre.org/techniques/T1568/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1568.003 DNS Calculation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568",
      "title": "Dynamic Resolution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568/",
      "source_url": "https://attack.mitre.org/techniques/T1568/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1568 Dynamic Resolution: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569.001",
      "title": "Launchctl",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569.001/",
      "source_url": "https://attack.mitre.org/techniques/T1569/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1569.001 Launchctl: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569.002",
      "title": "Service Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569.002/",
      "source_url": "https://attack.mitre.org/techniques/T1569/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1569.002 Service Execution: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569.003",
      "title": "Systemctl",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569.003/",
      "source_url": "https://attack.mitre.org/techniques/T1569/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1569.003 Systemctl: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569",
      "title": "System Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569/",
      "source_url": "https://attack.mitre.org/techniques/T1569/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1569 System Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1570",
      "title": "Lateral Tool Transfer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1570/",
      "source_url": "https://attack.mitre.org/techniques/T1570/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1570 Lateral Tool Transfer: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1570",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1570/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1571",
      "title": "Non-Standard Port",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1571/",
      "source_url": "https://attack.mitre.org/techniques/T1571/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1571 Non-Standard Port: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1571",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1571/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1572",
      "title": "Protocol Tunneling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1572/",
      "source_url": "https://attack.mitre.org/techniques/T1572/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1572 Protocol Tunneling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1572",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1572/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1573.001",
      "title": "Symmetric Cryptography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1573.001/",
      "source_url": "https://attack.mitre.org/techniques/T1573/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1573.001 Symmetric Cryptography: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1573.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1573/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1573.002",
      "title": "Asymmetric Cryptography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1573.002/",
      "source_url": "https://attack.mitre.org/techniques/T1573/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1573.002 Asymmetric Cryptography: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1573.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1573/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1573",
      "title": "Encrypted Channel",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1573/",
      "source_url": "https://attack.mitre.org/techniques/T1573/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1573 Encrypted Channel: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1573",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1573/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.001",
      "title": "DLL Search Order Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.001/",
      "source_url": "https://attack.mitre.org/techniques/T1574/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.001 DLL Search Order Hijacking: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.002",
      "title": "DLL Side-Loading",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.002/",
      "source_url": "https://attack.mitre.org/techniques/T1574/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.002 DLL Side-Loading: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.004",
      "title": "Dylib Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.004/",
      "source_url": "https://attack.mitre.org/techniques/T1574/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.004 Dylib Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.005",
      "title": "Executable Installer File Permissions Weakness",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.005/",
      "source_url": "https://attack.mitre.org/techniques/T1574/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.005 Executable Installer File Permissions Weakness…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.006",
      "title": "Dynamic Linker Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.006/",
      "source_url": "https://attack.mitre.org/techniques/T1574/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.006 Dynamic Linker Hijacking: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.007",
      "title": "Path Interception by PATH Environment Variable",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.007/",
      "source_url": "https://attack.mitre.org/techniques/T1574/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.007 Path Interception by PATH Environment Variable…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.008",
      "title": "Path Interception by Search Order Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.008/",
      "source_url": "https://attack.mitre.org/techniques/T1574/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.008 Path Interception by Search Order Hijacking: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.009",
      "title": "Path Interception by Unquoted Path",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.009/",
      "source_url": "https://attack.mitre.org/techniques/T1574/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.009 Path Interception by Unquoted Path: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.010",
      "title": "Services File Permissions Weakness",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.010/",
      "source_url": "https://attack.mitre.org/techniques/T1574/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.010 Services File Permissions Weakness: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.011",
      "title": "Services Registry Permissions Weakness",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.011/",
      "source_url": "https://attack.mitre.org/techniques/T1574/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.011 Services Registry Permissions Weakness: description, detection…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.012",
      "title": "COR_PROFILER",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.012/",
      "source_url": "https://attack.mitre.org/techniques/T1574/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.012 COR_PROFILER: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.013",
      "title": "KernelCallbackTable",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.013/",
      "source_url": "https://attack.mitre.org/techniques/T1574/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.013 KernelCallbackTable: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.014",
      "title": "AppDomainManager",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.014/",
      "source_url": "https://attack.mitre.org/techniques/T1574/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574.014 AppDomainManager: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574",
      "title": "Hijack Execution Flow",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574/",
      "source_url": "https://attack.mitre.org/techniques/T1574/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1574 Hijack Execution Flow: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.001",
      "title": "Create Snapshot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.001/",
      "source_url": "https://attack.mitre.org/techniques/T1578/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1578.001 Create Snapshot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1578.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.002",
      "title": "Create Cloud Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.002/",
      "source_url": "https://attack.mitre.org/techniques/T1578/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1578.002 Create Cloud Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.003",
      "title": "Delete Cloud Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.003/",
      "source_url": "https://attack.mitre.org/techniques/T1578/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1578.003 Delete Cloud Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.004",
      "title": "Revert Cloud Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.004/",
      "source_url": "https://attack.mitre.org/techniques/T1578/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1578.004 Revert Cloud Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.005",
      "title": "Modify Cloud Compute Configurations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.005/",
      "source_url": "https://attack.mitre.org/techniques/T1578/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1578.005 Modify Cloud Compute Configurations: description, detection logic, threat…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578",
