{
  "$schema": "./content-catalog.schema.json",
  "catalog_version": "2.2.0",
  "generated_at": "2026-09-06",
  "scope": "deployable-domain-catalog",
  "controlled_vocabularies": {
    "primary_types": [
      "research",
      "case-study",
      "guide",
      "lab",
      "tool",
      "platform",
      "documentation",
      "reference-entity",
      "generated-reference",
      "article",
      "redirect",
      "mirror",
      "contribution",
      "index",
      "profile",
      "policy"
    ],
    "primary_domains": [
      "threat-intelligence",
      "detection-engineering",
      "threat-hunting",
      "incident-response",
      "malware-analysis",
      "identity-security",
      "offensive-research",
      "cloud-security",
      "security-governance",
      "open-source-intelligence",
      "vulnerability-research",
      "ai-security",
      "application-security",
      "network-security",
      "platform-documentation",
      "professional-profile",
      "site-governance"
    ],
    "audiences": [
      "cti-analyst",
      "detection-engineer",
      "threat-hunter",
      "security-engineer",
      "security-leader",
      "platform-operator",
      "developer",
      "general"
    ],
    "statuses": [
      "released",
      "maintained",
      "current-development",
      "experimental",
      "superseded",
      "archived",
      "submitted",
      "accepted"
    ],
    "lifecycles": [
      "maintained",
      "stable-reference",
      "current-development",
      "preserved",
      "historical",
      "currentness-unknown",
      "superseded",
      "archived"
    ],
    "maturity": [
      "production",
      "stable",
      "beta",
      "experimental",
      "historical",
      "reference"
    ],
    "evidence_levels": [
      "source-backed",
      "lab-validated",
      "release-evidence",
      "externally-accepted",
      "illustrative",
      "unverified"
    ],
    "collection_tiers": [
      "core",
      "reference",
      "archive"
    ]
  },
  "canonical_policy": {
    "identity": "One catalogue item represents one public artefact. Its stable ID is independent of display category, and its canonical URL is unique.",
    "medium_and_local_mirrors": "A locally hosted companion or export is typed as mirror and records the Medium publication as source_url. The 1200km archive URL is the preferred stable URL when it contains durable local context or assets; otherwise the external publication remains canonical. Duplicate source links are not emitted as second items.",
    "trainsec_permitted_mirrors": "Each permitted TrainSec reproduction uses the exact TrainSec source URL as canonical identity, records the 1200km mirror route as an alternate URL, remains available through the local TrainSec hub, and is excluded from 1200km sitemaps, feeds, and full-site search.",
    "versioned_material": "Version-specific pages remain public only with an explicit version or applies_to boundary. Superseded material requires an archive reason and a visible historical or archive notice.",
    "redirects": "Legacy URLs are aliases, not independent catalogue items. They remain noindex redirects to the maintained canonical identity."
  },
  "declared_collections": [
    {
      "id": "collection:trainsec-library",
      "name": "TrainSec Knowledge Library externally canonical permitted mirrors",
      "canonical_prefix": "https://1200km.com/articles/trainsec/",
      "sitemap_url": "https://trainsec.net/library/",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "source_url": "https://trainsec.net/library/"
    },
    {
      "id": "collection:adversarygraph-docs",
      "name": "AdversaryGraph Documentation",
      "canonical_prefix": "https://1200km.com/adversarygraph-docs/",
      "sitemap_url": "https://1200km.com/adversarygraph-docs/sitemap.xml",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "collection_tier": "reference",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs"
    },
    {
      "id": "collection:cti-analyst-field-manual",
      "name": "CTI Analyst Field Manual",
      "canonical_prefix": "https://1200km.com/cti-analyst-field-manual/",
      "sitemap_url": "https://1200km.com/cti-analyst-field-manual/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "current CTI analyst practice",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual"
    },
    {
      "id": "collection:israel-government-threat-actors-cti",
      "name": "Israel Government Threat Actors CTI",
      "canonical_prefix": "https://1200km.com/israel-government-threat-actors-cti/",
      "sitemap_url": "https://1200km.com/israel-government-threat-actors-cti/sitemap.xml",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "public-source regional threat research",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti"
    },
    {
      "id": "collection:anomaly-detection-atlas",
      "name": "Anomaly Detection Atlas",
      "canonical_prefix": "https://1200km.com/anomaly-detection-atlas/",
      "sitemap_url": "https://1200km.com/anomaly-detection-atlas/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "current anomaly-detection practice",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas"
    },
    {
      "id": "collection:insider-threat-detection",
      "name": "Insider Threat Detection Engineering Guide",
      "canonical_prefix": "https://1200km.com/insider-threat-detection/",
      "sitemap_url": "https://1200km.com/insider-threat-detection/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "current insider-threat detection practice",
      "source_url": "https://github.com/anpa1200/insider-threat-detection"
    },
    {
      "id": "collection:operation-desert-hydra",
      "name": "Operation Desert Hydra",
      "canonical_prefix": "https://1200km.com/operation-desert-hydra/",
      "sitemap_url": "https://1200km.com/operation-desert-hydra/sitemap.xml",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "collection_tier": "core",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra"
    },
    {
      "id": "collection:opencti-intelligent-shield",
      "name": "OpenCTI Intelligent Shield",
      "canonical_prefix": "https://1200km.com/opencti-intelligent-shield/",
      "sitemap_url": "https://1200km.com/opencti-intelligent-shield/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "OpenCTI deployment and enrichment workflows",
      "source_url": "https://github.com/anpa1200/opencti-intelligent-shield"
    },
    {
      "id": "collection:cti-as-code",
      "name": "CTI as Code",
      "canonical_prefix": "https://1200km.com/CTI_as_a_Code/",
      "sitemap_url": "https://1200km.com/CTI_as_a_Code/sitemap.xml",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "collection_tier": "reference",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code"
    },
    {
      "id": "collection:customer-driven-ai-cti",
      "name": "Customer-Driven AI CTI Project",
      "canonical_prefix": "https://1200km.com/customer-driven-ai-cti-project/",
      "sitemap_url": "https://1200km.com/customer-driven-ai-cti-project/sitemap.xml",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "lifecycle": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "collection_tier": "reference",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project"
    },
    {
      "id": "collection:medium-export",
      "name": "1200km Article Archive",
      "canonical_prefix": "https://1200km.com/articles/",
      "sitemap_url": "https://1200km.com/articles/sitemap.xml",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "lifecycle": "currentness-unknown",
      "maturity": "reference",
      "evidence_level": "unverified",
      "collection_tier": "archive",
      "applies_to": "canonical local article pages with original publication URLs retained as provenance",
      "source_url": "https://github.com/anpa1200/medium-blog-navigation"
    }
  ],
  "aliases": [
    {
      "alias_url": "https://1200km.com/threatmapper/",
      "canonical_url": "https://1200km.com/adversarygraph/",
      "status": "superseded",
      "reason": "Historical product route retained as a redirect to AdversaryGraph."
    },
    {
      "alias_url": "https://1200km.com/threatmapper-docs/",
      "canonical_url": "https://1200km.com/adversarygraph-docs/",
      "status": "superseded",
      "prefix": true,
      "reason": "Historical documentation tree retained as noindex redirects to AdversaryGraph documentation."
    },
    {
      "alias_url": "https://1200km.com/threatmapper.html",
      "canonical_url": "https://1200km.com/adversarygraph/",
      "status": "superseded",
      "reason": "ThreatMapper is the historical product name replaced by AdversaryGraph."
    },
    {
      "alias_url": "https://1200km.com/threatmapper-web.html",
      "canonical_url": "https://1200km.com/adversarygraph-web-guide.html",
      "status": "superseded",
      "reason": "Historical public-workspace URL retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/threatmapper-web-guide.html",
      "canonical_url": "https://1200km.com/adversarygraph-web-guide.html",
      "status": "superseded",
      "reason": "Historical guide URL retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/articles/threatmapper-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform.html",
      "canonical_url": "https://1200km.com/articles/adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "status": "superseded",
      "reason": "Historical article slug retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/articles/threatmapper-v2-self-hosted-ai-cti-platform.html",
      "canonical_url": "https://1200km.com/articles/adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "status": "superseded",
      "reason": "Historical article slug retained as a redirect."
    },
    {
      "alias_url": "https://1200km.com/cyber-knowledge/short-guides/",
      "canonical_url": "https://1200km.com/cyber-knowledge/helping-materials/",
      "status": "superseded",
      "reason": "Short Guides were consolidated into the canonical Helping Materials collection."
    }
  ],
  "inventory": {
    "item_count": 1940,
    "indexable_count": 1842,
    "external_count": 98,
    "by_primary_type": {
      "article": 190,
      "case-study": 48,
      "contribution": 1,
      "documentation": 169,
      "generated-reference": 713,
      "guide": 172,
      "index": 107,
      "lab": 49,
      "mirror": 90,
      "platform": 1,
      "policy": 2,
      "profile": 2,
      "reference-entity": 175,
      "research": 209,
      "tool": 12
    },
    "by_primary_domain": {
      "ai-security": 30,
      "application-security": 65,
      "cloud-security": 36,
      "detection-engineering": 74,
      "identity-security": 130,
      "incident-response": 2,
      "malware-analysis": 63,
      "network-security": 28,
      "offensive-research": 61,
      "open-source-intelligence": 4,
      "platform-documentation": 89,
      "professional-profile": 4,
      "security-governance": 1,
      "site-governance": 82,
      "threat-hunting": 4,
      "threat-intelligence": 1261,
      "vulnerability-research": 6
    },
    "by_status": {
      "archived": 4,
      "current-development": 4,
      "experimental": 1,
      "maintained": 1728,
      "released": 202,
      "superseded": 1
    },
    "by_lifecycle": {
      "archived": 4,
      "current-development": 4,
      "currentness-unknown": 85,
      "historical": 5,
      "maintained": 627,
      "preserved": 87,
      "stable-reference": 1127,
      "superseded": 1
    },
    "by_evidence_level": {
      "externally-accepted": 1,
      "illustrative": 11,
      "lab-validated": 55,
      "release-evidence": 87,
      "source-backed": 1592,
      "unverified": 194
    },
    "by_collection_tier": {
      "archive": 176,
      "core": 68,
      "reference": 1696
    }
  },
  "items": [
    {
      "id": "site:home",
      "title": "Threat intelligence that turns into detection.",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "1200km current public portfolio",
      "canonical_url": "https://1200km.com/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Threat-intelligence research by Andrey Pautov: adversary behavior, ATT&CK mapping, malware analysis, detection engineering, and validated security tools.",
      "tags": [
        "author:Andrey Pautov",
        "detection-content",
        "detection-engineering",
        "index",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:about.html",
      "title": "Andrey Pautov",
      "primary_type": "profile",
      "primary_domain": "professional-profile",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current professional profile",
      "canonical_url": "https://1200km.com/about.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Meet Andrey Pautov, a threat-intelligence research engineer focused on adversary profiling, ATT&CK mapping, malware analysis, and detection-ready outcomes.",
      "tags": [
        "author:Andrey Pautov",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "profile",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/about.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:adversarygraph-docs",
      "title": "CTI-to-detection workbench for teams that need evidence, not guesswork",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Deploy and operate AdversaryGraph v7.0.0 with evidence-led guidance for architecture, CTI workflows, attack simulation, malware analysis, APIs, and validation.",
      "tags": [
        "adversarygraph",
        "attack-emulation",
        "documentation",
        "malware-analysis",
        "malware-behavior",
        "offensive-security",
        "platform-documentation",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:ai-analysis:chat-assistant",
      "title": "AI Chat Assistant",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/ai-analysis/chat-assistant/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AI Chat Assistant. AI Chat Assistant. Every technique in the detail panel has an embedded AI chat. This is not a generic chatbot — it is a threat intelligence…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "embedded-security",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:ai-analysis:domains",
      "title": "Working with All Three ATT&CK Domains",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/ai-analysis/domains/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Working with All Three ATT&CK Domains. Working with All Three ATT&CK Domains. Working with all three ATT&CK domains — Enterprise, Mobile, and ICS",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:ai-analysis:overview",
      "title": "AI Analysis",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/ai-analysis/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AI Analysis. AI Analysis. This is the core feature. Upload a threat report, paste raw text, or submit log / PCAP-derived telemetry and AdversaryGraph extracts…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "detection-content",
        "detection-engineering",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:analyze",
      "title": "Analysis API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/analyze/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Analysis API. Analysis API. Submit a Report",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:compare",
      "title": "Compare API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/compare/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Compare API. Compare API. Jaccard similarity ranking against ATT&CK groups and campaigns.",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:export",
      "title": "Export API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/export/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Export API. Export API. Analysis PDF",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:layers",
      "title": "Layers API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/layers/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Layers API. Layers API. Manage named Navigator layers stored in DB 2.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:overview",
      "title": "REST API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "REST API. REST API. AdversaryGraph exposes a full REST API. Drive the entire workflow programmatically — headless analysis, batch comparisons, layer management.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:api:sync",
      "title": "Sync API",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/api/sync/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Sync API. Sync API. Manage ATT&CK data versioning.",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:apt-library:overview",
      "title": "ATT&CK Group Library",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/apt-library/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "ATT&CK Group Library. ATT&CK Group Library. The ATT&CK Group Library gives you a searchable, browsable view of threat groups and named campaigns in the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:architecture",
      "title": "Architecture Diagrams",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/architecture/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Architecture Diagrams. Architecture Diagrams. AdversaryGraph is a self-hosted CTI-to-detection platform. The architecture is intentionally modular: the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:attack-data-model",
      "title": "ATT&CK and STIX Data Model",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/attack-data-model/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "ATT&CK and STIX Data Model. ATT&CK and STIX Data Model. AdversaryGraph stores ATT&CK and ATLAS data in two layers:",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:attack-simulation",
      "title": "Attack Simulation",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/attack-simulation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Attack Simulation. Attack Simulation. Attack Simulation is the AdversaryGraph v5 detection-validation workspace. It",
      "tags": [
        "adversarygraph",
        "attack-emulation",
        "documentation",
        "offensive-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:authentication-and-users",
      "title": "Authentication And Users",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/authentication-and-users/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Authentication And Users. Authentication And Users. The historical v5.5 release introduced enterprise access controls for controlled self-hosted",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:capabilities",
      "title": "Platform Capabilities",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/capabilities/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Platform Capabilities. Platform Capabilities. AdversaryGraph is a self-hosted CTI-to-detection platform. It connects reports, IOCs, malware behavior, threat…",
      "tags": [
        "adversarygraph",
        "documentation",
        "malware-analysis",
        "malware-behavior",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:case-studies-v6",
      "title": "AdversaryGraph v6 Reproducible Case Studies",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "6",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/case-studies-v6/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Reproduce three historical v6 scenarios covering report-to-detection review, asset exposure priority, and controlled simulation with explicit confidence limits.",
      "tags": [
        "adversarygraph",
        "case-study",
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "platform-documentation",
        "reverse-engineering",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:case-studies-validation",
      "title": "Case Studies And Validation Examples",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/case-studies-validation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Case Studies And Validation Examples. Case Studies And Validation Examples. These examples show how to validate AdversaryGraph workflows using screenshots…",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:commercial-trust",
      "title": "Commercial Trust",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/commercial-trust/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Commercial Trust. Commercial Trust. AdversaryGraph is being shaped as a commercial-grade, self-hosted CTI-to-detection workbench. This page gives reviewers…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:campaigns",
      "title": "Mode 2 — Campaigns (DB 1)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/campaigns/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Mode 2 — Campaigns (DB 1). Mode 2 — Campaigns (DB 1). Switch to Campaigns (DB 1) and click Compare vs Campaigns. This ranks named operations from the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:group-vs-group",
      "title": "Group vs Group",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/group-vs-group/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Group vs Group. Group vs Group. The Group vs Group page lets you compare up to 6 APT groups simultaneously, rather than comparing your own TTP layer against…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:groups",
      "title": "Mode 1 — Groups (DB 1)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/groups/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Mode 1 — Groups (DB 1). Mode 1 — Groups (DB 1). With techniques selected in Navigator (or injected from an AI analysis), navigate to Compare, select Groups…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:overview",
      "title": "Group & Campaign Similarity Deep-Dive",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Group & Campaign Similarity Deep-Dive. Group & Campaign Similarity Deep-Dive. AdversaryGraph compares a selected technique set with known ATT&CK group and…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:compare:reports",
      "title": "Mode 3 — Reports (DB 2)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/compare/reports/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Mode 3 — Reports (DB 2). Mode 3 — Reports (DB 2). Switch to Reports (DB 2). The left panel lists every AI analysis you have ever run. Click any report to…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:atomic-red-team",
      "title": "AdversaryGraph vs Atomic Red Team",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/atomic-red-team/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs Atomic Red Team. AdversaryGraph vs Atomic Red Team. Atomic Red Team provides small, focused tests mapped to MITRE ATT&CK techniques. It is…",
      "tags": [
        "adversarygraph",
        "attack-emulation",
        "documentation",
        "mitre-attack",
        "offensive-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:attack-navigator",
      "title": "AdversaryGraph vs ATT&CK Navigator",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/attack-navigator/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs ATT&CK Navigator. AdversaryGraph vs ATT&CK Navigator. MITRE ATT&CK Navigator is the standard matrix/layer visualization tool for ATT&CK…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:malware-sandboxes",
      "title": "AdversaryGraph vs Malware Sandboxes",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/malware-sandboxes/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs Malware Sandboxes. AdversaryGraph vs Malware Sandboxes. Malware sandboxes such as Cuckoo, CAPE, ANY.RUN, and Joe Sandbox focus on malware…",
      "tags": [
        "adversarygraph",
        "documentation",
        "malware-analysis",
        "malware-behavior",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:misp",
      "title": "AdversaryGraph vs MISP",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/misp/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs MISP. AdversaryGraph vs MISP. MISP is a threat intelligence sharing platform centered on events, attributes, galaxies, taxonomies…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:opencti",
      "title": "AdversaryGraph vs OpenCTI",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/opencti/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph vs OpenCTI. AdversaryGraph vs OpenCTI. OpenCTI is a full cyber threat intelligence platform built around a knowledge graph, entities…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:comparisons:overview",
      "title": "Comparison Overview",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/comparisons/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Comparison Overview. Comparison Overview. AdversaryGraph is not positioned as a replacement for mature CTI, sharing, ATT&CK visualization, emulation, or…",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:cve-cvss-intelligence",
      "title": "CVE Library",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/cve-cvss-intelligence/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "CVE Library. CVE Library. AdversaryGraph stores vulnerability intelligence as first-class data so analysts can review strict relationships between:",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:evaluation",
      "title": "Evaluation and Analyst Validation",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/evaluation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Evaluation and Analyst Validation. Evaluation and Analyst Validation. AdversaryGraph output is a first-pass structured analysis, not a substitute for analyst…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:full-flow",
      "title": "Get Started: Full Deployment Flow",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/full-flow/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Get Started: Full Deployment Flow. Get Started: Full Deployment Flow. This page covers the complete first-run path for the self-hosted AdversaryGraph…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:functionality-parity",
      "title": "Platform Scope",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/functionality-parity/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Platform Scope. Platform Scope. This documentation describes the self-hosted AdversaryGraph platform.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:generating-reports",
      "title": "Generating PDF Reports",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/generating-reports/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Generating PDF Reports. Generating PDF Reports. Generating PDF Reports — download from analysis results bar",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:getting-started",
      "title": "Setup (10 Minutes)",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/getting-started/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Setup (10 Minutes). Setup (10 Minutes). Prerequisites",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:intro",
      "title": "AdversaryGraph",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/intro/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph. AdversaryGraph. Current source release: v7.0.0; published tag: v7.0.0 · Project Hub · Commercial Trust · Architecture · Platform Guide ·…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:malware-analysis",
      "title": "Malware Analysis",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/malware-analysis/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Malware Analysis. Malware Analysis. Introduced in v4.0 and available in current v7.0.0, Malware Analysis",
      "tags": [
        "adversarygraph",
        "documentation",
        "malware-analysis",
        "malware-behavior",
        "platform-documentation",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:import-export",
      "title": "Import & Export",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/import-export/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Import & Export. Import & Export. Import an Existing Layer",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:layers",
      "title": "Saving and Loading Named Layers",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/layers/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Saving and Loading Named Layers. Saving and Loading Named Layers. Once you have built a TTP layer — through AI analysis, manual selection, or an APT campaign…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:overview",
      "title": "ATT&CK Matrix Workspace",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "ATT&CK Matrix Workspace. ATT&CK Matrix Workspace. The matrix is the central workspace for exploring ATT&CK, selecting techniques manually, overlaying group…",
      "tags": [
        "adversarygraph",
        "documentation",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:navigator:ttp-details",
      "title": "TTP Detail Panel",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/navigator/ttp-details/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "TTP Detail Panel. TTP Detail Panel. Every technique ID displayed anywhere in AdversaryGraph is clickable. Clicking one opens a slide-in detail panel on the…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:observability-security-validation",
      "title": "Observability, Security Scanning, And Validation Examples",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/observability-security-validation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Observability, Security Scanning, And Validation Examples. Observability, Security Scanning, And Validation Examples. AdversaryGraph includes operator-facing…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:operations:intelligence-pipeline",
      "title": "Intelligence Pipeline",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/operations/intelligence-pipeline/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Intelligence Pipeline. Intelligence Pipeline. AdversaryGraph includes an analyst-controlled collection, enrichment, and detection",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:operations:operations-overview",
      "title": "Operational Intelligence Workbench",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/operations/operations-overview/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Operational Intelligence Workbench. Operational Intelligence Workbench. AdversaryGraph adds persistent operational workflows beyond ATT&CK exploration.",
      "tags": [
        "adversarygraph",
        "documentation",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:platform-guide",
      "title": "AdversaryGraph Platform Guide",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/platform-guide/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph Platform Guide. AdversaryGraph Platform Guide. Current v7.0.0 platform documentation. AdversaryGraph is an analyst-assistance",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:release-readiness-v6",
      "title": "AdversaryGraph v6 Release Readiness",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "6",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/release-readiness-v6/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Review the historical v6 automated gate, deployment go/no-go criteria, and mandatory safety boundaries used to distinguish evidence from unsupported claims.",
      "tags": [
        "adversarygraph",
        "detection-content",
        "detection-engineering",
        "documentation",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "platform-documentation",
        "reverse-engineering",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:roadmap",
      "title": "Roadmap",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/roadmap/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Roadmap. Roadmap. Current source release: AdversaryGraph v7.0.0; published tag: v7.0.0.",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:security",
      "title": "Security and Deployment",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/security/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Security and Deployment. Security and Deployment. Self-Hosted Deployment Security",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:tips",
      "title": "Tips for Analysts",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/tips/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Tips for Analysts. Tips for Analysts. Calibrate your confidence threshold. Treat < 50% confidence as noise until you validate it manually. The LLM is trying…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "documentation",
        "llm-and-agent-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:two-databases",
      "title": "Two Databases: Actor Profiles and Your Report Library",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/two-databases/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Two Databases: Actor Profiles and Your Report Library. Two Databases: Actor Profiles and Your Report Library. AdversaryGraph maintains two separate databases…",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:unified-rag-mcp",
      "title": "Unified Intelligence RAG and MCP",
      "primary_type": "documentation",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "platform-operator",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "published AdversaryGraph v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/unified-rag-mcp/",
      "source_url": "https://github.com/anpa1200/adversarygraph/blob/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs/unified-rag-and-mcp.md",
      "published_at": "2026-07-21",
      "updated_at": "2026-08-14",
      "summary": "Architecture, indexed source coverage, governance, REST API, MCP boundary, analyst workflows, and known limits for AdversaryGraph Unified Intelligence RAG and…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "author:Andrey Pautov",
        "documentation",
        "llm-and-agent-security",
        "platform-documentation",
        "security-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "alternate_urls": [
        "https://github.com/anpa1200/adversarygraph/blob/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs/unified-rag-and-mcp.md"
      ],
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/blob/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs/unified-rag-and-mcp.md",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases",
      "title": "AdversaryGraph Use Cases",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph Use Cases. AdversaryGraph Use Cases. This page organizes AdversaryGraph workflows into three levels:",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-detection-content-from-intel",
      "title": "Defense: Create Detection Content From CTI",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-detection-content-from-intel/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Create Detection Content From CTI. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-executive-risk-coverage-report",
      "title": "Defense: Executive Risk And Coverage Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-executive-risk-coverage-report/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Executive Risk And Coverage Report. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-ioc-enrichment-pipeline",
      "title": "Defense: Build IOC Enrichment Pipeline",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-ioc-enrichment-pipeline/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Build IOC Enrichment Pipeline. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-mitre-coverage-baseline",
      "title": "Defense: Build MITRE Coverage Baseline",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-mitre-coverage-baseline/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Build MITRE Coverage Baseline. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:defense-sector-detection-roadmap",
      "title": "Defense: Create Sector-Based Detection Roadmap",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/defense-sector-detection-roadmap/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Defense: Create Sector-Based Detection Roadmap. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-build-sector-brief",
      "title": "Build A Sector Threat Brief",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-build-sector-brief/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Build A Sector Threat Brief. Build A Sector Threat Brief. Build Sector Threat Brief workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-compare-incident-to-actors",
      "title": "Compare Incident TTPs To Actors",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-compare-incident-to-actors/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Compare Incident TTPs To Actors. Compare Incident TTPs To Actors. Compare Incident TTPs to Actors workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-compare-two-reports",
      "title": "Compare Two Reports",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-compare-two-reports/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Compare Two Reports. Compare Two Reports. Compare Two Reports workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-enrich-actor-iocs",
      "title": "Enrich Actor IOCs",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-enrich-actor-iocs/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Enrich Actor IOCs. Enrich Actor IOCs. Enrich Actor IOCs workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-import-misp-json",
      "title": "Import MISP JSON",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-import-misp-json/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Import MISP JSON. Import MISP JSON. Import MISP JSON workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-map-report-to-attack",
      "title": "Map A Report To ATT&CK",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-map-report-to-attack/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Map A Report To ATT&CK. Map A Report To ATT&CK. Map Report to ATT&CK workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "mitre-attack",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-pull-taxii-stix",
      "title": "Pull TAXII Or Import STIX",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-pull-taxii-stix/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Pull TAXII Or Import STIX. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-review-coverage-gap",
      "title": "Review One Coverage Gap",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-review-coverage-gap/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Review One Coverage Gap. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-sync-yara-sigma",
      "title": "Sync YARA And Sigma Feeds",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-sync-yara-sigma/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Sync YARA And Sigma Feeds. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "detection-content",
        "detection-engineering",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:intermediate-use-local-llm",
      "title": "Use A Local LLM For Private Reports",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/intermediate-use-local-llm/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Use A Local LLM For Private Reports. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "case-study",
        "llm-and-agent-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-apt-campaign-cluster",
      "title": "Investigation: Cluster Multiple APT Reports",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-apt-campaign-cluster/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Cluster Multiple APT Reports. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-cloud-incident",
      "title": "Investigation: Cloud And Kubernetes Incident",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-cloud-incident/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Cloud And Kubernetes Incident. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "cloud-and-container-security",
        "cloud-security",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-malware-family",
      "title": "Investigation: Malware Family Behavior Mapping",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-malware-family/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Malware Family Behavior Mapping. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "malware-analysis",
        "malware-behavior",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-ransomware-intrusion",
      "title": "Investigation: From Log To Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-ransomware-intrusion/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: From Log To Report. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "malware-behavior",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:investigation-third-party-report-validation",
      "title": "Investigation: Validate A Third-Party CTI Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/investigation-third-party-report-validation/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Investigation: Validate A Third-Party CTI Report. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-add-custom-ioc-feed",
      "title": "Add A Custom IOC Feed",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-add-custom-ioc-feed/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Add A Custom IOC Feed. Add A Custom IOC Feed. Add Custom IOC Feed workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-check-an-ioc",
      "title": "Check One IOC",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-check-an-ioc/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Check One IOC. Check One IOC. Check One IOC workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-export-pdf-report",
      "title": "Export A PDF Report",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-export-pdf-report/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Export A PDF Report. Export A PDF Report. Export PDF Report workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-import-navigator-layer",
      "title": "Import A Navigator Layer",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-import-navigator-layer/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Import A Navigator Layer. Import A Navigator Layer. Import Navigator Layer workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-open-actor-profile",
      "title": "Open One Actor Profile",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-open-actor-profile/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Open One Actor Profile. Open One Actor Profile. Open Actor Profile workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-open-troubleshooting",
      "title": "Open Troubleshooting For An Error",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-open-troubleshooting/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Open Troubleshooting For An Error. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-run-selftest",
      "title": "Run Deployment Selftest",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-run-selftest/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Run Deployment Selftest. Run Deployment Selftest. Run Deployment Selftest workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-search-ioc-library",
      "title": "Search The IOC Library",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-search-ioc-library/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Search The IOC Library. Search The IOC Library. Search IOC Library workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-show-actor-on-matrix",
      "title": "Show Actor TTPs On The Matrix",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-show-actor-on-matrix/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Show Actor TTPs On The Matrix. Show Actor TTPs On The Matrix. Show Actor TTPs on Matrix workflow",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:use-cases:simple-sync-threatfox",
      "title": "Sync ThreatFox IOCs",
      "primary_type": "case-study",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/use-cases/simple-sync-threatfox/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "Sync ThreatFox IOCs. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "adversarygraph",
        "case-study",
        "platform-documentation",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-docs:visual-guide",
      "title": "AdversaryGraph Visual Guide",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph-docs/visual-guide/",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "published_at": null,
      "updated_at": "2026-07-12",
      "summary": "AdversaryGraph Visual Guide. AdversaryGraph Visual Guide. This guide shows the current AdversaryGraph platform, not only the older",
      "tags": [
        "adversarygraph",
        "documentation",
        "platform-documentation"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:adversarygraph-docs",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph-web-guide.html",
      "title": "Threat Matrix",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "Threat Matrix public ATT&CK workspace",
      "canonical_url": "https://1200km.com/adversarygraph-web-guide.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Threat Matrix. Guide to Threat Matrix: browser-native ATT&CK matrices, group library, TTP overlap scoring, group comparison, coverage…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "author:Andrey Pautov",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/adversarygraph-web-guide.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph",
      "title": "AdversaryGraph",
      "primary_type": "platform",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "platform-operator"
      ],
      "status": "released",
      "maturity": "production",
      "evidence_level": "release-evidence",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph/",
      "published_at": "2026-08-12",
      "updated_at": "2026-08-14",
      "summary": "Explore AdversaryGraph v7.0.0, a self-hosted CTI-to-detection workbench for ATT&CK mapping, IOC/CVE analysis, malware triage, and detection validation.",
      "tags": [
        "adversarygraph",
        "author:Andrey Pautov",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "platform",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "version": "7.0.0",
      "source_url": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/adversarygraph",
      "original_publication": "https://github.com/anpa1200/adversarygraph/tree/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph:full-version-feature-guides.html",
      "title": "AdversaryGraph Full-Version Guide — 31 Modules and Use Cases",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "platform-operator",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph v7.0.0 merged, CI-validated source release, matching the latest published immutable GitHub release v7.0.0",
      "canonical_url": "https://1200km.com/adversarygraph/full-version-feature-guides.html",
      "published_at": "2026-07-23",
      "updated_at": "2026-07-25",
      "summary": "Detailed single-column guide to all 31 governed AdversaryGraph workspaces with prerequisites, step-by-step workflows, outputs, worked use cases, acceptance evidence, screenshots, and explicit source-versus-published release boundaries.",
      "tags": [
        "adversarygraph",
        "case-studies",
        "detection-engineering",
        "guide",
        "platform-operations",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/adversarygraph/full-version-feature-guides.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:adversarygraph:use-cases.html",
      "title": "Use Cases for AI-Assisted CTI, Malware Analysis, ATT&CK Mapping, IOC Investigation, and Detection Handoff",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph analyst workflows",
      "canonical_url": "https://1200km.com/adversarygraph/use-cases.html",
      "published_at": null,
      "updated_at": "2026-07-17",
      "summary": "Use Cases for AI-Assisted CTI, Malware Analysis, ATT&CK Mapping, IOC Investigation, and Detection Handoff. Use Cases for AI-Assisted CTI, Malware Analysis…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "author:Andrey Pautov",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "research",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/adversarygraph/use-cases.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-attack-statistics",
      "title": "AI in Cyberattacks: A Statistical CTI Study of 111 Publications",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "security-leader"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "descriptive publication-level research about documented and discussed AI usage in cyberattacks; not an incident-prevalence estimate",
      "canonical_url": "https://1200km.com/ai-attack-statistics/",
      "published_at": "2026-08-29",
      "updated_at": "2026-08-29",
      "summary": "Analyze 111 publications and 103 eligible CTI records mapping attacker use of AI, evidence strength, research limits, datasets, and reproducible methods.",
      "tags": [
        "ai-security",
        "artificial-intelligence",
        "cti",
        "data-visualization",
        "incident-response",
        "statistics",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "lifecycle": "maintained",
      "source_url": "https://medium.com/@1200km/ai-in-cyberattacks-a-statistical-cti-study-of-114-publications-b8416d856b94",
      "source_platform": "1200km",
      "original_publication": "https://1200km.com/ai-attack-statistics/",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core"
    },
    {
      "id": "site:ai-attack-statistics:dashboard",
      "title": "AI in Cyberattacks: Interactive Statistical CTI Dashboard",
      "primary_type": "tool",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "interactive exploration of the 103-publication primary statistical denominator and its machine-extracted candidates",
      "canonical_url": "https://1200km.com/ai-attack-statistics/dashboard/",
      "published_at": "2026-08-29",
      "updated_at": "2026-08-29",
      "summary": "Explore 31 CTI views and 103 eligible publications on attacker AI use across actors, sectors, behaviors, providers, metrics, and IOC candidates.",
      "tags": [
        "ai-security",
        "artificial-intelligence",
        "cti",
        "dashboard",
        "data-visualization",
        "statistics",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "lifecycle": "maintained",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-attack-statistics/dashboard/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core"
    },
    {
      "id": "site:ai-attack-statistics:data",
      "title": "AI in Cyberattacks: Dataset and Downloads",
      "primary_type": "documentation",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "security-leader",
        "developer"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "governed normalized-data snapshot for reproducible publication-level analysis of AI usage in cyberattacks; candidate fields require source-level analyst validation",
      "canonical_url": "https://1200km.com/ai-attack-statistics/data/",
      "published_at": "2026-08-29",
      "updated_at": "2026-08-29",
      "summary": "Download the governed publication, tag, metric, IOC, quality, SQLite, and workbook snapshots behind the 1200km AI in Cyberattacks statistical CTI study.",
      "tags": [
        "ai-security",
        "artificial-intelligence",
        "cti",
        "dataset",
        "incident-response",
        "reproducible-research",
        "statistics",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "lifecycle": "maintained",
      "alternate_urls": [
        "https://1200km.com/ai-attack-statistics/data/README.md",
        "https://1200km.com/ai-attack-statistics/data/publications.csv",
        "https://1200km.com/ai-attack-statistics/data/tags_long.csv",
        "https://1200km.com/ai-attack-statistics/data/metrics_long.csv",
        "https://1200km.com/ai-attack-statistics/data/iocs_long.csv",
        "https://1200km.com/ai-attack-statistics/data/quality.csv",
        "https://1200km.com/ai-attack-statistics/data/tag_dictionary.csv",
        "https://1200km.com/ai-attack-statistics/data/summary.json",
        "https://1200km.com/ai-attack-statistics/data/ai_attack_statistics.sqlite",
        "https://1200km.com/ai-attack-statistics/data/ai_attack_statistics.xlsx",
        "https://1200km.com/ai-attack-statistics/data/source-collection-report.md",
        "https://1200km.com/ai-attack-statistics/data/source-uniqueness-report.tsv"
      ],
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-attack-statistics/data/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core"
    },
    {
      "id": "site:ai-offensive.html",
      "title": "AI in Offensive Security",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized AI-assisted offensive-security testing",
      "canonical_url": "https://1200km.com/ai-offensive.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "AI in Offensive Security. AI-driven offensive security by Andrey Pautov: HexStrike AI, MCP orchestration, autonomous attack chains…",
      "tags": [
        "ai-security",
        "attack-emulation",
        "author:Andrey Pautov",
        "llm-and-agent-security",
        "offensive-research",
        "offensive-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-offensive.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course.html",
      "title": "AI Security Engineering",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "developer",
        "security-leader"
      ],
      "status": "current-development",
      "maturity": "experimental",
      "evidence_level": "source-backed",
      "applies_to": "the original 15-module AI Security Engineering curriculum whose published modules are usable while the remaining syllabus stays explicitly under construction",
      "canonical_url": "https://1200km.com/ai-security-course.html",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "A market-informed, evidence-grounded AI security engineering course covering complete AI systems, adversarial ML, RAG, agents, MCP, detection, DFIR, and…",
      "tags": [
        "ai-security",
        "course",
        "cybersecurity-education",
        "learning-path",
        "security-training"
      ],
      "featured": false,
      "indexable": true,
      "lifecycle": "current-development",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core"
    },
    {
      "id": "site:ai-security-course:glossary.html",
      "title": "AI, ML & LLM Glossary",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/glossary.html",
      "published_at": null,
      "updated_at": "2026-09-04",
      "summary": "The canonical AI, machine learning, LLM, RAG, agent, MLOps, evaluation, and AI-security terminology used in the AI Security Engineering course.",
      "tags": [
        "ai-security",
        "llm-and-agent-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/glossary.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-00-instructor.html",
      "title": "Instructor Guide",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-00-instructor.html",
      "published_at": null,
      "updated_at": "2026-09-02",
      "summary": "Instructor runbook and assessment guidance for AI Security Engineering Module 00.",
      "tags": [
        "ai-security",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-00-instructor.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-00-workbook.html",
      "title": "AI, ML & LLM Foundations Workbook",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-00-workbook.html",
      "published_at": null,
      "updated_at": "2026-09-02",
      "summary": "Printable learner workbook for Module 00: AI, ML, and LLM Foundations.",
      "tags": [
        "ai-security",
        "llm-and-agent-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-00-workbook.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-00.html",
      "title": "AI, Machine Learning & LLM Foundations",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-00.html",
      "published_at": null,
      "updated_at": "2026-09-04",
      "summary": "The complete technical foundation for AI Security Engineering: AI, ML, neural networks, Transformers, LLMs, RAG, agents, MCP, evaluation, MLOps, and canonical…",
      "tags": [
        "ai-security",
        "llm-and-agent-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-00.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-00:chapter-01.html",
      "title": "AI Security Course, Module 00 — Part 1: Introduction, AI/ML Taxonomy, and Data Foundations",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-00/chapter-01.html",
      "published_at": null,
      "updated_at": "2026-09-04",
      "summary": "AI Security Course Module 00 Part 1: AI and ML taxonomy, symbolic rules, deep learning, generative AI, foundation models, LLMs, security cases, and data…",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-00/chapter-01.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-00:chapter-02.html",
      "title": "How Learning Systems Use Data",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-00/chapter-02.html",
      "published_at": null,
      "updated_at": "2026-08-05",
      "summary": "AI Security Course Module 00 Chapter 2: data, features, labels, parameters, hyperparameters, training, validation, testing, inference, and CTI evidence.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-00/chapter-02.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-00:chapter-03.html",
      "title": "AI Security Course, Module 00 — Chapter 3: Neural Networks and Optimization",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "developer",
        "threat-hunter"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "the completed Module 00 Chapter 3 course material, assessed neural-network evidence exercise, adversarial-machine-learning foundations, and MITRE ATLAS v2026.07 mappings",
      "canonical_url": "https://1200km.com/ai-security-course/module-00/chapter-03.html",
      "published_at": "2026-08-08",
      "updated_at": "2026-08-30",
      "summary": "Neural-network computation, optimization, reproducibility, attacker access, adversarial examples, robustness, poisoning, backdoors, inference attacks, and…",
      "tags": [
        "adversarial-machine-learning",
        "ai-security",
        "course",
        "cti",
        "mitre-atlas",
        "neural-networks",
        "security-training"
      ],
      "featured": false,
      "indexable": true,
      "lifecycle": "maintained",
      "source_url": "https://medium.com/@1200km/ai-security-course-module-00-chapter-3-1bf0411472f6",
      "source_platform": "Medium",
      "original_publication": "https://medium.com/@1200km/ai-security-course-module-00-chapter-3-1bf0411472f6",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference"
    },
    {
      "id": "site:ai-security-course:module-00:chapter-04.html",
      "title": "AI Security Course, Module 00 — Chapter 4: Transformers and LLM Generation",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "developer",
        "threat-hunter"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "the completed Module 00 Chapter 4 course material, assessed LLM request-trace exercise, Transformer and generation foundations, prompt-injection evidence boundaries, and MITRE ATLAS v2026.07 mappings",
      "canonical_url": "https://1200km.com/ai-security-course/module-00/chapter-04.html",
      "published_at": "2026-08-15",
      "updated_at": "2026-08-31",
      "summary": "Trace LLM requests through tokenization, chat templates, attention, decoding, prompt injection, deterministic controls, and reproducible evidence.",
      "tags": [
        "ai-security",
        "course",
        "cti",
        "large-language-models",
        "mitre-atlas",
        "prompt-injection",
        "security-training",
        "transformers"
      ],
      "featured": false,
      "indexable": true,
      "lifecycle": "maintained",
      "source_url": "https://medium.com/@1200km/ai-security-course-module-00-chapter-4-b8e3de0c3a9d",
      "source_platform": "Medium",
      "original_publication": "https://medium.com/@1200km/ai-security-course-module-00-chapter-4-b8e3de0c3a9d",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference"
    },
    {
      "id": "site:ai-security-course:module-01-instructor.html",
      "title": "Instructor Guide",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-01-instructor.html",
      "published_at": null,
      "updated_at": "2026-09-04",
      "summary": "Instructor runbook and assessment guidance for AI Security Engineering Module 1.",
      "tags": [
        "ai-security",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-01-instructor.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-01-workbook.html",
      "title": "Learner Workbook",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-01-workbook.html",
      "published_at": null,
      "updated_at": "2026-09-04",
      "summary": "Printable learner workbook for Module 1: AI Security Threat Landscape.",
      "tags": [
        "ai-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-01-workbook.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-security-course:module-01.html",
      "title": "AI Security Threat Landscape",
      "primary_type": "research",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-security-course/module-01.html",
      "published_at": null,
      "updated_at": "2026-09-04",
      "summary": "Module 1 of AI Security Engineering: real incidents, threat reports, vulnerabilities, malicious artifacts, and reproducible AI-security research.",
      "tags": [
        "ai-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-security-course/module-01.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:ai-vs-defense",
      "title": "Old Defense vs New-Age Attacks",
      "primary_type": "research",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ai-vs-defense/",
      "published_at": null,
      "updated_at": null,
      "summary": "Learn how AI lowers offensive skill barriers and how SOC and CTI teams can adapt with behavioral baselines, resilient detections, and a practical roadmap.",
      "tags": [
        "ai-security",
        "attack-emulation",
        "detection-content",
        "detection-engineering",
        "llm-and-agent-security",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ai-vs-defense/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:anomaly-detection-atlas",
      "title": "Understand deviation. Measure observable change.",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "A vendor-neutral reference for statistical anomaly types and security log sources.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:attack-activity-log-source-catalog",
      "title": "Suspicious and Malicious Activity by MITRE ATT&CK",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/attack-activity-log-source-catalog/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This catalog describes observable suspicious and malicious activity aligned to the current MITRE ATT&CK Enterprise tactics and techniques. Each activity links directly to the vendor-neutral log sources that can report it.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:attack-basic-detection-rule-catalog",
      "title": "Basic Detection Rules by MITRE ATT&CK TTP",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/attack-basic-detection-rule-catalog/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This catalog provides vendor-neutral algorithmic logic for basic deterministic detection rules mapped to MITRE ATT&CK Enterprise techniques and sub-techniques. Rules use signatures, fixed thresholds, allowlists, denylists, state changes, and bounded-window correlations. They do not depend on learned baselines or statistical anomaly models.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:attack-statistical-anomaly-mapping",
      "title": "Suspicious and Malicious Activity Explained by Statistical Anomalies",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/attack-statistical-anomaly-mapping/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This catalog explains how observable suspicious and malicious activity can manifest as statistical anomalies. It connects ATT&CK-aligned activity to the reference population, expected behavior, measurable deviation, applicable statistical anomaly types, and supporting log sources.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:security-log-source-taxonomy",
      "title": "Vendor-Neutral Security Log Source Taxonomy",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/security-log-source-taxonomy/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This document catalogs security-relevant log and telemetry source types without mapping them to vendors, detection rules, anomalies, or threat frameworks. Each entry describes what the source records and the kinds of activity it can report.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:anomaly-detection-atlas:statistical-anomaly-taxonomy",
      "title": "Statistical Anomaly Taxonomy",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current anomaly-detection practice",
      "canonical_url": "https://1200km.com/anomaly-detection-atlas/statistical-anomaly-taxonomy/",
      "source_url": "https://github.com/anpa1200/anomaly-detection-atlas",
      "published_at": null,
      "updated_at": null,
      "summary": "This document lists statistically relevant anomaly types without tying them to any specific application domain. An anomaly is an observation, group of observations, relationship, sequence, or distributional state that deviates meaningfully from an appropriate reference model.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:anomaly-detection-atlas",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/anomaly-detection-atlas",
      "original_publication": "https://github.com/anpa1200/anomaly-detection-atlas",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles",
      "title": "Security research articles, available locally.",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "current local article index",
      "canonical_url": "https://1200km.com/articles/",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Browse cybersecurity articles by Andrey Pautov covering CTI, AdversaryGraph, detection engineering, malware analysis, AI security, cloud research, and labs.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "index",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:adversarygraph-from-log-to-report-ioc-investigation.html",
      "title": "From Log to Report: Using AdversaryGraph to Turn Firewall and EDR Noise Into a CTI Investigation",
      "primary_type": "case-study",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "AdversaryGraph log-to-report investigation workflow using synthetic telemetry",
      "canonical_url": "https://1200km.com/articles/adversarygraph-from-log-to-report-ioc-investigation.html",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": "2026-06-27",
      "updated_at": "2026-06-27",
      "summary": "From Log to Report: Using AdversaryGraph to Turn Firewall and EDR Noise Into a CTI Investigation. From Log to Report: Using AdversaryGraph to Turn Firewall…",
      "tags": [
        "adversarygraph",
        "article",
        "author:Andrey Pautov",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "title": "Historical: AdversaryGraph v4 Capability Map",
      "primary_type": "mirror",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer"
      ],
      "status": "superseded",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "version": "AdversaryGraph v4",
      "applies_to": "historical AdversaryGraph v4 capability map",
      "canonical_url": "https://1200km.com/articles/adversarygraph-v2-self-hosted-ai-cti-platform.html",
      "source_url": "https://medium.com/@1200km/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "published_at": "2026-06-19",
      "updated_at": "2026-06-27",
      "summary": "Historical: AdversaryGraph v4 Capability Map. Historical, version-specific AdversaryGraph v4 capability map. The…",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "author:Andrey Pautov",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "archive_reason": "Preserved as a version-specific historical article; it does not describe the current stable release.",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "superseded"
    },
    {
      "id": "site:articles:read",
      "title": "Article Archive",
      "primary_type": "index",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "canonical local article pages with original publication URLs retained as provenance",
      "canonical_url": "https://1200km.com/articles/read/",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": null,
      "updated_at": "2026-09-08",
      "summary": "Article Archive. Full local Docusaurus archive of exported Medium articles by Andrey Pautov.",
      "tags": [
        "index",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2024:2024-10-17-wifi-cracking-with-aircrack-ng-d51cf98c789f",
      "title": "WiFi cracking with Aircrack-ng",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-17-wifi-cracking-with-aircrack-ng-d51cf98c789f/",
      "source_url": "https://medium.com/@1200km/wifi-cracking-with-aircrack-ng-d51cf98c789f",
      "published_at": "2024-10-17",
      "updated_at": "2024-10-17",
      "summary": "WiFi cracking with Aircrack-ng. In this article, I am going to explain how you can crack a WiFi network using Aircrack-ng and the PPG — Personal Pass.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/wifi-cracking-with-aircrack-ng-d51cf98c789f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-20-accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7",
      "title": "Accessing Remote Desktops: A Beginner’s Guide to RDP Cracking with Crowbar and PPG tools",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-20-accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7/",
      "source_url": "https://medium.com/@1200km/accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7",
      "published_at": "2024-10-20",
      "updated_at": "2024-10-20",
      "summary": "Accessing Remote Desktops: A Beginner’s Guide to RDP Cracking with Crowbar and PPG tools. Master the Techniques: Unveiling the Power of Crowbar and PPG to.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/accessing-remote-desktops-a-beginner-s-guide-to-rdp-cracking-with-crowbar-and-ppg-tools-5f50027115b7",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-20-personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c",
      "title": "Personal Pass Generator (PPG): The Ultimate Tool for Custom Password Lists",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-20-personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c/",
      "source_url": "https://medium.com/@1200km/personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c",
      "published_at": "2024-10-20",
      "updated_at": "2024-10-20",
      "summary": "Personal Pass Generator (PPG): The Ultimate Tool for Custom Password Lists. Hello, my name is Andrey Pautov, and today I’m excited to introduce you to my.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/personal-pass-generator-ppg-the-ultimate-tool-for-custom-password-lists-4979a3a1385c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-21-exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602",
      "title": "Exploiting FTP Vulnerabilities for Effective Penetration Testing",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-21-exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602/",
      "source_url": "https://medium.com/@1200km/exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602",
      "published_at": "2024-10-21",
      "updated_at": "2024-10-21",
      "summary": "Exploiting FTP Vulnerabilities for Effective Penetration Testing. In this guide, we will explore common vulnerabilities in the File Transfer Protocol (FTP).",
      "tags": [
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/exploiting-ftp-vulnerabilities-for-effective-penetration-testing-a2810df78602",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-22-cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09",
      "title": "Cracking Telnet: Exploring Weaknesses and Exploitation Techniques",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-22-cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09/",
      "source_url": "https://medium.com/@1200km/cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09",
      "published_at": "2024-10-22",
      "updated_at": "2024-10-22",
      "summary": "Cracking Telnet: Exploring Weaknesses and Exploitation Techniques. In this article, I will walk you through the process of cracking a Telnet service.",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-telnet-exploring-weaknesses-and-exploitation-techniques-af5d743abb09",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-23-cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee",
      "title": "Cracking RTSP Security: A Comprehensive Guide to Using the RTSP Brute Force Tool",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-23-cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee/",
      "source_url": "https://medium.com/@1200km/cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee",
      "published_at": "2024-10-23",
      "updated_at": "2024-10-23",
      "summary": "Cracking RTSP Security: A Comprehensive Guide to Using the RTSP Brute Force Tool. This article introduces a powerful tool designed for the RTSP Brute Force",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-rtsp-security-a-comprehensive-guide-to-using-the-rtsp-brute-force-tool-ad1c29b9e5ee",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-23-cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b",
      "title": "Cracking SSH with Metasploit: A Step-by-Step Guide to Exploiting Weak Credentials",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-23-cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b/",
      "source_url": "https://medium.com/@1200km/cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b",
      "published_at": "2024-10-23",
      "updated_at": "2024-10-23",
      "summary": "Cracking SSH with Metasploit: A Step-by-Step Guide to Exploiting Weak Credentials. In this article, I will walk you through the process of cracking SSH using.",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-ssh-with-metasploit-a-step-by-step-guide-to-exploiting-weak-credentials-3ec6ef4cee5b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-24-cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0",
      "title": "Cracking Web Interfaces with Burp Suite: A Comprehensive Tutorial",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-24-cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0/",
      "source_url": "https://medium.com/@1200km/cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0",
      "published_at": "2024-10-24",
      "updated_at": "2024-10-24",
      "summary": "Cracking Web Interfaces with Burp Suite: A Comprehensive Tutorial. In this guide, I will detail how to use Burp Suite, a popular web security tool, to.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cracking-web-interfaces-with-burp-suite-a-comprehensive-tutorial-33087bb286b0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-24-shodan-guide-how-you-can-find-everything-640f47f41bbe",
      "title": "Shodan , guide how you can find everything!",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-24-shodan-guide-how-you-can-find-everything-640f47f41bbe/",
      "source_url": "https://medium.com/@1200km/shodan-guide-how-you-can-find-everything-640f47f41bbe",
      "published_at": "2024-10-24",
      "updated_at": "2024-10-24",
      "summary": "Shodan , guide how you can find everything!. In this guide, we’ll explore how to navigate Shodan, understand the information it provides, and",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/shodan-guide-how-you-can-find-everything-640f47f41bbe",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-26-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 1",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-26-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0",
      "published_at": "2024-10-26",
      "updated_at": "2024-10-26",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 1. This comprehensive post will delve into the powerful network.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-1-f36d74d1b2c0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-27-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 2",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-27-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c",
      "published_at": "2024-10-27",
      "updated_at": "2024-10-27",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 2. This a second part of comprehensive Medium post will delve into.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-2-d5a95569031c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 3",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 3. This a third part of comprehensive Medium post will delve into.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-3-450eec6e9db2",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4",
      "title": "Office file (DOC, DOCX, PPT…) Password cracking. Guide with real life examples!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4/",
      "source_url": "https://medium.com/@1200km/office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "Office file (DOC, DOCX, PPT…) Password cracking. Guide with real life examples!. Unlock the secrets of Office file password cracking with our in-depth guide..",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/office-file-doc-docx-ppt-password-cracking-guide-with-real-life-examples-f8e356144ca4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4",
      "title": "PDF file Password cracking. Guide with real life examples!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4/",
      "source_url": "https://medium.com/@1200km/pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "PDF file Password cracking. Guide with real life examples!. Unlock the secrets of PDF file password cracking with our in-depth guide. Learn the tools.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/pdf-file-password-cracking-guide-with-real-life-examples-901ee411a6f4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-28-zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897",
      "title": "ZIP file Password cracking. Guide with real life examples!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-28-zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897/",
      "source_url": "https://medium.com/@1200km/zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897",
      "published_at": "2024-10-28",
      "updated_at": "2024-10-28",
      "summary": "ZIP file Password cracking. Guide with real life examples!. Unlock the secrets of ZIP file password cracking with our in-depth guide. Learn the tools.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/zip-file-password-cracking-guide-with-real-life-examples-4e8705d51897",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-29-passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd",
      "title": "Passwords cracking.ZIP, PDF, WEB, RDP, SSH, Cameras…",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-29-passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd/",
      "source_url": "https://medium.com/@1200km/passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd",
      "published_at": "2024-10-29",
      "updated_at": "2024-10-29",
      "summary": "Passwords cracking.ZIP, PDF, WEB, RDP, SSH, Cameras…. Dive into the art of password cracking with our guide that covers everything from brute force to.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/passwords-cracking-zip-pdf-web-rdp-ssh-cameras-c1bacbd592cd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-10-30-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f",
      "title": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 4. Scripts",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-10-30-mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f/",
      "source_url": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f",
      "published_at": "2024-10-30",
      "updated_at": "2024-10-30",
      "summary": "Mastering Nmap: A Comprehensive Guide to Network Exploration and Security Auditing. Part 4. Scripts. This a third part of comprehensive Medium post will.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-nmap-a-comprehensive-guide-to-network-exploration-and-security-auditing-part-4-s-5ec77704057f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-01-mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1",
      "title": "Mastering Hydra: The Ultimate Guide to Network Logon Cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-01-mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1/",
      "source_url": "https://medium.com/@1200km/mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1",
      "published_at": "2024-11-01",
      "updated_at": "2024-11-01",
      "summary": "Mastering Hydra: The Ultimate Guide to Network Logon Cracking. Unlocking the Gates of Network Security: An In-Depth Exploration into Mastering Hydra for.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-hydra-the-ultimate-guide-to-network-logon-cracking-182579dbaed1",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-03-breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8",
      "title": "Breaking the Code: How to Use Hashcat for Effective Password Cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-03-breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8/",
      "source_url": "https://medium.com/@1200km/breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8",
      "published_at": "2024-11-03",
      "updated_at": "2024-11-03",
      "summary": "Breaking the Code: How to Use Hashcat for Effective Password Cracking. Your step-by-step guide to mastering Hashcat, from setting it up on your system to.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/breaking-the-code-how-to-use-hashcat-for-effective-password-cracking-15f8da8facb8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-04-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83",
      "title": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 1. (basic, wizard)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-04-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83/",
      "source_url": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83",
      "published_at": "2024-11-04",
      "updated_at": "2024-11-04",
      "summary": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 1. (basic, wizard). Learn how SQLMap transforms the landscape of database security by.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-1-basic-wizard-6dd540363c83",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-05-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53",
      "title": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 2. (Advanced, custom setup)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-05-sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53/",
      "source_url": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53",
      "published_at": "2024-11-05",
      "updated_at": "2024-11-05",
      "summary": "SQLMap: A Deep Dive into Automated SQL Injection Testing. Part 2. (Advanced, custom setup). Learn how SQLMap transforms the landscape of database security by.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sqlmap-a-deep-dive-into-automated-sql-injection-testing-part-2-advanced-custom-setup-0136ac6ffe53",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-06-owasp-amass-project-guide-94bd55521f91",
      "title": "OWASP Amass Project guide",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-06-owasp-amass-project-guide-94bd55521f91/",
      "source_url": "https://medium.com/@1200km/owasp-amass-project-guide-94bd55521f91",
      "published_at": "2024-11-06",
      "updated_at": "2024-11-06",
      "summary": "OWASP Amass Project guide. In-depth Attack Surface Mapping and Asset Discovery.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/owasp-amass-project-guide-94bd55521f91",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-07-sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712",
      "title": "Sublist3r. Your Essential Tool for Subdomain Enumeration",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-07-sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712/",
      "source_url": "https://medium.com/@1200km/sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712",
      "published_at": "2024-11-07",
      "updated_at": "2024-11-07",
      "summary": "Sublist3r. Your Essential Tool for Subdomain Enumeration. Uncovering Subdomains for Enhanced Reconnaissance: A Comprehensive Guide to Using Sublist3r for.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sublist3r-your-essential-tool-for-subdomain-enumeration-c1910121d712",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-07-theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3",
      "title": "theHarvester: Your Essential Tool for OSINT and Reconnaissance in Cybersecurity",
      "primary_type": "article",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-07-theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3/",
      "source_url": "https://medium.com/@1200km/theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3",
      "published_at": "2024-11-07",
      "updated_at": "2024-11-07",
      "summary": "theHarvester: Your Essential Tool for OSINT and Reconnaissance in Cybersecurity. Learn how to leverage theHarvester to gather emails, subdomains, IPs, and.",
      "tags": [
        "ai-security",
        "article",
        "open-source-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/theharvester-your-essential-tool-for-osint-and-reconnaissance-in-cybersecurity-10aa6d76f5b3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-09-mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394",
      "title": "Mastering the Basics: Essential CLI Tools for Reconnaissance in Penetration Testing",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-09-mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394/",
      "source_url": "https://medium.com/@1200km/mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394",
      "published_at": "2024-11-09",
      "updated_at": "2024-11-09",
      "summary": "Mastering the Basics: Essential CLI Tools for Reconnaissance in Penetration Testing. A Comprehensive Guide to Command Line Tools for Network Exploration: How.",
      "tags": [
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-the-basics-essential-cli-tools-for-reconnaissance-in-penetration-testing-ee7fd9e36394",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-censys-for-enhanced-cybersecurity-insight-533df14794bd",
      "title": "Censys for Enhanced Cybersecurity Insight",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-censys-for-enhanced-cybersecurity-insight-533df14794bd/",
      "source_url": "https://medium.com/@1200km/censys-for-enhanced-cybersecurity-insight-533df14794bd",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Censys for Enhanced Cybersecurity Insight. A professional guide to understanding and utilizing Censys for advanced digital threat intelligence.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/censys-for-enhanced-cybersecurity-insight-533df14794bd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b",
      "title": "Mastering DirBuster: A Strategic Approach to Uncovering Hidden Web Assets",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b/",
      "source_url": "https://medium.com/@1200km/mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Mastering DirBuster: A Strategic Approach to Uncovering Hidden Web Assets. A comprehensive guide to using DirBuster for uncovering hidden directories and.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-dirbuster-a-strategic-approach-to-uncovering-hidden-web-assets-31c8406a892b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411",
      "title": "Unlocking Web Intelligence: A Deep Dive into WhatWeb",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411/",
      "source_url": "https://medium.com/@1200km/unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Unlocking Web Intelligence: A Deep Dive into WhatWeb. Explore how WhatWeb deciphers the technologies powering websites, enhancing security and reconnaissance.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/unlocking-web-intelligence-a-deep-dive-into-whatweb-8ee4e64ce411",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-10-web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399",
      "title": "Web Applications Penetretion Testing. Stage 1: Reconnaissance",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-10-web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399/",
      "source_url": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399",
      "published_at": "2024-11-10",
      "updated_at": "2024-11-10",
      "summary": "Web Applications Penetretion Testing. Stage 1: Reconnaissance. Unveil the first steps in securing web applications by exploring the essential techniques and.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-1-reconnaissance-6b6b7aae0399",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-11-mastering-burp-suite-vulnerability-scanner-019ed82c8bac",
      "title": "Mastering Burp Suite Vulnerability Scanner",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-11-mastering-burp-suite-vulnerability-scanner-019ed82c8bac/",
      "source_url": "https://medium.com/@1200km/mastering-burp-suite-vulnerability-scanner-019ed82c8bac",
      "published_at": "2024-11-11",
      "updated_at": "2024-11-11",
      "summary": "Mastering Burp Suite Vulnerability Scanner. From configuration to result analysis, discover how to leverage Burp Suite’s automatic scanner for faster and.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-burp-suite-vulnerability-scanner-019ed82c8bac",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-12-nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21",
      "title": "Nikto: Uncovering Web Server Vulnerabilities with an Open-Source Scanner",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-12-nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21/",
      "source_url": "https://medium.com/@1200km/nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21",
      "published_at": "2024-11-12",
      "updated_at": "2024-11-12",
      "summary": "Nikto: Uncovering Web Server Vulnerabilities with an Open-Source Scanner. A Guide to Using Nikto for Identifying Security Flaws and Misconfigurations in Web.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/nikto-uncovering-web-server-vulnerabilities-with-an-open-source-scanner-6d2d2fbc1e21",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-12-owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b",
      "title": "OWASP ZAP: A Comprehensive Guide to Web Application Security Testing",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-12-owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b/",
      "source_url": "https://medium.com/@1200km/owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b",
      "published_at": "2024-11-12",
      "updated_at": "2024-11-12",
      "summary": "OWASP ZAP: A Comprehensive Guide to Web Application Security Testing. Using OWASP ZAP for Identifying and Mitigating Web Application Vulnerabilities",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/owasp-zap-a-comprehensive-guide-to-web-application-security-testing-6c247f4be39b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-13-web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130",
      "title": "Web Applications Penetretion Testing. Stage 2: Scanning and Vulnerability Assessment",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-13-web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130/",
      "source_url": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130",
      "published_at": "2024-11-13",
      "updated_at": "2024-11-13",
      "summary": "Web Applications Penetretion Testing. Stage 2: Scanning and Vulnerability Assessment. Identifying Weaknesses: Mastering the Art of Scanning and Vulnerability.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/web-applications-penetretion-testing-stage-2-scanning-and-vulnerability-assessment-15021e81c130",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-15-2john-9bb0bd44ed64",
      "title": "2John",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-15-2john-9bb0bd44ed64/",
      "source_url": "https://medium.com/@1200km/2john-9bb0bd44ed64",
      "published_at": "2024-11-15",
      "updated_at": "2024-11-15",
      "summary": "2John. Full list of tools",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/2john-9bb0bd44ed64",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-15-john-the-ripper-hash-formats-f2ec958acaf8",
      "title": "John The Ripper Hash Formats",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-15-john-the-ripper-hash-formats-f2ec958acaf8/",
      "source_url": "https://medium.com/@1200km/john-the-ripper-hash-formats-f2ec958acaf8",
      "published_at": "2024-11-15",
      "updated_at": "2024-11-15",
      "summary": "John The Ripper Hash Formats. Reference",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/john-the-ripper-hash-formats-f2ec958acaf8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-15-mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71",
      "title": "Mastering John the Ripper: A Complete Guide to Password Cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-15-mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71/",
      "source_url": "https://medium.com/@1200km/mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71",
      "published_at": "2024-11-15",
      "updated_at": "2024-11-15",
      "summary": "Mastering John the Ripper: A Complete Guide to Password Cracking. Unlock the power of John the Ripper, from basic setups to advanced password recovery.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/mastering-john-the-ripper-a-complete-guide-to-password-cracking-e42d68239c71",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-16-the-basic-toolkit-for-penetration-testing-303da9234d82",
      "title": "The Basic Toolkit for Penetration Testing",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-16-the-basic-toolkit-for-penetration-testing-303da9234d82/",
      "source_url": "https://medium.com/@1200km/the-basic-toolkit-for-penetration-testing-303da9234d82",
      "published_at": "2024-11-16",
      "updated_at": "2024-11-16",
      "summary": "The Basic Toolkit for Penetration Testing. Unlocking Vulnerabilities: A Comprehensive Guide to Essential Tools for Pen Testing",
      "tags": [
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-basic-toolkit-for-penetration-testing-303da9234d82",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-17-the-ultimate-guide-to-metasploit-part-1-43c8573487df",
      "title": "The Ultimate Guide to Metasploit. Part 1.",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-17-the-ultimate-guide-to-metasploit-part-1-43c8573487df/",
      "source_url": "https://medium.com/@1200km/the-ultimate-guide-to-metasploit-part-1-43c8573487df",
      "published_at": "2024-11-17",
      "updated_at": "2024-11-17",
      "summary": "The Ultimate Guide to Metasploit. Part 1.. A Complete Guide to Exploiting Vulnerabilities and Strengthening Security with Metasploit",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-ultimate-guide-to-metasploit-part-1-43c8573487df",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-18-metasploit-modules-guide-auxiliary-1821db1712f0",
      "title": "Metasploit modules guide. Auxiliary",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-18-metasploit-modules-guide-auxiliary-1821db1712f0/",
      "source_url": "https://medium.com/@1200km/metasploit-modules-guide-auxiliary-1821db1712f0",
      "published_at": "2024-11-18",
      "updated_at": "2024-11-18",
      "summary": "Metasploit modules guide. Auxiliary. Complete Explanation of Auxiliary Mode in Metasploit",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/metasploit-modules-guide-auxiliary-1821db1712f0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-20-how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3",
      "title": "How to Create a Vulnerable Windows Virtual Machine for Pentesting Training with scripts!",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-20-how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3/",
      "source_url": "https://medium.com/@1200km/how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3",
      "published_at": "2024-11-20",
      "updated_at": "2024-11-20",
      "summary": "How to Create a Vulnerable Windows Virtual Machine for Pentesting Training with scripts!. Building Your Cybersecurity Playground: Step-by-Step Guide to.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/how-to-create-a-vulnerable-windows-virtual-machine-for-pentesting-training-with-scripts-6dc39f0b3bb3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2024:2024-11-24-title-metasploit-modules-guide-exploit-73eecb50e3c3",
      "title": "Title Metasploit modules guide. Exploit",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2024/2024-11-24-title-metasploit-modules-guide-exploit-73eecb50e3c3/",
      "source_url": "https://medium.com/@1200km/title-metasploit-modules-guide-exploit-73eecb50e3c3",
      "published_at": "2024-11-24",
      "updated_at": "2024-11-24",
      "summary": "Title Metasploit modules guide. Exploit. Complete Explanation of Exploit Mode in Metasploit",
      "tags": [
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/title-metasploit-modules-guide-exploit-73eecb50e3c3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-02-24-soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476",
      "title": "SOC Tier 1: The Complete Onboarding Guide to Security Monitoring and Incident Response",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-02-24-soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476/",
      "source_url": "https://medium.com/@1200km/soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476",
      "published_at": "2025-02-24",
      "updated_at": "2025-02-24",
      "summary": "SOC Tier 1: The Complete Onboarding Guide to Security Monitoring and Incident Response. Part 1.",
      "tags": [
        "article",
        "digital-forensics",
        "incident-response",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/soc-tier-1-the-complete-onboarding-guide-to-security-monitoring-and-incident-response-824a1dfe4476",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-14-authenticator-exe-dearsteeler-0c1d69767939",
      "title": "Authenticator.exe/DearSteeler",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-14-authenticator-exe-dearsteeler-0c1d69767939/",
      "source_url": "https://medium.com/@1200km/authenticator-exe-dearsteeler-0c1d69767939",
      "published_at": "2025-03-14",
      "updated_at": "2025-03-14",
      "summary": "Authenticator.exe/DearSteeler. Malware research report",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/authenticator-exe-dearsteeler-0c1d69767939",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-24-spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295",
      "title": "SPW AW25 — PO.010 SMS.exe.exe (AgentTesla)",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-24-spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295/",
      "source_url": "https://medium.com/@1200km/spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295",
      "published_at": "2025-03-24",
      "updated_at": "2025-03-24",
      "summary": "SPW AW25 — PO.010 SMS.exe.exe (AgentTesla). Malware research report",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/spw-aw25-po-010-sms-exe-exe-agenttesla-767fbc920295",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-29-static-malware-analysis-strings-analysis-e876640cfdb0",
      "title": "Static Malware Analysis. Strings analysis.",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-29-static-malware-analysis-strings-analysis-e876640cfdb0/",
      "source_url": "https://medium.com/@1200km/static-malware-analysis-strings-analysis-e876640cfdb0",
      "published_at": "2025-03-29",
      "updated_at": "2025-03-29",
      "summary": "Static Malware Analysis. Strings analysis.. Understanding Strings",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/static-malware-analysis-strings-analysis-e876640cfdb0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-03-30-static-malware-analysis-obfuscation-51de3992065d",
      "title": "Static Malware Analysis . Obfuscation.",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-03-30-static-malware-analysis-obfuscation-51de3992065d/",
      "source_url": "https://medium.com/@1200km/static-malware-analysis-obfuscation-51de3992065d",
      "published_at": "2025-03-30",
      "updated_at": "2025-03-30",
      "summary": "Static Malware Analysis . Obfuscation.. Understanding Code Obfuscation in Malware",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/static-malware-analysis-obfuscation-51de3992065d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-04-01-static-malware-analysis-file-fingerprinting-3ddf9bdd7864",
      "title": "Static Malware Analysis. File Fingerprinting",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-04-01-static-malware-analysis-file-fingerprinting-3ddf9bdd7864/",
      "source_url": "https://medium.com/@1200km/static-malware-analysis-file-fingerprinting-3ddf9bdd7864",
      "published_at": "2025-04-01",
      "updated_at": "2025-04-01",
      "summary": "Static Malware Analysis. File Fingerprinting. Understanding File Signatures, Hash, Digital Signatures",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/static-malware-analysis-file-fingerprinting-3ddf9bdd7864",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-04-17-deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87",
      "title": "Deep Dive: Automating Static Malware Analysis with Three Python Tools",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-04-17-deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87/",
      "source_url": "https://medium.com/@1200km/deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87",
      "published_at": "2025-04-17",
      "updated_at": "2025-04-17",
      "summary": "Deep Dive: Automating Static Malware Analysis with Three Python Tools. Static malware analysis involves multiple stages, each revealing different facets of a.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deep-dive-automating-static-malware-analysis-with-three-python-tools-46a26c0a7f87",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-06-17-tools-by-mitre-att-and-ck-guide-77c4d947ba36",
      "title": "Tools by MITRE ATT&CK Guide",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-06-17-tools-by-mitre-att-and-ck-guide-77c4d947ba36/",
      "source_url": "https://medium.com/@1200km/tools-by-mitre-att-and-ck-guide-77c4d947ba36",
      "published_at": "2025-06-17",
      "updated_at": "2025-06-17",
      "summary": "Tools by MITRE ATT&CK Guide. Reconnecense",
      "tags": [
        "article",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/tools-by-mitre-att-and-ck-guide-77c4d947ba36",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-08-fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f",
      "title": "Fluent Bit on AWS-EKS: Centralized Kubernetes Log Shipping to XPLG",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-08-fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f/",
      "source_url": "https://medium.com/@1200km/fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f",
      "published_at": "2025-07-08",
      "updated_at": "2025-07-08",
      "summary": "Fluent Bit on AWS-EKS: Centralized Kubernetes Log Shipping to XPLG. Deploy Fluent Bit as a DaemonSet with full metadata enrichment, RBAC, and HTTP output to.",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/fluent-bit-on-aws-eks-centralized-kubernetes-log-shipping-to-xplg-78811b8db55f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-09-threat-hunting-with-the-pyramid-of-pain-8add3cedb380",
      "title": "Threat Hunting with the Pyramid of Pain",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-09-threat-hunting-with-the-pyramid-of-pain-8add3cedb380/",
      "source_url": "https://medium.com/@1200km/threat-hunting-with-the-pyramid-of-pain-8add3cedb380",
      "published_at": "2025-07-09",
      "updated_at": "2025-07-09",
      "summary": "Threat Hunting with the Pyramid of Pain. A practical guide to using threat indicators that actually hurt your attackers, based on David J. Bianco’s model..",
      "tags": [
        "article",
        "detection-content",
        "threat-hunting"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/threat-hunting-with-the-pyramid-of-pain-8add3cedb380",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-11-fluentbit-on-kubernetes-demonset-deployment-13c3915113ba",
      "title": "FluentBit on Kubernetes DemonSet Deployment.",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-11-fluentbit-on-kubernetes-demonset-deployment-13c3915113ba/",
      "source_url": "https://medium.com/@1200km/fluentbit-on-kubernetes-demonset-deployment-13c3915113ba",
      "published_at": "2025-07-11",
      "updated_at": "2025-07-11",
      "summary": "FluentBit on Kubernetes DemonSet Deployment.. Cluster-wide log collection using Fluent Bit on every node",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/fluentbit-on-kubernetes-demonset-deployment-13c3915113ba",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-11-sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b",
      "title": "Sending EKS Control Plane Logs via AWS Lambda",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-11-sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b/",
      "source_url": "https://medium.com/@1200km/sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b",
      "published_at": "2025-07-11",
      "updated_at": "2025-07-11",
      "summary": "Sending EKS Control Plane Logs via AWS Lambda. A step-by-step guide to forwarding Amazon EKS control plane logs to SIEM/LogCOllector/XPLG using a lightweight.",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security",
        "detection-content",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/sending-eks-control-plane-logs-via-aws-lambda-c4ce0cf84c5b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-20-cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54",
      "title": "Cyberattacks on 4G/LTE Telecom Networks: Threat Mapping and Defense",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-20-cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54/",
      "source_url": "https://medium.com/@1200km/cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54",
      "published_at": "2025-07-20",
      "updated_at": "2025-07-20",
      "summary": "Cyberattacks on 4G/LTE Telecom Networks: Threat Mapping and Defense. This research provides an in-depth analysis of cyber threats targeting LTE telecom core.",
      "tags": [
        "article",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cyberattacks-on-4g-lte-telecom-networks-threat-mapping-and-defense-bd0e7fe76f54",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-20-cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df",
      "title": "Cyberattacks on 5G Telecom Networks: Threat Mapping and Defense",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-20-cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df/",
      "source_url": "https://medium.com/@1200km/cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df",
      "published_at": "2025-07-20",
      "updated_at": "2025-07-20",
      "summary": "Cyberattacks on 5G Telecom Networks: Threat Mapping and Defense. This research provides an in-depth analysis of cyber threats targeting 5G telecom core.",
      "tags": [
        "article",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cyberattacks-on-5g-telecom-networks-threat-mapping-and-defense-aa74f680a7df",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-25-information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c",
      "title": "Information Security Awareness: Principles and Best Practices for Employees",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-25-information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c/",
      "source_url": "https://medium.com/@1200km/information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c",
      "published_at": "2025-07-25",
      "updated_at": "2025-07-25",
      "summary": "Information Security Awareness: Principles and Best Practices for Employees. What Is Information Security and Why Does It Matter",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/information-security-awareness-principles-and-best-practices-for-employees-6e518eda752c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-25-phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511",
      "title": "Phishing Email Awareness: Protecting Employees and Organizations",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-25-phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511/",
      "source_url": "https://medium.com/@1200km/phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511",
      "published_at": "2025-07-25",
      "updated_at": "2025-07-25",
      "summary": "Phishing Email Awareness: Protecting Employees and Organizations. What is Email Phishing and Why It’s Dangerous",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/phishing-email-awareness-protecting-employees-and-organizations-cf5bc57a0511",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-07-27-quick-start-server-hardening-checklist-all-open-source-08e9887b9faa",
      "title": "Quick‑Start Server Hardening Checklist (all open‑source)",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-07-27-quick-start-server-hardening-checklist-all-open-source-08e9887b9faa/",
      "source_url": "https://medium.com/@1200km/quick-start-server-hardening-checklist-all-open-source-08e9887b9faa",
      "published_at": "2025-07-27",
      "updated_at": "2025-07-27",
      "summary": "Quick‑Start Server Hardening Checklist (all open‑source). ISO 27001-Based Server Hardening Plan",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/quick-start-server-hardening-checklist-all-open-source-08e9887b9faa",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-08-01-the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25",
      "title": "The 20x Employee: A Strategic Framework for Unlocking Hyper-Productivity with Artificial…",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-08-01-the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25/",
      "source_url": "https://medium.com/@1200km/the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25",
      "published_at": "2025-08-01",
      "updated_at": "2025-08-01",
      "summary": "The 20x Employee: A Strategic Framework for Unlocking Hyper-Productivity with Artificial…. A Strategic Blueprint for Augmenting Human Talent with Generative.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-20x-employee-a-strategic-framework-for-unlocking-hyper-productivity-with-artificial-8f49cde95a25",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-08-31-from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83",
      "title": "From Bugs to Breaches: Learning Secure Coding Through the OWASP Top 10",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-08-31-from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83/",
      "source_url": "https://medium.com/@1200km/from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83",
      "published_at": "2025-08-31",
      "updated_at": "2025-08-31",
      "summary": "From Bugs to Breaches: Learning Secure Coding Through the OWASP Top 10. Practical scenarios that show how small developer mistakes lead to big security.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/from-bugs-to-breaches-learning-secure-coding-through-the-owasp-top-10-21b425fafb83",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-13-villager-the-ai-powered-penetration-testing-framework-8df10532e265",
      "title": "Villager: The AI-Powered Penetration Testing Framework",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-13-villager-the-ai-powered-penetration-testing-framework-8df10532e265/",
      "source_url": "https://medium.com/@1200km/villager-the-ai-powered-penetration-testing-framework-8df10532e265",
      "published_at": "2025-10-13",
      "updated_at": "2025-10-13",
      "summary": "Villager: The AI-Powered Penetration Testing Framework. How “Villager,” a DeepSeek-driven framework from China’s Cyberspike collective, automates.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/villager-the-ai-powered-penetration-testing-framework-8df10532e265",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-14-the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3",
      "title": "The Invisible Pipeline: Defending CI/CD from Targeted Attacks",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-14-the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3/",
      "source_url": "https://medium.com/@1200km/the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3",
      "published_at": "2025-10-14",
      "updated_at": "2025-10-14",
      "summary": "The Invisible Pipeline: Defending CI/CD from Targeted Attacks. How adversaries weaponize build systems — and the concrete tools & controls you can use to.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-invisible-pipeline-defending-ci-cd-from-targeted-attacks-456283ee5ed3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-18-automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a",
      "title": "Automating a Safe DVWA Lab with Ansible: Build a Reproducible Vulnerable Environment for Training…",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-18-automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a/",
      "source_url": "https://medium.com/@1200km/automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a",
      "published_at": "2025-10-18",
      "updated_at": "2025-10-18",
      "summary": "Automating a Safe DVWA Lab with Ansible: Build a Reproducible Vulnerable Environment for Training…. How to deploy Damn Vulnerable Web App in minutes inside.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/automating-a-safe-dvwa-lab-with-ansible-build-a-reproducible-vulnerable-environment-for-tr-026d74697c4a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-19-augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5",
      "title": "Augmenting Digital Forensics with AI: How ChatGPT Transforms Investigation Workflows",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-19-augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5/",
      "source_url": "https://medium.com/@1200km/augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5",
      "published_at": "2025-10-19",
      "updated_at": "2025-10-19",
      "summary": "Augmenting Digital Forensics with AI: How ChatGPT Transforms Investigation Workflows. From evidence triage to report generation — applying large language.",
      "tags": [
        "ai-security",
        "article",
        "digital-forensics",
        "incident-response"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/augmenting-digital-forensics-with-ai-how-chatgpt-transforms-investigation-workflows-34eb10887ea5",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-10-20-meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085",
      "title": "Meet syscheck_beauty: a colorful Linux system report with deep storage insights (and exportable…",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-10-20-meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085/",
      "source_url": "https://medium.com/@1200km/meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085",
      "published_at": "2025-10-20",
      "updated_at": "2025-10-20",
      "summary": "Meet syscheck_beauty: a colorful Linux system report with deep storage insights (and exportable…. TL;DR: I built a single-file Python tool that prints a.",
      "tags": [
        "ai-security",
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/meet-syscheck-beauty-a-colorful-linux-system-report-with-deep-storage-insights-and-exporta-a38329dfe085",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-01-the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9",
      "title": "The Atomic Standard: A Practitioner’s Compendium for Single-Event Threat Detection",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-01-the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9/",
      "source_url": "https://medium.com/@1200km/the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9",
      "published_at": "2025-11-01",
      "updated_at": "2025-11-01",
      "summary": "The Atomic Standard: A Practitioner’s Compendium for Single-Event Threat Detection. Part 1: The Theoretical Foundation of Atomic Detection",
      "tags": [
        "article",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-atomic-standard-a-practitioner-s-compendium-for-single-event-threat-detection-570c4241d4d9",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-02-deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8",
      "title": "Deploying Fluent Bit as a Windows Service for Centralized Log Forwarding",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-02-deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8/",
      "source_url": "https://medium.com/@1200km/deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8",
      "published_at": "2025-11-02",
      "updated_at": "2025-11-02",
      "summary": "Deploying Fluent Bit as a Windows Service for Centralized Log Forwarding. A step-by-step guide to collecting Windows Event Logs and securely shipping them to.",
      "tags": [
        "article",
        "identity-and-access",
        "identity-security",
        "windows-internals"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deploying-fluent-bit-as-a-windows-service-for-centralized-log-forwarding-baec55b8aaf8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-07-cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1",
      "title": "Cloud-Native Security Threats, Attacks, and Detection Strategies",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-07-cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1/",
      "source_url": "https://medium.com/@1200km/cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1",
      "published_at": "2025-11-07",
      "updated_at": "2025-11-07",
      "summary": "Cloud-Native Security Threats, Attacks, and Detection Strategies. Securing Cloud‑Native Environments — A Comprehensive Guide to Kubernetes Threats, Detection.",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cloud-native-security-threats-attacks-and-detection-strategies-55b3dd6ea2d1",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-23-spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f",
      "title": "SpiderFoot Deep Dive: Installation, Scans, and Practical Use Cases",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-23-spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f/",
      "source_url": "https://medium.com/@1200km/spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f",
      "published_at": "2025-11-23",
      "updated_at": "2025-11-23",
      "summary": "SpiderFoot Deep Dive: Installation, Scans, and Practical Use Cases. How to run SpiderFoot, pick the right modules, interpret results, and use it responsibly.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/spiderfoot-deep-dive-installation-scans-and-practical-use-cases-11ea6537ad6f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-24-reinventing-recon-nmap-meets-chatgpt-e2acb6130be5",
      "title": "Reinventing Recon: Nmap Meets ChatGPT",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-24-reinventing-recon-nmap-meets-chatgpt-e2acb6130be5/",
      "source_url": "https://medium.com/@1200km/reinventing-recon-nmap-meets-chatgpt-e2acb6130be5",
      "published_at": "2025-11-24",
      "updated_at": "2025-11-24",
      "summary": "Reinventing Recon: Nmap Meets ChatGPT. How I leveled up penetration tests by pairing classic tools (NMAP) with LLMs like ChatGPT.",
      "tags": [
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/reinventing-recon-nmap-meets-chatgpt-e2acb6130be5",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-25-getting-more-from-burp-suite-with-llms-fdd03cec343d",
      "title": "Getting More from Burp Suite with LLMs",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-25-getting-more-from-burp-suite-with-llms-fdd03cec343d/",
      "source_url": "https://medium.com/@1200km/getting-more-from-burp-suite-with-llms-fdd03cec343d",
      "published_at": "2025-11-25",
      "updated_at": "2025-11-25",
      "summary": "Getting More from Burp Suite with LLMs. How ChatGPT Accelerates Scan Analysis, Prioritization and Mitigation. Practical workflow and prompt recipes for.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/getting-more-from-burp-suite-with-llms-fdd03cec343d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-11-26-enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139",
      "title": "Enhancing Penetration Testing with HackerAI: Step-by-Step Guide (Metasploitable Lab)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-11-26-enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139/",
      "source_url": "https://medium.com/@1200km/enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139",
      "published_at": "2025-11-26",
      "updated_at": "2025-11-26",
      "summary": "Enhancing Penetration Testing with HackerAI: Step-by-Step Guide (Metasploitable Lab). Learn how to integrate AI into every phase of the penetration testing.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/enhancing-penetration-testing-with-hackerai-step-by-step-guide-metasploitable-lab-b2ab2cdd4139",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-01-single-event-detection-rules-in-cybersecurity-aa7498f665bd",
      "title": "Single-Event Detection Rules in Cybersecurity",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-01-single-event-detection-rules-in-cybersecurity-aa7498f665bd/",
      "source_url": "https://medium.com/@1200km/single-event-detection-rules-in-cybersecurity-aa7498f665bd",
      "published_at": "2025-12-01",
      "updated_at": "2025-12-01",
      "summary": "Single-Event Detection Rules in Cybersecurity. Introduction",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/single-event-detection-rules-in-cybersecurity-aa7498f665bd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-02-correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb",
      "title": "Correlation-Based Detection Rules in Cybersecurity: From Atomic Events to Behavioral Insight",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-02-correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb/",
      "source_url": "https://medium.com/@1200km/correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb",
      "published_at": "2025-12-02",
      "updated_at": "2025-12-02",
      "summary": "Correlation-Based Detection Rules in Cybersecurity: From Atomic Events to Behavioral Insight. A comprehensive exploration of multi-event analytics, temporal.",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/correlation-based-detection-rules-in-cybersecurity-from-atomic-events-to-behavioral-insigh-1b3df31597bb",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-12-protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6",
      "title": "Protocol-Level Network Threat Hunting: A Wireshark-Centric Guide",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-12-protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6/",
      "source_url": "https://medium.com/@1200km/protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6",
      "published_at": "2025-12-12",
      "updated_at": "2025-12-12",
      "summary": "Protocol-Level Network Threat Hunting: A Wireshark-Centric Guide. Uncovering Stealthy Attacks Through IOCs, Anomaly Detection, and Practical Playbooks",
      "tags": [
        "article",
        "detection-content",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/protocol-level-network-threat-hunting-a-wireshark-centric-guide-a6770ffc96c6",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-14-endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113",
      "title": "Endpoint Threat Hunting: Proactive Detection on Windows, Linux, and macOS",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-14-endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113/",
      "source_url": "https://medium.com/@1200km/endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113",