      "title": "Modify Cloud Compute Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578/",
      "source_url": "https://attack.mitre.org/techniques/T1578/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1578 Modify Cloud Compute Infrastructure: description, detection logic, threat…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1580",
      "title": "Cloud Infrastructure Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1580/",
      "source_url": "https://attack.mitre.org/techniques/T1580/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1580 Cloud Infrastructure Discovery: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1580",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1580/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.001",
      "title": "Domains",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.001/",
      "source_url": "https://attack.mitre.org/techniques/T1583/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.001 Domains: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.002",
      "title": "DNS Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.002/",
      "source_url": "https://attack.mitre.org/techniques/T1583/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.002 DNS Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.003",
      "title": "Virtual Private Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.003/",
      "source_url": "https://attack.mitre.org/techniques/T1583/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.003 Virtual Private Server: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.004",
      "title": "Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.004/",
      "source_url": "https://attack.mitre.org/techniques/T1583/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.004 Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.005",
      "title": "Botnet",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.005/",
      "source_url": "https://attack.mitre.org/techniques/T1583/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.005 Botnet: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.006",
      "title": "Web Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.006/",
      "source_url": "https://attack.mitre.org/techniques/T1583/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.006 Web Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.007",
      "title": "Serverless",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.007/",
      "source_url": "https://attack.mitre.org/techniques/T1583/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.007 Serverless: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.008",
      "title": "Malvertising",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.008/",
      "source_url": "https://attack.mitre.org/techniques/T1583/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583.008 Malvertising: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583",
      "title": "Acquire Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583/",
      "source_url": "https://attack.mitre.org/techniques/T1583/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1583 Acquire Infrastructure: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.001",
      "title": "Domains",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.001/",
      "source_url": "https://attack.mitre.org/techniques/T1584/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.001 Domains: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.002",
      "title": "DNS Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.002/",
      "source_url": "https://attack.mitre.org/techniques/T1584/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.002 DNS Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.003",
      "title": "Virtual Private Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.003/",
      "source_url": "https://attack.mitre.org/techniques/T1584/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.003 Virtual Private Server: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.004",
      "title": "Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.004/",
      "source_url": "https://attack.mitre.org/techniques/T1584/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.004 Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.005",
      "title": "Botnet",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.005/",
      "source_url": "https://attack.mitre.org/techniques/T1584/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.005 Botnet: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.006",
      "title": "Web Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.006/",
      "source_url": "https://attack.mitre.org/techniques/T1584/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.006 Web Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.007",
      "title": "Serverless",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.007/",
      "source_url": "https://attack.mitre.org/techniques/T1584/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.007 Serverless: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.008",
      "title": "Network Devices",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.008/",
      "source_url": "https://attack.mitre.org/techniques/T1584/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584.008 Network Devices: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584",
      "title": "Compromise Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584/",
      "source_url": "https://attack.mitre.org/techniques/T1584/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1584 Compromise Infrastructure: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585.001",
      "title": "Social Media Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585.001/",
      "source_url": "https://attack.mitre.org/techniques/T1585/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1585.001 Social Media Accounts: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1585.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585.002",
      "title": "Email Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585.002/",
      "source_url": "https://attack.mitre.org/techniques/T1585/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1585.002 Email Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1585.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585.003",
      "title": "Cloud Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585.003/",
      "source_url": "https://attack.mitre.org/techniques/T1585/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1585.003 Cloud Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1585.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585",
      "title": "Establish Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585/",
      "source_url": "https://attack.mitre.org/techniques/T1585/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1585 Establish Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1585",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586.001",
      "title": "Social Media Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586.001/",
      "source_url": "https://attack.mitre.org/techniques/T1586/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1586.001 Social Media Accounts: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1586.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586.002",
      "title": "Email Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586.002/",
      "source_url": "https://attack.mitre.org/techniques/T1586/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1586.002 Email Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1586.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586.003",
      "title": "Cloud Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586.003/",
      "source_url": "https://attack.mitre.org/techniques/T1586/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1586.003 Cloud Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1586.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586",
      "title": "Compromise Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586/",
      "source_url": "https://attack.mitre.org/techniques/T1586/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1586 Compromise Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1586",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.001",
      "title": "Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.001/",
      "source_url": "https://attack.mitre.org/techniques/T1587/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1587.001 Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "mitre-attack",
        "t1587.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.002",
      "title": "Code Signing Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.002/",
      "source_url": "https://attack.mitre.org/techniques/T1587/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1587.002 Code Signing Certificates: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1587.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.003",
      "title": "Digital Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.003/",
      "source_url": "https://attack.mitre.org/techniques/T1587/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1587.003 Digital Certificates: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1587.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.004",
      "title": "Exploits",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.004/",
      "source_url": "https://attack.mitre.org/techniques/T1587/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1587.004 Exploits: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1587.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587",