      "published_at": "2025-12-14",
      "updated_at": "2025-12-14",
      "summary": "Endpoint Threat Hunting: Proactive Detection on Windows, Linux, and macOS. Uncovering Advanced Compromises Through Telemetry, Artifacts, MITRE ATT&CK.",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-hunting"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/endpoint-threat-hunting-proactive-detection-on-windows-linux-and-macos-f892d9b8a113",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-18-hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949",
      "title": "HexStrike AI: Install, Configure, and Run MCP with Gemini, OpenAI, Cursor, Llama",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-18-hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949/",
      "source_url": "https://medium.com/@1200km/hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949",
      "published_at": "2025-12-18",
      "updated_at": "2025-12-18",
      "summary": "HexStrike AI: Install, Configure, and Run MCP with Gemini, OpenAI, Cursor, Llama. A practical, end-to-end guide to installing HexStrike AI, wiring it as an.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-ai-install-configure-and-run-mcp-with-gemini-openai-cursor-llama-85a0e5752949",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-21-ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde",
      "title": "AI-Driven Pentesting at Home: Using HexStrike-AI for Full Network Discovery and Exploitation",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-21-ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde/",
      "source_url": "https://medium.com/@1200km/ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde",
      "published_at": "2025-12-21",
      "updated_at": "2025-12-21",
      "summary": "AI-Driven Pentesting at Home: Using HexStrike-AI for Full Network Discovery and Exploitation. How I Used Gemini + HexStrike-AI on Kali Linux to Scan.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-pentesting-at-home-using-hexstrike-ai-for-full-network-discovery-and-exploitatio-00a9e88b3bde",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-22-ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040",
      "title": "AI-Driven Web Application Pentesting with HexStrike-AI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-22-ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040/",
      "source_url": "https://medium.com/@1200km/ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040",
      "published_at": "2025-12-22",
      "updated_at": "2025-12-22",
      "summary": "AI-Driven Web Application Pentesting with HexStrike-AI. A Practical, End-to-End Guide to Modern Web Application Penetration Testing Using LLM-Orchestrated.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "llm-and-agent-security",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-web-application-pentesting-with-hexstrike-ai-67f3dae32040",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-23-integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e",
      "title": "Integrating Shodan with HexStrike-AI Using Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-23-integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e/",
      "source_url": "https://medium.com/@1200km/integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e",
      "published_at": "2025-12-23",
      "updated_at": "2025-12-23",
      "summary": "Integrating Shodan with HexStrike-AI Using Gemini-CLI. A Practical Guide to AI-Driven External Reconnaissance and Vulnerability Analysis",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/integrating-shodan-with-hexstrike-ai-using-gemini-cli-b6f9fcbe8e6e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-24-ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4",
      "title": "AI-Driven Wireless Penetration Testing. One Promt WIFI cracking",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-24-ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4/",
      "source_url": "https://medium.com/@1200km/ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4",
      "published_at": "2025-12-24",
      "updated_at": "2025-12-24",
      "summary": "AI-Driven Wireless Penetration Testing. One Promt WIFI cracking. Using Aircrack-ng with HexStrike-AI and Gemini-CLI",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-wireless-penetration-testing-one-promt-wifi-cracking-6477c06f6af4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-25-ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc",
      "title": "AI-Driven ZIP Password Recovery with HexStrike-AI and Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-25-ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc/",
      "source_url": "https://medium.com/@1200km/ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc",
      "published_at": "2025-12-25",
      "updated_at": "2025-12-25",
      "summary": "AI-Driven ZIP Password Recovery with HexStrike-AI and Gemini-CLI. From Encrypted Archive to Flag Using LLM-Orchestrated Tooling",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-zip-password-recovery-with-hexstrike-ai-and-gemini-cli-b8fc5c475ebc",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-25-hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae",
      "title": "HexStrike-AI: A Force Multiplier for Red Teams — and a Dangerous Shift in the Threat Landscape",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-25-hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae/",
      "source_url": "https://medium.com/@1200km/hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae",
      "published_at": "2025-12-25",
      "updated_at": "2025-12-25",
      "summary": "HexStrike-AI: A Force Multiplier for Red Teams — and a Dangerous Shift in the Threat Landscape. Why AI-Orchestrated Pentesting Is a Force Multiplier for Red.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-ai-a-force-multiplier-for-red-teams-and-a-dangerous-shift-in-the-threat-landscap-3e1d4e86f3ae",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-26-hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b",
      "title": "HexStrike + Gemini vs. HackerAI: “Ops Copilot” vs. “Chatbot with Tools”",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-26-hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b/",
      "source_url": "https://medium.com/@1200km/hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b",
      "published_at": "2025-12-26",
      "updated_at": "2025-12-26",
      "summary": "HexStrike + Gemini vs. HackerAI: “Ops Copilot” vs. “Chatbot with Tools”. A practical lab comparison: Why orchestration quality beats raw model IQ in.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-gemini-vs-hackerai-ops-copilot-vs-chatbot-with-tools-1d799845410b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-29-ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d",
      "title": "AI-Driven Office Documents Password Recovery with HexStrike-AI and Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-29-ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d/",
      "source_url": "https://medium.com/@1200km/ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d",
      "published_at": "2025-12-29",
      "updated_at": "2025-12-29",
      "summary": "AI-Driven Office Documents Password Recovery with HexStrike-AI and Gemini-CLI. From Encrypted Document to Readable Content Using LLM-Orchestrated Tooling",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-office-documents-password-recovery-with-hexstrike-ai-and-gemini-cli-3c8bb7deb82d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-29-ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91",
      "title": "AI-Driven PDF Password Recovery with HexStrike-AI and Gemini-CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-29-ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91/",
      "source_url": "https://medium.com/@1200km/ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91",
      "published_at": "2025-12-29",
      "updated_at": "2025-12-29",
      "summary": "AI-Driven PDF Password Recovery with HexStrike-AI and Gemini-CLI. From Encrypted Document to Readable Content Using LLM-Orchestrated Tooling",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-pdf-password-recovery-with-hexstrike-ai-and-gemini-cli-cfa7eb0fae91",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2025:2025-12-31-hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596",
      "title": "HexStrike MCP Orchestration with Ollama: Ubuntu Host, Kali VM, SSH Bridging, and Performance…",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "preserved publication from before 2026-01-01; current technical applicability is not asserted",
      "canonical_url": "https://1200km.com/articles/read/2025/2025-12-31-hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596/",
      "source_url": "https://medium.com/@1200km/hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596",
      "published_at": "2025-12-31",
      "updated_at": "2025-12-31",
      "summary": "HexStrike MCP Orchestration with Ollama: Ubuntu Host, Kali VM, SSH Bridging, and Performance…. How to wire Ubuntu (Ollama) to Kali (HexStrike) with MCP over.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-mcp-orchestration-with-ollama-ubuntu-host-kali-vm-ssh-bridging-and-performance-f049ab140596",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "preserved"
    },
    {
      "id": "site:articles:read:2026:2026-01-02-burp-suite-mcp-gemini-cli-c1229edfe092",
      "title": "Burp Suite MCP + Gemini CLI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-02-burp-suite-mcp-gemini-cli-c1229edfe092/",
      "source_url": "https://medium.com/@1200km/burp-suite-mcp-gemini-cli-c1229edfe092",
      "published_at": "2026-01-02",
      "updated_at": "2026-01-02",
      "summary": "Burp Suite MCP + Gemini CLI. Connect Burp Suite to Gemini CLI using Model Context Protocol (MCP) and Turn Burp into an AI-callable toolset and accelerate.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/burp-suite-mcp-gemini-cli-c1229edfe092",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-03-hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f",
      "title": "HexStrike+OpenAI Codex. AI-Driven Exploitation of Metasploitable.",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-03-hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f/",
      "source_url": "https://medium.com/@1200km/hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f",
      "published_at": "2026-01-03",
      "updated_at": "2026-01-03",
      "summary": "HexStrike+OpenAI Codex. AI-Driven Exploitation of Metasploitable.. How I Used an LLM-Orchestrated Toolchain to Enumerate and Exploit a Deliberately.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-openai-codex-ai-driven-exploitation-of-metasploitable-b892c07be39f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-04-hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b",
      "title": "HexStrike + Gemini. AI-Assisted SSH Credential Brute-Force",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-04-hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b/",
      "source_url": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b",
      "published_at": "2026-01-04",
      "updated_at": "2026-01-04",
      "summary": "HexStrike + Gemini. AI-Assisted SSH Credential Brute-Force. From Service Validation → Dependency Fixes → Findings → Defensive Takeaways",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-ssh-credential-brute-force-a9162f8e253b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-05-building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c",
      "title": "Building an Extremely Vulnerable Windows 10 Lab: A Step-by-Step Guide (Bonus :Full PT with…",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-05-building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c/",
      "source_url": "https://medium.com/@1200km/building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c",
      "published_at": "2026-01-05",
      "updated_at": "2026-01-05",
      "summary": "Building an Extremely Vulnerable Windows 10 Lab: A Step-by-Step Guide (Bonus :Full PT with…. Hands-on guide to creating an intentionally insecure Windows 10.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-an-extremely-vulnerable-windows-10-lab-a-step-by-step-guide-bonus-full-pt-with-9290d388744c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-05-hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4",
      "title": "HexStrike + Gemini. AI-Assisted SMB Exposure Credential Brute-Force",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-05-hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4/",
      "source_url": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4",
      "published_at": "2026-01-05",
      "updated_at": "2026-01-05",
      "summary": "HexStrike + Gemini. AI-Assisted SMB Exposure Credential Brute-Force. From Toolchain Failures → Service Fingerprinting → Authentication Findings → Share Risk",
      "tags": [
        "ai-security",
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-gemini-ai-assisted-smb-exposure-credential-brute-force-2c5f99dcdbf4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-06-building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b",
      "title": "Building an Extremely Vulnerable Ubuntu 24.04 Server Lab (Bonus: Full PT with Hexstrike)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-06-building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b/",
      "source_url": "https://medium.com/@1200km/building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b",
      "published_at": "2026-01-06",
      "updated_at": "2026-01-06",
      "summary": "Building an Extremely Vulnerable Ubuntu 24.04 Server Lab (Bonus: Full PT with Hexstrike). A Step-by-Step Guide: Hands-on guide to creating an intentionally.",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-an-extremely-vulnerable-ubuntu-24-04-server-lab-bonus-full-pt-with-hexstrike-90034032775b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-08-hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7",
      "title": "HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough)",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-08-hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7/",
      "source_url": "https://medium.com/@1200km/hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7",
      "published_at": "2026-01-08",
      "updated_at": "2026-01-08",
      "summary": "HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough). A real end-to-end lab engagement: recon → credential discovery →.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-cursor-mcp-from-single-target-full-subnet-compromise-lab-pt-walkthrough-f2e1fd793ad7",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-11-hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30",
      "title": "HexStrike + Cursor for OSINT: From One Email to a Full Exposure Map",
      "primary_type": "article",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-11-hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30/",
      "source_url": "https://medium.com/@1200km/hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30",
      "published_at": "2026-01-11",
      "updated_at": "2026-01-11",
      "summary": "HexStrike + Cursor for OSINT: From One Email to a Full Exposure Map. Why OSINT is harder than “hack the box,” what an AI-assisted workflow looks like in.",
      "tags": [
        "ai-security",
        "article",
        "open-source-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hexstrike-cursor-for-osint-from-one-email-to-a-full-exposure-map-ffdfc7ba1b30",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-15-building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe",
      "title": "Building a USB Rubber Ducky with Arduino Leonardo with Cursor.",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-15-building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe/",
      "source_url": "https://medium.com/@1200km/building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe",
      "published_at": "2026-01-15",
      "updated_at": "2026-01-15",
      "summary": "Building a USB Rubber Ducky with Arduino Leonardo with Cursor.. Integrating Cursor AI into your hardware hacking workflow is a game-changer. From Human.",
      "tags": [
        "ai-security",
        "application-security",
        "article",
        "embedded-security",
        "hardware-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-usb-rubber-ducky-with-arduino-leonardo-with-cursor-a23dd64d1bbe",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-16-hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845",
      "title": "Hacker Tool Development Workflow: Android Rubber Ducky Payloads in Cursor AI",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-16-hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845/",
      "source_url": "https://medium.com/@1200km/hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845",
      "published_at": "2026-01-16",
      "updated_at": "2026-01-16",
      "summary": "Hacker Tool Development Workflow: Android Rubber Ducky Payloads in Cursor AI. From plain-English prompts to reliable HID flows — validated with emulator.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hacker-tool-development-workflow-android-rubber-ducky-payloads-in-cursor-ai-47fcccb9c845",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-17-the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071",
      "title": "The One-Prompt PT Lab: Autonomous Android Security Research with Cursor AI",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-17-the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071/",
      "source_url": "https://medium.com/@1200km/the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071",
      "published_at": "2026-01-17",
      "updated_at": "2026-01-17",
      "summary": "The One-Prompt PT Lab: Autonomous Android Security Research with Cursor AI. From Bare Directory to Full Exploitation: A Case Study on OWASP UnCrackable L1",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-one-prompt-pt-lab-autonomous-android-security-research-with-cursor-ai-b96ed2053071",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-19-the-ai-revolution-in-offensive-security-31e44704d51a",
      "title": "The AI Revolution in Offensive Security",
      "primary_type": "article",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-19-the-ai-revolution-in-offensive-security-31e44704d51a/",
      "source_url": "https://medium.com/@1200km/the-ai-revolution-in-offensive-security-31e44704d51a",
      "published_at": "2026-01-19",
      "updated_at": "2026-01-19",
      "summary": "The AI Revolution in Offensive Security. Practical Hands-On Guide to AI-Accelerated Offensive Security: Burp Suite, Nmap, OSINT, Exploitation, and End-to-End.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "offensive-security",
        "open-source-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-ai-revolution-in-offensive-security-31e44704d51a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-23-deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc",
      "title": "Deploy a Complete Active Directory PenTest Lab in One Prompt with Cursor AI",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-23-deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc/",
      "source_url": "https://medium.com/@1200km/deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc",
      "published_at": "2026-01-23",
      "updated_at": "2026-01-23",
      "summary": "Deploy a Complete Active Directory PenTest Lab in One Prompt with Cursor AI. How I automated the deployment of a complex AD lab environment using AI assistance",
      "tags": [
        "ai-security",
        "article",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deploy-a-complete-active-directory-pentest-lab-in-one-prompt-with-cursor-ai-ff926fd2b3fc",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-24-active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d",
      "title": "Active Directory Lab for PenTest. Manual Deployment Guide",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-24-active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d/",
      "source_url": "https://medium.com/@1200km/active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d",
      "published_at": "2026-01-24",
      "updated_at": "2026-01-24",
      "summary": "Active Directory Lab for PenTest. Manual Deployment Guide. This guide is a manual, step-by-step deployment of a GOAD-Mini Active Directory environment on.",
      "tags": [
        "article",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/active-directory-lab-for-pentest-manual-deployment-guide-cab28cd4ad8d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-25-hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191",
      "title": "Hi! Two of my articles have been in pending status for the past few days.",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-25-hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191/",
      "source_url": "https://medium.com/@1200km/hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191",
      "published_at": "2026-01-25",
      "updated_at": "2026-01-25",
      "summary": "Hi! Two of my articles have been in pending status for the past few days.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/hi-two-of-my-articles-have-been-in-pending-status-for-the-past-few-days-cac7ab7d9191",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-26-active-directory-penetration-testing-745cfb31d7d3",
      "title": "Active Directory Penetration Testing",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-26-active-directory-penetration-testing-745cfb31d7d3/",
      "source_url": "https://medium.com/@1200km/active-directory-penetration-testing-745cfb31d7d3",
      "published_at": "2026-01-26",
      "updated_at": "2026-01-26",
      "summary": "Active Directory Penetration Testing. A Deep Dive into GOAD-Mini Lab Assessment. Step-by-step guide.",
      "tags": [
        "article",
        "attack-emulation",
        "identity-and-access",
        "identity-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/active-directory-penetration-testing-745cfb31d7d3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-27-ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7",
      "title": "AI-Driven Black Box Active Directory Penetration Testing",
      "primary_type": "article",
      "primary_domain": "identity-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-27-ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7/",
      "source_url": "https://medium.com/@1200km/ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7",
      "published_at": "2026-01-27",
      "updated_at": "2026-01-27",
      "summary": "AI-Driven Black Box Active Directory Penetration Testing. Fully Automated AD Discovery and Exploitation with Cursor AI and HexStrike-ai MCP. From IP to Full.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "identity-and-access",
        "identity-security",
        "llm-and-agent-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-driven-black-box-active-directory-penetration-testing-8de0b9ad38b7",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-28-adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d",
      "title": "ADCS ESC8 Attack: Certificate-Based Domain Compromise — Complete Guide",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-28-adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d/",
      "source_url": "https://medium.com/@1200km/adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d",
      "published_at": "2026-01-28",
      "updated_at": "2026-01-28",
      "summary": "ADCS ESC8 Attack: Certificate-Based Domain Compromise — Complete Guide. Abstract",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adcs-esc8-attack-certificate-based-domain-compromise-complete-guide-7ec76562fa6d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-29-building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff",
      "title": "Building a Vulnerable GCP Pentest Lab with Terraform",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-29-building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff/",
      "source_url": "https://medium.com/@1200km/building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff",
      "published_at": "2026-01-29",
      "updated_at": "2026-01-29",
      "summary": "Building a Vulnerable GCP Pentest Lab with Terraform. A complete, step-by-step guide to deploying intentionally misconfigured cloud resources for hands-on.",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-vulnerable-gcp-pentest-lab-with-terraform-9d1edfcd8eff",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-29-cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58",
      "title": "Cursor + Hexstrike. Fully Automated ADCS ESC8 Attack",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-29-cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58/",
      "source_url": "https://medium.com/@1200km/cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58",
      "published_at": "2026-01-29",
      "updated_at": "2026-01-29",
      "summary": "Cursor + Hexstrike. Fully Automated ADCS ESC8 Attack. One-Prompt Domain Compromise",
      "tags": [
        "article",
        "offensive-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cursor-hexstrike-fully-automated-adcs-esc8-attack-8736fec53c58",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-31-a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd",
      "title": "A Complete Cloud Penetration Testing Walkthrough",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-31-a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd/",
      "source_url": "https://medium.com/@1200km/a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd",
      "published_at": "2026-01-31",
      "updated_at": "2026-01-31",
      "summary": "A Complete Cloud Penetration Testing Walkthrough. How I Discovered Critical Vulnerabilities in a Cloud Environment Using Basic Tools and Methodical Testing",
      "tags": [
        "article",
        "attack-emulation",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/a-complete-cloud-penetration-testing-walkthrough-1914f687d7fd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-01-31-ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258",
      "title": "AI-Assisted Web and Cloud Penetration Testing with Cursor + MCP HexStrike and Burp Suite MCP.",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-01-31-ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258/",
      "source_url": "https://medium.com/@1200km/ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258",
      "published_at": "2026-01-31",
      "updated_at": "2026-01-31",
      "summary": "AI-Assisted Web and Cloud Penetration Testing with Cursor + MCP HexStrike and Burp Suite MCP.. A Complete Guide to Modern AI-Powered Security Testing. From.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "cloud-security",
        "llm-and-agent-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-assisted-web-and-cloud-penetration-testing-with-cursor-mcp-hexstrike-and-burp-suite-mcp-01c02eed5258",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-02-building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91",
      "title": "Building a Vulnerable Kubernetes Lab: A Complete Guide to 25 Critical Security Issues",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-02-building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91/",
      "source_url": "https://medium.com/@1200km/building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91",
      "published_at": "2026-02-02",
      "updated_at": "2026-02-02",
      "summary": "Building a Vulnerable Kubernetes Lab: A Complete Guide to 25 Critical Security Issues. Learn Kubernetes security by building a comprehensive penetration.",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-vulnerable-kubernetes-lab-a-complete-guide-to-25-critical-security-issues-fae4fc8e3a91",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-03-black-box-kubernetes-penetration-testing-playbook-56350b178af4",
      "title": "Black-Box Kubernetes Penetration Testing Playbook",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-03-black-box-kubernetes-penetration-testing-playbook-56350b178af4/",
      "source_url": "https://medium.com/@1200km/black-box-kubernetes-penetration-testing-playbook-56350b178af4",
      "published_at": "2026-02-03",
      "updated_at": "2026-02-03",
      "summary": "Black-Box Kubernetes Penetration Testing Playbook. A Manual, End-to-End Walkthrough from First Signal to Cluster Takeover",
      "tags": [
        "article",
        "attack-emulation",
        "cloud-and-container-security",
        "cloud-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/black-box-kubernetes-penetration-testing-playbook-56350b178af4",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-04-my-lab-82d780962213",
      "title": "My lab:",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-04-my-lab-82d780962213/",
      "source_url": "https://medium.com/@1200km/my-lab-82d780962213",
      "published_at": "2026-02-04",
      "updated_at": "2026-02-04",
      "summary": "My lab:. Building a vulnerable Kubernetes lab",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/my-lab-82d780962213",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-04-one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e",
      "title": "One-Prompt AI-Powered Black-Box Kubernetes Penetration Test",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-04-one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e/",
      "source_url": "https://medium.com/@1200km/one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e",
      "published_at": "2026-02-04",
      "updated_at": "2026-02-04",
      "summary": "One-Prompt AI-Powered Black-Box Kubernetes Penetration Test. How Cursor + HexStrike MCP Automatically Discovers and Exploits Vulnerabilities. From single.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "cloud-and-container-security",
        "cloud-security",
        "llm-and-agent-security",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/one-prompt-ai-powered-black-box-kubernetes-penetration-test-c75a4747960e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-05-warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19",
      "title": "⚠️ WARNING: I Just Built Real Malware by using just human language prompts!",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-05-warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19/",
      "source_url": "https://medium.com/@1200km/warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19",
      "published_at": "2026-02-05",
      "updated_at": "2026-02-05",
      "summary": "⚠️ WARNING: I Just Built Real Malware by using just human language prompts!. A Complete Walkthrough: From “I Want to Build Malware” to Fully Functional.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/warning-i-just-built-real-malware-by-using-just-human-language-prompts-8949628dee19",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-06-welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503",
      "title": "Welcome to the New Era: When a Teenager Can Crash Your Company in Minutes",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-06-welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503/",
      "source_url": "https://medium.com/@1200km/welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503",
      "published_at": "2026-02-06",
      "updated_at": "2026-02-06",
      "summary": "Welcome to the New Era: When a Teenager Can Crash Your Company in Minutes. An Urgent Message for CISOs and C-Level Executives. The threat landscape has.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/welcome-to-the-new-era-when-a-teenager-can-crash-your-company-in-minutes-8818fb6c0503",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-09-gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d",
      "title": "GCP Penetration Testing: A Step-by-Step Attack Guide",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-09-gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d/",
      "source_url": "https://medium.com/@1200km/gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d",
      "published_at": "2026-02-09",
      "updated_at": "2026-02-09",
      "summary": "GCP Penetration Testing: A Step-by-Step Attack Guide. A practical GCP lab case study: overprivileged identities, leaked creds, weak controls — and how it all.",
      "tags": [
        "article",
        "attack-emulation",
        "cloud-and-container-security",
        "cloud-security",
        "identity-and-access",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/gcp-penetration-testing-a-step-by-step-attack-guide-9e39bc3eb96d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-11-kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80",
      "title": "Kubernetes Logging and Monitoring: Complete Guide",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-11-kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80/",
      "source_url": "https://medium.com/@1200km/kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80",
      "published_at": "2026-02-11",
      "updated_at": "2026-02-11",
      "summary": "Kubernetes Logging and Monitoring: Complete Guide. A comprehensive reference for every major log type in Kubernetes: what it is, what you can monitor with.",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/kubernetes-logging-and-monitoring-complete-guide-2ce9d4bdba80",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-13-build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e",
      "title": "Build a Vulnerable IIS SharePoint Lab with Fluent Bit: Complete Deployment Guide",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-13-build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e/",
      "source_url": "https://medium.com/@1200km/build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e",
      "published_at": "2026-02-13",
      "updated_at": "2026-02-13",
      "summary": "Build a Vulnerable IIS SharePoint Lab with Fluent Bit: Complete Deployment Guide. A full step-by-step guide with all scripts to deploy a vulnerable.",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/build-a-vulnerable-iis-sharepoint-lab-with-fluent-bit-complete-deployment-guide-8fe947e8439e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-19-the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca",
      "title": "The Complete Guide to AI-Driven Penetration Testing: Cursor, MCP, and the Modern PT Workflow",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-19-the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca/",
      "source_url": "https://medium.com/@1200km/the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca",
      "published_at": "2026-02-19",
      "updated_at": "2026-02-19",
      "summary": "The Complete Guide to AI-Driven Penetration Testing: Cursor, MCP, and the Modern PT Workflow. A comprehensive, step-by-step guide to running penetration.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "llm-and-agent-security",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/the-complete-guide-to-ai-driven-penetration-testing-cursor-mcp-and-the-modern-pt-workflow-8f27ff19f9ca",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-21-one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de",
      "title": "One Tool to Rule Them All: File Metadata & Static Analysis for Malware Analysts and SOC Teams",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-21-one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de/",
      "source_url": "https://medium.com/@1200km/one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de",
      "published_at": "2026-02-21",
      "updated_at": "2026-02-21",
      "summary": "One Tool to Rule Them All: File Metadata & Static Analysis for Malware Analysts and SOC Teams. Extract hashes, PE/ELF/Mach-O metadata, strings, YARA hits.",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/one-tool-to-rule-them-all-file-metadata-and-static-analysis-for-malware-analysts-and-soc-t-c6dba1f5b7de",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-26-a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868",
      "title": "A Practical Guide to String Analyzer: Extract and Analyze Strings from Binaries (Without the…",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-26-a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868/",
      "source_url": "https://medium.com/@1200km/a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868",
      "published_at": "2026-02-26",
      "updated_at": "2026-02-26",
      "summary": "A Practical Guide to String Analyzer: Extract and Analyze Strings from Binaries (Without the…. Turn executables, memory dumps, and disk images into.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/a-practical-guide-to-string-analyzer-extract-and-analyze-strings-from-binaries-without-the-875dc74e4868",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-26-pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3",
      "title": "PE Import Analyzer: A Practical Guide for Malware Analysts and Reverse Engineers",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-26-pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3/",
      "source_url": "https://medium.com/@1200km/pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3",
      "published_at": "2026-02-26",
      "updated_at": "2026-02-26",
      "summary": "PE Import Analyzer: A Practical Guide for Malware Analysts and Reverse Engineers. How to quickly understand what a Windows executable does — before you run it.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/pe-import-analyzer-a-practical-guide-for-malware-analysts-and-reverse-engineers-29b8b98aeaf3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-02-28-unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b",
      "title": "Unpacker: A Practical Guide to Modular Malware Packer Detection and Unpacking",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-02-28-unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b/",
      "source_url": "https://medium.com/@1200km/unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b",
      "published_at": "2026-02-28",
      "updated_at": "2026-02-28",
      "summary": "Unpacker: A Practical Guide to Modular Malware Packer Detection and Unpacking. Extract and validate unpacked PE/ELF samples with real examples — and prove it.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/unpacker-a-practical-guide-to-modular-malware-packer-detection-and-unpacking-cf8ba924f25b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-01-basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8",
      "title": "Basic Static Malware Analysis: From Triage to Unpacking — Explained and Automated",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-01-basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8/",
      "source_url": "https://medium.com/@1200km/basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8",
      "published_at": "2026-03-01",
      "updated_at": "2026-03-01",
      "summary": "Basic Static Malware Analysis: From Triage to Unpacking — Explained and Automated. What static malware analysis is, why each step matters, and how to run the.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/basic-static-malware-analysis-from-triage-to-unpacking-explained-and-automated-9442ef3b11b8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-06-cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8",
      "title": "CTI Research: Handala Hack Group (aka Handala Hack Team)",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-06-cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8/",
      "source_url": "https://medium.com/@1200km/cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8",
      "published_at": "2026-03-06",
      "updated_at": "2026-03-06",
      "summary": "CTI Research: Handala Hack Group (aka Handala Hack Team). Evidence-Labeled Threat Intelligence Assessment and SOC Defensive Guidance (December 2023 to March.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-handala-hack-group-aka-handala-hack-team-ddbdd294cfb8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-07-cti-research-sandworm-apt44-649332e8af44",
      "title": "CTI Research: Sandworm / APT44",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-07-cti-research-sandworm-apt44-649332e8af44/",
      "source_url": "https://medium.com/@1200km/cti-research-sandworm-apt44-649332e8af44",
      "published_at": "2026-03-07",
      "updated_at": "2026-03-07",
      "summary": "CTI Research: Sandworm / APT44. Evidence-Labeled Threat Intelligence Assessment and SOC Defensive Guidance (2009 — March 2026)",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-sandworm-apt44-649332e8af44",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-09-cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061",
      "title": "CTI Research: MuddyWater/Seedworm (Mango Sandstorm)",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-09-cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061/",
      "source_url": "https://medium.com/@1200km/cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061",
      "published_at": "2026-03-09",
      "updated_at": "2026-03-09",
      "summary": "CTI Research: MuddyWater/Seedworm (Mango Sandstorm). Evidence-Labeled Threat Intelligence Assessment and SOC Defensive Guidance (2017 — March 2026)",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-muddywater-seedworm-mango-sandstorm-ebf6af5ba061",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-11-building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59",
      "title": "Building a Dockerized AI-Powered Host Vulnerability Assessment Tool",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-11-building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59/",
      "source_url": "https://medium.com/@1200km/building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59",
      "published_at": "2026-03-11",
      "updated_at": "2026-03-11",
      "summary": "Building a Dockerized AI-Powered Host Vulnerability Assessment Tool. How I automated security auditing with Claude, Python, and Docker — and what it found on.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-dockerized-ai-powered-host-vulnerability-assessment-tool-cd6e2147ce59",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-13-building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e",
      "title": "Building a Vulnerable Cloud Pentest Lab with Terraform",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-13-building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e/",
      "source_url": "https://medium.com/@1200km/building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e",
      "published_at": "2026-03-13",
      "updated_at": "2026-03-13",
      "summary": "Building a Vulnerable Cloud Pentest Lab with Terraform. A complete, step-by-step guide to deploying intentionally misconfigured cloud resources for hands-on.",
      "tags": [
        "article",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-a-vulnerable-cloud-pentest-lab-with-terraform-9858ac96b29e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-14-ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a",
      "title": "AI-Powered Malware Debugger That Explains Every Function It Sees",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-14-ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a/",
      "source_url": "https://medium.com/@1200km/ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a",
      "published_at": "2026-03-14",
      "updated_at": "2026-03-14",
      "summary": "AI-Powered Malware Debugger That Explains Every Function It Sees. How I combined Claude AI, Frida, Capstone, and a suite of static analysis engines into a.",
      "tags": [
        "ai-security",
        "article",
        "malware-analysis",
        "malware-behavior"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-powered-malware-debugger-that-explains-every-function-it-sees-2a28ef75df8a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-14-stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84",
      "title": "StratusAI: I Built an AI-Powered Cloud Security Scanner for AWS and GCP — Here’s Everything",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-14-stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84/",
      "source_url": "https://medium.com/@1200km/stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84",
      "published_at": "2026-03-14",
      "updated_at": "2026-03-14",
      "summary": "StratusAI: I Built an AI-Powered Cloud Security Scanner for AWS and GCP — Here’s Everything. A complete engineering walkthrough of building, testing, and.",
      "tags": [
        "ai-security",
        "article",
        "cloud-and-container-security",
        "cloud-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/stratusai-i-built-an-ai-powered-cloud-security-scanner-for-aws-and-gcp-here-s-everything-89c6702d3b84",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-16-navigate-my-blog-all-articles-by-topic-ffd800ef5480",
      "title": "Navigate My Blog: All Articles by Topic",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-16-navigate-my-blog-all-articles-by-topic-ffd800ef5480/",
      "source_url": "https://medium.com/@1200km/navigate-my-blog-all-articles-by-topic-ffd800ef5480",
      "published_at": "2026-03-16",
      "updated_at": "2026-03-16",
      "summary": "Navigate My Blog: All Articles by Topic. A single entry point to 100+ articles on offensive security, AI-driven pentesting, red team, labs, and defense. Use.",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/navigate-my-blog-all-articles-by-topic-ffd800ef5480",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-19-att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101",
      "title": "ATT&CK as a Working Tool: Theory and Hands-On Practical Usage",
      "primary_type": "article",
      "primary_domain": "threat-hunting",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-19-att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101/",
      "source_url": "https://medium.com/@1200km/att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101",
      "published_at": "2026-03-19",
      "updated_at": "2026-03-19",
      "summary": "ATT&CK as a Working Tool: Theory and Hands-On Practical Usage. A practitioner’s guide for CTI analysts, detection engineers, and threat hunters",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/att-and-ck-as-a-working-tool-theory-and-hands-on-practical-usage-d63835c9f101",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-20-attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced",
      "title": "Attribution Methodology: How to Build, Defend, and Challenge a Threat Actor Attribution",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-20-attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced/",
      "source_url": "https://medium.com/@1200km/attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced",
      "published_at": "2026-03-20",
      "updated_at": "2026-03-20",
      "summary": "Attribution Methodology: How to Build, Defend, and Challenge a Threat Actor Attribution. A practitioner’s guide for CTI analysts — from evidence collection.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/attribution-methodology-how-to-build-defend-and-challenge-a-threat-actor-attribution-071066437ced",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-21-infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c",
      "title": "Infrastructure Pivoting: How CTI Analysts Expand From a Single IOC to a Full Attacker Network",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-21-infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c/",
      "source_url": "https://medium.com/@1200km/infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c",
      "published_at": "2026-03-21",
      "updated_at": "2026-03-21",
      "summary": "Infrastructure Pivoting: How CTI Analysts Expand From a Single IOC to a Full Attacker Network. The field manual for tracing attacker infrastructure — from.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/infrastructure-pivoting-how-cti-analysts-expand-from-a-single-ioc-to-a-full-attacker-netwo-1295d50ec29c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-24-cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456",
      "title": "CVSS v4.0: The Practical Field Guide for Vulnerability Management",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-24-cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456/",
      "source_url": "https://medium.com/@1200km/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456",
      "published_at": "2026-03-24",
      "updated_at": "2026-03-24",
      "summary": "CVSS v4.0: The Practical Field Guide for Vulnerability Management. From a number that nobody trusts to a tool that changes how you work",
      "tags": [
        "application-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-03-30-android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12",
      "title": "Android APK Analysis Tool: AI-Powered Static Malware Analysis in Your Terminal",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-30-android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12/",
      "source_url": "https://medium.com/@1200km/android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12",
      "published_at": "2026-03-30",
      "updated_at": "2026-03-30",
      "summary": "Android APK Analysis Tool: AI-Powered Static Malware Analysis in Your Terminal. A practical guide to analyzing Android applications with Claude, OpenAI.",
      "tags": [
        "ai-security",
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-apk-analysis-tool-ai-powered-static-malware-analysis-in-your-terminal-4beb239dad12",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-03-30-android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d",
      "title": "Android Malware Analysis: A Practical Guide for Security Analysts",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-03-30-android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d/",
      "source_url": "https://medium.com/@1200km/android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d",
      "published_at": "2026-03-30",
      "updated_at": "2026-03-30",
      "summary": "Android Malware Analysis: A Practical Guide for Security Analysts. From APK unpacking to behavioral analysis — with three real-world malware case studies and.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-malware-analysis-a-practical-guide-for-security-analysts-9cda5efb181d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-06-building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622",
      "title": "Building an Android App Analysis Lab on Ubuntu: A Practical Setup Guide",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-06-building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622/",
      "source_url": "https://medium.com/@1200km/building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622",
      "published_at": "2026-04-06",
      "updated_at": "2026-04-06",
      "summary": "Building an Android App Analysis Lab on Ubuntu: A Practical Setup Guide. A practical step-by-step guide to building an Android malware analysis and security.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/building-an-android-app-analysis-lab-on-ubuntu-a-practical-setup-guide-4a09fff37622",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-07-android-emulation-and-virtualisation-2f6b33fcc4aa",
      "title": "Android Emulation & Virtualisation",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-07-android-emulation-and-virtualisation-2f6b33fcc4aa/",
      "source_url": "https://medium.com/@1200km/android-emulation-and-virtualisation-2f6b33fcc4aa",
      "published_at": "2026-04-07",
      "updated_at": "2026-04-07",
      "summary": "Android Emulation & Virtualisation. Complete Research Lab Guide. From Zero to a Fully Instrumented Android Research Environment",
      "tags": [
        "article",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-emulation-and-virtualisation-2f6b33fcc4aa",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-08-android-apk-vulnerability-research-complete-guide-a8fcae0f4849",
      "title": "Android APK Vulnerability Research Complete Guide",
      "primary_type": "article",
      "primary_domain": "vulnerability-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-08-android-apk-vulnerability-research-complete-guide-a8fcae0f4849/",
      "source_url": "https://medium.com/@1200km/android-apk-vulnerability-research-complete-guide-a8fcae0f4849",
      "published_at": "2026-04-08",
      "updated_at": "2026-04-08",
      "summary": "Android APK Vulnerability Research Complete Guide. Practical, end-to-end APK analysis for red teamers, bug hunters, and defenders.",
      "tags": [
        "article",
        "attack-emulation",
        "offensive-security",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/android-apk-vulnerability-research-complete-guide-a8fcae0f4849",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-08-deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415",
      "title": "Deliberately Vulnerable Android App Covering Every OWASP Mobile Top 10 Class",
      "primary_type": "article",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-08-deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415/",
      "source_url": "https://medium.com/@1200km/deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415",
      "published_at": "2026-04-08",
      "updated_at": "2026-04-08",
      "summary": "Deliberately Vulnerable Android App Covering Every OWASP Mobile Top 10 Class. A hands-on reference for mobile security researchers, bug bounty hunters, and.",
      "tags": [
        "article",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/deliberately-vulnerable-android-app-covering-every-owasp-mobile-top-10-class-7be775fc6415",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-12-ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9",
      "title": "AI in Offensive Operations: How Threat Actors Use Artificial Intelligence",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-12-ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9/",
      "source_url": "https://medium.com/@1200km/ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9",
      "published_at": "2026-04-12",
      "updated_at": "2026-04-12",
      "summary": "AI in Offensive Operations: How Threat Actors Use Artificial Intelligence. A CTI assessment of documented malicious and dual-use AI activity through April.",
      "tags": [
        "ai-security",
        "article",
        "offensive-research",
        "offensive-security",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-in-offensive-operations-how-threat-actors-use-artificial-intelligence-4eaeeaf029a9",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-14-from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426",
      "title": "From Threat Intelligence to Detection: A Practitioner’s Guide",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-14-from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426/",
      "source_url": "https://medium.com/@1200km/from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426",
      "published_at": "2026-04-14",
      "updated_at": "2026-04-14",
      "summary": "From Threat Intelligence to Detection: A Practitioner’s Guide. Building atomic, collection, correlational, TTP-based, and anomaly detection rules from real.",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/from-threat-intelligence-to-detection-a-practitioner-s-guide-2d930b168426",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-04-18-what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12",
      "title": "What AI-Assisted Offensive Work Actually Means for Your Detection Program: A Practitioner’s…",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-18-what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12/",
      "source_url": "https://medium.com/@1200km/what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12",
      "published_at": "2026-04-18",
      "updated_at": "2026-04-18",
      "summary": "What AI-Assisted Offensive Work Actually Means for Your Detection Program: A Practitioner’s…. What the public record supports, what it does not, and how to.",
      "tags": [
        "ai-security",
        "article",
        "detection-engineering",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/what-ai-assisted-offensive-work-actually-means-for-your-detection-program-a-practitioner-s-9c27a8f40f12",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-20-malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12",
      "title": "Malicious Activity as a Statistical Signal: A Detection Engineering Analysis of Anomaly-Based…",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-20-malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12/",
      "source_url": "https://medium.com/@1200km/malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12",
      "published_at": "2026-04-20",
      "updated_at": "2026-04-20",
      "summary": "Malicious Activity as a Statistical Signal: A Detection Engineering Analysis of Anomaly-Based…. An evidence-based examination of the hypothesis that.",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-04-22-detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82",
      "title": "Detecting Malicious Insider Activity: A Technical Detection Engineering Guide",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-22-detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82/",
      "source_url": "https://medium.com/@1200km/detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82",
      "published_at": "2026-04-22",
      "updated_at": "2026-04-22",
      "summary": "Detecting Malicious Insider Activity: A Technical Detection Engineering Guide. Detection logic, case evidence from 14 documented incidents, and a four-phase.",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/detecting-malicious-insider-activity-a-technical-detection-engineering-guide-3c3b41e95e82",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-04-25-cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87",
      "title": "CTI Research: Kubernetes & Cloud-Native Threat Landscape",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-25-cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87/",
      "source_url": "https://medium.com/@1200km/cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87",
      "published_at": "2026-04-25",
      "updated_at": "2026-04-25",
      "summary": "CTI Research: Kubernetes & Cloud-Native Threat Landscape. Technical Kill Chain Analysis, Detection Engineering, and Defensive Architecture (2023 — Q2 2026)",
      "tags": [
        "article",
        "cloud-and-container-security",
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-research-kubernetes-and-cloud-native-threat-landscape-70373d6d7a87",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-28-vulnerable-ai-lab-3747e96314dd",
      "title": "Vulnerable AI Lab",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-28-vulnerable-ai-lab-3747e96314dd/",
      "source_url": "https://medium.com/@1200km/vulnerable-ai-lab-3747e96314dd",
      "published_at": "2026-04-28",
      "updated_at": "2026-04-28",
      "summary": "Vulnerable AI Lab. Technical Guide for Usage, Attack Testing, Scenario Authoring, and Vulnerability Module Development",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/vulnerable-ai-lab-3747e96314dd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-04-29-ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86",
      "title": "AI Offensive Security: Practical Attacks Against LLM Agents",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-04-29-ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86/",
      "source_url": "https://medium.com/@1200km/ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86",
      "published_at": "2026-04-29",
      "updated_at": "2026-04-29",
      "summary": "AI Offensive Security: Practical Attacks Against LLM Agents. Red-Team and AppSec Practitioner Guide",
      "tags": [
        "ai-security",
        "article",
        "attack-emulation",
        "llm-and-agent-security",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-offensive-security-practical-attacks-against-llm-agents-516dbdabbf86",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-02-apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6",
      "title": "APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-02-apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6/",
      "source_url": "https://medium.com/@1200km/apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6",
      "published_at": "2026-05-02",
      "updated_at": "2026-05-02",
      "summary": "APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise. Threat Intelligence Report | Operation DragonRx",
      "tags": [
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c",
      "title": "Lab Architecture — Operation DragonRx",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c/",
      "source_url": "https://medium.com/@1200km/lab-architecture-operation-dragonrx-38602f432e5c",
      "published_at": "2026-05-02",
      "updated_at": "2026-05-02",
      "summary": "Lab Architecture — Operation DragonRx. Part of the Operation DragonRx series · Overview · Lab Architecture · Attack Playbook · DFIR Walkthrough",
      "tags": [
        "ai-security",
        "article",
        "digital-forensics",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/lab-architecture-operation-dragonrx-38602f432e5c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-04-attack-playbook-operation-dragonrx-91339316f0df",
      "title": "Attack Playbook — Operation DragonRx",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-04-attack-playbook-operation-dragonrx-91339316f0df/",
      "source_url": "https://medium.com/@1200km/attack-playbook-operation-dragonrx-91339316f0df",
      "published_at": "2026-05-04",
      "updated_at": "2026-05-04",
      "summary": "Attack Playbook — Operation DragonRx. Phase-by-Phase Attack Guide: Exact Commands Against the Deployed Lab",
      "tags": [
        "ai-security",
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/attack-playbook-operation-dragonrx-91339316f0df",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-08-manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc",