      "title": "Develop Capabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587/",
      "source_url": "https://attack.mitre.org/techniques/T1587/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1587 Develop Capabilities: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1587",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.001",
      "title": "Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.001/",
      "source_url": "https://attack.mitre.org/techniques/T1588/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.001 Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "mitre-attack",
        "t1588.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.002",
      "title": "Tool",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.002/",
      "source_url": "https://attack.mitre.org/techniques/T1588/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.002 Tool: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.003",
      "title": "Code Signing Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.003/",
      "source_url": "https://attack.mitre.org/techniques/T1588/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.003 Code Signing Certificates: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.004",
      "title": "Digital Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.004/",
      "source_url": "https://attack.mitre.org/techniques/T1588/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.004 Digital Certificates: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.005",
      "title": "Exploits",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.005/",
      "source_url": "https://attack.mitre.org/techniques/T1588/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.005 Exploits: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1588.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.006",
      "title": "Vulnerabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.006/",
      "source_url": "https://attack.mitre.org/techniques/T1588/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.006 Vulnerabilities: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.007",
      "title": "Artificial Intelligence",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.007/",
      "source_url": "https://attack.mitre.org/techniques/T1588/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588.007 Artificial Intelligence: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1588.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588",
      "title": "Obtain Capabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588/",
      "source_url": "https://attack.mitre.org/techniques/T1588/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1588 Obtain Capabilities: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589.001",
      "title": "Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589.001/",
      "source_url": "https://attack.mitre.org/techniques/T1589/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1589.001 Credentials: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1589.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589.002",
      "title": "Email Addresses",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589.002/",
      "source_url": "https://attack.mitre.org/techniques/T1589/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1589.002 Email Addresses: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1589.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589.003",
      "title": "Employee Names",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589.003/",
      "source_url": "https://attack.mitre.org/techniques/T1589/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1589.003 Employee Names: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1589.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589",
      "title": "Gather Victim Identity Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589/",
      "source_url": "https://attack.mitre.org/techniques/T1589/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1589 Gather Victim Identity Information: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "identity-security",
        "mitre-attack",
        "t1589",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.001",
      "title": "Domain Properties",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.001/",
      "source_url": "https://attack.mitre.org/techniques/T1590/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590.001 Domain Properties: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.002",
      "title": "DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.002/",
      "source_url": "https://attack.mitre.org/techniques/T1590/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590.002 DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.003",
      "title": "Network Trust Dependencies",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.003/",
      "source_url": "https://attack.mitre.org/techniques/T1590/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590.003 Network Trust Dependencies: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.004",
      "title": "Network Topology",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.004/",
      "source_url": "https://attack.mitre.org/techniques/T1590/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590.004 Network Topology: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.005",
      "title": "IP Addresses",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.005/",
      "source_url": "https://attack.mitre.org/techniques/T1590/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590.005 IP Addresses: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.006",
      "title": "Network Security Appliances",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.006/",
      "source_url": "https://attack.mitre.org/techniques/T1590/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590.006 Network Security Appliances: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590",
      "title": "Gather Victim Network Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590/",
      "source_url": "https://attack.mitre.org/techniques/T1590/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1590 Gather Victim Network Information: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.001",
      "title": "Determine Physical Locations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.001/",
      "source_url": "https://attack.mitre.org/techniques/T1591/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1591.001 Determine Physical Locations: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.002",
      "title": "Business Relationships",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.002/",
      "source_url": "https://attack.mitre.org/techniques/T1591/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1591.002 Business Relationships: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.003",
      "title": "Identify Business Tempo",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.003/",
      "source_url": "https://attack.mitre.org/techniques/T1591/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1591.003 Identify Business Tempo: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.004",
      "title": "Identify Roles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.004/",
      "source_url": "https://attack.mitre.org/techniques/T1591/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1591.004 Identify Roles: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591",
      "title": "Gather Victim Org Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591/",
      "source_url": "https://attack.mitre.org/techniques/T1591/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1591 Gather Victim Org Information: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.001",
      "title": "Hardware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.001/",
      "source_url": "https://attack.mitre.org/techniques/T1592/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1592.001 Hardware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1592.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.002",
      "title": "Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.002/",
      "source_url": "https://attack.mitre.org/techniques/T1592/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1592.002 Software: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1592.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.003",
      "title": "Firmware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.003/",
      "source_url": "https://attack.mitre.org/techniques/T1592/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1592.003 Firmware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1592.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.004",
      "title": "Client Configurations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.004/",
      "source_url": "https://attack.mitre.org/techniques/T1592/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1592.004 Client Configurations: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1592.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592",
      "title": "Gather Victim Host Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592/",
      "source_url": "https://attack.mitre.org/techniques/T1592/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1592 Gather Victim Host Information: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1592",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593.001",
      "title": "Social Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593.001/",
      "source_url": "https://attack.mitre.org/techniques/T1593/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1593.001 Social Media: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593.002",
      "title": "Search Engines",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593.002/",
      "source_url": "https://attack.mitre.org/techniques/T1593/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1593.002 Search Engines: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593.003",
      "title": "Code Repositories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593.003/",
      "source_url": "https://attack.mitre.org/techniques/T1593/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1593.003 Code Repositories: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593",
      "title": "Search Open Websites/Domains",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593/",
      "source_url": "https://attack.mitre.org/techniques/T1593/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1593 Search Open Websites/Domains: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1594",
      "title": "Search Victim-Owned Websites",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1594/",
      "source_url": "https://attack.mitre.org/techniques/T1594/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1594 Search Victim-Owned Websites: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1594",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1594/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595.001",
      "title": "Scanning IP Blocks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595.001/",
      "source_url": "https://attack.mitre.org/techniques/T1595/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1595.001 Scanning IP Blocks: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595.002",
      "title": "Vulnerability Scanning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595.002/",
      "source_url": "https://attack.mitre.org/techniques/T1595/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1595.002 Vulnerability Scanning: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595.003",
      "title": "Wordlist Scanning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595.003/",
      "source_url": "https://attack.mitre.org/techniques/T1595/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1595.003 Wordlist Scanning: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595",
      "title": "Active Scanning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595/",
      "source_url": "https://attack.mitre.org/techniques/T1595/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1595 Active Scanning: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.001",
      "title": "DNS/Passive DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.001/",
      "source_url": "https://attack.mitre.org/techniques/T1596/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1596.001 DNS/Passive DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.002",
      "title": "WHOIS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.002/",
      "source_url": "https://attack.mitre.org/techniques/T1596/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1596.002 WHOIS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.003",
      "title": "Digital Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.003/",
      "source_url": "https://attack.mitre.org/techniques/T1596/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1596.003 Digital Certificates: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.004",
      "title": "CDNs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.004/",
      "source_url": "https://attack.mitre.org/techniques/T1596/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1596.004 CDNs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.005",
      "title": "Scan Databases",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.005/",
      "source_url": "https://attack.mitre.org/techniques/T1596/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1596.005 Scan Databases: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596",
      "title": "Search Open Technical Databases",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596/",
      "source_url": "https://attack.mitre.org/techniques/T1596/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1596 Search Open Technical Databases: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1597.001",
      "title": "Threat Intel Vendors",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1597.001/",
      "source_url": "https://attack.mitre.org/techniques/T1597/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1597.001 Threat Intel Vendors: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1597.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1597/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1597.002",
      "title": "Purchase Technical Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1597.002/",
      "source_url": "https://attack.mitre.org/techniques/T1597/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1597.002 Purchase Technical Data: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1597.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1597/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1597",
      "title": "Search Closed Sources",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1597/",
      "source_url": "https://attack.mitre.org/techniques/T1597/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1597 Search Closed Sources: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1597",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1597/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.001",
      "title": "Spearphishing Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.001/",
      "source_url": "https://attack.mitre.org/techniques/T1598/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1598.001 Spearphishing Service: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.002",
      "title": "Spearphishing Attachment",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.002/",
      "source_url": "https://attack.mitre.org/techniques/T1598/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1598.002 Spearphishing Attachment: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.003",
      "title": "Spearphishing Link",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.003/",
      "source_url": "https://attack.mitre.org/techniques/T1598/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1598.003 Spearphishing Link: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.004",
      "title": "Spearphishing Voice",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.004/",
      "source_url": "https://attack.mitre.org/techniques/T1598/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1598.004 Spearphishing Voice: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598",
      "title": "Phishing for Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598/",
      "source_url": "https://attack.mitre.org/techniques/T1598/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1598 Phishing for Information: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1599.001",
      "title": "Network Address Translation Traversal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1599.001/",
      "source_url": "https://attack.mitre.org/techniques/T1599/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1599.001 Network Address Translation Traversal: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1599.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1599/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1599",
      "title": "Network Boundary Bridging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1599/",
      "source_url": "https://attack.mitre.org/techniques/T1599/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1599 Network Boundary Bridging: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1599",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1599/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1600.001",
      "title": "Reduce Key Space",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1600.001/",
      "source_url": "https://attack.mitre.org/techniques/T1600/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1600.001 Reduce Key Space: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1600.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1600/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1600.002",
      "title": "Disable Crypto Hardware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1600.002/",
      "source_url": "https://attack.mitre.org/techniques/T1600/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1600.002 Disable Crypto Hardware: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1600.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1600/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1600",
      "title": "Weaken Encryption",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1600/",
      "source_url": "https://attack.mitre.org/techniques/T1600/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1600 Weaken Encryption: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1600",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1600/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1601.001",
      "title": "Patch System Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1601.001/",
      "source_url": "https://attack.mitre.org/techniques/T1601/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1601.001 Patch System Image: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1601.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1601/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1601.002",
      "title": "Downgrade System Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1601.002/",
      "source_url": "https://attack.mitre.org/techniques/T1601/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1601.002 Downgrade System Image: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1601.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1601/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1601",