      "title": "Manual CTI vs. AI-Assisted CTI: A Step-by-Step Clock Comparison",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-08-manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc/",
      "source_url": "https://medium.com/@1200km/manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc",
      "published_at": "2026-05-08",
      "updated_at": "2026-05-08",
      "summary": "Manual CTI vs. AI-Assisted CTI: A Step-by-Step Clock Comparison. Which steps compress, which do not, and what you risk if you do not understand the difference.",
      "tags": [
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/manual-cti-vs-ai-assisted-cti-a-step-by-step-clock-comparison-ee08325203fc",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-09-cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979",
      "title": "CTI Kill Chain: An Analyst Guide With Real-World Evidence",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-09-cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979/",
      "source_url": "https://medium.com/@1200km/cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979",
      "published_at": "2026-05-09",
      "updated_at": "2026-05-09",
      "summary": "CTI Kill Chain: An Analyst Guide With Real-World Evidence. Mapping adversary behavior from preparation to impact without overstating the evidence",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-kill-chain-an-analyst-guide-with-real-world-evidence-c3bef6fd2979",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-09-cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31",
      "title": "CTI-Led Defensive Strategy for a Cellular Provider (Case Study)",
      "primary_type": "article",
      "primary_domain": "cloud-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-09-cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31/",
      "source_url": "https://medium.com/@1200km/cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31",
      "published_at": "2026-05-09",
      "updated_at": "2026-05-09",
      "summary": "CTI-Led Defensive Strategy for a Cellular Provider (Case Study). A full end-to-end practitioner guide for telecom core, cloud-native operations, SOC/NOC.",
      "tags": [
        "article",
        "cloud-security",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-led-defensive-strategy-for-a-cellular-provider-case-study-c77bc5765b31",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-10-applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b",
      "title": "Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-10-applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b/",
      "source_url": "https://medium.com/@1200km/applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b",
      "published_at": "2026-05-10",
      "updated_at": "2026-05-10",
      "summary": "Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide. Estimative language, evidence discipline, and analytic integrity for cyber.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/applying-sherman-kent-s-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-11-customer-driven-ai-cti-project-template-part-1-foundations-745861507d03",
      "title": "Customer-Driven AI CTI Project Template. Part 1: Foundations",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-11-customer-driven-ai-cti-project-template-part-1-foundations-745861507d03/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-1-foundations-745861507d03",
      "published_at": "2026-05-11",
      "updated_at": "2026-05-11",
      "summary": "Customer-Driven AI CTI Project Template. Part 1: Foundations. From pure CTI to hands-on detection engineering with strict validation gates",
      "tags": [
        "ai-security",
        "article",
        "detection-content",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-1-foundations-745861507d03",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-12-customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59",
      "title": "Customer-Driven AI CTI Project Template. Part 2A: Phase-by-Phase Execution Guide",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-12-customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59",
      "published_at": "2026-05-12",
      "updated_at": "2026-05-12",
      "summary": "Customer-Driven AI CTI Project Template. Part 2A: Phase-by-Phase Execution Guide. From pure CTI to hands-on detection engineering with strict validation gates.",
      "tags": [
        "ai-security",
        "article",
        "detection-content",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2a-phase-by-phase-execution-guide-f9751a8bcb59",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-12-customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943",
      "title": "Customer-Driven AI CTI Project Template :Part 2B: Reference Toolkit",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-12-customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943",
      "published_at": "2026-05-12",
      "updated_at": "2026-05-12",
      "summary": "Customer-Driven AI CTI Project Template :Part 2B: Reference Toolkit. From pure CTI to hands-on detection engineering with strict validation gates",
      "tags": [
        "ai-security",
        "article",
        "detection-content",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-template-part-2b-reference-toolkit-3a56fab0b943",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-13-customer-driven-ai-cti-project-c0db3cdc1830",
      "title": "Customer-Driven AI CTI Project",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-13-customer-driven-ai-cti-project-c0db3cdc1830/",
      "source_url": "https://medium.com/@1200km/customer-driven-ai-cti-project-c0db3cdc1830",
      "published_at": "2026-05-13",
      "updated_at": "2026-05-13",
      "summary": "Customer-Driven AI CTI Project. Full Workflow Quick Reference",
      "tags": [
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/customer-driven-ai-cti-project-c0db3cdc1830",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-18-cti-analyst-field-manual-complete-reference-ef2a370bb21f",
      "title": "CTI Analyst Field Manual — Complete Reference",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-18-cti-analyst-field-manual-complete-reference-ef2a370bb21f/",
      "source_url": "https://medium.com/@1200km/cti-analyst-field-manual-complete-reference-ef2a370bb21f",
      "published_at": "2026-05-18",
      "updated_at": "2026-05-18",
      "summary": "CTI Analyst Field Manual — Complete Reference. A practitioner field manual for cyber threat intelligence: from collection requirements to production detection.",
      "tags": [
        "article",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/cti-analyst-field-manual-complete-reference-ef2a370bb21f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-05-21-the-intelligent-shield-opencti-057c9b4b9394",
      "title": "The Intelligent Shield. OpenCTI",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-21-the-intelligent-shield-opencti-057c9b4b9394/",
      "source_url": "https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394",
      "published_at": "2026-05-21",
      "updated_at": "2026-05-21",
      "summary": "The Intelligent Shield. OpenCTI. In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-22-one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c",
      "title": "One place for my cybersecurity projects, guides, articles, labs, tools, and research workflows",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-22-one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c/",
      "source_url": "https://medium.com/@1200km/one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c",
      "published_at": "2026-05-22",
      "updated_at": "2026-05-22",
      "summary": "One place for my cybersecurity projects, guides, articles, labs, tools, and research workflows. Andrey Pautov - CTI, Detection Engineering & Security Research",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/one-place-for-my-cybersecurity-projects-guides-articles-labs-tools-and-research-workflows-5d358753c86c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-05-23-operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0",
      "title": "Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana",
      "primary_type": "article",
      "primary_domain": "offensive-research",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-23-operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0/",
      "source_url": "https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0",
      "published_at": "2026-05-23",
      "updated_at": "2026-05-23",
      "summary": "Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana. Most threat actor writeups stop too early. They describe the group, list ATT&CK.",
      "tags": [
        "ai-security",
        "article",
        "mitre-attack",
        "offensive-research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-05-29-cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46",
      "title": "CTI as a Code: Complete Step-by-Step Methodology",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-29-cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46/",
      "source_url": "https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46",
      "published_at": "2026-05-29",
      "updated_at": "2026-05-29",
      "summary": "CTI as a Code: Complete Step-by-Step Methodology. The evidence problem.An analyst writes “the adversary used T1078” in a report. Six months later nobody can.",
      "tags": [
        "article",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-05-30-cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f",
      "title": "CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "stable reference article; environment-specific commands and product details still require validation",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-05-30-cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f/",
      "source_url": "https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f",
      "published_at": "2026-05-30",
      "updated_at": "2026-05-30",
      "summary": "CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma. All organizations, names, and data are fictional. This is training assignment A01 from.",
      "tags": [
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:articles:read:2026:2026-06-07-adversarygraph-i-built-a-self-hosted-ai-threat-intelligence-platform-here-s-how-to-use-it-0aa7673e6bd8",
      "title": "AdversaryGraph: I Built a Self-Hosted AI Threat Intelligence Platform — Here’s How to Use It",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-07-adversarygraph-i-built-a-self-hosted-ai-threat-intelligence-platform-here-s-how-to-use-it-0aa7673e6bd8/",
      "source_url": "https://infosecwriteups.com/threatmapper-i-built-a-self-hosted-ai-threat-intelligence-platform-heres-how-to-use-it-0aa7673e6bd8",
      "published_at": "2026-06-07",
      "updated_at": "2026-06-07",
      "summary": "AdversaryGraph: I Built a Self-Hosted AI Threat Intelligence Platform — Here’s How to Use It. GitHub - anpa1200/threatmapper: AI-powered MITRE ATT&CK threat.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/threatmapper-i-built-a-self-hosted-ai-threat-intelligence-platform-heres-how-to-use-it-0aa7673e6bd8",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-16-adversarygraph-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65",
      "title": "AdversaryGraph v2.0: I Built a Self-Hosted AI Threat Intelligence Platform",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "2.0",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-16-adversarygraph-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65/",
      "source_url": "https://infosecwriteups.com/threatmapper-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65",
      "published_at": "2026-06-16",
      "updated_at": "2026-06-16",
      "summary": "AdversaryGraph v2.0: I Built a Self-Hosted AI Threat Intelligence Platform. A report is not enough. A PDF from a vendor, an incident response write-up, a.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "digital-forensics",
        "incident-response",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/threatmapper-v2-0-i-built-a-self-hosted-ai-threat-intelligence-platform-941a80cc5a65",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-19-adversarygraph-usecases-820d03c3a7ab",
      "title": "AdversaryGraph Usecases",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-19-adversarygraph-usecases-820d03c3a7ab/",
      "source_url": "https://medium.com/@1200km/adversarygraph-usecases-820d03c3a7ab",
      "published_at": "2026-06-19",
      "updated_at": "2026-06-19",
      "summary": "AdversaryGraph Usecases. AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adversarygraph-usecases-820d03c3a7ab",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-06-19-adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "title": "AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "2.5",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-19-adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e/",
      "source_url": "https://infosecwriteups.com/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "published_at": "2026-06-19",
      "updated_at": "2026-06-19",
      "summary": "AdversaryGraph v2.5: New Name, New Release, Full AI CTI Platform Capability Map. This release marks an important transition for the project: the tool now has.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/adversarygraph-v2-5-new-name-new-release-full-ai-cti-platform-capability-map-93cd9224127e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-21-from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "title": "From Log to Report: Using AdversaryGraph!",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-21-from-log-to-report-using-adversarygraph-eff2e1d8f2cd/",
      "source_url": "https://medium.com/@1200km/from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "published_at": "2026-06-21",
      "updated_at": "2026-06-21",
      "summary": "From Log to Report: Using AdversaryGraph!. The harder problem is turning scattered technical evidence into a defensible investigation",
      "tags": [
        "adversarygraph",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/from-log-to-report-using-adversarygraph-eff2e1d8f2cd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-06-26-adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platfo-8dfbf1db2c9e",
      "title": "AdversaryGraph v4.0: I Added a Full Malware Analysis Workbench to My Self-Hosted CTI Platform",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "4.0",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-26-adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platfo-8dfbf1db2c9e/",
      "source_url": "https://infosecwriteups.com/adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platform-8dfbf1db2c9e",
      "published_at": "2026-06-26",
      "updated_at": "2026-06-26",
      "summary": "AdversaryGraph v4.0: I Added a Full Malware Analysis Workbench to My Self-Hosted CTI Platform. You upload a sample to one tool for hash reputation. You open.",
      "tags": [
        "adversarygraph",
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/adversarygraph-v4-0-i-added-a-full-malware-analysis-workbench-to-my-self-hosted-cti-platform-8dfbf1db2c9e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-06-29-adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39",
      "title": "AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "historical",
      "evidence_level": "unverified",
      "version": "5.0",
      "applies_to": "version-specific or time-bound historical publication; not current product guidance",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-06-29-adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39/",
      "source_url": "https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39",
      "published_at": "2026-06-29",
      "updated_at": "2026-06-29",
      "summary": "AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation. How can a security team move from threat intelligence to detection.",
      "tags": [
        "adversarygraph",
        "article",
        "attack-emulation",
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "historical"
    },
    {
      "id": "site:articles:read:2026:2026-07-03-comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmwa-8a151f8d5f1b",
      "title": "Comprehensive Cyber Intelligence Research: Attacks Against Embedded Systems, Hardware, Firmware…",
      "primary_type": "article",
      "primary_domain": "application-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-03-comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmwa-8a151f8d5f1b/",
      "source_url": "https://infosecwriteups.com/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "published_at": "2026-07-03",
      "updated_at": "2026-07-03",
      "summary": "Comprehensive Cyber Intelligence Research: Attacks Against Embedded Systems, Hardware, Firmware…. 2. Post-compromise persistence is the real risk, not only.",
      "tags": [
        "application-security",
        "article",
        "embedded-security",
        "hardware-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-07-07-when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-curso-55eea06b69bd",
      "title": "When AI Coding Agents Say Yes Too Easily: Testing Suspicious Cybersecurity Prompts in Cursor",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-07-when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-curso-55eea06b69bd/",
      "source_url": "https://medium.com/@1200km/when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-cursor-55eea06b69bd",
      "published_at": "2026-07-07",
      "updated_at": "2026-07-07",
      "summary": "When AI Coding Agents Say Yes Too Easily: Testing Suspicious Cybersecurity Prompts in Cursor. I ran a small test inside Cursor to compare how different AI.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/when-ai-coding-agents-say-yes-too-easily-testing-suspicious-cybersecurity-prompts-in-cursor-55eea06b69bd",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-07-11-newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "title": "Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry",
      "primary_type": "article",
      "primary_domain": "detection-engineering",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-11-newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556/",
      "source_url": "https://infosecwriteups.com/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "published_at": "2026-07-11",
      "updated_at": "2026-07-11",
      "summary": "Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry. 7. Technique 4: Weak-Signal Aggregation and Risk-Based Alerting",
      "tags": [
        "article",
        "detection-content",
        "detection-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-07-23-adversarygraph-40df3439b90c",
      "title": "AdversaryGraph",
      "primary_type": "article",
      "primary_domain": "threat-intelligence",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-23-adversarygraph-40df3439b90c/",
      "source_url": "https://medium.com/@1200km/adversarygraph-40df3439b90c",
      "published_at": "2026-07-23",
      "updated_at": "2026-07-23",
      "summary": "AdversaryGraph. AdversaryGraph is a self-hosted security intelligence workbench for teams that need to move from threat reports and observables to reviewed.",
      "tags": [
        "adversarygraph",
        "article",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/adversarygraph-40df3439b90c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-07-31-i-m-building-an-ai-security-engineering-course-55e29e6c035e",
      "title": "I’m Building an AI Security Engineering Course",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-07-31-i-m-building-an-ai-security-engineering-course-55e29e6c035e/",
      "source_url": "https://medium.com/@1200km/im-building-an-ai-security-engineering-course-55e29e6c035e",
      "published_at": "2026-07-31",
      "updated_at": "2026-07-31",
      "summary": "I’m Building an AI Security Engineering Course. AI security has moved beyond a narrow conversation about prompt injection",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/im-building-an-ai-security-engineering-course-55e29e6c035e",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-01-ai-security-course-module-00-part-1-introduction-ai-ml-taxonomy-2e26c0740a17",
      "title": "AI Security Course, Module 00 — Part 1: Introduction, AI/ML Taxonomy",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-01-ai-security-course-module-00-part-1-introduction-ai-ml-taxonomy-2e26c0740a17/",
      "source_url": "https://infosecwriteups.com/ai-security-course-module-00-part-1-introduction-ai-ml-taxonomy-and-data-foundations-2e26c0740a17",
      "published_at": "2026-08-01",
      "updated_at": "2026-08-01",
      "summary": "AI Security Course, Module 00 — Part 1: Introduction, AI/ML Taxonomy. AI security conversations often begin with prompt injection, jailbreaks, or a new.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/ai-security-course-module-00-part-1-introduction-ai-ml-taxonomy-and-data-foundations-2e26c0740a17",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-02-ai-security-course-module-00-part-2-69381c74a59c",
      "title": "AI Security Course, Module 00 — Part 2",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-02-ai-security-course-module-00-part-2-69381c74a59c/",
      "source_url": "https://medium.com/@1200km/ai-security-course-module-00-chapter-2-69381c74a59c",
      "published_at": "2026-08-02",
      "updated_at": "2026-08-02",
      "summary": "AI Security Course, Module 00 — Part 2. Data, features, labels, parameters, hyperparameters, training, validation, testing, and inference are different.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-security-course-module-00-chapter-2-69381c74a59c",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-06-what-is-malware-93746950ce9a",
      "title": "What Is Malware?",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-06-what-is-malware-93746950ce9a/",
      "source_url": "https://medium.com/@1200km/what-is-malware-93746950ce9a",
      "published_at": "2026-08-06",
      "updated_at": "2026-08-06",
      "summary": "What Is Malware?. Malware, short formalicious software, is software or code intentionally used to compromise the confidentiality, integrity, or availability.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/what-is-malware-93746950ce9a",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-07-how-to-build-a-safe-malware-analysis-lab-with-flare-vm-remnux-and-inetsim-0287d3964602",
      "title": "How to Build a Safe Malware Analysis Lab with FLARE-VM, REMnux, and INetSim",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-07-how-to-build-a-safe-malware-analysis-lab-with-flare-vm-remnux-and-inetsim-0287d3964602/",
      "source_url": "https://medium.com/@1200km/how-to-build-a-safe-malware-analysis-lab-with-flare-vm-remnux-and-inetsim-0287d3964602",
      "published_at": "2026-08-07",
      "updated_at": "2026-08-07",
      "summary": "How to Build a Safe Malware Analysis Lab with FLARE-VM, REMnux, and INetSim. A practical, safety-first guide to preparing an isolated Windows.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/how-to-build-a-safe-malware-analysis-lab-with-flare-vm-remnux-and-inetsim-0287d3964602",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-08-ai-security-course-module-00-chapter-3-1bf0411472f6",
      "title": "AI Security Course, Module 00 — Chapter 3: Neural Networks and Optimization",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-08-ai-security-course-module-00-chapter-3-1bf0411472f6/",
      "source_url": "https://medium.com/@1200km/ai-security-course-module-00-chapter-3-1bf0411472f6",
      "published_at": "2026-08-08",
      "updated_at": "2026-08-08",
      "summary": "AI Security Course, Module 00 — Chapter 3: Neural Networks and Optimization. This chapter explains neural-network computation, optimization, reproducibility.",
      "tags": [
        "ai-security",
        "article"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-security-course-module-00-chapter-3-1bf0411472f6",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-09-assembly-for-malware-analysis-be0679241940",
      "title": "Assembly for Malware Analysis: A Practical x86/x64 Guide",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-09-assembly-for-malware-analysis-be0679241940/",
      "source_url": "https://medium.com/@1200km/assembly-for-malware-analysis-be0679241940",
      "published_at": "2026-08-09",
      "updated_at": "2026-08-09",
      "summary": "Assembly for Malware Analysis: A Practical x86/x64 Guide. Learn how to read x86 and x64 assembly for malware analysis with hands-on AIDebug labs covering.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/assembly-for-malware-analysis-be0679241940",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-10-pe-file-structure-for-malware-analysis-d93acb97d9f3",
      "title": "PE File Structure for Malware Analysis: A Practical Guide",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-10-pe-file-structure-for-malware-analysis-d93acb97d9f3/",
      "source_url": "https://medium.com/@1200km/pe-file-structure-for-malware-analysis-d93acb97d9f3",
      "published_at": "2026-08-10",
      "updated_at": "2026-08-10",
      "summary": "PE File Structure for Malware Analysis: A Practical Guide. Understand Windows PE files for malware analysis: headers, sections, imports, exports, resources.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/pe-file-structure-for-malware-analysis-d93acb97d9f3",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-12-strings-analysis-for-malware-analysis-turning-391815ee35e2",
      "title": "Strings Analysis for Malware Analysis: Turning Binary Text into Defensible Hypotheses",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-12-strings-analysis-for-malware-analysis-turning-391815ee35e2/",
      "source_url": "https://medium.com/@1200km/strings-analysis-for-malware-analysis-turning-391815ee35e2",
      "published_at": "2026-08-12",
      "updated_at": "2026-08-12",
      "summary": "Strings Analysis for Malware Analysis: Turning Binary Text into Defensible Hypotheses. Turn extracted binary text into defensible malware-analysis hypotheses.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/strings-analysis-for-malware-analysis-turning-391815ee35e2",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-13-aidebug-3-1-full-release-review",
      "title": "AIDebug 3.1 Full Release Review: From Binary Intake to String Intelligence",
      "primary_type": "article",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "unverified",
      "applies_to": "current core 1200km research selected by the maintained article lifecycle policy",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-13-aidebug-3-1-full-release-review/",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": "2026-08-13",
      "updated_at": "2026-08-13",
      "summary": "AIDebug 3.1 Full Release Review: From Binary Intake to String Intelligence. A complete, evidence-first review of AIDebug 3.1 covering static triage, PE.",
      "tags": [
        "article",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "InfoSec Write-ups",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:read:2026:2026-08-15-ai-security-course-module-00-chapter-4-b8e3de0c3a9d",
      "title": "AI Security Course, Module 00 — Chapter 4",
      "primary_type": "article",
      "primary_domain": "ai-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-15-ai-security-course-module-00-chapter-4-b8e3de0c3a9d/",
      "source_url": "https://medium.com/@1200km/ai-security-course-module-00-chapter-4-b8e3de0c3a9d",
      "published_at": "2026-08-15",
      "updated_at": "2026-08-15",
      "summary": "AI Security Course, Module 00 — Chapter 4. Trace an LLM request from structured messages to generated output, then place authorization, validation, and.",
      "tags": [
        "ai-security",
        "article",
        "llm-and-agent-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/ai-security-course-module-00-chapter-4-b8e3de0c3a9d",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:read:2026:2026-08-19-course-review-trainsec-malware-analyst-professional-level-1-203ca89b76a2",
      "title": "Course Review — TrainSec Malware Analyst Professional — Level 1",
      "primary_type": "article",
      "primary_domain": "malware-analysis",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "published article whose technical currentness has not yet been reverified",
      "canonical_url": "https://1200km.com/articles/read/2026/2026-08-19-course-review-trainsec-malware-analyst-professional-level-1-203ca89b76a2/",
      "source_url": "https://medium.com/@1200km/course-review-trainsec-malware-analyst-professional-level-1-203ca89b76a2",
      "published_at": "2026-08-19",
      "updated_at": "2026-08-19",
      "summary": "Course Review — TrainSec Malware Analyst Professional — Level 1. A practical review of TrainSec's Malware Analyst Professional Level 1 course, its learning.",
      "tags": [
        "article",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://medium.com/@1200km/course-review-trainsec-malware-analyst-professional-level-1-203ca89b76a2",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:trainsec-library.html",
      "title": "TrainSec Knowledge Library",
      "primary_type": "index",
      "primary_domain": "network-security",
      "audience": [
        "general"
      ],
      "status": "released",
      "maturity": "reference",
      "evidence_level": "unverified",
      "applies_to": "canonical local article pages with original publication URLs retained as provenance",
      "canonical_url": "https://1200km.com/articles/trainsec-library.html",
      "source_url": "https://infosecwriteups.com/@1200km",
      "published_at": "2026-08-03",
      "updated_at": "2026-08-03",
      "summary": "Source-linked catalogue of 87 TrainSec Knowledge Library articles with authors, dates, domains, modes, tags, and original media links.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "network-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:medium-export",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/medium-blog-navigation",
      "original_publication": "https://infosecwriteups.com/@1200km",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "archive",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:articles:trainsec:authors.html",
      "title": "TrainSec Authors",
      "primary_type": "index",
      "primary_domain": "network-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://1200km.com/articles/trainsec/authors.html",
      "source_url": "https://trainsec.net/library/",
      "published_at": "2026-09-06",
      "updated_at": "2026-09-06",
      "summary": "Author index for the permitted TrainSec Knowledge Library mirrors. Every name links to the locally integrated articles and retains the original source…",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "network-security",
        "trainsec"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:articles:trainsec:domains.html",
      "title": "TrainSec Domains",
      "primary_type": "index",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://1200km.com/articles/trainsec/domains.html",
      "source_url": "https://trainsec.net/library/",
      "published_at": "2026-09-06",
      "updated_at": "2026-09-06",
      "summary": "Domain index for the permitted TrainSec Knowledge Library mirrors. Use these cross-links to move between malware analysis, Windows internals, hardware…",
      "tags": [
        "author:Andrey Pautov",
        "embedded-security",
        "index",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering",
        "trainsec",
        "windows-internals"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:courses",
      "title": "Courses & Learning Paths",
      "primary_type": "index",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "the maintained 1200km index of original cybersecurity courses, completed independent course reviews, and evidence-backed learning paths",
      "canonical_url": "https://1200km.com/courses/",
      "published_at": "2026-08-01",
      "updated_at": "2026-09-02",
      "summary": "Independent cybersecurity course reviews and evidence-backed learning paths with completed study records, practical materials, limitations, and recommendations.",
      "tags": [
        "course-review",
        "cybersecurity-education",
        "learning-path",
        "security-training"
      ],
      "featured": true,
      "indexable": true,
      "lifecycle": "maintained",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/courses/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core"
    },
    {
      "id": "site:courses:trainsec-malware-analyst-professional-level-1",
      "title": "TrainSec Malware Analyst Professional Level 1",
      "primary_type": "case-study",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer",
        "cti-analyst",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "the completed TrainSec Malware Analyst Professional Level 1 learning record, independent recommendation, and five original companion guides",
      "canonical_url": "https://1200km.com/courses/trainsec-malware-analyst-professional-level-1/",
      "published_at": "2026-08-19",
      "updated_at": "2026-09-02",
      "summary": "An independent learning record for TrainSec Malware Analyst Professional Level 1, with strengths, limitations, advertised duration, and five companion guides.",
      "tags": [
        "course-review",
        "learning-record",
        "malware-analysis",
        "reverse-engineering",
        "security-training",
        "aidebug"
      ],
      "featured": false,
      "indexable": true,
      "lifecycle": "maintained",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/courses/trainsec-malware-analyst-professional-level-1/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core"
    },
    {
      "id": "site:cti_as_a_code",
      "title": "CTI as a Code",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Version-controlled CTI methodology, evidence-traced analysis, and deployable detections. Docker Compose lab stack and 8 structured training assignments.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:architecture",
      "title": "Architecture",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/architecture/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "See how the lab combines OpenCTI, TheHive, Cortex, Elasticsearch, Kibana, and Logstash in one Docker Compose stack with clear shared data flows.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:celltronx-proactive-case-study",
      "title": "CTI as a Code in Practice: Proactive Assessment — CelltronX Telecom",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/celltronx-proactive-case-study/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Apply proactive CTI to a telecom supply-chain scenario: connect four intelligence triggers, model attack paths, prioritize gaps, and produce five Sigma rules.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:cti-as-a-code-methodology",
      "title": "CTI as a Code: Complete Step-by-Step Methodology",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/cti-as-a-code-methodology/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Follow an evidence-traced CTI workflow from intake and source evaluation through claims, ATT&CK mapping, Sigma validation, and a detection backlog.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/ecosystem/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Connect the lab, field manual, sector research, AI-assisted delivery, AdversaryGraph, and validation tooling into practical analyst workflows.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:intake-form",
      "title": "Investigation Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intake-form/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Capture incident scope, stakeholders, known facts, evidence gaps, reporting needs, and response constraints before starting a reactive CTI investigation.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:intake-fullcycle",
      "title": "Full-Cycle CTI Program Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intake-fullcycle/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Capture program mandate, stakeholders, intelligence requirements, collection gaps, governance, sharing, metrics, and delivery constraints before design.",
      "tags": [
        "lab",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:intake-proactive",
      "title": "Proactive Assessment Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intake-proactive/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Capture the trigger, decision, stakeholders, time horizon, scope, assumptions, evidence needs, and deliverables before a proactive threat assessment.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:integrations:opencti-thehive",
      "title": "OpenCTI → TheHive Integration",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/integrations/opencti-thehive/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Move confirmed indicators and campaign context into incident cases, then return enriched observables to the intelligence platform with traceable workflow steps.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:integrations:threat-feeds",
      "title": "Threat Feeds and Data Sources",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/integrations/threat-feeds/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Populate the lab with real threat intelligence by connecting external feeds. See the ecosystem for how feeds fit into the overall lab stack.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:intro",
      "title": "CTI as a Code",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/intro/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Build repeatable threat-intelligence investigations with a Docker Compose lab, evidence-traced claims, deployable Sigma rules, and eight training scenarios.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:lifetech-pharma-case-study",
      "title": "Case Study: CTI as a Code in Practice — LifeTech Pharma",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/lifetech-pharma-case-study/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Reconstruct a pharmaceutical intrusion through dual entry paths, DCSync, R&D exfiltration, and a ten-day telemetry gap, then derive defensible detections.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:methodology",
      "title": "CTI as a Code — Methodology",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/methodology/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Use version control, templates, evidence labels, claims ledgers, ATT&CK mapping, and detection backlogs to make CTI work reproducible and auditable.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:prerequisites",
      "title": "Prerequisites",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/prerequisites/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Prepare a Linux host, Docker tooling, memory, storage, ports, environment secrets, and network settings before bringing up the full intelligence lab.",
      "tags": [
        "ai-security",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:proactive-walkthrough",
      "title": "CTI as a Code in Practice: Proactive Threat Assessment — CelltronX Telecom",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/proactive-walkthrough/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Turn four threat triggers, contractor exposure, active TTPs, and a compliance gap into prioritized attack scenarios and a sprint-ready detection backlog.",
      "tags": [
        "lab",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:quick-start",
      "title": "Quick Start",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/quick-start/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Clone the repository, configure secrets, start the Docker Compose services, verify health, and open each analyst platform in a working local lab.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:reactive-walkthrough",
      "title": "CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/reactive-walkthrough/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-05-31",
      "summary": "A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:services:elastic-siem",
      "title": "Elastic SIEM",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/elastic-siem/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Connect the shared data store, Kibana, and optional Logstash ingestion to support alert triage, timeline analysis, dashboards, and detection validation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:services:elasticsearch",
      "title": "Elasticsearch",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/elasticsearch/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Configure the shared 8.x data store used by intelligence, case management, enrichment, and SIEM services, including health checks and index access.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:services:opencti",
      "title": "OpenCTI",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/opencti/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Configure the core STIX2 intelligence platform for actors, malware, campaigns, attack patterns, and indicators, with graph-based investigation workflows.",
      "tags": [
        "lab",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:services:thehive-cortex",
      "title": "TheHive 5 + Cortex",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/services/thehive-cortex/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "TheHive is the incident response case management system. Cortex is the companion automated enrichment engine that runs analyzers against observables.",
      "tags": [
        "digital-forensics",
        "incident-response",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:setup:cortex-setup",
      "title": "Cortex Setup and TheHive Integration",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/cortex-setup/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Create the enrichment-engine administrator, connect the service to TheHive, add analyzers, and verify observable analysis in the local lab stack.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:setup:first-run",
      "title": "First-Run Checklist",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/first-run/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Verify each Docker service after setup, confirm web access and health, create required accounts, test integrations, and catch configuration failures early.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:setup:opencti-setup",
      "title": "OpenCTI First-Run Setup",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/opencti-setup/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Complete first-run administration for the intelligence platform: sign in, configure organization settings, add connectors, and verify ingestion health.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:setup:thehive-setup",
      "title": "TheHive First-Run Setup",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/setup/thehive-setup/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Create the initial case-management organization and administrator, connect the shared data store, set permissions, and verify analyst access.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training",
      "title": "Training Assignments",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Practice reactive, proactive, full-cycle, and emulation work through eight structured scenarios with synthetic evidence, analyst files, and worked solutions.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:emulation-ndsa",
      "title": "A08 — Adversary Emulation (Gov): NDSA INCD Section 8",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/emulation-ndsa/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Run an annual government detection-validation exercise across fifteen TTPs, score eleven modules, document evidence, and prioritize remediation work.",
      "tags": [
        "attack-emulation",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:emulation-techpay",
      "title": "A04 — Adversary Emulation: TechPay (Operation Desert Cipher)",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/emulation-techpay/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Validate eight payment-sector detections against an emulation plan, record pass, partial, and fail evidence, and turn coverage gaps into engineering actions.",
      "tags": [
        "ai-security",
        "attack-emulation",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:full-cycle-ndsa",
      "title": "A07 — Full CTI Cycle (Gov): NDSA CTI Program",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/full-cycle-ndsa/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Design a twelve-month government intelligence program after a breach, covering requirements, collection gaps, sharing, governance, and compliance milestones.",
      "tags": [
        "lab",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:full-cycle-techpay",
      "title": "A03 — Full CTI Cycle: TechPay FinTech",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/full-cycle-techpay/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Build a standing intelligence program for a payment processor: define requirements, collection, governance, sharing, metrics, and an auditable roadmap.",
      "tags": [
        "lab",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:proactive-celltronx",
      "title": "A02 — Proactive CTI: CelltronX Telecom",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/proactive-celltronx/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Assess nation-state telecom targeting before an incident, model contractor and internet-facing paths, rank intelligence gaps, and build a detection backlog.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:proactive-govid2",
      "title": "A06 — Proactive CTI (Gov): GovID 2.0 Pre-Launch",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/proactive-govid2/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Assess threats to a national biometric gateway before launch, connect four triggers, model likely attack paths, and deliver a defensible go or no-go decision.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:reactive-lifetech",
      "title": "A01 — Reactive IR: LifeTech Pharma",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/reactive-lifetech/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Investigate a 52-hour pharmaceutical intrusion, trace dual entry points and DCSync, assess exfiltration, and write four Sigma detections from evidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "incident-response",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:training:reactive-ndsa",
      "title": "A05 — Reactive IR (Gov): NDSA Biometric Breach",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/training/reactive-ndsa/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Reconstruct a government contractor breach affecting biometric records, document the timeline and notifications, map TTPs, and derive five Sigma rules.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "incident-response",
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:workflows:fullcycle-program",
      "title": "Full-Cycle CTI Program — Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/fullcycle-program/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Scope a new or recovering intelligence program by clarifying mandate, stakeholders, requirements, collection gaps, governance, sharing, and success measures.",
      "tags": [
        "lab",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:workflows:ioc-triage",
      "title": "IOC Triage Workflow",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/ioc-triage/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Turn a suspicious indicator into an evidence-traced product through enrichment, correlation, confidence scoring, case handling, and detection handoff.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:workflows:proactive-assessment",
      "title": "Proactive Assessment — Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/proactive-assessment/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Frame an intelligence assessment before collection by defining the trigger, decision, stakeholders, time horizon, scope, assumptions, and evidence needs.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:workflows:reactive-investigation",
      "title": "Reactive Investigation — Intake",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/reactive-investigation/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Define the incident decision, stakeholders, scope, known facts, evidence gaps, and reporting cadence before opening logs or launching enrichment queries.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti_as_a_code:workflows:threat-actor-research",
      "title": "Threat Actor Research Workflow",
      "primary_type": "lab",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "version-controlled CTI training and investigation workflows",
      "canonical_url": "https://1200km.com/CTI_as_a_Code/workflows/threat-actor-research/",
      "source_url": "https://github.com/anpa1200/CTI_as_a_Code",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Build an evidence-traced actor profile from public sources, normalize aliases and infrastructure, map TTPs, record confidence, and hand off detections.",
      "tags": [
        "lab",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-as-code",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/CTI_as_a_Code",
      "original_publication": "https://github.com/anpa1200/CTI_as_a_Code",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual",
      "title": "CTI Analyst Field Manual",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Learn practical CTI tradecraft for evidence handling, source assessment, attribution, infrastructure pivoting, threat hunting, and detection-ready outputs.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:actor-profile-template",
      "title": "Actor Profile Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/actor-profile-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Structure an actor profile around aliases, evidence, targeting, behaviors, infrastructure, tools, uncertainty, defensive relevance, and update history.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:actor-update-workflow",
      "title": "Actor Update Workflow",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/actor-update-workflow/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Refresh actor profiles through dated source intake, claim-level comparison, contradiction review, confidence changes, and downstream detection updates.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:apt41-dragonrx",
      "title": "APT41 / Operation DragonRx",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/apt41-dragonrx/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Use public reporting on APT41 and Operation DragonRx to practice source separation, evidence labeling, ATT&CK mapping, and detection handoff.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:handala",
      "title": "Handala / Void Manticore Research Method",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/handala/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Separate Handala's public persona claims from the operational cluster tracked as Void Manticore, preserving source attribution and uncertainty.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:actor-research:muddywater-seedworm",
      "title": "MuddyWater / Seedworm",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/actor-research/muddywater-seedworm/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Build a calibrated profile of the Iran-nexus cluster using public advisories and vendor reporting without merging every alias, campaign, or tool claim.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:ai-cti-control-matrix",
      "title": "AI CTI Control Matrix",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/ai-cti-control-matrix/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Classify CTI tasks and data by whether AI use is allowed, restricted, or prohibited, with human review, source verification, and handling controls.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:ai-quality-gates",
      "title": "AI Quality Gates",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/ai-quality-gates/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Require source fidelity, evidence traceability, uncertainty, safe handling, factual review, and human approval before AI-assisted CTI can be used.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:hallucination-control",
      "title": "Hallucination Control",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/hallucination-control/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Prevent fabricated CTI claims by constraining inputs, requiring citations, checking source support, separating inference, and rejecting unverifiable output.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:manual-vs-ai-assisted-cti",
      "title": "Manual vs AI-Assisted CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/manual-vs-ai-assisted-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-18",
      "summary": "Compare tasks suited to human judgment with bounded AI assistance for extraction, normalization, comparison, drafting, and quality-control support.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:prompt-library",
      "title": "Prompt Library",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/prompt-library/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Use reusable prompts for source extraction, claim comparison, evidence review, ATT&CK suggestions, and detection handoff with explicit verification gates.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ai-assisted-cti:safe-llm-research-workflow",
      "title": "Safe LLM Research Workflow",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ai-assisted-cti/safe-llm-research-workflow/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-18",
      "summary": "Run public CTI research through scoped collection, data classification, constrained prompts, citation checks, human review, and auditable evidence records.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "llm-and-agent-security",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:alternative-hypotheses",
      "title": "Alternative Hypotheses",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/alternative-hypotheses/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Document competing explanations, test each against the same evidence, and define collection that can distinguish them before making a CTI judgment.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:analyst-checklist",
      "title": "Analyst Checklist",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/analyst-checklist/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Review CTI outputs for requirements, source quality, evidence labels, uncertainty, contradictions, relevance, and actionable next steps before publication.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:assumptions-and-gaps",
      "title": "Assumptions and Gaps",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/assumptions-and-gaps/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Make assumptions and intelligence gaps visible, state how each affects confidence, and assign collection actions instead of letting uncertainty weaken analysis.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:contradiction-handling",
      "title": "Contradiction Handling",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/contradiction-handling/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Classify conflicting claims as factual, taxonomic, temporal, or interpretive, then preserve each source and explain how the conflict affects judgment.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:estimative-language",
      "title": "Estimative Language",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/estimative-language/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Use practical wording for CTI judgments where evidence is incomplete, and enforce consistency so readers can interpret confidence correctly.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:analytic-discipline:sherman-kent-for-cti",
      "title": "Sherman Kent for CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/analytic-discipline/sherman-kent-for-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Use Sherman Kent's separation and calibration principles to distinguish facts, reporting, inference, assumptions, gaps, and confidence in CTI writing.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:attribution-methodology",
      "title": "Attribution Methodology",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/attribution-methodology/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Build attribution judgments from weighted technical, infrastructure, behavioral, victimology, temporal, and source evidence while preserving alternatives.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:attribution-worked-example",
      "title": "Attribution Worked Example",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/attribution-worked-example/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Follow a defensive attribution exercise that separates observed facts, reported claims, inferences, alternatives, and confidence without naming a real actor.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:confidence-vs-probability",
      "title": "Confidence vs Probability",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/confidence-vs-probability/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Separate likelihood of an event from trust in the evidence and reasoning behind a judgment, then communicate both concepts without implying certainty.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:evidence-strength-ladder",
      "title": "Evidence Strength Ladder",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/evidence-strength-ladder/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Rank attribution signals by evidentiary strength, from weak stylistic or victimology clues to corroborated infrastructure and source-backed technical links.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:attribution:false-flag-analysis",
      "title": "False Flag Analysis",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/attribution/false-flag-analysis/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "How to identify and analyze false flag operations in CTI — when to consider deception, how to weight conflicting indicators, and how to hedge assessments.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:confidence-language",
      "title": "Confidence Language",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/confidence-language/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Confidence communicates the analyst's trust in a judgment based on evidence quality, source access, corroboration, analytic consistency, and known gaps.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:evidence-labels",
      "title": "Evidence Labels",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/evidence-labels/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "CTI evidence labeling system: how to tag claims with source quality, confidence tier, and evidence type to maintain analytic rigor across investigations.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:finished-intelligence-vs-research-notes",
      "title": "Finished Intelligence vs Research Notes",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/finished-intelligence-vs-research-notes/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Distinguish source collection and working notes from intelligence that explains meaning, uncertainty, relevance, and the decision or defensive action required.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:intelligence-cycle",
      "title": "Intelligence Cycle",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/intelligence-cycle/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Apply direction, collection, processing, analysis, dissemination, and feedback as a traceable workflow that connects a CTI requirement to action.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:pir-sir-eei",
      "title": "PIR, SIR, and EEI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/pir-sir-eei/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "How to define Priority Intelligence Requirements (PIR), Specific Intelligence Requirements (SIR), and Essential Elements of Information (EEI) for CTI programs.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:source-reliability",
      "title": "Source Reliability",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/source-reliability/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Information credibility describes how believable a specific claim is after considering corroboration, detail, consistency, and proximity to evidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-foundations:what-is-cti",
      "title": "What Is CTI?",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-foundations/what-is-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Learn how to define cyber threat intelligence as an analytic discipline that supports decisions, not as a synonym for IOCs, threat feeds, or long reports.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:detection-backlog",
      "title": "Detection Backlog",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/detection-backlog/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Prioritize CTI-derived detection candidates by evidence, defensive value, telemetry availability, readiness, ownership, validation state, and known gaps.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:detection-readiness-levels",
      "title": "Detection Readiness Levels",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/detection-readiness-levels/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Use a staged readiness model to distinguish ideas, hypotheses, testable logic, validated rules, and production coverage without overstating maturity.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:hunting-hypothesis-template",
      "title": "Hunting Hypothesis Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/hunting-hypothesis-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Template and methodology for writing threat hunting hypotheses from CTI — actor-anchored, behavior-anchored, and anomaly-anchored hypothesis formats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:intelligence-to-detection",
      "title": "Intelligence to Detection",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/intelligence-to-detection/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Converting CTI claims into telemetry requirements, detection hypotheses, KQL/Sigma rules, and SOC handoff packages — the complete CTI-to-detection workflow.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:sigma-kql-spl-examples",
      "title": "Sigma, KQL, and SPL Examples",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/sigma-kql-spl-examples/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Compare equivalent Sigma, KQL, and SPL detection logic while documenting field assumptions, platform differences, false positives, and validation needs.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:soc-handoff",
      "title": "SOC Handoff",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/soc-handoff/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "How to hand off CTI findings to SOC teams: structured handoff note format, telemetry requirements, detection readiness levels, and triage guidance.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:cti-to-detection:telemetry-requirements",
      "title": "Telemetry Requirements",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/cti-to-detection/telemetry-requirements/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Define required logs, fields, retention, normalization, coverage, and quality before treating a CTI-derived hunt or rule as observable and testable.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/ecosystem/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Navigate the connected CTI projects by using this manual for tradecraft, the customer project for delivery gates, and the Israel knowledge base for cases.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:fact-correlation",
      "title": "Cross-Project Fact Correlation",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/fact-correlation/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Align shared CTI methodology, taxonomy, ownership, and production-readiness rules across three books so updates do not create conflicting guidance.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:attck-mapping-mistakes",
      "title": "ATT&CK Mapping Mistakes",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/attck-mapping-mistakes/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Avoid over-tagging actor reports, mapping capabilities as observed behavior, and claiming coverage without telemetry or validation when using ATT&CK.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:cyber-kill-chain",
      "title": "Cyber Kill Chain",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/cyber-kill-chain/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Sequence intrusion activity, identify evidence and defensive opportunities, and note where cloud-native or identity behavior does not fit the model.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:diamond-model",
      "title": "Diamond Model",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/diamond-model/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Relate adversary, capability, infrastructure, and victim while testing the evidence and uncertainty behind every connection instead of filling missing vertices.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-security",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:mitre-attack-as-working-tool",
      "title": "MITRE ATT&CK as a Working Tool",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/mitre-attack-as-working-tool/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "How to use MITRE ATT&CK as a working CTI tool — technique mapping, gap analysis, detection prioritization, and common analyst mistakes to avoid.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:frameworks:pyramid-of-pain",
      "title": "Pyramid of Pain",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/frameworks/pyramid-of-pain/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Prioritize behaviors, tools, and techniques that cost adversaries more to change, while treating short-lived hashes and addresses as supporting evidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:governance:cross-project-correlation-register",
      "title": "Cross-Project Correlation Register",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/governance/cross-project-correlation-register/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Identify the canonical owner of each shared CTI concept, record dependent projects, and define the review sequence for synchronized updates.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "security-governance",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:asn-hosting-pivots",
      "title": "ASN and Hosting Pivots",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/asn-hosting-pivots/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Use ASN and hosting context to bound infrastructure research, identify shared environments, and avoid treating provider co-location as malicious ownership.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:certificates",
      "title": "Certificates",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/certificates/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Use TLS certificate subjects, issuers, fingerprints, and validity windows as time-bounded clustering features that require corroboration before attribution.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:infrastructure-pivoting-worked-case",
      "title": "Infrastructure Pivoting Worked Case",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/infrastructure-pivoting-worked-case/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Follow a bounded investigation from one synthetic indicator through passive DNS, certificates, hosting context, link scoring, and rejected pivots.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:passive-dns",
      "title": "Passive DNS",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/passive-dns/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Use historical domain-to-address observations to build timelines and infrastructure clusters while recognizing that shared hosting is not proof of control.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:pivoting-limitations",
      "title": "Pivoting Limitations",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/pivoting-limitations/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-18",
      "summary": "Control false positives in infrastructure research by recording time windows, shared services, weak links, rejected pivots, and explicit stopping conditions.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:infrastructure-pivoting:single-ioc-to-network",
      "title": "Single IOC to Network",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/infrastructure-pivoting/single-ioc-to-network/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Step-by-step workflow for expanding a single IOC into a full infrastructure cluster using WHOIS, passive DNS, certificate transparency, and ASN pivoting.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:intro",
      "title": "CTI Analyst Field Manual",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/intro/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Use an evidence-led model for CTI requirements, source handling, analytic judgment, infrastructure research, detection handoff, and executive reporting.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:limitations",
      "title": "Known Limitations",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/limitations/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Honest assessment of what the CTI Analyst Field Manual covers, what it doesn't, and how to apply its tradecraft with appropriate calibration.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:references:authoritative-bibliography",
      "title": "Authoritative Bibliography",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/references/authoritative-bibliography/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-19",
      "summary": "Find primary standards, original framework papers, and strong practitioner references that support CTI doctrine separately from author inspiration.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:references:medium-source-index",
      "title": "Medium Source Index",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/references/medium-source-index/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace the author's public Medium material used as an inspiration layer while keeping doctrine, campaign claims, and evidence anchored to stronger sources.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:review:publication-grade-review",
      "title": "Publication-Grade Review Backlog",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/review/publication-grade-review/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Track unresolved evidence, reference, validation, example, and peer-review gaps that prevent the manual from claiming publication-grade maturity.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:role-based-reading-paths",
      "title": "Role-Based Reading Paths",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/role-based-reading-paths/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Reading guide for the CTI Analyst Field Manual by role: CTI analyst, SOC analyst, detection engineer, and threat hunter — with recommended page sequences.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:cellular-provider-case-study",
      "title": "Cellular Provider Case Study",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/cellular-provider-case-study/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Apply requirements, asset context, evidence labels, threat scenarios, telemetry needs, and SOC handoff to a fictional cellular provider case.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:israel-public-sector-notes",
      "title": "Israel Public-Sector Notes",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/israel-public-sector-notes/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Use Israel-focused public reporting with sector context, source caveats, and defensive relevance while avoiding unsupported targeting or attribution claims.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:telecom-4g-threats",
      "title": "Telecom 4G Threats",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/telecom-4g-threats/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Assess 4G telecom exposure across core, radio, roaming, signaling, management, suppliers, and identities, then connect scenarios to telemetry and controls.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:sector-cti:telecom-5g-threats",
      "title": "Telecom 5G Threats",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/sector-cti/telecom-5g-threats/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Assess how cloud-native cores, network slicing, APIs, orchestration, suppliers, and identity change CTI requirements and defensive telemetry for 5G.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:actor-profile-template",
      "title": "Actor Profile Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/actor-profile-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Capture aliases, scope, sources, behaviors, infrastructure, tools, targeting, confidence, gaps, defensive relevance, and change history in one profile.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:collection-gap-register",
      "title": "Collection Gap Register",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/collection-gap-register/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Record missing intelligence, its effect on a judgment or decision, priority, collection path, owner, due date, status, and closure evidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:detection-backlog-item",
      "title": "Detection Backlog Item",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/detection-backlog-item/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Track a detection candidate from CTI claim through behavior, ATT&CK mapping, telemetry, logic, false positives, validation, ownership, and retirement.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:evidence-register-template",
      "title": "Evidence Register Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/evidence-register-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Record each claim with its source, evidence type, reliability, credibility, confidence, contradictions, limitations, review status, and downstream use.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:executive-summary",
      "title": "Executive Summary Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/executive-summary/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Brief senior decision-makers with the key judgment, business relevance, confidence, evidence basis, uncertainty, recommended action, and decision deadline.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:finished-intel-report-template",
      "title": "Finished Intelligence Report Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/finished-intel-report-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Structure a finished CTI report around requirements, judgments, evidence, confidence, gaps, relevance, defensive actions, and source traceability.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:hunting-hypothesis-template",
      "title": "Hunting Hypothesis Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/hunting-hypothesis-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Create a falsifiable hunt plan with its CTI basis, expected behavior, required telemetry, query logic, false positives, validation steps, and owner.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:infrastructure-pivot-log",
      "title": "Infrastructure Pivot Log",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/infrastructure-pivot-log/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Document every accepted, rejected, or pending infrastructure pivot with dates, link type, strength, evidence, limitations, and analyst decision.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:soc-handoff-note",
      "title": "SOC Handoff Note",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/soc-handoff-note/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Package a hunt or detection for SOC use with threat context, first checks, required logs, expected false positives, escalation criteria, and ownership.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:templates:source-register-template",
      "title": "Source Register Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/templates/source-register-template/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Track publisher, source type, dates, provenance, reliability, claim credibility, review status, archive location, and use in downstream judgments.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:validation:ci-validation-evidence",
      "title": "CI Validation Evidence",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/validation/ci-validation-evidence/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-19",
      "summary": "Distinguish configured quality controls from proven runs by recording workflow checks, run evidence, commit identifiers, scope, and validation limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:validation:link-check-report",
      "title": "Link-Check Report",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/validation/link-check-report/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Record internal-link policy, build validation, external-link caveats, latest results, and the evidence needed before a link check is treated as current.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:actor-research",
      "title": "Worked Examples: Actor Research",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/actor-research/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Compare a synthetic actor exercise with a public-source MuddyWater case to practice claim labels, alias caveats, ATT&CK precision, and confidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:ai-assisted-cti",
      "title": "Worked Examples: AI-Assisted CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/ai-assisted-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Apply data classification, source verification, claim checking, and human approval to decide where AI can assist CTI and where it must be blocked.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:analytic-discipline",
      "title": "Worked Examples: Analytic Discipline",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/analytic-discipline/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Turn assumptions, contradictions, alternative explanations, and confidence reasons into visible artifacts that a skeptical CTI reviewer can challenge.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:attribution",
      "title": "Worked Examples: Attribution",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/attribution/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Rewrite a weak actor claim by separating evidence types, testing alternatives, downgrading unsupported certainty, and explaining confidence limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:cti-foundations",
      "title": "Worked Examples: CTI Foundations",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/cti-foundations/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review complete examples of a decision requirement, source record, evidence register, confidence statement, and collection gap before analysis begins.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:cti-to-detection",
      "title": "Worked Examples: CTI to Detection",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/cti-to-detection/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Trace a CTI claim through behavior extraction, telemetry requirements, hunt logic, readiness labeling, validation evidence, and SOC handoff.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:frameworks",
      "title": "Worked Examples: Frameworks",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/frameworks/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Compare useful and misleading applications of ATT&CK, the Diamond Model, Cyber Kill Chain, and Pyramid of Pain in evidence-led CTI analysis.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-security",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:infrastructure-pivoting",
      "title": "Worked Examples: Infrastructure Pivoting",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/infrastructure-pivoting/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Follow bounded pivots from one indicator while scoring link strength, preserving rejected candidates, controlling shared-hosting bias, and knowing when to stop.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti-analyst-field-manual:docs:worked-examples:sector-cti",
      "title": "Worked Examples: Sector CTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI analyst practice",
      "canonical_url": "https://1200km.com/cti-analyst-field-manual/docs/worked-examples/sector-cti/",
      "source_url": "https://github.com/anpa1200/cti-analyst-field-manual",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Translate a telecom threat scenario into relevant assets, telemetry owners, expected benign activity, defensive questions, and customer-specific actions.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:cti-analyst-field-manual",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/cti-analyst-field-manual",
      "original_publication": "https://github.com/anpa1200/cti-analyst-field-manual",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cti.html",
      "title": "Selected Security Research",
      "primary_type": "index",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current threat-intelligence research index",
      "canonical_url": "https://1200km.com/cti.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Explore source-backed CTI research on adversary behavior, attribution, ATT&CK mapping, infrastructure analysis, hunting hypotheses, and detection engineering.",
      "tags": [
        "author:Andrey Pautov",
        "detection-content",
        "detection-engineering",
        "index",
        "mitre-attack",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cti.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:customer-driven-ai-cti-project",
      "title": "Customer-Driven AI CTI Project",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Run intelligence work as a gated delivery program that connects customer decisions, validated evidence, threat models, telemetry, and production detections.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs",
      "title": "Customer-Driven AI CTI Project",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Apply a customer-led, AI-assisted threat intelligence method with requirements, evidence controls, analyst gates, telemetry mapping, and measurable outcomes.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/ecosystem/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Navigate the connected 1200km research set and choose the right field manual, actor profiles, workbench, or repository for each stage of CTI delivery.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:fact-correlation",
      "title": "Cross-Project Fact Correlation",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/fact-correlation/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Keep three connected CTI books consistent by following clear ownership rules for methodology, delivery gates, actor facts, and production-readiness guidance.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:infographics",
      "title": "Published Article Index",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/infographics/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-17",
      "summary": "Find the published Medium series and its visual assets in one source-linked index covering the workflow, execution method, templates, and reference toolkit.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:complete-template",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/complete-template/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Use one delivery document to move cyber threat intelligence from customer requirements through evidence, telemetry, hunting, detection, validation, and handoff.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:foundations",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/foundations/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Establish the analytic standards, governance, scoring, roles, artifacts, and readiness criteria required for defensible CTI-to-detection delivery.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:phase-by-phase-execution-guide",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/phase-by-phase-execution-guide/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Execute phases 0–14 with activities, validation tests, templates, evidence gates, and exit criteria for a controlled intelligence-to-detection engagement.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:methodology:reference-toolkit",
      "title": "Customer-Driven AI CTI Project Template",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/methodology/reference-toolkit/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-17",
      "summary": "Use AI workflow cards, quality gates, registers, worked examples, and delivery artifacts to start and govern a defensible CTI engagement from week one.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package",
      "title": "Practitioner Package",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Practice the method with a synthetic project kit containing fabricated identities, events, decisions, artifacts, and outcomes for safe replay and training.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:complete-worked-case",
      "title": "Complete Worked Case: Cloud Identity to Backup Deletion",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/complete-worked-case/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Trace a synthetic logistics scenario from a CISO decision through PIRs, evidence, telemetry, detection engineering, pilot review, and executive reporting.",
      "tags": [
        "ai-security",
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:detection-artifacts",
      "title": "Detection Artifacts",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/detection-artifacts/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Inspect the sample Sigma rule, Sentinel and Splunk queries, unit tests, and validation evidence used to detect privileged identity and backup-deletion activity.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:fake-customer-scenario",
      "title": "Fake Customer Scenario",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/fake-customer-scenario/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Use a fabricated logistics organization to practice PIR scoping, cloud-identity threat modeling, a 30-day engineering decision, and evidence-led delivery.",
      "tags": [
        "ai-security",
        "cloud-security",
        "guide",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:gate-evidence-packs",
      "title": "Gate Evidence Packs",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/gate-evidence-packs/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review sample Gate A–F evidence packages showing analyst validation, confidence records, approval state, and a conditional monitor-only production start.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:replay-example",
      "title": "Replay Example",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/replay-example/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Run the supplied cloud-identity dataset through the replay script and compare the generated JSON result with the expected synthetic detection outcome.",
      "tags": [
        "ai-security",
        "cloud-security",
        "guide",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:sample-registers",
      "title": "Sample Registers",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/sample-registers/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Follow CSV records that connect a customer decision to evidence, intelligence requirements, detection ownership, pilot health, and final acceptance.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:practitioner-package:workflow-output-screenshots",
      "title": "Workflow Output Screenshots",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/practitioner-package/workflow-output-screenshots/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "View synthetic SVG outputs from the worked case, including the register dashboard, replay result, gate status, and executive summary used in the method.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:changelog",
      "title": "Changelog",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/changelog/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Review the documented public release history and the scope of the initial stable documentation package without relying on undocumented product claims.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:deprecated",
      "title": "Deprecated Sections",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/deprecated/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Check which methodology sections have been retired, what replaces them, and the target removal release; the current public release retires none.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:roadmap",
      "title": "Roadmap",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/roadmap/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "See planned validation, schema, automation, and practitioner-package work while keeping future intentions clearly separated from released capabilities.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:project-governance:versioning",
      "title": "Versioning",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/project-governance/versioning/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Understand the semantic release policy for public methodology and artifact changes, including reproducibility expectations and required release records.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "security-governance",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:published-articles",
      "title": "Published Articles",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/published-articles/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Open canonical Medium sources for the four-part project series and locate the checked-in local copies that preserve the documentation source material.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:artifact-contracts",
      "title": "Artifact Contracts",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/artifact-contracts/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Define the minimum fields for reusable PIR, SIR, EEI, evidence, threat-model, and detection outputs so every handoff remains complete and auditable.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:attack-mappings",
      "title": "ATT&CK and D3FEND Mappings",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/attack-mappings/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Apply evidence-based ATT&CK technique selection and D3FEND relationships, then connect validated mappings to customer decisions and defensive deliverables.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:normative-language",
      "title": "Normative Language",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/normative-language/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Interpret MUST, SHOULD, and MAY consistently so requirements remain auditable, exceptions are recorded, and methodology claims retain clear strength.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:standard:schemas-and-validation",
      "title": "Schemas and Validation",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/standard/schemas-and-validation/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Validate machine-readable examples, telemetry field mappings, links, and replay outputs with the repository checks required before publishing changes.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:customer-driven-ai-cti-project:docs:workflow:full-workflow-quick-reference",
      "title": "Customer-Driven AI CTI Project: Full Workflow Quick Reference",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "customer-scoped AI-assisted CTI engagements",
      "canonical_url": "https://1200km.com/customer-driven-ai-cti-project/docs/workflow/full-workflow-quick-reference/",
      "source_url": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Move from customer decisions to production detections through a 15-phase operating map with explicit evidence, ownership, validation, and acceptance gates.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:customer-driven-ai-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "original_publication": "https://github.com/anpa1200/customer-driven-ai-cti-project",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cv.html",
      "title": "Andrey Pautov",
      "primary_type": "profile",
      "primary_domain": "professional-profile",
      "audience": [
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current public CV",
      "canonical_url": "https://1200km.com/cv.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Review Andrey Pautov’s cybersecurity experience, skills, certifications, publications, projects, and CTI-to-detection work, with a downloadable PDF résumé.",
      "tags": [
        "author:Andrey Pautov",
        "detection-engineering",
        "profile",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cv.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge",
      "title": "Cybersecurity Knowledge Base and Practitioner Field Guides",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "security-leader",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "the maintained 1200km Cyber Knowledge collection and its ten source-reviewed practitioner field guides",
      "canonical_url": "https://1200km.com/cyber-knowledge/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "Cyber Knowledge. A syllabus-style reference hub covering CTI, red team, blue team, vulnerability research, malware analysis, secure code, DFIR, cloud, GRC…",
      "tags": [
        "attack-emulation",
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "malware-analysis",
        "malware-behavior",
        "offensive-security",
        "research",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:ai-security.html",
      "title": "AI Security",
      "primary_type": "guide",
      "primary_domain": "ai-security",
      "audience": [
        "security-engineer",
        "developer",
        "security-leader",
        "detection-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AI application and model security, RAG integrity, prompt injection, agent and MCP authorization, model supply-chain assurance, adversarial testing, monitoring, incident response, governance, and secure AI delivery",
      "canonical_url": "https://1200km.com/cyber-knowledge/ai-security.html",
      "published_at": "2026-07-28",
      "updated_at": "2026-07-28",
      "summary": "A 14-module practitioner guide to securing AI systems end to end: threat modeling, RAG and retrieval integrity, model supply chain, prompt injection, agents…",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "llm-and-agent-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/ai-security.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:attack-matrix.html",
      "title": "MITRE ATT&CK Knowledge Mesh",
      "primary_type": "tool",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "MITRE ATT&CK Enterprise 19.1 technique exploration and governed cross-domain Cyber Knowledge discovery",
      "canonical_url": "https://1200km.com/cyber-knowledge/attack-matrix.html",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Explore ATT&CK Enterprise techniques, defensive relationships, threat groups, and linked 1200km Cyber Knowledge learning routes.",
      "tags": [
        "mitre-attack",
        "threat-intelligence",
        "tool"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/attack-matrix.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:blue-team.html",
      "title": "Blue Team & Defensive Security",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "security operations, telemetry engineering, detection development, threat hunting, investigation, incident response, validation, and controlled AI assistance",
      "canonical_url": "https://1200km.com/cyber-knowledge/blue-team.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Blue Team field guide covering SOC operations, telemetry, detection engineering, threat hunting, cloud defense, incident response, AI, and validation.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "digital-forensics",
        "incident-response",
        "research",
        "threat-hunting"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/blue-team.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:cloud-security.html",
      "title": "Cloud Security",
      "primary_type": "guide",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "developer",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "multi-cloud governance, shared responsibility, landing zones, human and workload identity, network and data protection, infrastructure delivery, containers, Kubernetes, detection, posture and exposure management, incident response, SaaS, suppliers, and cloud AI systems",
      "canonical_url": "https://1200km.com/cyber-knowledge/cloud-security.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Cloud-security guide covering shared responsibility, IAM, networks, data, IaC, containers, Kubernetes, detection, incident response, SaaS, and AI.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "cloud-and-container-security",
        "cloud-security",
        "detection-engineering",
        "digital-forensics",
        "identity-and-access",
        "identity-security",
        "incident-response",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/cloud-security.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:cti.html",
      "title": "Cyber Threat Intelligence (CTI)",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current CTI foundations, analysis, sharing, hunting, and detection practice",
      "canonical_url": "https://1200km.com/cyber-knowledge/cti.html",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "Source-linked CTI field guide covering intelligence requirements, collection, analysis, ATT&CK, actor research, sharing, hunting, and detection.",
      "tags": [
        "author:Andrey Pautov",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/cti.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:dfir.html",
      "title": "Digital Forensics & Incident Response (DFIR)",
      "primary_type": "guide",
      "primary_domain": "incident-response",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "incident preparation, declaration, triage, evidence preservation, endpoint, disk, memory, network, cloud, identity and malware investigation, containment, recovery, reporting, post-incident learning, and controlled AI assistance",
      "canonical_url": "https://1200km.com/cyber-knowledge/dfir.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "DFIR field guide covering readiness, triage, evidence integrity, endpoint, memory, network, cloud, identity, containment, recovery, reporting, and AI.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "identity-and-access",
        "identity-security",
        "incident-response",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/dfir.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:editorial-policy",
      "title": "Editorial and Source Policy",
      "primary_type": "policy",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "Cyber Knowledge source selection, review, corrections, versioning, and AI-assistance boundaries",
      "canonical_url": "https://1200km.com/cyber-knowledge/editorial-policy/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-28",
      "summary": "How 1200km Cyber Knowledge selects sources, reviews claims, records versions, handles AI assistance, and corrects factual issues.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/editorial-policy/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:glossary",
      "title": "Cyber Knowledge Glossary",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "defined terms extracted from the maintained Cyber Knowledge field guides",
      "canonical_url": "https://1200km.com/cyber-knowledge/glossary/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "A source-linked glossary of cybersecurity terminology consolidated from the ten 1200km practitioner field guides.",
      "tags": [
        "author:Andrey Pautov",
        "research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/glossary/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:grc.html",
      "title": "Governance, Risk & Compliance (GRC)",
      "primary_type": "guide",
      "primary_domain": "security-governance",
      "audience": [
        "security-leader",
        "security-engineer",
        "developer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "cybersecurity governance, organizational context, scenario-based risk assessment and treatment, security frameworks, policies, controls, evidence, audit and assurance, legal and contractual obligations, third-party and software supply-chain risk, privacy, resilience, metrics, cloud and product governance, and controlled AI-assisted GRC",
      "canonical_url": "https://1200km.com/cyber-knowledge/grc.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Cybersecurity GRC guide covering governance, scenario-based risk, NIST CSF 2.0, controls, audit evidence, suppliers, privacy, resilience, and AI.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "research",
        "security-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/grc.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:helping-materials",
      "title": "Helping Materials",
      "primary_type": "index",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "cti-analyst",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "study aids, concise cybersecurity guides, lab notes, checklists, and infographics connected to Cyber Knowledge domains, course learning records, sources, labs, and research",
      "canonical_url": "https://1200km.com/cyber-knowledge/helping-materials/",
      "published_at": null,
      "updated_at": "2026-08-19",
      "summary": "Original cybersecurity study aids, lab notes, checklists, visual guides, and analyst references, indexed by topic, course, provenance, and practical use.",
      "tags": [
        "helping-materials",
        "short-guide",
        "malware-analysis",
        "reverse-engineering",
        "lab",
        "trainsec",
        "visual-guide"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/helping-materials/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "security-leader",
        "developer",
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "the reviewed 1200km catalog of cybersecurity knowledge sources, including source-specific scope, quality dimensions, limitations, tags, and learning use cases",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud, application security…",
      "tags": [
        "cybersecurity-knowledge",
        "reference-directory",
        "source-assessment",
        "security-training"
      ],
      "featured": false,
      "indexable": true,
      "lifecycle": "stable-reference",
      "collection_tier": "reference",
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/",
      "canonical_owner": "1200km / Andrey Pautov"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:10",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/10/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 10 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/10/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:11",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/11/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 11 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/11/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:12",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/12/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 12 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/12/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:13",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/13/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 13 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/13/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:14",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/14/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 14 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/14/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:15",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/15/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 15 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/15/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:16",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/16/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 16 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/16/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:17",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/17/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 17 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/17/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:18",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/18/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 18 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/18/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:19",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/19/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 19 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/19/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:2",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/2/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 2 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/2/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:20",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/20/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 20 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/20/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:21",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/21/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 21 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/21/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:3",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/3/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 3 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/3/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:4",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/4/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 4 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/4/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:5",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/5/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 5 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/5/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:6",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/6/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 6 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/6/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:7",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/7/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 7 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/7/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:8",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/8/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 8 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/8/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:knowledge-sources:page:9",
      "title": "Cybersecurity Knowledge Sources",
      "primary_type": "index",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/cyber-knowledge/knowledge-sources/page/9/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Page 9 of 21: Search and compare 165 assessed cybersecurity knowledge sources across government guidance, frameworks, threat research, DFIR, cloud…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "digital-forensics",
        "index"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/knowledge-sources/page/9/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:malware-analysis.html",
      "title": "Malware Analysis & Reverse Engineering",
      "primary_type": "guide",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer",
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized malware triage, reverse engineering, behavior analysis, detection development, threat-intelligence enrichment, and incident-response handoff",
      "canonical_url": "https://1200km.com/cyber-knowledge/malware-analysis.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Malware-analysis and reverse-engineering guide covering safe triage, disassembly, debugging, unpacking, memory, Android, YARA, AI, and defensive handoff.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/malware-analysis.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:osint.html",
      "title": "OSINT & Reconnaissance",
      "primary_type": "guide",
      "primary_domain": "open-source-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized and ethical open-source collection, investigator OPSEC, intelligence requirements, search and archives, DNS, RDAP, certificate transparency, internet exposure, web and API reconnaissance, organization research, public code and cloud artifacts, media verification, threat-infrastructure pivoting, automation, AI assistance, external attack-surface monitoring, evidence preservation, and reporting",
      "canonical_url": "https://1200km.com/cyber-knowledge/osint.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "A 14-module OSINT field guide to ethical collection, infrastructure discovery, media verification, threat research, AI assistance, evidence, and reporting.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "open-source-intelligence",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/osint.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:red-team.html",
      "title": "Red Team & Offensive Security",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized offensive-security testing, adversary emulation, laboratories, and defensive validation",
      "canonical_url": "https://1200km.com/cyber-knowledge/red-team.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "A 14-module red-team field guide covering authorization, recon, web, cloud, identity, clients, AI/MCP, labs, validation, evidence, and reporting.",
      "tags": [
        "ai-security",
        "attack-emulation",
        "author:Andrey Pautov",
        "cloud-security",
        "identity-and-access",
        "identity-security",
        "llm-and-agent-security",
        "offensive-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/red-team.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:secure-code.html",
      "title": "Secure Code & Application Security",
      "primary_type": "guide",
      "primary_domain": "application-security",
      "audience": [
        "developer",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "secure software design, implementation, verification, supply-chain assurance, AI application security, release, and remediation",
      "canonical_url": "https://1200km.com/cyber-knowledge/secure-code.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Application-security guide covering threat modeling, identity, authorization, APIs, cryptography, supply chains, testing, AI systems, and remediation.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "identity-and-access",
        "identity-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/secure-code.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:cyber-knowledge:sources",
      "title": "Cyber Knowledge Source Index",
      "primary_type": "documentation",
      "primary_domain": "platform-documentation",
      "audience": [
        "general",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "external sources referenced by the maintained Cyber Knowledge field guides",
      "canonical_url": "https://1200km.com/cyber-knowledge/sources/",
      "published_at": "2026-07-25",
      "updated_at": "2026-07-27",
      "summary": "Authoritative, first-party, research, and practitioner sources referenced across the 1200km Cyber Knowledge field guides.",
      "tags": [
        "author:Andrey Pautov",
        "research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/sources/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:cyber-knowledge:vulnerability-research.html",
      "title": "Vulnerability Research & Exploit Development",
      "primary_type": "guide",
      "primary_domain": "vulnerability-research",
      "audience": [
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized vulnerability research, exploitability validation, coordinated disclosure, and remediation verification",
      "canonical_url": "https://1200km.com/cyber-knowledge/vulnerability-research.html",
      "published_at": "2026-06-27",
      "updated_at": "2026-07-27",
      "summary": "Vulnerability-research guide covering safe labs, static and dynamic analysis, fuzzing, exploitability, coordinated disclosure, remediation, and AI.",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "malware-analysis",
        "offensive-security",
        "research",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/cyber-knowledge/vulnerability-research.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:embedded-systems-hardware-firmware",
      "title": "Embedded Systems, Hardware, Firmware",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "embedded, hardware, and firmware threat research companion",
      "canonical_url": "https://1200km.com/embedded-systems-hardware-firmware/",
      "published_at": "2026-07-03",
      "updated_at": "2026-07-03",
      "summary": "Embedded Systems, Hardware, Firmware. Source-verified CTI research on embedded systems, edge appliances, BMC, UEFI…",
      "tags": [
        "application-security",
        "author:Andrey Pautov",
        "embedded-security",
        "hardware-security",
        "research",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "source_url": "https://medium.com/@1200km/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://medium.com/@1200km/comprehensive-cyber-intelligence-research-attacks-against-embedded-systems-hardware-firmware-8a151f8d5f1b",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:external-validation.html",
      "title": "Public evidence for the 1200km security research ecosystem.",
      "primary_type": "contribution",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "externally-accepted",
      "applies_to": "accepted and open external contribution evidence, kept separate",
      "canonical_url": "https://1200km.com/external-validation.html",
      "published_at": null,
      "updated_at": "2026-09-03",
      "summary": "Public evidence for the 1200km security research ecosystem.. Evidence-backed validation for 1200km: accepted upstream contributions, separately tracked open…",
      "tags": [
        "author:Andrey Pautov",
        "research",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/external-validation.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:guides.html",
      "title": "Security Research Library",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current guide index",
      "canonical_url": "https://1200km.com/guides.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Security Research Library. Security guides by Andrey Pautov: CTI tradecraft, ATT&CK mapping, detection engineering, anomaly…",
      "tags": [
        "author:Andrey Pautov",
        "detection-content",
        "detection-engineering",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/guides.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:hexstrike-ai-guide",
      "title": "HexStrike AI Penetration Testing Orchestrator",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/Hexstrike-AI-guide/",
      "published_at": null,
      "updated_at": null,
      "summary": "HexStrike AI — bridge LLMs to 150+ security tools via MCP for authorized lab assessment, evidence collection, troubleshooting, and reporting.",
      "tags": [
        "ai-security",
        "attack-emulation",
        "guide",
        "llm-and-agent-security",
        "offensive-research",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/Hexstrike-AI-guide/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "site:hexstrike.html",
      "title": "HexStrike",
      "primary_type": "guide",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized offensive-security testing",
      "canonical_url": "https://1200km.com/hexstrike.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "HexStrike. HexStrike by Andrey Pautov: AI-assisted pentesting, privilege escalation, lateral movement, credential theft, post-exploitation…",
      "tags": [
        "ai-security",
        "author:Andrey Pautov",
        "identity-and-access",
        "offensive-research",
        "offensive-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/hexstrike.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection",
      "title": "Insider Threat Detection",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Build a defensible insider-risk program with 14 documented cases, tiered detection logic, required telemetry, legal constraints, and phased implementation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies",
      "title": "3. Documented Case Studies",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Compare 14 incidents using primary records, with consistent notes on what happened, retrospective signals, missed opportunities, triggers, and lessons.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:barile",
      "title": "3.14 Juliana Barile — Former New York Credit Union Employee (2021)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/barile/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Analyze destructive post-termination access at a New York credit union, including retained credentials, deleted data, delayed discovery, and prevention lessons.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:desjardins",
      "title": "3.11 Desjardins Group — Employee Data Theft (2017–2019)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/desjardins/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Review prolonged data exfiltration at a Canadian financial group, the monitoring gaps it crossed, and the police notification that exposed the incident.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:duronio",
      "title": "3.3 Roger Duronio — UBS Systems Administrator (2002)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/duronio/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Study a disgruntled administrator's logic-bomb sabotage at UBS, the precursor access and code signals, and the destructive system event that exposed it.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:kvashuk",
      "title": "3.10 Volodymyr Kvashuk — Microsoft Software Engineer (2018–2019)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/kvashuk/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Analyze Microsoft's test-environment gift-card fraud, how access enabled the scheme, and why unusual redemption activity became the decisive detection signal.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:levandowski",
      "title": "3.4 Anthony Levandowski — Waymo Engineer (2016)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/levandowski/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Trace large-scale Waymo intellectual-property downloads before departure, retrospective access signals, and civil discovery that revealed the transfer.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:manning",
      "title": "3.1 Chelsea Manning — US Army Intelligence Analyst (2010)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/manning/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Examine mass classified-data exfiltration at the US Army, the access and removable-media signals visible in retrospect, and why a human tip triggered discovery.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:ramesh",
      "title": "3.5 Sudhish Kasaba Ramesh — Cisco Engineer (2018)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/ramesh/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Analyze post-termination access to Cisco cloud infrastructure, the destructive actions that caused a service outage, and controls that could reduce recurrence.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:ruiz",
      "title": "3.8 Reyes Daniel Ruiz — Yahoo Software Engineer (2018)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/ruiz/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Study a Yahoo engineer's misuse of access, the account activity that drew employer attention, and monitoring lessons for privileged application roles.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:sharp",
      "title": "3.9 Nickolas Sharp — Ubiquiti Developer (2020–2021)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/sharp/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Trace data theft and extortion at Ubiquiti, including cloud access, log manipulation, and the VPN failure that exposed a residential address in audit records.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:skelton",
      "title": "3.7 Andrew Skelton — Morrisons Internal Auditor (2014)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/skelton/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Examine a Morrisons payroll-data leak by a disgruntled auditor, including authorized access, exfiltration signals, and external contact before publication.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:snowden",
      "title": "3.2 Edward Snowden — NSA Contractor (2013)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/snowden/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Review an NSA contractor data-exfiltration incident, including privileged access, collection patterns, missed signals, and publication as the external trigger.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:tesla",
      "title": "3.12 Tesla — Departing Employee Data Leak (2023)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/tesla/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Examine a 100 GB data leak attributed to former employees, the access and transfer signals available, and journalist contact that triggered discovery.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:twitter",
      "title": "3.13 Twitter — Saudi Arabia State-Sponsored Insider Espionage (2015)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/twitter/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Study state-linked misuse of social-media access, the suspicious account activity management noticed, and safeguards for high-trust internal user tools.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:case-studies:zheng",