      "title": "Modify System Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1601/",
      "source_url": "https://attack.mitre.org/techniques/T1601/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1601 Modify System Image: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1601",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1601/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1602.001",
      "title": "SNMP (MIB Dump)",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1602.001/",
      "source_url": "https://attack.mitre.org/techniques/T1602/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1602.001 SNMP (MIB Dump): description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1602.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1602/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1602.002",
      "title": "Network Device Configuration Dump",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1602.002/",
      "source_url": "https://attack.mitre.org/techniques/T1602/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1602.002 Network Device Configuration Dump: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1602.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1602/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1602",
      "title": "Data from Configuration Repository",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1602/",
      "source_url": "https://attack.mitre.org/techniques/T1602/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1602 Data from Configuration Repository: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1602",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1602/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1606.001",
      "title": "Web Cookies",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1606.001/",
      "source_url": "https://attack.mitre.org/techniques/T1606/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1606.001 Web Cookies: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1606.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1606/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1606.002",
      "title": "SAML Tokens",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1606.002/",
      "source_url": "https://attack.mitre.org/techniques/T1606/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1606.002 SAML Tokens: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1606.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1606/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1606",
      "title": "Forge Web Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1606/",
      "source_url": "https://attack.mitre.org/techniques/T1606/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1606 Forge Web Credentials: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1606",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1606/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.001",
      "title": "Upload Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.001/",
      "source_url": "https://attack.mitre.org/techniques/T1608/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608.001 Upload Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "mitre-attack",
        "t1608.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.002",
      "title": "Upload Tool",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.002/",
      "source_url": "https://attack.mitre.org/techniques/T1608/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608.002 Upload Tool: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.003",
      "title": "Install Digital Certificate",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.003/",
      "source_url": "https://attack.mitre.org/techniques/T1608/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608.003 Install Digital Certificate: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.004",
      "title": "Drive-by Target",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.004/",
      "source_url": "https://attack.mitre.org/techniques/T1608/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608.004 Drive-by Target: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.005",
      "title": "Link Target",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.005/",
      "source_url": "https://attack.mitre.org/techniques/T1608/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608.005 Link Target: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.006",
      "title": "SEO Poisoning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.006/",
      "source_url": "https://attack.mitre.org/techniques/T1608/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608.006 SEO Poisoning: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608",
      "title": "Stage Capabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608/",
      "source_url": "https://attack.mitre.org/techniques/T1608/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1608 Stage Capabilities: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1609",
      "title": "Container Administration Command",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1609/",
      "source_url": "https://attack.mitre.org/techniques/T1609/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1609 Container Administration Command: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1609",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1609/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1610",
      "title": "Deploy Container",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1610/",
      "source_url": "https://attack.mitre.org/techniques/T1610/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1610 Deploy Container: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1610",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1610/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1611",
      "title": "Escape to Host",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1611/",
      "source_url": "https://attack.mitre.org/techniques/T1611/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1611 Escape to Host: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1611",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1611/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1612",
      "title": "Build Image on Host",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1612/",
      "source_url": "https://attack.mitre.org/techniques/T1612/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1612 Build Image on Host: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1612",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1612/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1613",
      "title": "Container and Resource Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1613/",
      "source_url": "https://attack.mitre.org/techniques/T1613/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1613 Container and Resource Discovery: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1613",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1613/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1614.001",
      "title": "System Language Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1614.001/",
      "source_url": "https://attack.mitre.org/techniques/T1614/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1614.001 System Language Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1614.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1614/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1614",
      "title": "System Location Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1614/",
      "source_url": "https://attack.mitre.org/techniques/T1614/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1614 System Location Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1614",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1614/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1615",
      "title": "Group Policy Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1615/",
      "source_url": "https://attack.mitre.org/techniques/T1615/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1615 Group Policy Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1615",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1615/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1619",
      "title": "Cloud Storage Object Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1619/",
      "source_url": "https://attack.mitre.org/techniques/T1619/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1619 Cloud Storage Object Discovery: description, detection logic, threat actors, correlated…",
      "tags": [
        "ai-security",
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1619",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1619/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1620",
      "title": "Reflective Code Loading",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1620/",
      "source_url": "https://attack.mitre.org/techniques/T1620/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1620 Reflective Code Loading: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1620",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1620/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1621",
      "title": "Multi-Factor Authentication Request Generation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1621/",
      "source_url": "https://attack.mitre.org/techniques/T1621/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1621 Multi-Factor Authentication Request Generation…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1621",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1621/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1622",
      "title": "Debugger Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1622/",