      "title": "3.6 Xiaoqing Zheng — GE Aviation Engineer (2019 indictment)",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/case-studies/zheng/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Review theft of GE Aviation turbine designs, the concealment and transfer behaviors visible in retrospect, and the external referral that prompted action.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:conclusion",
      "title": "9. Conclusion and Coverage Gaps",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/conclusion/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Assess the persistent gap between technical monitoring and how real incidents are discovered, then use layered controls without claiming complete prevention.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods",
      "title": "4. Detection Methods",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Implement defender-operable controls tied to documented evidence, with explicit labels for engineering inference and requirements for local testing and tuning.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:behavioural-heuristics",
      "title": "4.2 Behavioural Heuristics",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/behavioural-heuristics/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Detect authorized but abnormal activity with tuned baselines for volume, timing, access breadth, and peer deviation while managing expected false positives.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:covering-tracks",
      "title": "4.7 Covering-Tracks Detection",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/covering-tracks/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Detect audit-log deletion, logging disablement, and other evidence-removal behavior to preserve forensic trails and gain a second opportunity for response.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "incident-response"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:deterministic-rules",
      "title": "4.1 Deterministic Rules",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/deterministic-rules/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Deploy high-signal controls for rare patterns, including terminated-account access and privileged changes, before investing in baseline-dependent analytics.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:exfiltration-paths",
      "title": "4.4 Exfiltration Path Coverage",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/exfiltration-paths/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Cover email, cloud storage, removable media, repositories, printing, and other meaningful data-loss routes instead of relying on email DLP alone.",
      "tags": [
        "ai-security",
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:identity-privilege",
      "title": "4.3 Identity and Privilege Anomalies",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/identity-privilege/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Monitor administrative account creation, privilege escalation, and unusual entitlement changes with approved-service exclusions, context, and review workflows.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:sabotage-signals",
      "title": "4.5 Sabotage Signals",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/sabotage-signals/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Monitor control-plane changes, bulk deletion, destructive commands, and safety-control weakening separately from ordinary file and email access analytics.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:detection-methods:ueba-anomaly",
      "title": "4.6 UEBA and Anomaly Models",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/detection-methods/ueba-anomaly/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Use converging weak signals as a corroborating risk layer for authorized but unusual behavior, without replacing precise rule-based controls or analyst review.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:implementation",
      "title": "8. Implementation Guidance",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/implementation/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Roll out the program in four phases, beginning with legal authority and telemetry, then adding high-value rules, baselines, and mature graph-based detection.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:intro",
      "title": "Detecting Malicious Insider Activity: A Technical Detection Engineering Guide",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/intro/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-06-18",
      "summary": "Use an evidence-labeled guide for malicious insider activity, covering documented incidents, telemetry, detection logic, privacy, and deployment limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:legal-privacy",
      "title": "7. Legal and Privacy Constraints",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/legal-privacy/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Plan employee monitoring within applicable legal and privacy boundaries, document purpose and proportionality, and obtain qualified counsel before deployment.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:priority-matrix",
      "title": "5. Detection Priority Matrix",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/priority-matrix/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Prioritize controls by realistic implementation effort and coverage, starting with high-signal events already available before adding complex behavioral models.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:references",
      "title": "10. References",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/references/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Verify the guide's claims through cited DOJ releases, court records, regulatory findings, government research, and clearly identified supplementary sources.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:required-telemetry",
      "title": "6. Required Telemetry",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/required-telemetry/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Collect and retain the identity, endpoint, cloud, data-access, HR, and control-plane records required by the guide's rules and behavioral analytics.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:taxonomy",
      "title": "2. Insider Threat Taxonomy and Kill Chain",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/taxonomy/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Classify intentional, accidental, and credential-compromise scenarios, then map harmful employee activity through a practical six-phase kill chain.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:insider-threat-detection:docs:why-harder",
      "title": "1. Why Insider Detection Is Structurally Harder",
      "primary_type": "guide",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current insider-threat detection practice",
      "canonical_url": "https://1200km.com/insider-threat-detection/docs/why-harder/",
      "source_url": "https://github.com/anpa1200/insider-threat-detection",
      "published_at": null,
      "updated_at": "2026-05-25",
      "summary": "Understand why valid access, organizational knowledge, and normal-looking actions make harmful employee behavior harder to distinguish from legitimate work.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "guide",
        "identity-and-access"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:insider-threat-detection",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/insider-threat-detection",
      "original_publication": "https://github.com/anpa1200/insider-threat-detection",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti",
      "title": "Israel Government Threat Actors CTI",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Explore public-source intelligence for Israeli government and public-sector defense through actors, tools, evidence, TTPs, hunts, and detection readiness.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors",
      "title": "Actor Index",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Browse actor profiles joined to TTPs, IOC references, malware, tools, hunts, detections, exposed surfaces, evidence records, and source-review status.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:agrius",
      "title": "Agrius",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/agrius/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review an Iran-aligned destructive cluster targeting Israeli organizations with wipers disguised as ransomware and BlackShadow or Moneybird personas.",
      "tags": [
        "agrius",
        "detection-content",
        "detection-engineering",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:apt35",
      "title": "Magic Hound / APT35",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/apt35/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review Magic Hound as an IRGC-IO-attributed espionage group using persona-led spearphishing and credential theft against government and civil targets.",
      "tags": [
        "apt35",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:apt39",
      "title": "APT39",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/apt39/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-12",
      "summary": "Assess a MOIS-linked espionage cluster focused on long-dwell access and bulk collection from telecom, travel, government, and identity-rich systems.",
      "tags": [
        "apt39",
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:apt42",
      "title": "APT42",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/apt42/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Assess an IRGC-IO-attributed surveillance cluster using persona-based social engineering and credential theft against officials, journalists, and researchers.",
      "tags": [
        "apt42",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:arid-viper",
      "title": "APT-C-23 / Arid Viper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/arid-viper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review Arid Viper as a Hamas-affiliated mobile threat actor using Android spyware against Israeli military, civil-society, and regional political targets.",
      "tags": [
        "arid-viper",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:cotton-sandstorm",
      "title": "Cotton Sandstorm",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/cotton-sandstorm/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Assess an IRGC-affiliated influence actor combining intrusion, data theft, account creation, phishing, and messaging against Israeli and Western audiences.",
      "tags": [
        "cotton-sandstorm",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:cyber-toufan",
      "title": "Cyber Toufan",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/cyber-toufan/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review an October 2023 persona associated with data theft, wiper operations, supplier access, public leak claims, and targeting of Israeli organizations.",
      "tags": [
        "cyber-toufan",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:cyberav3ngers",
      "title": "CyberAv3ngers",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/cyberav3ngers/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Assess the IRGC-linked persona targeting exposed ICS, SCADA, water-treatment, PLC, and HMI systems through device access and parameter manipulation.",
      "tags": [
        "cyberav3ngers",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:darkbit",
      "title": "DarkBit",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/darkbit/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-12",
      "summary": "Review the single-campaign pseudo-ransomware persona used in the 2023 Technion incident and its reported MuddyWater access-to-impact handoff model.",
      "tags": [
        "darkbit",
        "detection-content",
        "detection-engineering",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:handala",
      "title": "Void Manticore / Handala",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/handala/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review Void Manticore as a MOIS-linked destructive cluster combining data theft, wipers, cloud-account abuse, and public influence claims against Israel.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "handala",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:imperial-kitten",
      "title": "Imperial Kitten",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/imperial-kitten/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-12",
      "summary": "Assess an IRGC-aligned cluster using strategic web compromise, IMAP-based command and control, and managed-code injection against Israeli logistics targets.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "imperial-kitten",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:lebanese-cedar",
      "title": "Lebanese Cedar",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/lebanese-cedar/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review a Hezbollah-affiliated espionage group using public-server compromise, web shells, and long-lived persistence against telecom and government suppliers.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lebanese-cedar",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:lyceum",
      "title": "Lyceum",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/lyceum/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-12",
      "summary": "Assess an Iranian espionage cluster targeting telecom, energy, and IT providers through recruiting lures, DNS-based C2, backdoors, and credential access.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "lyceum",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:muddywater",
      "title": "MuddyWater",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/muddywater/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review a MOIS-attributed espionage group targeting Israeli government and critical infrastructure through phishing, scripting, RMM abuse, and custom malware.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "muddywater",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:oilrig",
      "title": "OilRig",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/oilrig/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Assess a prolific Iranian espionage cluster using phishing, PowerShell, DNS tunneling, cloud-service C2, and custom backdoors across Middle Eastern sectors.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "oilrig",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:pioneer-kitten",
      "title": "Pioneer Kitten",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/pioneer-kitten/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-12",
      "summary": "Review an Iranian edge-exploitation specialist that gains appliance access for espionage or handoff to ransomware affiliates, including Israeli targets.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-behavior",
        "offensive-security",
        "pioneer-kitten",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:scarred-manticore",
      "title": "Scarred Manticore",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/scarred-manticore/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Assess a MOIS-linked access cluster using passive IIS backdoors against government and telecom networks, with reported handoff to destructive operators.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "scarred-manticore",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:ta402",
      "title": "TA402",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/ta402/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review a Palestinian-aligned espionage group using political lures, staged downloaders, geofencing, and custom implants against regional government targets.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "ta402",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:unc1860",
      "title": "UNC1860",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/unc1860/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-12",
      "summary": "Assess a likely MOIS-affiliated access-enablement cluster using passive web-server backdoors and custom tooling for persistent footholds and actor handoffs.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence",
        "unc1860"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:unc3890",
      "title": "UNC3890",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/unc3890/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review an Iran-linked cluster targeting Israeli shipping, aviation, healthcare, and government organizations through watering holes and credential theft.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence",
        "unc3890"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:actors:wirte",
      "title": "WIRTE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/actors/wirte/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Assess a Hamas-affiliated cluster that evolved from espionage to disruptive activity, including a multi-platform wiper used against Israeli organizations.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence",
        "wirte"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:connected-tips",
      "title": "Connected TIPs And CTI Feeds",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/connected-tips/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-22",
      "summary": "Use free public CTI connectors to create review candidates, then validate provenance, relevance, freshness, and evidence before promoting any feed item.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:customer-environment-use",
      "title": "Customer Environment Use",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/customer-environment-use/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Adapt public CTI and hunt starters to a real environment by collecting asset, identity, telemetry, platform, ownership, and false-positive context first.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:backend-conversion-results",
      "title": "Backend Conversion Results",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/backend-conversion-results/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Review local Sigma conversion evidence for Splunk and Elasticsearch backends, including commands, per-rule outcomes, limitations, and validation scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:detection-lifecycle",
      "title": "Detection Lifecycle",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/detection-lifecycle/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Move CTI-derived logic from requirement and evidence through telemetry mapping, testing, pilot review, production approval, monitoring, and retirement.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:detection-status-dashboard",
      "title": "Detection Status Dashboard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/detection-status-dashboard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Inspect each repository detection by release status, readiness level, platform, owner, validation evidence, known blockers, and production-coverage boundary.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:drl-evidence-packs",
      "title": "DRL Evidence Packs",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/drl-evidence-packs/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Review conservative readiness evidence packs that record test scope, results, untested conditions, blockers, and proof required before production claims.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:platform-field-mapping",
      "title": "Platform Field Mapping",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/platform-field-mapping/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Map portable hunt concepts to real platform tables, indexes, fields, parsers, retention, and test evidence before calling a query deployment-ready.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:platform-query-variants",
      "title": "Platform Query Variants",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/platform-query-variants/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Track backend-specific query variants separately from portable logic, with field mappings, test data, expected results, owners, and validation status.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:quality-gates",
      "title": "Quality Gates",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/quality-gates/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Require a defensible PIR, evidence, ATT&CK precision, telemetry, false-positive analysis, testing, ownership, and approval before detection promotion.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:replay-datasets",
      "title": "Replay Datasets",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/replay-datasets/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Use synthetic replay data to check parsers, walkthroughs, positive matches, and benign boundaries without treating lab examples as production performance.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:sigma-validation-results",
      "title": "Sigma Validation Results",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/sigma-validation-results/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Review local sigma-cli semantic validation across repository rules, including the command, backend-independent checks, outcomes, and remaining limitations.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:soc-handoff-packet",
      "title": "SOC Handoff Packet",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/soc-handoff-packet/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Inspect a customer-style pilot handoff for suspicious RMM downloads, with threat context, logic, telemetry, triage, false positives, evidence, and ownership.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:detection-engineering:soc-triage-playbooks",
      "title": "SOC Triage Playbooks",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/detection-engineering/soc-triage-playbooks/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Use first-response playbooks for destructive activity, cloud administration abuse, RMM misuse, phishing chains, and exposed OT interfaces in analyst triage.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:ecosystem",
      "title": "CTI Project Ecosystem",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/ecosystem/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Connect the Israel-focused actor knowledge base to the field manual for CTI tradecraft and the customer project for governed delivery and acceptance gates.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:fact-correlation",
      "title": "Cross-Project Fact Correlation",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/fact-correlation/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Keep actor facts and TTP navigation aligned with the ecosystem's canonical tradecraft and delivery rules while preventing conflicting readiness claims.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:intelligence-updates",
      "title": "Intelligence Update Queue",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/intelligence-updates/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-22",
      "summary": "Review unverified candidates from no-key public feeds, including ATT&CK and CISA KEV updates, before promoting them into sources, profiles, or detections.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:israel-government-threat-model",
      "title": "Israel Government Threat Model",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/israel-government-threat-model/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Model espionage, disruption, credential theft, destructive operations, and influence risks across Israeli identity, email, web, endpoint, cloud, and OT assets.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:known-limitations",
      "title": "Known Limitations",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/known-limitations/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Understand gaps in public evidence, claim-level coverage, local telemetry, detection validation, IOC freshness, and external review before operational use.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:malware-tool-intelligence",
      "title": "Malware And Tool Intelligence",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/malware-tool-intelligence/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Navigate defensive malware and tool records by actor, behavior, IOC status, source, confidence, ATT&CK mappings, hunting notes, and handling limitations.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:artifact-contracts",
      "title": "Artifact Contracts",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/artifact-contracts/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Define mandatory fields for reusable PIR, source, evidence, actor, TTP, hunt, detection, validation, and SOC handoff artifacts across the repository.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:operating-standard",
      "title": "CTI-To-Detection Operating Standard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/operating-standard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Apply evidence, source, confidence, freshness, ATT&CK, IOC, hunt, validation, and production-readiness rules across the CTI-to-detection workflow.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:scoring-models",
      "title": "Scoring Models",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/scoring-models/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Keep source reliability, information credibility, analyst confidence, threat priority, and detection readiness as distinct, reviewable scoring systems.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:methodology:source-freshness",
      "title": "Source Freshness",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/methodology/source-freshness/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Track publication, access, publisher-update, and repository-review dates so public reporting and indicators do not silently become stale assumptions.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:navigation:actor-workbench",
      "title": "Actor Navigation Workbench",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/navigation/actor-workbench/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Pivot from each actor to structured TTPs, IOC sources, malware, tools, hunts, detections, surfaces, evidence records, and unresolved coverage gaps.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:navigation:surface-capability-matrix",
      "title": "Surface And Capability Matrix",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/navigation/surface-capability-matrix/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Start with an exposed surface or defensive capability, then route to relevant actors, attack behaviors, telemetry fields, hunts, and detection candidates.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:navigation:ttp-detection-matrix",
      "title": "TTP To Detection Matrix",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/navigation/ttp-detection-matrix/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Pivot from an ATT&CK technique to source-backed actors, mapping quality, repository hunts, detections, readiness status, and missing defensive coverage.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports",
      "title": "Report Index",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Navigate scored source research, imported intake artifacts, worked cases, validation evidence, release notes, and the machine-readable source register.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:actor-deep-research-prompts",
      "title": "Actor Deep Research Prompts",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/actor-deep-research-prompts/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Use constrained research prompts to refresh public actor, tool, ATT&CK, hunt, and detection records without bypassing source and evidence validation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:additional-research-gemeni",
      "title": "Cyber Threat Intelligence Dossier: Iranian and Hamas-Aligned Operations Targeting Israeli and Allied Ecosystems (2023-2026)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/additional-research-gemeni/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review imported Gemini research as lead-generation material, then verify its claims, citations, indicators, actor mappings, and detection ideas independently.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:andrey-medium-articles",
      "title": "Andrey Pautov Medium Articles",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/andrey-medium-articles/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-13",
      "summary": "Trace relevant author articles used for CTI and methodology context while returning to their cited primary sources for attribution or operational decisions.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:apt35-oilrig-israel-deep-research",
      "title": "Executive Summary",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/apt35-oilrig-israel-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review imported research on Magic Hound and OilRig activity affecting Israel, then validate actor, campaign, tool, IOC, TTP, and detection claims at source.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:apt39-arid-viper-unc3890-cyber-toufan-deep-research",
      "title": "APT39 (Chafer / Remix Kitten)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/apt39-arid-viper-unc3890-cyber-toufan-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review imported evidence on four regional clusters, then verify their aliases, targeting, tools, indicators, techniques, and defensive recommendations.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:ci-validation-evidence",
      "title": "CI Validation Evidence",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/ci-validation-evidence/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-15",
      "summary": "Record public workflow evidence for data generation, schema checks, links, rules, and site builds without treating configured jobs as proof of a passing run.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:defensive-cti-threats-to-israeli-public-sector",
      "title": "Defensive CTI Research on Threats to Israeli Government and Public-Sector Environments",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/defensive-cti-threats-to-israeli-public-sector/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Review public-source research on threats to Israeli government environments, with actor context, defensive priorities, source caveats, and validation needs.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:israel-critical-infrastructure-escalation",
      "title": "Defensive Cyber Threat Intelligence Report: Israeli Critical Infrastructure and Geopolitical Escalation (2024-2026)",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/israel-critical-infrastructure-escalation/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Review a defensive assessment of geopolitical escalation risks to Israeli critical infrastructure, with threat scenarios, evidence limits, and priorities.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:muddywater-deep-research",
      "title": "1. Executive Summary",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/muddywater-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review imported evidence on a MOIS-linked intrusion cluster, then validate aliases, targeting, access methods, tooling, indicators, techniques, and detections.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:oilrig-magic-hound-deep-research",
      "title": "OilRig and Magic Hound research intake",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "experimental",
      "maturity": "experimental",
      "evidence_level": "unverified",
      "applies_to": "two individually sourced campaign examples and reviewed procedure mappings; substantial preserved intake remains unverified; scoped review 2026-09-09",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/oilrig-magic-hound-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Read two sourced campaign examples and reviewed procedure mappings alongside the preserved unresolved intake, with explicit evidence limits and review scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "lifecycle": "currentness-unknown",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:pioneer-kitten-deep-research",
      "title": "Pioneer Kitten (Fox Kitten, Lemon Sandstorm, UNC757) – Actor Deep Research",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/pioneer-kitten-deep-research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review imported evidence on an Iranian edge-access cluster, then validate aliases, exploited appliances, targeting, handoffs, indicators, and hunt ideas.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:release-notes",
      "title": "Release Notes",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/release-notes/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Track repository maturity changes, new data and navigation layers, validation improvements, known gaps, and the explicit boundary around production use.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:research-intake-upgrade-summary",
      "title": "Research Intake Upgrade Summary",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/research-intake-upgrade-summary/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "See how imported research was routed into review queues and candidate upgrades without silently promoting unverified LLM claims into authoritative CTI.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "llm-and-agent-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:resourses_research",
      "title": "Israel Government Threat Actors CTI: Evidentiary Foundation Intake",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/resourses_research/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Review the supplied research collection map with its mix of primary reporting, secondary synthesis, taxonomy shortcuts, and claims requiring corroboration.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:reports:worked-cases",
      "title": "Worked Cases",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/reports/worked-cases/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Follow public reporting through evidence review, actor context, behavior extraction, hunting hypotheses, readiness labels, and defensive handoff examples.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:source-rating",
      "title": "Source Rating",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/source-rating/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-06-11",
      "summary": "Rate source reliability separately from claim credibility using Admiralty-style scales, examples, corroboration rules, freshness, and confidence guidance.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:threat-hunting:hunt-workflow",
      "title": "Threat Hunting Workflow",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/threat-hunting/hunt-workflow/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-14",
      "summary": "Run a hunt from PIR and falsifiable hypothesis through telemetry, query, expected outcomes, execution evidence, conclusion, and detection or gap handoff.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-hunting",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools",
      "title": "Malicious Tools Index",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Browse defensive software records linked to actors, behavior summaries, IOC status, sources, confidence, ATT&CK mappings, hunts, and handling caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:antak-aspxspy",
      "title": "ANTAK / ASPXSPY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/antak-aspxspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence web shell record for APT39 across delivery and execution behavior, persistence signals, source provenance, and hunt limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:apostle",
      "title": "Apostle",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/apostle/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "MITRE ATT&CK lists the software as used by Agrius; track it as destructive or ransomware-like impact behavior (SRC-MITRE-G1030; medium confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-behavior",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:aridspy",
      "title": "AridSpy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/aridspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review high-confidence ESET reporting on multi-stage Android spyware using trojanized apps, Firebase C2, HTTPS exfiltration, sensor access, and data collection.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ashtag",
      "title": "AshTag",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ashtag/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a high-confidence WIRTE modular .NET suite using DLL side-loading, HTML payload retrieval, staging, modular collection, and Rclone exfiltration.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:aspxspy",
      "title": "ASPXSpy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/aspxspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "MITRE ATT&CK lists the software as used by Agrius; track it as server-side web shell persistence, recorded at medium confidence under SRC-MITRE-G1030.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bfg-agonizer",
      "title": "BFG Agonizer",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bfg-agonizer/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review this medium-confidence wiper record for Agrius, focusing on wiping or encryption signals, source context, and response priorities under SRC-MITRE-G1030.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bibi-bibi-wiper-lineage",
      "title": "BiBi / BiBi Wiper lineage",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bibi-bibi-wiper-lineage/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Hunt extension renaming, destructive writes, VSS deletion, backup tampering, and ransom-note decoy behavior (SRC-AP-HANDALA; medium confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bitsadmin",
      "title": "BITSAdmin",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bitsadmin/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review baseline exceptions, execution signals, source provenance, and response guidance in this medium-confidence living-off-the-land binary entry for Lyceum.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:blackbeard",
      "title": "BlackBeard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/blackbeard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Backdoor named in INCD MuddyWater phishing reporting. Hunt fake-official phishing chains, unusual archives, and post-click endpoint execution.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:blackshadow",
      "title": "BlackShadow",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/blackshadow/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Agrius-linked destructive extortion persona and malware reference depending on source context. Treat persona claims through the persona-claims register.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bondupdater",
      "title": "BONDUPDATER",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bondupdater/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence MITRE-listed software record for OilRig across source traceability, technique context, IOC limits, and confidence rationale.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:bugsleep",
      "title": "BugSleep",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/bugsleep/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a high-confidence MuddyWater backdoor with victim fingerprinting, command execution, file transfer, recurring check-ins, and post-phishing C2 behavior.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:cadelspy",
      "title": "Cadelspy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/cadelspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence backdoor entry associated with APT39; review command execution, persistence paths, network activity, and source caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:caterpillar-webshell",
      "title": "Caterpillar WebShell",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/caterpillar-webshell/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Modified JSP file browser and web shell used by Lebanese Cedar for persistence on public-facing servers. Use behavior and webroot integrity monitoring.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:certutil",
      "title": "certutil",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/certutil/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence living-off-the-land binary record for OilRig across user and host context, command arguments, telemetry quality, and review scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:charmpower",
      "title": "CharmPower",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/charmpower/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence PowerShell backdoor record for Magic Hound across execution ancestry, recurring access, outbound traffic, and triage scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:chimneysweep",
      "title": "CHIMNEYSWEEP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/chimneysweep/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence wiper entry associated with Void Manticore or Handala; review impact behavior, recovery risks, indicators, and response hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:connectwise",
      "title": "ConnectWise",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/connectwise/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence remote monitoring and management tool record for MuddyWater across connection behavior, approved-use baselines, and hunt limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:crackmapexec",
      "title": "CrackMapExec",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/crackmapexec/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a medium-confidence post-exploitation tool linked to MuddyWater and APT39, with network credential validation, lateral movement, and dual-use caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:cryptoslay",
      "title": "CRYPTOSLAY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/cryptoslay/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence malware family entry associated with UNC1860; review loader or implant behavior, command channels, mappings, and validation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:cyber-toufan-supplier-access-playbook",
      "title": "Cyber Toufan supplier-access playbook",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/cyber-toufan-supplier-access-playbook/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence credential and admin-interface abuse entry associated with Cyber Toufan; review access behavior, IOCs, mappings, and defensive hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:danbot",
      "title": "DanBot",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/danbot/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Lyceum and HEXANE-associated backdoor family referenced in MITRE and public reporting. Validate sample-level claims before detection engineering.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:darkbit-ransomware",
      "title": "DarkBit ransomware",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/darkbit-ransomware/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence pseudo-ransomware or destructive malware record for DarkBit across impact behavior, recovery risks, indicators, and response hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:dchspy",
      "title": "DCHSpy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/dchspy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence MITRE-listed software record for MuddyWater across source validation, actor association, mapped techniques, and hunt evidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:deadwood",
      "title": "DEADWOOD",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/deadwood/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence wiper entry associated with Agrius; review impact techniques, local telemetry, source provenance, and response guidance.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:desert-scorpion",
      "title": "Desert Scorpion",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/desert-scorpion/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence mobile malware entry associated with APT-C-23; review malware staging, command handling, file transfer, and detection evidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:dindoor",
      "title": "Dindoor",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/dindoor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Hunt unusual Deno runtime execution, user-path staging, and network egress not tied to development hosts (SRC-THREAT-HUNTER-V3; low confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:dnssystem",
      "title": "DnsSystem",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/dnssystem/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence backdoor entry associated with Lyceum; review initial delivery, follow-on commands, persistence evidence, and hunt boundaries.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:downpaper",
      "title": "DownPaper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/downpaper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence backdoor record for Magic Hound across execution, persistence, C2 behavior, IOC handling, and defensive hunt context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:empire",
      "title": "Empire",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/empire/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence post-exploitation framework entry associated with MuddyWater and Lyceum; review access behavior, IOCs, mappings, and defensive hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:explosive-rat",
      "title": "Explosive RAT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/explosive-rat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Custom RAT associated with Lebanese Cedar or Volatile Cedar reporting. Hunt Java web compromise leading to RAT staging and long-lived outbound access.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:fakeset",
      "title": "Fakeset",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/fakeset/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a low-confidence backdoor entry associated with MuddyWater; review command execution, persistence paths, network activity, and source caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:fooder-muddyviper",
      "title": "Fooder / MuddyViper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/fooder-muddyviper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a MuddyWater loader and backdoor pairing using in-memory payloads, sandbox-delay logic, RMM-assisted access, and post-compromise collection.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:frozencell",
      "title": "FrozenCell",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/frozencell/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence mobile malware entry associated with APT-C-23; review implant delivery, host changes, C2 signals, and defensive validation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:frp-plink",
      "title": "FRP / Plink",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/frp-plink/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence dual-use tunneling or proxy tooling record for Magic Hound across connection behavior, approved-use baselines, and hunt limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ftp",
      "title": "ftp",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ftp/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence living-off-the-land utility record for OilRig and APT39 across process context, local baselines, mappings, and hunt limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:handala-linked-destructive-installer-chains",
      "title": "Handala-linked destructive installer chains",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/handala-linked-destructive-installer-chains/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Archive or installer-centered destructive chains used as a defensive first-30-minute response model. Validate against original technical references.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:helminth",
      "title": "Helminth",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/helminth/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence MITRE-listed software entry associated with OilRig; review source provenance, actor mappings, IOC caveats, and hunt context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:imaploader",
      "title": "IMAPLoader",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/imaploader/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a high-confidence Imperial Kitten .NET loader using legitimate or compromised email accounts for IMAP-based C2, target discovery, and payload delivery.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:impacket",
      "title": "Impacket",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/impacket/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a medium-confidence Python protocol toolkit linked to Magic Hound and Void Manticore, with SMB, credential-access, and lateral-movement behavior.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:iocontrol",
      "title": "IOControl",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/iocontrol/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a high-confidence OT/IoT malware entry associated with CyberAv3ngers; review loader or implant behavior, command channels, mappings, and validation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "embedded-security",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ipconfig",
      "title": "ipconfig",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ipconfig/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence use of the system discovery utility by OilRig and Magic Hound, focusing on network configuration discovery and admin baselines.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ipsec-helper",
      "title": "IPsec Helper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ipsec-helper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review source validation, actor association, mapped techniques, and hunt evidence in this medium-confidence MITRE-listed software entry for Agrius.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ironwind",
      "title": "IronWind",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ironwind/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review high-confidence TA402 reporting on a staged downloader using PPAM, XLL, or RAR lures, DLL side-loading, cloud retrieval, geofencing, and C2.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:isminjector",
      "title": "ISMInjector",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/isminjector/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review source traceability, technique context, IOC limits, and confidence rationale in this medium-confidence MITRE-listed software entry for OilRig.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:kevin",
      "title": "Kevin",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/kevin/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Lyceum-associated backdoor line referenced by public reporting. Use as enrichment term for Lyceum hunting until behavior is source-backed locally.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:koadic",
      "title": "Koadic",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/koadic/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review execution and credential context, source quality, and detection limitations in this medium-confidence post-exploitation framework entry for MuddyWater.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:lazagne",
      "title": "LaZagne",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/lazagne/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review tooling behavior, identity signals, ATT&CK context, and triage guidance in this medium-confidence credential access tool entry for OilRig and MuddyWater.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:liontail",
      "title": "Liontail",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/liontail/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess high-confidence Scarred Manticore server tooling that uses IIS native modules or HTTP.sys-adjacent patterns for stealthy inbound-controlled access.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:lp-notes",
      "title": "LP-Notes",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/lp-notes/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "For MuddyWater, use this medium-confidence MITRE-listed software entry to examine source-backed linkage, mapped techniques, IOC status, and review scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mango",
      "title": "Mango",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mango/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence reporting that links OilRig to this MITRE-listed software; the entry covers actor linkage, source scope, IOCs, mappings, and hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mechaflounder",
      "title": "MechaFlounder",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mechaflounder/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence reporting that links APT39 to this backdoor; the entry covers source-backed capabilities, host behavior, C2, and defensive priorities.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:micropsia",
      "title": "Micropsia",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/micropsia/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence reporting that links APT-C-23 to this backdoor; the entry covers implant delivery, host changes, C2 signals, and defensive validation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:milan",
      "title": "Milan",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/milan/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review this medium-confidence backdoor record for Lyceum, focusing on execution, persistence, C2, indicators, and hunt scope under SRC-MITRE-G1001.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mimikatz-sqlmap-havij",
      "title": "Mimikatz / SQLMap / Havij",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mimikatz-sqlmap-havij/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "MITRE reports Magic Hound use of public tools including Mimikatz, sqlmap, Havij, Metasploit, and Plink. Do not infer actor identity from common public tools.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mimikatz",
      "title": "Mimikatz",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mimikatz/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a medium-confidence credential-dumping record spanning seven tracked actors, using LSASS-memory context, process ancestry, IOCs, and attribution caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:moneybird",
      "title": "Moneybird",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/moneybird/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review destructive execution, backup risk, telemetry evidence, and incident scope in this medium-confidence ransomware or destructive malware entry for Agrius.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:mori",
      "title": "Mori",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/mori/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "The medium-confidence MITRE-listed software record for MuddyWater supports review of source-backed linkage, mapped techniques, IOC status, and review scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:multilayer-wiper",
      "title": "MultiLayer Wiper",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/multilayer-wiper/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence wiper record for Agrius across execution and impact signals, recovery safeguards, source limits, and validation needs.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:nbtscan",
      "title": "NBTscan",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/nbtscan/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review local usage patterns, suspicious invocation, mapping quality, and hunt boundaries in this medium-confidence network scanner entry for APT39 and Agrius.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:net",
      "title": "Net",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/net/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review process context, local baselines, mappings, and hunt limits in this medium-confidence Windows administration utility entry for OilRig and Magic Hound.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:netsh",
      "title": "netsh",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/netsh/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review approved operations, anomalous execution, IOC caveats, and hunt planning in this medium-confidence network configuration utility entry for Magic Hound.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:netstat",
      "title": "netstat",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/netstat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review approved operations, anomalous execution, IOC caveats, and hunt planning in this medium-confidence system discovery utility entry for OilRig and Lyceum.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ngrok-ligolo",
      "title": "NGROK / Ligolo",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ngrok-ligolo/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Dual-use tunneling tools used after edge compromise in Pioneer Kitten or Fox Kitten reporting, recorded at high confidence under SRC-CISA-AA24-241A.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ngrok",
      "title": "ngrok",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ngrok/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review remote-access behavior, enterprise inventory, telemetry, and defensive hunt limits in this medium-confidence tunneling or proxy tooling entry for OilRig.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:nicecurl",
      "title": "NICECURL",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/nicecurl/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Hunt uncommon HTTPS egress from user-path executables after credential phishing or social-engineering lures (SRC-MITRE-G1044; medium confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:odagent",
      "title": "ODAgent",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/odagent/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review ESET's high-confidence record of an OilRig cloud-service-powered downloader found in an Israeli manufacturer network and used to maintain access.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:oilbooster",
      "title": "OilBooster",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/oilbooster/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess an OilRig downloader reported against Israeli organizations that uses attacker-controlled Microsoft cloud accounts and APIs for C2 and data exchange.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:oilcheck",
      "title": "OilCheck",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/oilcheck/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a high-confidence OilRig downloader using cloud-based email services for C2 and sharing logic with the actor's other cloud-powered downloaders.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:oopsie",
      "title": "OopsIE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/oopsie/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence MITRE-listed software entry associated with OilRig; review confidence rationale, source references, technique links, and IOC limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:out1",
      "title": "Out1",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/out1/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "For MuddyWater, use this medium-confidence MITRE-listed software entry to examine association evidence, ATT&CK context, indicators, and validation gaps.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:phenakite",
      "title": "Phenakite",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/phenakite/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence mobile malware record for APT-C-23 across execution ancestry, recurring access, outbound traffic, and triage scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:ping",
      "title": "Ping",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/ping/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence use of the network utility by Magic Hound and Lyceum, with host-discovery behavior, local admin baselines, and source-linked hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:pipesnoop",
      "title": "PipeSnoop",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/pipesnoop/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Use as a research pivot term for UNC1860 tooling; require source-backed behavior before detection logic (SRC-MALPEDIA-UNC1860; low confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:poshc2",