      "source_url": "https://attack.mitre.org/techniques/T1622/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1622 Debugger Evasion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1622",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1622/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1647",
      "title": "Plist File Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1647/",
      "source_url": "https://attack.mitre.org/techniques/T1647/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1647 Plist File Modification: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1647",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1647/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1648",
      "title": "Serverless Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1648/",
      "source_url": "https://attack.mitre.org/techniques/T1648/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1648 Serverless Execution: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1648",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1648/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1649",
      "title": "Steal or Forge Authentication Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1649/",
      "source_url": "https://attack.mitre.org/techniques/T1649/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1649 Steal or Forge Authentication Certificates: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1649",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1649/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1650",
      "title": "Acquire Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1650/",
      "source_url": "https://attack.mitre.org/techniques/T1650/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1650 Acquire Access: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1650",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1650/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1651",
      "title": "Cloud Administration Command",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1651/",
      "source_url": "https://attack.mitre.org/techniques/T1651/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1651 Cloud Administration Command: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1651",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1651/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1652",
      "title": "Device Driver Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1652/",
      "source_url": "https://attack.mitre.org/techniques/T1652/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1652 Device Driver Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1652",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1652/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1653",
      "title": "Power Settings",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1653/",
      "source_url": "https://attack.mitre.org/techniques/T1653/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1653 Power Settings: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1653",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1653/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1654",
      "title": "Log Enumeration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1654/",
      "source_url": "https://attack.mitre.org/techniques/T1654/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1654 Log Enumeration: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1654",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1654/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1656",
      "title": "Impersonation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1656/",
      "source_url": "https://attack.mitre.org/techniques/T1656/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1656 Impersonation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1656",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1656/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1657",
      "title": "Financial Theft",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1657/",
      "source_url": "https://attack.mitre.org/techniques/T1657/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1657 Financial Theft: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1657",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1657/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1659",
      "title": "Content Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1659/",
      "source_url": "https://attack.mitre.org/techniques/T1659/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1659 Content Injection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1659",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1659/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1665",
      "title": "Hide Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1665/",
      "source_url": "https://attack.mitre.org/techniques/T1665/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1665 Hide Infrastructure: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1665",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1665/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1666",
      "title": "Modify Cloud Resource Hierarchy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1666/",
      "source_url": "https://attack.mitre.org/techniques/T1666/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "T1666 Modify Cloud Resource Hierarchy: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1666",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1666/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1667",
      "title": "Email Bombing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1667/",
      "source_url": "https://attack.mitre.org/techniques/T1667/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1667 Email Bombing: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1667",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1667/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1668",
      "title": "Exclusive Control",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1668/",
      "source_url": "https://attack.mitre.org/techniques/T1668/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1668 Exclusive Control: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1668",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1668/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1669",
      "title": "Wi-Fi Networks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1669/",
      "source_url": "https://attack.mitre.org/techniques/T1669/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1669 Wi-Fi Networks: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1669",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1669/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1671",
      "title": "Cloud Application Integration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1671/",
      "source_url": "https://attack.mitre.org/techniques/T1671/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1671 Cloud Application Integration: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1671",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1671/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1673",
      "title": "Virtual Machine Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1673/",
      "source_url": "https://attack.mitre.org/techniques/T1673/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1673 Virtual Machine Discovery: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1673",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1673/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1674",
      "title": "Input Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1674/",
      "source_url": "https://attack.mitre.org/techniques/T1674/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1674 Input Injection: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1674",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1674/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1675",
      "title": "ESXi Administration Command",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1675/",
      "source_url": "https://attack.mitre.org/techniques/T1675/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1675 ESXi Administration Command: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1675",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1675/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1677",
      "title": "Poisoned Pipeline Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1677/",
      "source_url": "https://attack.mitre.org/techniques/T1677/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1677 Poisoned Pipeline Execution: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1677",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1677/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1678",
      "title": "Delay Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1678/",
      "source_url": "https://attack.mitre.org/techniques/T1678/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1678 Delay Execution: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1678",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1678/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1679",
      "title": "Selective Exclusion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1679/",
      "source_url": "https://attack.mitre.org/techniques/T1679/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1679 Selective Exclusion: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1679",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1679/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1680",
      "title": "Local Storage Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1680/",