      "title": "PoshC2",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/poshc2/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review credential collection, execution context, IOC handling, and escalation criteria in this medium-confidence post-exploitation framework entry for Lyceum.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerexchange",
      "title": "PowerExchange",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerexchange/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "The medium-confidence MITRE-listed software record for OilRig supports review of association confidence, source records, mapped behaviors, and hunt boundaries.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerless",
      "title": "PowerLess",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerless/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review delivery and execution behavior, persistence signals, source provenance, and hunt limits in this medium-confidence backdoor entry for Magic Hound.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerpost",
      "title": "POWERPOST",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerpost/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence script or collection tool entry associated with APT42; review behavior, source scope, IOCs, mappings, and defensive hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powersploit",
      "title": "PowerSploit",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powersploit/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence MuddyWater use of a PowerShell post-exploitation framework, including offensive module execution, dual-use caveats, and hunt context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powerstats",
      "title": "POWERSTATS",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powerstats/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Explore association evidence, ATT&CK context, indicators, and validation gaps for this MITRE-listed software, associated with MuddyWater at medium confidence.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powgoop",
      "title": "PowGoop",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powgoop/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "MuddyWater is linked at medium confidence to this MITRE-listed software; review evidence provenance, behavior mappings, indicator caveats, and hunt planning.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:powruner",
      "title": "POWRUNER",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/powruner/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Use this MITRE-listed software record to review OilRig's medium-confidence linkage and reported software use, evidence quality, IOC status, and detection gaps.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:psexec",
      "title": "PsExec",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/psexec/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess medium-confidence use of a remote execution utility by OilRig and Magic Hound, focusing on service-based lateral movement and admin baselines.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:pupy",
      "title": "Pupy",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/pupy/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review delivery chain, endpoint behavior, C2 patterns, and response guidance in this medium-confidence RAT or post-exploitation framework entry for Magic Hound.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:pwdump",
      "title": "pwdump",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/pwdump/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence credential access tool entry associated with APT39; review access evidence, process ancestry, credential telemetry, and review scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:quadagent",
      "title": "QUADAGENT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/quadagent/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Explore evidence lineage, actor context, technique coverage, and validation needs for this MITRE-listed software, associated with OilRig at medium confidence.",
      "tags": [
        "ai-security",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rawdisk",
      "title": "RawDisk",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rawdisk/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence disk access driver or tool record for Void Manticore or Handala across behavior, source scope, IOCs, mappings, and defensive hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rclone",
      "title": "Rclone",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rclone/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence MuddyWater use of a cloud synchronization utility for storage and exfiltration, with approved baselines, connections, and hunt scope.",
      "tags": [
        "ai-security",
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rdat",
      "title": "RDAT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rdat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review the medium-confidence MITRE-listed software association with OilRig; use the page for source provenance, actor mappings, IOC caveats, and hunt context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:redalertapk",
      "title": "RedAlert.apk",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/redalertapk/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Hunt smishing delivery, sideloaded alert apps, OTP and SMS access permissions, and spoofed app identities (SRC-CYBERNEWS-REDALERT-2026; low confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:reg",
      "title": "Reg",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/reg/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review administrative context, invocation patterns, source quality, and alert limits in this medium-confidence Windows configuration utility entry for OilRig.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:remexi",
      "title": "Remexi",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/remexi/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "MITRE reports APT39 use of the software for system owner/user discovery and related collection behavior (SRC-MITRE-G0087; medium confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:remote-monitoring-and-management-tools",
      "title": "Remote Monitoring and Management tools",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/remote-monitoring-and-management-tools/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Compare RMM binaries, installation paths, remote URLs, and parents against approved enterprise inventory (SRC-MITRE-G0069; high confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:remoteutilities",
      "title": "RemoteUtilities",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/remoteutilities/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review command execution, approved workflows, indicator limits, and telemetry needs in this medium-confidence remote administration tool entry for MuddyWater.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rgdoor",
      "title": "RGDoor",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rgdoor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Examine evidence linking OilRig to this MITRE-listed software at medium confidence, with attention to actor linkage, source scope, IOCs, mappings, and hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:roadsweep",
      "title": "ROADSWEEP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/roadsweep/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace this medium-confidence wiper record for Void Manticore or Handala across file-system damage, recovery artifacts, mappings, and escalation criteria.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:rustywater",
      "title": "RustyWater",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/rustywater/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence MITRE record linking MuddyWater to this software, with parent-process, host-role, account, staging, and intrusion-chain context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:saitama",
      "title": "Saitama",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/saitama/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Hunt high-entropy subdomains, long query names, and high-frequency single-domain DNS from one host (SRC-UNIT42-OILRIG-DNS-TUNNELING; high confidence).",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:samecoin",
      "title": "SameCoin",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/samecoin/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a high-confidence WIRTE multi-platform wiper using fake security updates, Active Directory propagation, file overwrite, and Android destructive logic.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:samplecheck5000",
      "title": "SampleCheck5000",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/samplecheck5000/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a medium-confidence MITRE software association with OilRig, including Web Shell and network-connection discovery mappings, IOC caveats, and source scope.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sasheyaway",
      "title": "SASHEYAWAY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sasheyaway/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Mandiant reports the software as a low-detection dropper that can enable execution of full passive backdoors such as TEMPLEDOOR, FACEFACE, and SPARKLOAD.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:seasharpee",
      "title": "SEASHARPEE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/seasharpee/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess medium-confidence reporting associating OilRig with this software; prioritize web-shell persistence, connection discovery, IOC renewal, and context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:shark",
      "title": "Shark",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/shark/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review this low-confidence backdoor record for Lyceum, focusing on implant behavior, actor association, IOC context, and telemetry needs under SRC-MITRE-G1001.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sharpstats",
      "title": "SHARPSTATS",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sharpstats/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a medium-confidence MITRE software link to MuddyWater, with phishing, PowerShell, remote-access, cloud-exfiltration, and contextual hunt evidence.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sidetwist",
      "title": "SideTwist",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sidetwist/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace a medium-confidence MITRE association with OilRig through Web Shell persistence, network-connection discovery, source provenance, and IOC limits.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:small-sieve",
      "title": "Small Sieve",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/small-sieve/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a medium-confidence MuddyWater software record using its phishing, PowerShell, remote-access, and cloud-exfiltration mappings to frame defensive review.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:solar",
      "title": "Solar",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/solar/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Use the medium-confidence OilRig software record to assess Web Shell persistence and connection discovery while preserving source, IOC, and attribution caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:spyc23",
      "title": "SpyC23",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/spyc23/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence APT-C-23 mobile spyware reporting on surveillance, malicious-file execution, phishing delivery, staging context, and IOC currency.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:standardkeyboard",
      "title": "StandardKeyboard",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/standardkeyboard/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence vendor reporting linking Imperial Kitten to email-based C2, while preserving evidence gaps and avoiding unsupported behavior claims.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:starwhale",
      "title": "STARWHALE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/starwhale/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Examine the medium-confidence MuddyWater software association through phishing, PowerShell, remote-access, cloud-exfiltration, source, and IOC handling context.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:stayshante",
      "title": "STAYSHANTE",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/stayshante/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a high-confidence UNC1860 web shell deployed on compromised servers, controlled through VIROGREEN, and reported in 2024 activity against Israeli sectors.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:sugarush-sugardump",
      "title": "SUGARUSH / SUGARDUMP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/sugarush-sugardump/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess medium-confidence UNC3890 information-stealer reporting for Israeli shipping and logistics, covering browser data, credentials, IOCs, and collection.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:systeminfo",
      "title": "Systeminfo",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/systeminfo/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence host discovery associated with OilRig and Magic Hound, using process ancestry, host role, account, staging, and source context.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:tamecat",
      "title": "TAMECAT",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/tamecat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess medium-confidence APT42 backdoor reporting on script execution, discovery commands, encrypted sessions, lure context, provenance, and IOC handling.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:tasklist",
      "title": "Tasklist",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/tasklist/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence OilRig process discovery using parent process, host role, account, staging, and intrusion-chain context to limit admin false positives.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templedoor",
      "title": "TEMPLEDOOR",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templedoor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a high-confidence UNC1860 passive backdoor supporting command execution, file transfer, endpoint selection, HTTP proxying, and RDP reachability.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templedrop",
      "title": "TEMPLEDROP",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templedrop/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a high-confidence UNC1860 implant that repurposes a legitimate Iranian antivirus file-system filter driver to protect deployed files from modification.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templelock",
      "title": "TEMPLELOCK",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templelock/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a high-confidence UNC1860 .NET utility used with foothold tools and passive implants to stop or restart Windows Event Log service operation.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:templeplay",
      "title": "TEMPLEPLAY",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/templeplay/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review a high-confidence UNC1860 .NET controller supporting command execution, file transfer, HTTP proxying, endpoint selection, and passive-backdoor tests.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:tsundere-botnet",
      "title": "Tsundere Botnet",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/tsundere-botnet/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Trace medium-confidence MITRE reporting linking MuddyWater to this software through phishing, PowerShell, remote access, cloud exfiltration, and source limits.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:unitronics-vision-plc-webhmi",
      "title": "Unitronics Vision PLC Web/HMI",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/unitronics-vision-plc-webhmi/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess high-confidence CyberAv3ngers targeting of Unitronics PLCs through HMI inventory, password controls, restricted access, and defacement monitoring.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:virogreen",
      "title": "VIROGREEN",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/virogreen/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess a high-confidence UNC1860 framework for scanning and exploiting SharePoint servers, then controlling payloads, backdoors, and command execution.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "offensive-security",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:wezrat",
      "title": "WezRat",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/wezrat/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review high-confidence reporting on a modular infostealer and RAT delivered through fake INCD phishing, with command, screenshot, and data-theft capabilities.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:windows-credential-editor",
      "title": "Windows Credential Editor",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/windows-credential-editor/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Review medium-confidence APT39 credential-access reporting through LSASS memory, execution context, host role, account activity, source scope, and IOC caveats.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:tools:zerocleare",
      "title": "ZeroCleare",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/tools/zerocleare/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Assess medium-confidence tooling linked to OilRig and Void Manticore, covering raw-disk wiping, data destruction, recovery inhibition, and response hunts.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:israel-government-threat-actors-cti:virustotal-enrichment",
      "title": "VirusTotal Malware Enrichment",
      "primary_type": "research",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "public-source regional threat research",
      "canonical_url": "https://1200km.com/israel-government-threat-actors-cti/virustotal-enrichment/",
      "source_url": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "published_at": null,
      "updated_at": "2026-05-16",
      "summary": "Use VirusTotal only to enrich source-backed hashes with public metadata while avoiding sample retrieval, attribution from labels, and benign assumptions.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "malware-analysis",
        "malware-behavior",
        "research",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:israel-government-threat-actors-cti",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "original_publication": "https://github.com/anpa1200/israel-government-threat-actors-cti",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr",
      "title": "ITDR",
      "primary_type": "research",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR. ITDR. Protocols, attack techniques, detection engineering, and simulations for identity-centric security.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:acl-abuse",
      "title": "Acl Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/acl-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Acl Abuse. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/acl-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:adminsdholder-abuse",
      "title": "AdminSDHolder Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/adminsdholder-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AdminSDHolder Abuse. AdminSDHolder Abuse. AdminSDHolder persistence — backdoor ACLs on the AdminSDHolder template propagate to all protected groups via SDProp.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/adminsdholder-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:asrep-roasting",
      "title": "AS-REP Roasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/asrep-roasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AS-REP Roasting. AS-REP Roasting. AS-REP Roasting — targeting accounts with pre-authentication disabled to obtain crackable TGT material.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/asrep-roasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:constrained-delegation",
      "title": "Constrained Delegation Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/constrained-delegation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Constrained Delegation Abuse. Constrained Delegation Abuse. Constrained Kerberos delegation abuse — S4U2Self + S4U2Proxy to impersonate any user to specific…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/constrained-delegation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:dcshadow",
      "title": "DCShadow",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/dcshadow/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "DCShadow. DCShadow. DCShadow — rogue domain controller injection to push malicious AD changes without generating standard event logs.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/dcshadow/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:dcsync",
      "title": "Dcsync",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/dcsync/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Dcsync. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/dcsync/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:golden-ticket",
      "title": "Golden Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/golden-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Golden Ticket. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/golden-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:kerberoasting",
      "title": "Kerberoasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/kerberoasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kerberoasting. Kerberoasting. Kerberoasting — requesting Kerberos service tickets for SPN accounts and cracking them offline.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/kerberoasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:pass-the-hash",
      "title": "Pass-the-Hash (PtH)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-hash/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Pass-the-Hash (PtH). Pass-the-Hash (PtH). Pass-the-Hash — authenticating with an NTLM hash instead of a plaintext password.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-hash/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:pass-the-ticket",
      "title": "Pass The Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Pass The Ticket. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/pass-the-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:rbcd",
      "title": "Resource-Based Constrained Delegation (RBCD) Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/rbcd/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Resource-Based Constrained Delegation (RBCD) Abuse. Resource-Based Constrained Delegation (RBCD) Abuse. RBCD abuse — write…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/rbcd/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:sid-history-abuse",
      "title": "Sid History Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/sid-history-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Sid History Abuse. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/sid-history-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:silver-ticket",
      "title": "Silver Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/silver-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Silver Ticket. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/silver-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:skeleton-key",
      "title": "Skeleton Key",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/skeleton-key/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Skeleton Key. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/skeleton-key/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:active-directory:unconstrained-delegation",
      "title": "Unconstrained Delegation Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/active-directory/unconstrained-delegation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Unconstrained Delegation Abuse. Unconstrained Delegation Abuse. Unconstrained Kerberos delegation — a service can impersonate any user to any service…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/active-directory/unconstrained-delegation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:adcs-certificates:certificate-theft",
      "title": "Certificate Theft",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/certificate-theft/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Certificate Theft. Certificate Theft. Stealing certificates and private keys from Windows certificate stores, disk, and memory.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/certificate-theft/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:adcs-certificates:esc1-template-abuse",
      "title": "ESC1 — Certificate Template Privilege Escalation",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc1-template-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ESC1 — Certificate Template Privilege Escalation. ESC1 — Certificate Template Privilege Escalation. ESC1 — abusing misconfigured ADCS templates to request…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc1-template-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:adcs-certificates:esc4-esc8",
      "title": "ESC4–ESC8 — CA-Level and ACL Attacks",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc4-esc8/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ESC4–ESC8 — CA-Level and ACL Attacks. ESC4–ESC8 — CA-Level and ACL Attacks. ADCS ESC4 (template ACL), ESC6 (CA flag), ESC7 (CA ACL), ESC8 (NTLM relay to CA).",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/adcs-certificates/esc4-esc8/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:cross-platform:credential-stuffing",
      "title": "Credential Stuffing",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/cross-platform/credential-stuffing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Credential Stuffing. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/cross-platform/credential-stuffing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:cross-platform:hybrid-attack-chains",
      "title": "Hybrid Attack Chains",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/cross-platform/hybrid-attack-chains/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Hybrid Attack Chains. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/cross-platform/hybrid-attack-chains/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:cross-platform:mfa-bypass-techniques",
      "title": "Mfa Bypass Techniques",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/cross-platform/mfa-bypass-techniques/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Mfa Bypass Techniques. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/cross-platform/mfa-bypass-techniques/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:aitm-phishing",
      "title": "AiTM Phishing (Adversary-in-the-Middle)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/aitm-phishing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AiTM Phishing (Adversary-in-the-Middle). AiTM Phishing (Adversary-in-the-Middle). AiTM reverse-proxy phishing bypasses MFA by relaying credentials and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/aitm-phishing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:conditional-access-bypass",
      "title": "Conditional Access Bypass",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/conditional-access-bypass/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Conditional Access Bypass. Conditional Access Bypass. Techniques for bypassing Entra ID Conditional Access policies — legacy auth, CAP gaps, device compliance…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security",
        "security-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/conditional-access-bypass/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:device-code-phishing",
      "title": "Device Code Phishing",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/device-code-phishing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Device Code Phishing. Device Code Phishing. OAuth2 Device Authorization Grant abused to steal tokens — no credentials captured, no MFA bypass needed.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/device-code-phishing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:golden-saml",
      "title": "Golden SAML",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/golden-saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Golden SAML. Golden SAML. Golden SAML — forging SAML assertions using a stolen IdP signing key to authenticate as any user.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/golden-saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:illicit-consent-grant",
      "title": "Illicit Consent Grant",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/illicit-consent-grant/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Illicit Consent Grant. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/illicit-consent-grant/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:managed-identity-abuse",
      "title": "Managed Identity Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/managed-identity-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Managed Identity Abuse. Managed Identity Abuse. Azure managed identity abuse — IMDS token theft from compromised VMs, containers, and serverless workloads.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/managed-identity-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:mfa-fatigue",
      "title": "Mfa Fatigue",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/mfa-fatigue/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Mfa Fatigue. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/mfa-fatigue/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:oauth-token-theft",
      "title": "Oauth Token Theft",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/oauth-token-theft/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Oauth Token Theft. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/oauth-token-theft/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:pass-the-prt",
      "title": "Pass The Prt",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/pass-the-prt/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Pass The Prt. Practical security guidance with scope, evidence, and validation boundaries.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/pass-the-prt/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:scim-abuse",
      "title": "SCIM Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/scim-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SCIM Abuse. SCIM Abuse. SCIM provisioning token theft and abuse — unauthorized user provisioning, group manipulation, and account takeover via SCIM API.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/scim-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:entra-cloud:service-principal-abuse",
      "title": "Service Principal Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/entra-cloud/service-principal-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Service Principal Abuse. Service Principal Abuse. Service principal and app registration abuse in Entra ID — credential theft, over-privileged SPs, and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/entra-cloud/service-principal-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:api-token-abuse",
      "title": "API Token Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/api-token-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "API Token Abuse. API Token Abuse. API token theft and abuse in SaaS platforms — GitHub PATs, Slack tokens, Salesforce API keys, and CI/CD secrets.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/api-token-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:oauth-app-abuse",
      "title": "OAuth App Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/oauth-app-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OAuth App Abuse. OAuth App Abuse. OAuth application abuse — malicious app consent, over-privileged third-party apps, and persistent access without credentials.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/oauth-app-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:session-hijacking",
      "title": "Session Hijacking",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/session-hijacking/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Session Hijacking. Session Hijacking. Web session cookie theft and hijacking for SaaS applications — infostealer malware, XSS, and cookie replay.",
      "tags": [
        "documentation",
        "identity-security",
        "malware-analysis",
        "malware-behavior"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/session-hijacking/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:attacks:saas:shadow-admin",
      "title": "Shadow Admin",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/attacks/saas/shadow-admin/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Shadow Admin. Shadow Admin. Shadow admins in SaaS — accounts with administrative capabilities through indirect role paths, bypassing formal admin lists.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/attacks/saas/shadow-admin/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-acl-abuse",
      "title": "Detecting Acl Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-acl-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Acl Abuse. Detecting Acl Abuse. Scaffold — detection rules for Acl Abuse.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-acl-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-asrep-roasting",
      "title": "Detecting Asrep Roasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-asrep-roasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Asrep Roasting. Detecting Asrep Roasting. Scaffold — detection rules for Asrep Roasting.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-asrep-roasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-dcsync",
      "title": "Detecting Dcsync",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-dcsync/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Dcsync. Detecting Dcsync. Scaffold — detection rules for Dcsync.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-dcsync/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-golden-ticket",
      "title": "Detecting Golden Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-golden-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Golden Ticket. Detecting Golden Ticket. Scaffold — detection rules for Golden Ticket.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-golden-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-kerberoasting",
      "title": "Detecting Kerberoasting",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-kerberoasting/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Kerberoasting. Detecting Kerberoasting. Detection rules for Kerberoasting — Event 4769, RC4 ticket requests, bulk SPN queries.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-kerberoasting/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-pass-the-hash",
      "title": "Detecting Pass The Hash",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-hash/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Pass The Hash. Detecting Pass The Hash. Scaffold — detection rules for Pass The Hash.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-hash/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:ad-attack-detection:detect-pass-the-ticket",
      "title": "Detecting Pass The Ticket",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-ticket/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Pass The Ticket. Detecting Pass The Ticket. Scaffold — detection rules for Pass The Ticket.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/ad-attack-detection/detect-pass-the-ticket/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:adcs-detection:detect-certificate-attacks",
      "title": "Detecting ADCS / Certificate Attacks",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/adcs-detection/detect-certificate-attacks/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting ADCS / Certificate Attacks. Detecting ADCS / Certificate Attacks. Detection rules for ESC1, certificate enrollment abuse, and certificate-based…",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/adcs-detection/detect-certificate-attacks/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-device-code-phishing",
      "title": "Detecting Device Code Phishing",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-device-code-phishing/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Device Code Phishing. Detecting Device Code Phishing. Scaffold — detection rules for Device Code Phishing in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-device-code-phishing/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-golden-saml",
      "title": "Detecting Golden Saml",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-golden-saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Golden Saml. Detecting Golden Saml. Scaffold — detection rules for Golden Saml in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-golden-saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-mfa-fatigue",
      "title": "Detecting Mfa Fatigue",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-mfa-fatigue/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Mfa Fatigue. Detecting Mfa Fatigue. Scaffold — detection rules for Mfa Fatigue in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-mfa-fatigue/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:cloud-attack-detection:detect-oauth-abuse",
      "title": "Detecting Oauth Abuse",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-oauth-abuse/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detecting Oauth Abuse. Detecting Oauth Abuse. Scaffold — detection rules for Oauth Abuse in Entra ID / cloud environments.",
      "tags": [
        "cloud-security",
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/cloud-attack-detection/detect-oauth-abuse/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:detection:detection-framework",
      "title": "Detection Framework",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/detection/detection-framework/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Detection Framework. Detection Framework. ITDR detection engineering framework — telemetry requirements, DRL levels, rule structure, and validation methodology.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/detection/detection-framework/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:identity-as-perimeter",
      "title": "Identity as the New Perimeter",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/identity-as-perimeter/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity as the New Perimeter. Identity as the New Perimeter. Why identity replaced the network perimeter as the primary security boundary, and what this…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/identity-as-perimeter/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:identity-attack-surface",
      "title": "Identity Attack Surface",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/identity-attack-surface/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity Attack Surface. Identity Attack Surface. Taxonomy of the identity attack surface across on-premises, cloud, and hybrid environments — credential…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/identity-attack-surface/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:identity-frameworks",
      "title": "Identity Frameworks & Standards",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/identity-frameworks/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity Frameworks & Standards. Identity Frameworks & Standards. Key frameworks for identity security — NIST IAM, MITRE ATT&CK, CIS Controls, and how they…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security",
        "mitre-attack"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/identity-frameworks/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:what-is-identity",
      "title": "What is Identity?",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/what-is-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "What is Identity?. What is Identity?. Core identity concepts — principals, authentication, authorization, credentials, and the identity lifecycle.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/what-is-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:identity-foundations:what-is-itdr",
      "title": "What is ITDR?",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/identity-foundations/what-is-itdr/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "What is ITDR?. What is ITDR?. Identity Threat Detection and Response — definition, scope, lifecycle, and how it differs from SIEM/EDR.",
      "tags": [
        "detection-content",
        "detection-engineering",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/identity-foundations/what-is-itdr/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:iga:iga-overview",
      "title": "Identity Governance & Administration (IGA)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/iga/iga-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Identity Governance & Administration (IGA). Identity Governance & Administration (IGA). IGA discipline and vendors — SailPoint, Saviynt, Omada, One Identity —…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security",
        "security-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/iga/iga-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:intro",
      "title": "ITDR — Identity Threat Detection & Response",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/intro/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR — Identity Threat Detection & Response. ITDR — Identity Threat Detection & Response. Overview of the ITDR handbook — what it covers, how to use it, and…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/intro/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:itdr-vendors:itdr-vendor-landscape",
      "title": "ITDR Vendor Landscape",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/itdr-vendors/itdr-vendor-landscape/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR Vendor Landscape. ITDR Vendor Landscape. Major ITDR vendors — Palo Alto Networks, CrowdStrike, Microsoft, Silverfort, Semperis, Permiso, Veza, Astrix…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/itdr-vendors/itdr-vendor-landscape/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:labs:lab-ad-setup",
      "title": "Active Directory Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-ad-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory Lab Setup. Active Directory Lab Setup. Build an AD lab with Domain Controller, workstation, ADCS, vulnerable configurations, and logging.",
      "tags": [
        "identity-and-access",
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-ad-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-architecture",
      "title": "Lab Architecture",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-architecture/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Lab Architecture. Lab Architecture. ITDR lab environment design — topology, components, tooling, and what each lab enables.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-architecture/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-entra-setup",
      "title": "Entra ID Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-entra-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra ID Lab Setup. Entra ID Lab Setup. Set up an Entra ID lab tenant for cloud identity attack simulation — OAuth, device code, Golden SAML.",
      "tags": [
        "attack-emulation",
        "cloud-security",
        "identity-and-access",
        "identity-security",
        "lab",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-entra-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-linux-setup",
      "title": "Linux Identity Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-linux-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux Identity Lab Setup. Linux Identity Lab Setup. Set up a Linux lab with AD integration via SSSD, PAM, Kerberos, and sudo for identity attack practice.",
      "tags": [
        "identity-and-access",
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-linux-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:labs:lab-okta-setup",
      "title": "Okta Lab Setup",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/labs/lab-okta-setup/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta Lab Setup. Okta Lab Setup. Set up an Okta developer org for MFA fatigue and admin console attack simulation.",
      "tags": [
        "attack-emulation",
        "identity-security",
        "lab",
        "offensive-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/labs/lab-okta-setup/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:mfa:mfa-technologies",
      "title": "MFA Technologies",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/mfa/mfa-technologies/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "MFA Technologies. MFA Technologies. Complete MFA taxonomy — TOTP, HOTP, push MFA, smart cards, FIDO2, passkeys, biometrics, SMS, email OTP — with phishing…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/mfa/mfa-technologies/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:pam:pam-overview",
      "title": "Privileged Access Management (PAM)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/pam/pam-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Privileged Access Management (PAM). Privileged Access Management (PAM). PAM discipline and vendors — CyberArk, BeyondTrust, Delinea, One Identity, Wallix —…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/pam/pam-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ad-overview",
      "title": "Active Directory — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory — Overview. Active Directory — Overview. Active Directory DS architecture, domains, forests, trusts, and security boundaries.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ad-trusts",
      "title": "Active Directory Trusts",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-trusts/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory Trusts. Active Directory Trusts. AD trust types, transitivity, SID filtering, and trust-based attack paths.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ad-trusts/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:adcs",
      "title": "Active Directory Certificate Services (ADCS)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/adcs/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Active Directory Certificate Services (ADCS). Active Directory Certificate Services (ADCS). ADCS architecture, certificate templates, enrollment permissions…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/adcs/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:group-policy",
      "title": "Group Policy",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/group-policy/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Group Policy. Group Policy. Group Policy Objects — structure, application order, security settings, and how attackers abuse GPO for persistence and lateral…",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/group-policy/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:kerberos",
      "title": "Kerberos Protocol",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/kerberos/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kerberos Protocol. Kerberos Protocol. Kerberos v5 internals — AS, TGS, ticket structure, encryption types, and delegation models.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/kerberos/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ldap",
      "title": "LDAP in Active Directory",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ldap/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "LDAP in Active Directory. LDAP in Active Directory. LDAP protocol in AD — queries, ACLs, anonymous bind, LDAPS, and how attackers use LDAP for enumeration and…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ldap/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:ntlm",
      "title": "NTLM Authentication",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/ntlm/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "NTLM Authentication. NTLM Authentication. NTLM challenge-response internals, NTLMv1 vs NTLMv2, relay attacks, and why NTLM persists in modern environments.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/ntlm/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:active-directory:spnego-gssapi",
      "title": "SPNEGO & GSSAPI",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/active-directory/spnego-gssapi/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SPNEGO & GSSAPI. SPNEGO & GSSAPI. SPNEGO auth negotiation and GSSAPI security API — how Windows chooses Kerberos vs NTLM, and the attack implications.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/active-directory/spnego-gssapi/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:aws-cognito",
      "title": "AWS Cognito",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-cognito/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS Cognito. AWS Cognito. AWS Cognito — User Pools, Identity Pools, and security considerations.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-cognito/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:aws-iam-overview",
      "title": "AWS IAM — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-iam-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS IAM — Overview. AWS IAM — Overview. AWS IAM — principals, policies, roles, permission boundaries, and the IAM attack surface.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-iam-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:aws-sts",
      "title": "AWS Security Token Service (STS)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-sts/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS Security Token Service (STS). AWS Security Token Service (STS). STS AssumeRole flows, cross-account access, IMDS token theft, and role chaining attacks.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/aws-sts/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:aws-iam:iam-identity-center",
      "title": "AWS IAM Identity Center",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/aws-iam/iam-identity-center/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "AWS IAM Identity Center. AWS IAM Identity Center. AWS IAM Identity Center (SSO) — permission sets, account assignment, federated IdP integration, and attack…",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/aws-iam/iam-identity-center/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:auth0",
      "title": "Auth0 (Okta Customer Identity Cloud)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/auth0/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Auth0 (Okta Customer Identity Cloud). Auth0 (Okta Customer Identity Cloud). Auth0 / Okta Customer Identity Cloud — CIAM platform, tenant architecture, and…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/auth0/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:duo-security",
      "title": "Duo Security (Cisco)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/duo-security/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Duo Security (Cisco). Duo Security (Cisco). Duo Security — MFA and zero-trust access platform, authentication proxy, and integration patterns.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/duo-security/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:jumpcloud",
      "title": "JumpCloud",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/jumpcloud/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "JumpCloud. JumpCloud. JumpCloud — cloud directory service replacing AD, SSO, device management, and security considerations.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/jumpcloud/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:onelogin",
      "title": "OneLogin",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/onelogin/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OneLogin. OneLogin. OneLogin — cloud IdP, SSO, MFA, and Trusted Experience Platform.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/onelogin/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:cloud-idp:ping-identity",
      "title": "Ping Identity",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/cloud-idp/ping-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Ping Identity. Ping Identity. Ping Identity — PingOne, PingFederate, PingAccess, and the Ping Identity platform.",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/cloud-idp/ping-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:conditional-access",
      "title": "Conditional Access",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/conditional-access/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Conditional Access. Conditional Access. Entra ID Conditional Access — signals, policy structure, grant controls, and bypass techniques.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/conditional-access/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:entra-connect-sync",
      "title": "Entra Connect Sync (AD Connect)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-connect-sync/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra Connect Sync (AD Connect). Entra Connect Sync (AD Connect). Entra Connect Sync — sync modes, architecture, the sync account's dangerous privileges, and…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-connect-sync/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:entra-overview",
      "title": "Entra ID (Azure AD) — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra ID (Azure AD) — Overview. Entra ID (Azure AD) — Overview. Microsoft Entra ID architecture — tenants, directory objects, authentication protocols, and…",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/entra-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:identity-protection",
      "title": "Entra ID Identity Protection",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/identity-protection/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Entra ID Identity Protection. Entra ID Identity Protection. Entra ID Identity Protection — risk detection types, risk levels, risk-based Conditional Access…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/identity-protection/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:oauth2",
      "title": "OAuth 2.0",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/oauth2/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OAuth 2.0. OAuth 2.0. OAuth 2.0 grant types, token types, scopes, and how each flow is abused in identity attacks.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/oauth2/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:oidc",
      "title": "OpenID Connect (OIDC)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/oidc/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OpenID Connect (OIDC). OpenID Connect (OIDC). OpenID Connect — ID tokens, claims, discovery, and how OIDC federation is abused.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/oidc/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:pim",
      "title": "Privileged Identity Management (PIM)",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/pim/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Privileged Identity Management (PIM). Privileged Identity Management (PIM). Entra ID PIM — JIT privilege, approval workflows, and how PIM is bypassed or abused.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/pim/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:saml",
      "title": "SAML 2.0",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SAML 2.0. SAML 2.0. SAML 2.0 protocol — SP/IdP roles, assertion structure, bindings, and Golden SAML attack surface.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:entra-id:ws-federation",
      "title": "WS-Federation",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/entra-id/ws-federation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "WS-Federation. WS-Federation. WS-Federation protocol — passive requestor profile, STS tokens, and how it relates to SAML and modern federation.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/entra-id/ws-federation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:gcp-iam",
      "title": "Google Cloud IAM",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/gcp-iam/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Google Cloud IAM. Google Cloud IAM. Google Cloud IAM — principals, roles, policy bindings, service accounts, and the GCP attack surface.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/gcp-iam/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:gws-overview",
      "title": "Google Workspace — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Google Workspace — Overview. Google Workspace — Overview. Google Workspace identity architecture — Cloud Identity, Admin SDK, OAuth2 scopes, and Super Admin…",
      "tags": [
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:gws-saml-oidc",
      "title": "Google Workspace SAML & OIDC",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-saml-oidc/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Google Workspace SAML & OIDC. Google Workspace SAML & OIDC. Google Workspace as IdP (SAML) and as SP (third-party IdP federation), and OIDC for GCP/API access.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/gws-saml-oidc/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:google-workspace:workload-identity-federation",
      "title": "Workload Identity Federation",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/google-workspace/workload-identity-federation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Workload Identity Federation. Workload Identity Federation. Google Workload Identity Federation and Workforce Identity Federation — federated access without…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/google-workspace/workload-identity-federation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:kubernetes:k8s-rbac",
      "title": "Kubernetes RBAC",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-rbac/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kubernetes RBAC. Kubernetes RBAC. Kubernetes RBAC — roles, bindings, cluster-admin escalation paths, and audit logging.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-rbac/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:kubernetes:k8s-service-accounts",
      "title": "Kubernetes Service Accounts",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-service-accounts/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kubernetes Service Accounts. Kubernetes Service Accounts. Kubernetes service accounts — token mounting, OIDC federation, projected volumes, and the attack…",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/kubernetes/k8s-service-accounts/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:kubernetes:spiffe-spire",
      "title": "SPIFFE & SPIRE",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/kubernetes/spiffe-spire/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "SPIFFE & SPIRE. SPIFFE & SPIRE. SPIFFE workload identity standard and SPIRE implementation — SVIDs, trust bundles, and zero-trust workload auth.",
      "tags": [
        "cloud-and-container-security",
        "cloud-security",
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/kubernetes/spiffe-spire/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-kerberos",
      "title": "Kerberos on Linux",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-kerberos/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Kerberos on Linux. Kerberos on Linux. Kerberos credential caches on Linux, ccache theft, and keytab abuse.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-kerberos/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-pam",
      "title": "Linux PAM",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-pam/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux PAM. Linux PAM. Pluggable Authentication Modules — stack structure, modules, and security configuration.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-pam/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-sssd",
      "title": "Linux SSSD",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sssd/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux SSSD. Linux SSSD. SSSD — connecting Linux to Active Directory, Kerberos authentication, and group policy via realm.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sssd/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:linux-identity:linux-sudo",
      "title": "Linux sudo & Privilege",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sudo/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Linux sudo & Privilege. Linux sudo & Privilege. sudo configuration, sudoers file, common misconfigurations, and privilege escalation via sudo.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/linux-identity/linux-sudo/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:network-auth:radius",
      "title": "RADIUS",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/network-auth/radius/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "RADIUS. RADIUS. RADIUS protocol — authentication, authorization, accounting, and how it is used for network access control.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/network-auth/radius/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:network-auth:tacacs-plus",