      "source_url": "https://attack.mitre.org/techniques/T1680/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1680 Local Storage Discovery: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1680",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1680/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1681",
      "title": "Search Threat Vendor Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1681/",
      "source_url": "https://attack.mitre.org/techniques/T1681/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1681 Search Threat Vendor Data: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1681",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1681/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1682",
      "title": "Query Public AI Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1682/",
      "source_url": "https://attack.mitre.org/techniques/T1682/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1682 Query Public AI Services: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1682",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1682/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1683.001",
      "title": "Written Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1683.001/",
      "source_url": "https://attack.mitre.org/techniques/T1683/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1683.001 Written Content: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1683.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1683/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1683.002",
      "title": "Audio-Visual Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1683.002/",
      "source_url": "https://attack.mitre.org/techniques/T1683/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1683.002 Audio-Visual Content: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1683.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1683/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1683",
      "title": "Generate Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1683/",
      "source_url": "https://attack.mitre.org/techniques/T1683/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1683 Generate Content: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1683",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1683/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1684.001",
      "title": "Impersonation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1684.001/",
      "source_url": "https://attack.mitre.org/techniques/T1684/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1684.001 Impersonation: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1684.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1684/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1684.002",
      "title": "Email Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1684.002/",
      "source_url": "https://attack.mitre.org/techniques/T1684/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1684.002 Email Spoofing: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1684.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1684/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1684",
      "title": "Social Engineering",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1684/",
      "source_url": "https://attack.mitre.org/techniques/T1684/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1684 Social Engineering: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1684",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1684/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.001",
      "title": "Disable or Modify Windows Event Log",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.001/",
      "source_url": "https://attack.mitre.org/techniques/T1685/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.001 Disable or Modify Windows Event Log: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.002",
      "title": "Disable or Modify Cloud Log",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.002/",
      "source_url": "https://attack.mitre.org/techniques/T1685/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.002 Disable or Modify Cloud Log: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1685.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.003",
      "title": "Modify or Spoof Tool UI",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.003/",
      "source_url": "https://attack.mitre.org/techniques/T1685/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.003 Modify or Spoof Tool UI: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.004",
      "title": "Disable or Modify Linux Audit System Log",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.004/",
      "source_url": "https://attack.mitre.org/techniques/T1685/004/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.004 Disable or Modify Linux Audit System Log: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.005",
      "title": "Clear Windows Event Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.005/",
      "source_url": "https://attack.mitre.org/techniques/T1685/005/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.005 Clear Windows Event Logs: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.006",
      "title": "Clear Linux or Mac System Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.006/",
      "source_url": "https://attack.mitre.org/techniques/T1685/006/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.006 Clear Linux or Mac System Logs: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685",
      "title": "Disable or Modify Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685/",
      "source_url": "https://attack.mitre.org/techniques/T1685/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685 Disable or Modify Tools: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686.001",
      "title": "Cloud Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686.001/",
      "source_url": "https://attack.mitre.org/techniques/T1686/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686.001 Cloud Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1686.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686.002",
      "title": "Network Device Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686.002/",
      "source_url": "https://attack.mitre.org/techniques/T1686/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686.002 Network Device Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1686.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686.003",
      "title": "Windows Host Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686.003/",
      "source_url": "https://attack.mitre.org/techniques/T1686/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686.003 Windows Host Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1686.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686",
      "title": "Disable or Modify System Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686/",
      "source_url": "https://attack.mitre.org/techniques/T1686/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686 Disable or Modify System Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1686",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1687",
      "title": "Exploitation for Defense Impairment",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1687/",
      "source_url": "https://attack.mitre.org/techniques/T1687/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1687 Exploitation for Defense Impairment: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1687",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1687/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1688",
      "title": "Safe Mode Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1688/",
      "source_url": "https://attack.mitre.org/techniques/T1688/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1688 Safe Mode Boot: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1688",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1688/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1689",
      "title": "Downgrade Attack",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1689/",
      "source_url": "https://attack.mitre.org/techniques/T1689/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1689 Downgrade Attack: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1689",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1689/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1690",
      "title": "Prevent Command History Logging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1690/",
      "source_url": "https://attack.mitre.org/techniques/T1690/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1690 Prevent Command History Logging: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1690",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1690/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:adversarygraph-docs:unified-rag-mcp",
      "title": "Unified Intelligence RAG and MCP",
      "primary_type": "documentation",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "platform-operator",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph v6.5.0 source release; not part of the older immutable v6.0.0 release",
      "canonical_url": "https://github.com/anpa1200/adversarygraph/blob/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs/unified-rag-and-mcp.md",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "published_at": "2026-07-21",
      "updated_at": "2026-07-21",
      "summary": "Architecture, indexed source coverage, governance, REST API, MCP boundary, analyst workflows, and known limits for AdversaryGraph Unified Intelligence RAG and MCP.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:adversarygraph-docs",
      "alternate_urls": [
        "https://1200km.com/adversarygraph-docs/unified-rag-mcp/"
      ],
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/aeee13dcaec1e2993b9f0969290c9ee414bb4cf6/docs",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:aidebug",
      "title": "AIDebug",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer",
        "cti-analyst"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "1.1.0",
      "applies_to": "released malware triage and reverse-engineering assistant",
      "canonical_url": "https://github.com/anpa1200/AIDebug",
      "source_url": "https://pypi.org/project/1200km-aidebug/",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "AI-assisted malware triage and reverse-engineering tool with ATT&CK candidates, YARA seeds, IOC output, and analyst reports.",
      "tags": [
        "malware-analysis",
        "reverse-engineering",
        "tool",
        "yara"
      ],
      "featured": true,
      "indexable": false,
      "source_platform": "PyPI",
      "source_repository": "https://github.com/anpa1200/AIDebug",
      "original_publication": "https://pypi.org/project/1200km-aidebug/",
      "canonical_owner": "anpa1200",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:auditai",
      "title": "AuditAI",
      "primary_type": "tool",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "1.0.0",
      "applies_to": "authorized Linux host vulnerability assessment",
      "canonical_url": "https://github.com/anpa1200/AuditAI",
      "source_url": "https://pypi.org/project/1200km-auditai/",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Linux host vulnerability assessment tool with optional AI-assisted review.",
      "tags": [
        "linux",
        "offensive-security",
        "tool",
        "vulnerability-assessment"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "PyPI",
      "source_repository": "https://github.com/anpa1200/AuditAI",
      "original_publication": "https://pypi.org/project/1200km-auditai/",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:basic-file-information-gathering-script",
      "title": "FileInfo",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "current-development",
      "maturity": "beta",
      "evidence_level": "source-backed",
      "applies_to": "source repository; the advertised PyPI target was not published when verified",
      "canonical_url": "https://github.com/anpa1200/Basic-File-Information-Gathering-Script",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "First-pass file metadata, hashing, strings, entropy, YARA, and static-triage utility under development.",
      "tags": [
        "current-development",
        "file-triage",
        "malware-analysis",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Basic-File-Information-Gathering-Script",
      "original_publication": "https://github.com/anpa1200/Basic-File-Information-Gathering-Script",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "current-development"
    },
    {
      "id": "github-com:anpa1200:lpi",
      "title": "lpi",
      "primary_type": "tool",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/lpi",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical repository retained for reference and marked archived by GitHub.",
      "tags": [
        "archived",
        "offensive-security",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/lpi",
      "original_publication": "https://github.com/anpa1200/lpi",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:malware-analysis",
      "title": "Malware_analysis",
      "primary_type": "research",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/Malware_analysis",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical malware-analysis repository retained for reference and marked archived by GitHub.",
      "tags": [
        "archived",
        "malware-analysis",
        "research"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Malware_analysis",
      "original_publication": "https://github.com/anpa1200/Malware_analysis",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:networking",
      "title": "Networking",
      "primary_type": "research",
      "primary_domain": "network-security",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/Networking",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical networking repository retained for reference and marked archived by GitHub.",
      "tags": [
        "archived",
        "networking",
        "research"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Networking",
      "original_publication": "https://github.com/anpa1200/Networking",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:pe-import-analyzer",
      "title": "PE Import Analyzer",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "current-development",
      "maturity": "beta",
      "evidence_level": "source-backed",
      "applies_to": "source repository; the advertised PyPI target was not published when verified",
      "canonical_url": "https://github.com/anpa1200/PE-Import-Analyzer",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "PE import-table capability triage utility under development for malware analysts.",
      "tags": [
        "current-development",
        "malware-analysis",
        "pe",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/PE-Import-Analyzer",
      "original_publication": "https://github.com/anpa1200/PE-Import-Analyzer",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "current-development"
    },
    {
      "id": "github-com:anpa1200:stratus-ai",
      "title": "stratus-ai",
      "primary_type": "tool",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized AWS and GCP security assessment",
      "canonical_url": "https://github.com/anpa1200/stratus-ai",
      "published_at": null,
      "updated_at": null,
      "summary": "Multi-cloud security assessment and detection-coverage tool for authorized AWS and GCP environments.",
      "tags": [
        "aws",
        "cloud-security",
        "gcp",
        "tool"
      ],
      "featured": true,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/stratus-ai",
      "original_publication": "https://github.com/anpa1200/stratus-ai",
      "canonical_owner": "anpa1200",
      "collection_tier": "core",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "github-com:anpa1200:string-analyzer",
      "title": "String Analyzer",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "2.0.0",
      "applies_to": "released binary-string triage utility",
      "canonical_url": "https://github.com/anpa1200/String-Analyzer",
      "source_url": "https://pypi.org/project/string-analyzer/",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Extracts strings, URLs, IP addresses, registry keys, APIs, and analyst prompts from binary files.",
      "tags": [
        "ioc",
        "malware-analysis",
        "static-analysis",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "PyPI",
      "source_repository": "https://github.com/anpa1200/String-Analyzer",
      "original_publication": "https://pypi.org/project/string-analyzer/",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:systemcheck",
      "title": "SystemCheck",
      "primary_type": "tool",
      "primary_domain": "application-security",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/SystemCheck",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical system-checking repository retained for reference and marked archived by GitHub.",
      "tags": [
        "application-security",
        "archived",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/SystemCheck",
      "original_publication": "https://github.com/anpa1200/SystemCheck",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:unpacker",
      "title": "Unpacker",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "current-development",
      "maturity": "beta",
      "evidence_level": "source-backed",
      "applies_to": "source repository; the advertised PyPI target was not published when verified",
      "canonical_url": "https://github.com/anpa1200/Unpacker",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Packer detection and unpacking workflow under development for malware triage.",
      "tags": [
        "current-development",
        "malware-analysis",
        "tool",
        "unpacking"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Unpacker",
      "original_publication": "https://github.com/anpa1200/Unpacker",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "current-development"
    },
    {
      "id": "infosecwriteups-com:adversarygraph-usecases-820d03c3a7ab",
      "title": "Original source ↗",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "released",
      "lifecycle": "currentness-unknown",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "external publication linked from a maintained 1200km index",
      "canonical_url": "https://infosecwriteups.com/adversarygraph-usecases-820d03c3a7ab",
      "published_at": null,
      "updated_at": null,
      "summary": "AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://infosecwriteups.com/adversarygraph-usecases-820d03c3a7ab",
      "canonical_owner": "InfoSec Write-ups / Andrey Pautov",
      "collection_tier": "reference"
    },
    {
      "id": "infosecwriteups-com:from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "title": "Original source ↗",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "released",
      "lifecycle": "currentness-unknown",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "external publication linked from a maintained 1200km index",
      "canonical_url": "https://infosecwriteups.com/from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "published_at": null,
      "updated_at": null,
      "summary": "The harder problem is turning scattered technical evidence into a defensible investigation",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://infosecwriteups.com/from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "canonical_owner": "InfoSec Write-ups / Andrey Pautov",
      "collection_tier": "reference"
    }
  ]
}