      "title": "TACACS+",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/network-auth/tacacs-plus/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "TACACS+. TACACS+. TACACS+ vs RADIUS, use for network device authentication, and command authorization.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/network-auth/tacacs-plus/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-mfa",
      "title": "Okta MFA",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-mfa/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta MFA. Okta MFA. Okta MFA factors, authenticator types, enrollment policies, and push bombing attack surface.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-mfa/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-overview",
      "title": "Okta — Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta — Overview. Okta — Overview. Okta architecture, org types, identity protocols supported, and key security features.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-policies",
      "title": "Okta Policies & Network Zones",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-policies/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta Policies & Network Zones. Okta Policies & Network Zones. Okta sign-on, MFA, and password policies — structure, precedence, and security gaps.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-policies/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:okta:okta-scim",
      "title": "Okta SCIM Provisioning",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/okta/okta-scim/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Okta SCIM Provisioning. Okta SCIM Provisioning. SCIM 2.0 protocol in Okta — provisioning flows, attribute mapping, and security considerations.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/okta/okta-scim/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:open-source-directories:389ds",
      "title": "389 Directory Server",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/open-source-directories/389ds/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "389 Directory Server. 389 Directory Server. 389 Directory Server — the LDAP engine behind FreeIPA and Red Hat Directory Server.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/open-source-directories/389ds/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:open-source-directories:freeipa",
      "title": "FreeIPA",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/open-source-directories/freeipa/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "FreeIPA. FreeIPA. FreeIPA — integrated Linux identity management (LDAP + Kerberos + DNS + CA) and its attack surface.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/open-source-directories/freeipa/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:open-source-directories:openldap",
      "title": "OpenLDAP",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/open-source-directories/openldap/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "OpenLDAP. OpenLDAP. OpenLDAP — architecture, schema, replication, security configuration, and attack surface.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/open-source-directories/openldap/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:fido2-webauthn",
      "title": "FIDO2 & WebAuthn",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/fido2-webauthn/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "FIDO2 & WebAuthn. FIDO2 & WebAuthn. FIDO2 and WebAuthn — passwordless authentication, phishing resistance, authenticator types, and enterprise deployment.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/fido2-webauthn/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:passkeys",
      "title": "Passkeys",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/passkeys/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Passkeys. Passkeys. Passkeys — synced FIDO2 credentials, platform implementations, enterprise considerations, and security model.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/passkeys/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:pki-overview",
      "title": "PKI Overview",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/pki-overview/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "PKI Overview. PKI Overview. Public Key Infrastructure — CAs, trust chains, certificate lifecycle, and PKI in enterprise identity.",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/pki-overview/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:smart-cards",
      "title": "Smart Cards & Hardware Tokens",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/smart-cards/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Smart Cards & Hardware Tokens. Smart Cards & Hardware Tokens. Smart card authentication, PIV standard, YubiKey, FIDO2, and the limits of hardware-based…",
      "tags": [
        "documentation",
        "embedded-security",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/smart-cards/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:protocols:pki-certificates:x509-certificates",
      "title": "X.509 Certificates",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/protocols/pki-certificates/x509-certificates/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "X.509 Certificates. X.509 Certificates. X.509 certificate structure, encoding formats, validation, and common certificate attack paths.",
      "tags": [
        "documentation",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/protocols/pki-certificates/x509-certificates/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:roadmap",
      "title": "ITDR Professional Roadmap",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/roadmap/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "ITDR Professional Roadmap. ITDR Professional Roadmap. Complete learning path from identity fundamentals to professional-level ITDR — protocols, attack…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/roadmap/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:saas-platforms:github-identity",
      "title": "GitHub Identity Security",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/saas-platforms/github-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "GitHub Identity Security. GitHub Identity Security. GitHub identity attack surface — org admin compromise, PAT abuse, Actions secrets exfiltration, and supply…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/saas-platforms/github-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:saas-platforms:m365-identity",
      "title": "Microsoft 365 Identity",
      "primary_type": "documentation",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/saas-platforms/m365-identity/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Microsoft 365 Identity. Microsoft 365 Identity. M365 identity security — authentication, attack surface, and detection in Exchange, Teams, SharePoint, and the…",
      "tags": [
        "documentation",
        "identity-and-access",
        "identity-security"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/saas-platforms/m365-identity/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:certificate-escalation",
      "title": "Scenario: Certificate Escalation",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/certificate-escalation/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Certificate Escalation. Scenario: Certificate Escalation. Scaffold — full attack-defense simulation for Certificate Escalation.",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/certificate-escalation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:cloud-identity-takeover",
      "title": "Scenario: Cloud Identity Takeover",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/cloud-identity-takeover/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Cloud Identity Takeover. Scenario: Cloud Identity Takeover. Scaffold — full attack-defense simulation for Cloud Identity Takeover.",
      "tags": [
        "cloud-security",
        "identity-and-access",
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/cloud-identity-takeover/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:domain-compromise-chain",
      "title": "Scenario: Domain Compromise Chain",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/domain-compromise-chain/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Domain Compromise Chain. Scenario: Domain Compromise Chain. Full AD compromise simulation — Kerberoasting → Pass-the-Hash → DCSync → Golden Ticket…",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/domain-compromise-chain/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:scenarios:hybrid-golden-saml",
      "title": "Scenario: Hybrid Golden Saml",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/scenarios/hybrid-golden-saml/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Scenario: Hybrid Golden Saml. Scenario: Hybrid Golden Saml. Scaffold — full attack-defense simulation for Hybrid Golden Saml.",
      "tags": [
        "identity-and-access",
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/scenarios/hybrid-golden-saml/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:itdr:docs:simulations:simulation-framework",
      "title": "Attack–Defense Simulation Framework",
      "primary_type": "lab",
      "primary_domain": "identity-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "illustrative",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/ITDR/docs/simulations/simulation-framework/",
      "published_at": null,
      "updated_at": "2026-07-22",
      "summary": "Attack–Defense Simulation Framework. Attack–Defense Simulation Framework. How ITDR simulations are structured — scenario format, lab prerequisites, attacker…",
      "tags": [
        "identity-security",
        "lab"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/ITDR/docs/simulations/simulation-framework/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:labs.html",
      "title": "Lab Work",
      "primary_type": "index",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "lab-validated",
      "applies_to": "authorized security lab index",
      "canonical_url": "https://1200km.com/labs.html",
      "published_at": null,
      "updated_at": "2026-08-07",
      "summary": "Lab Work. Security labs by Andrey Pautov: APT41 simulation, vulnerable AD and cloud infrastructure, Android malware analysis, Sliver C2, and…",
      "tags": [
        "author:Andrey Pautov",
        "cloud-security",
        "index",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/labs.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:learning-paths",
      "title": "Practical security learning paths",
      "primary_type": "index",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer",
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/learning-paths/",
      "published_at": null,
      "updated_at": "2026-09-09",
      "summary": "Ordered CTI, detection, AI security, and malware-triage tasks with prerequisites and expected outputs.",
      "tags": [
        "ai-security",
        "index",
        "malware-analysis",
        "malware-behavior",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/learning-paths/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:learning-paths:agent-permission-validation",
      "title": "Validate a simulated agent permission boundary",
      "primary_type": "research",
      "primary_domain": "network-security",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/learning-paths/agent-permission-validation/",
      "published_at": "2026-09-09",
      "updated_at": "2026-09-09",
      "summary": "Run a benign local permission simulator and check allow/deny decisions, audit completeness, and negative controls.",
      "tags": [
        "network-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/learning-paths/agent-permission-validation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:learning-paths:command-shell-validation",
      "title": "Validate a command-shell detection candidate with benign events",
      "primary_type": "research",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/learning-paths/command-shell-validation/",
      "published_at": "2026-09-09",
      "updated_at": "2026-09-09",
      "summary": "Read benign synthetic process events and verify a narrow detection candidate with positive and negative controls.",
      "tags": [
        "detection-engineering",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/learning-paths/command-shell-validation/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:learning-paths:safe-artifact-triage",
      "title": "Triage a reproducible benign artifact",
      "primary_type": "research",
      "primary_domain": "network-security",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/learning-paths/safe-artifact-triage/",
      "published_at": "2026-09-09",
      "updated_at": "2026-09-09",
      "summary": "Inspect a deterministic benign ZIP with hashes, structured observations, corroboration, and negative controls.",
      "tags": [
        "network-security",
        "research"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/learning-paths/safe-artifact-triage/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:newest-detection-engineering-techniques",
      "title": "Newest Detection Engineering Techniques",
      "primary_type": "mirror",
      "primary_domain": "detection-engineering",
      "audience": [
        "detection-engineer",
        "threat-hunter",
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "current detection-engineering research companion",
      "canonical_url": "https://1200km.com/newest-detection-engineering-techniques/",
      "published_at": "2026-07-11",
      "updated_at": "2026-07-11",
      "summary": "Read a practical guide to modern detection engineering, from telemetry and ATT&CK mapping to detection-as-code, validation, tuning, and analyst handoff.",
      "tags": [
        "author:Andrey Pautov",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "research"
      ],
      "featured": true,
      "indexable": true,
      "source_url": "https://medium.com/@1200km/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "source_platform": "Medium",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://medium.com/@1200km/newest-detection-engineering-techniques-from-rules-to-validated-security-telemetry-a5ccb46d5556",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:opencti-intelligent-shield",
      "title": "The Intelligent Shield",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "OpenCTI deployment and enrichment workflows",
      "canonical_url": "https://1200km.com/opencti-intelligent-shield/",
      "source_url": "https://github.com/anpa1200/opencti-intelligent-shield",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Build an analyst-reviewed OpenCTI workflow with STIX 2.1, trusted feeds, Claude enrichment, ATT&CK mapping, security hardening, and practical investigations.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:opencti-intelligent-shield",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/opencti-intelligent-shield",
      "original_publication": "https://github.com/anpa1200/opencti-intelligent-shield",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:opencti-intelligent-shield:docs:intelligent-shield",
      "title": "The Intelligent Shield: Building an AI-Powered CTI Platform with OpenCTI",
      "primary_type": "guide",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "platform-operator"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "OpenCTI deployment and enrichment workflows",
      "canonical_url": "https://1200km.com/opencti-intelligent-shield/docs/intelligent-shield/",
      "source_url": "https://github.com/anpa1200/opencti-intelligent-shield",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Deploy OpenCTI as a structured CTI platform with STIX 2.1 feeds, ATT&CK relationships, Claude enrichment, hardened services, and investigation workflows.",
      "tags": [
        "ai-security",
        "guide",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:opencti-intelligent-shield",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/opencti-intelligent-shield",
      "original_publication": "https://github.com/anpa1200/opencti-intelligent-shield",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra",
      "title": "Operation Desert Hydra",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-08-14",
      "summary": "Follow a reproducible MuddyWater CTI pipeline from research through OpenCTI knowledge modeling, detection design, lab validation, and Kibana evidence.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": true,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:for-defenders",
      "title": "What Defenders Should Do Right Now",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/for-defenders/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Prioritize MuddyWater defenses by baselining RMM tools, enabling PowerShell and Sysmon telemetry, hunting PT43M tasks, and validating key coverage gaps.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:intro",
      "title": "Why MuddyWater?",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/intro/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Follow a complete MuddyWater CTI-to-detection workflow: assess sources, model procedures in OpenCTI, engineer rules, and validate them in a live lab.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:limitations",
      "title": "Limitations",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/limitations/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-18",
      "summary": "Understand what the lab results prove, where simulations and public reporting fall short, and which MuddyWater detections still require production tuning.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-1-source-gathering",
      "title": "Phase 1: Source Gathering",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-1-source-gathering/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Build a defensible MuddyWater source register with manual and AI-assisted discovery, reliability ratings, claim deduplication, and preserved evidence.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-2-procedure-dataset",
      "title": "Phase 2: Procedure Dataset",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-2-procedure-dataset/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Turn rated MuddyWater reporting into source-bound procedure records with evidence labels, ATT&CK candidates, telemetry needs, and validation plans.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-3-opencti",
      "title": "Phase 3: OpenCTI Knowledge Graph",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-3-opencti/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Import MuddyWater sources and procedures into OpenCTI as linked STIX 2.1 objects, then verify relationships, ATT&CK mappings, and downstream usability.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-4-detection-atlas",
      "title": "Phase 4: Detection Atlas",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-4-detection-atlas/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Translate source-backed MuddyWater behavior into detection records with telemetry gates, pseudologic, tuning guidance, readiness scores, and review evidence.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-5-results",
      "title": "Phase 5: Validation Results Summary",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-5-results/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Review 16 lab rule checks with 14 passes, one partial result, and one failure, including the evidence, root causes, and coverage implications for each.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-5-validation-lab",
      "title": "Phase 5: Validation Lab",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-5-validation-lab/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Reproduce the Windows detection environment with Kibana, Elasticsearch, Sysmon, Winlogbeat, Ansible, and benign simulations that generate auditable evidence.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:phase-6-coverage-matrix",
      "title": "Phase 6: Coverage Matrix",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/phase-6-coverage-matrix/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Measure MuddyWater detection coverage by ATT&CK technique, readiness score, telemetry gate, and lab result while preserving documented gaps and caveats.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:pipeline",
      "title": "The Pipeline",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/pipeline/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Trace six phases from source collection and procedure modeling through OpenCTI, detection engineering, lab validation, proof capture, and coverage scoring.",
      "tags": [
        "ai-security",
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:production-scars",
      "title": "Production Scars",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/production-scars/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Learn from failed simulations, missing telemetry, query errors, and infrastructure constraints encountered while turning CTI claims into validated detections.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:operation-desert-hydra:docs:reproduce",
      "title": "Reproduce It Yourself",
      "primary_type": "case-study",
      "primary_domain": "detection-engineering",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "lab-validated",
      "applies_to": "MuddyWater CTI-to-detection validation scenario",
      "canonical_url": "https://1200km.com/operation-desert-hydra/docs/reproduce/",
      "source_url": "https://github.com/anpa1200/operation-desert-hydra",
      "published_at": null,
      "updated_at": "2026-06-13",
      "summary": "Deploy the complete project with Docker, VirtualBox, Vagrant, and Ansible; run its simulations, inspect expected outputs, and preserve or remove the lab safely.",
      "tags": [
        "case-study",
        "detection-content",
        "detection-engineering",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "collection_id": "collection:operation-desert-hydra",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/operation-desert-hydra",
      "original_publication": "https://github.com/anpa1200/operation-desert-hydra",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:privacy.html",
      "title": "Privacy and Data Handling",
      "primary_type": "policy",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "1200km public-site data handling",
      "canonical_url": "https://1200km.com/privacy.html",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Privacy and Data Handling. Privacy, analytics, local search, browser storage, and public-demo data-handling information for…",
      "tags": [
        "ai-security",
        "policy",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/privacy.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:projects.html",
      "title": "1200km projects, packages, research, and external submissions.",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current public project registry",
      "canonical_url": "https://1200km.com/projects.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Explore Andrey Pautov’s cybersecurity projects: AdversaryGraph, malware-analysis tools, CTI research, detection engineering, AI security, and practical labs.",
      "tags": [
        "adversarygraph",
        "ai-security",
        "author:Andrey Pautov",
        "detection-content",
        "detection-engineering",
        "index",
        "malware-analysis",
        "malware-behavior",
        "reverse-engineering",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/projects.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:pt-tools.html",
      "title": "PT Tools & Techniques",
      "primary_type": "index",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized penetration-testing tools",
      "canonical_url": "https://1200km.com/pt-tools.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "PT Tools & Techniques. Security assessment tools by Andrey Pautov: RTSP testing, password tooling, StratusAI, AuditAI, Nmap…",
      "tags": [
        "author:Andrey Pautov",
        "offensive-research",
        "tool"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/pt-tools.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "ai-security",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter",
        "security-engineer",
        "security-leader"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "deduplicated public research references about AI usage in cyberattacks, indexed for discovery and correlation",
      "canonical_url": "https://1200km.com/references/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "ai-security",
        "artificial-intelligence",
        "cti",
        "incident-response",
        "research-reference",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:10",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/10/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 10 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/10/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:11",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/11/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 11 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/11/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:12",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/12/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 12 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/12/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:13",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/13/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 13 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/13/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:14",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/14/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 14 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/14/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:15",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/15/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 15 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/15/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:16",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/16/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 16 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/16/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:17",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/17/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 17 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/17/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:18",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/18/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 18 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/18/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:19",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/19/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 19 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/19/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:2",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/2/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 2 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/2/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:20",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/20/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 20 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/20/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:21",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/21/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 21 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/21/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:22",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/22/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 22 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/22/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:23",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/23/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 23 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/23/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:24",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/24/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 24 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/24/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:25",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/25/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 25 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/25/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:26",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/26/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 26 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/26/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:27",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/27/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 27 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/27/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:28",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/28/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 28 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/28/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:29",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/29/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 29 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/29/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:3",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/3/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 3 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/3/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:30",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/30/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 30 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/30/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:31",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/31/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 31 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/31/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:32",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/32/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 32 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/32/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:33",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/33/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 33 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/33/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:34",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/34/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 34 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/34/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:35",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/35/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 35 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/35/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:36",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/36/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 36 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/36/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:37",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/37/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 37 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/37/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:38",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/38/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 38 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/38/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:39",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/39/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 39 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/39/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:4",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/4/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 4 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/4/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:40",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/40/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 40 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/40/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:41",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/41/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 41 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/41/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:42",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/42/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 42 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/42/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:43",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/43/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 43 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/43/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:44",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/44/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 44 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/44/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:45",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/45/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 45 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/45/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:46",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/46/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 46 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/46/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:47",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/47/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 47 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/47/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:48",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/48/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 48 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/48/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:49",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/49/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 49 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/49/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:5",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/5/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 5 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/5/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:50",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/50/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 50 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/50/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:51",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/51/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 51 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/51/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:52",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/52/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 52 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/52/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:53",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/53/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 53 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/53/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:54",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/54/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 54 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/54/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:55",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/55/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 55 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/55/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:56",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/56/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 56 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/56/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:57",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/57/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 57 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/57/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:58",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/58/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 58 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/58/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:59",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/59/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 59 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/59/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:6",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/6/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 6 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/6/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:60",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/60/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 60 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/60/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:61",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/61/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 61 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/61/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:62",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/62/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 62 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/62/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:63",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/63/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 63 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/63/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:64",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/64/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 64 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/64/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:65",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/65/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 65 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/65/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:66",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/66/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 66 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/66/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:67",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/67/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 67 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/67/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:68",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/68/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 68 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/68/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:69",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/69/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 69 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/69/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:7",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/7/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 7 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/7/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:70",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/70/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 70 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/70/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:71",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/71/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 71 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/71/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:8",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/8/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 8 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/8/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:references:page:9",
      "title": "Articles and Guides — References",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/references/page/9/",
      "published_at": "2026-08-29",
      "updated_at": "2026-09-09",
      "summary": "Page 9 of 71: Search 1682 deduplicated external sources cited across maintained 1200km articles, guides, research, case studies, documentation, and labs.",
      "tags": [
        "author:Andrey Pautov",
        "index",
        "site-governance"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/references/page/9/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:search.html",
      "title": "Search 1200km research",
      "primary_type": "index",
      "primary_domain": "site-governance",
      "audience": [
        "general"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "1200km public content catalogue",
      "canonical_url": "https://1200km.com/search.html",
      "published_at": null,
      "updated_at": "2026-07-20",
      "summary": "Search 1200km research. Search the complete 1200km security research ecosystem: AdversaryGraph, threat actors, ATT&CK techniques, CTI…",
      "tags": [
        "adversarygraph",
        "author:Andrey Pautov",
        "index",
        "mitre-attack",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/search.html",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix",
      "title": "Threat Matrix — AdversaryGraph Light",
      "primary_type": "tool",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst",
        "detection-engineer",
        "threat-hunter"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "AdversaryGraph Light public web workspace; browser-only ATT&CK exploration with full-version module gates",
      "canonical_url": "https://1200km.com/threat-matrix/",
      "published_at": null,
      "updated_at": "2026-07-23",
      "summary": "Threat Matrix — AdversaryGraph Light. Threat Matrix is the public light web version of AdversaryGraph: browser-only…",
      "tags": [
        "adversarygraph",
        "author:Andrey Pautov",
        "threat-intelligence",
        "tool"
      ],
      "featured": true,
      "indexable": true,
      "source_platform": "1200km",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://1200km.com/threat-matrix/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "site:threat-matrix:actors:g0001",
      "title": "Axiom",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0001/",
      "source_url": "https://attack.mitre.org/groups/G0001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Axiom. Axiom actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0001",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0002",
      "title": "Moafee",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0002/",
      "source_url": "https://attack.mitre.org/groups/G0002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Moafee. Moafee actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0002",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0003",
      "title": "Cleaver",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0003/",
      "source_url": "https://attack.mitre.org/groups/G0003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cleaver. Cleaver actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0003",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0004",
      "title": "Ke3chang",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0004/",
      "source_url": "https://attack.mitre.org/groups/G0004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ke3chang. Ke3chang actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0004",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0005",
      "title": "APT12",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0005/",
      "source_url": "https://attack.mitre.org/groups/G0005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT12. APT12 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0005",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0006",
      "title": "APT1",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0006/",
      "source_url": "https://attack.mitre.org/groups/G0006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT1. APT1 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0006",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0007",
      "title": "APT28",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0007/",
      "source_url": "https://attack.mitre.org/groups/G0007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT28. APT28 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0007",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0008",
      "title": "Carbanak",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0008/",
      "source_url": "https://attack.mitre.org/groups/G0008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Carbanak. Carbanak actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0008",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0009",
      "title": "Deep Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0009/",
      "source_url": "https://attack.mitre.org/groups/G0009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Deep Panda. Deep Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0009",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0010",
      "title": "Turla",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0010/",
      "source_url": "https://attack.mitre.org/groups/G0010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Turla. Turla actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0010",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0011",
      "title": "PittyTiger",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0011/",
      "source_url": "https://attack.mitre.org/groups/G0011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PittyTiger. PittyTiger actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0011",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0012",
      "title": "Darkhotel",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0012/",
      "source_url": "https://attack.mitre.org/groups/G0012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Darkhotel. Darkhotel actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0012",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0013",
      "title": "APT30",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0013/",
      "source_url": "https://attack.mitre.org/groups/G0013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT30. APT30 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0013",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0016",
      "title": "APT29",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0016/",
      "source_url": "https://attack.mitre.org/groups/G0016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT29. APT29 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0016",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0017",
      "title": "DragonOK",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0017/",
      "source_url": "https://attack.mitre.org/groups/G0017/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DragonOK. DragonOK actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "ai-security",
        "g0017",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0018",
      "title": "admin@338",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0018/",
      "source_url": "https://attack.mitre.org/groups/G0018/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "admin@338. admin@338 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0018",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0019",
      "title": "Naikon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0019/",
      "source_url": "https://attack.mitre.org/groups/G0019/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Naikon. Naikon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0019",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0019/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0020",
      "title": "Equation",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0020/",
      "source_url": "https://attack.mitre.org/groups/G0020/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Equation. Equation actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0020",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0020/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0021",
      "title": "Molerats",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0021/",
      "source_url": "https://attack.mitre.org/groups/G0021/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Molerats. Molerats actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0021",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0021/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0022",
      "title": "APT3",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0022/",
      "source_url": "https://attack.mitre.org/groups/G0022/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT3. APT3 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0022",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0022/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0023",
      "title": "APT16",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0023/",
      "source_url": "https://attack.mitre.org/groups/G0023/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT16. APT16 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0023",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0023/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0024",
      "title": "Putter Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0024/",
      "source_url": "https://attack.mitre.org/groups/G0024/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Putter Panda. Putter Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0024",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0024/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0025",
      "title": "APT17",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0025/",
      "source_url": "https://attack.mitre.org/groups/G0025/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT17. APT17 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0025",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0025/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0026",
      "title": "APT18",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0026/",
      "source_url": "https://attack.mitre.org/groups/G0026/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT18. APT18 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0026",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0026/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0027",
      "title": "Threat Group-3390",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0027/",
      "source_url": "https://attack.mitre.org/groups/G0027/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Threat Group-3390. Threat Group-3390 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0027",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0027/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0028",
      "title": "Threat Group-1314",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0028/",
      "source_url": "https://attack.mitre.org/groups/G0028/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Threat Group-1314. Threat Group-1314 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0028",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0028/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0029",
      "title": "Scarlet Mimic",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0029/",
      "source_url": "https://attack.mitre.org/groups/G0029/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scarlet Mimic. Scarlet Mimic actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0029",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0029/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0030",
      "title": "Lotus Blossom",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0030/",
      "source_url": "https://attack.mitre.org/groups/G0030/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lotus Blossom. Lotus Blossom actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0030",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0030/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0032",
      "title": "Lazarus Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0032/",
      "source_url": "https://attack.mitre.org/groups/G0032/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lazarus Group. Lazarus Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0032",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0032/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0033",
      "title": "Poseidon Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0033/",
      "source_url": "https://attack.mitre.org/groups/G0033/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Poseidon Group. Poseidon Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0033",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0033/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0034",
      "title": "Sandworm Team",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0034/",
      "source_url": "https://attack.mitre.org/groups/G0034/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sandworm Team. Sandworm Team actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0034",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0034/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0035",
      "title": "Dragonfly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0035/",
      "source_url": "https://attack.mitre.org/groups/G0035/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dragonfly. Dragonfly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "ai-security",
        "g0035",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0035/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0036",
      "title": "GCMAN",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0036/",
      "source_url": "https://attack.mitre.org/groups/G0036/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GCMAN. GCMAN actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0036",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0036/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0037",
      "title": "FIN6",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0037/",
      "source_url": "https://attack.mitre.org/groups/G0037/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN6. FIN6 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0037",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0037/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0038",
      "title": "Stealth Falcon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0038/",
      "source_url": "https://attack.mitre.org/groups/G0038/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Stealth Falcon. Stealth Falcon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0038",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0038/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0039",
      "title": "Suckfly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0039/",
      "source_url": "https://attack.mitre.org/groups/G0039/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Suckfly. Suckfly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0039",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0039/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0040",
      "title": "Patchwork",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0040/",
      "source_url": "https://attack.mitre.org/groups/G0040/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Patchwork. Patchwork actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0040",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0040/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0041",
      "title": "Strider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0041/",
      "source_url": "https://attack.mitre.org/groups/G0041/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Strider. Strider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0041",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0041/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0043",
      "title": "Group5",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0043/",
      "source_url": "https://attack.mitre.org/groups/G0043/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Group5. Group5 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0043",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0043/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0044",
      "title": "Winnti Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0044/",
      "source_url": "https://attack.mitre.org/groups/G0044/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Winnti Group. Winnti Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0044",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0044/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0045",
      "title": "menuPass",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0045/",
      "source_url": "https://attack.mitre.org/groups/G0045/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "menuPass. menuPass actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0045",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0045/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0046",
      "title": "FIN7",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0046/",
      "source_url": "https://attack.mitre.org/groups/G0046/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN7. FIN7 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0046",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0046/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0047",
      "title": "Gamaredon Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0047/",
      "source_url": "https://attack.mitre.org/groups/G0047/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gamaredon Group. Gamaredon Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0047",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0047/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0048",
      "title": "RTM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0048/",
      "source_url": "https://attack.mitre.org/groups/G0048/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "RTM. RTM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0048",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0048/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0049",
      "title": "OilRig",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0049/",
      "source_url": "https://attack.mitre.org/groups/G0049/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "OilRig. OilRig actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0049",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0049/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0050",
      "title": "APT32",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0050/",
      "source_url": "https://attack.mitre.org/groups/G0050/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT32. APT32 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0050",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0050/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0051",
      "title": "FIN10",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0051/",
      "source_url": "https://attack.mitre.org/groups/G0051/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN10. FIN10 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0051",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0051/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0052",
      "title": "CopyKittens",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0052/",
      "source_url": "https://attack.mitre.org/groups/G0052/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "CopyKittens. CopyKittens actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0052",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0052/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0053",
      "title": "FIN5",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0053/",
      "source_url": "https://attack.mitre.org/groups/G0053/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN5. FIN5 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0053",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0053/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0054",
      "title": "Sowbug",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0054/",
      "source_url": "https://attack.mitre.org/groups/G0054/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sowbug. Sowbug actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0054",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0054/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0055",
      "title": "NEODYMIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0055/",
      "source_url": "https://attack.mitre.org/groups/G0055/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "NEODYMIUM. NEODYMIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0055",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0055/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0056",
      "title": "PROMETHIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0056/",
      "source_url": "https://attack.mitre.org/groups/G0056/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PROMETHIUM. PROMETHIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0056",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0056/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0059",
      "title": "Magic Hound",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0059/",
      "source_url": "https://attack.mitre.org/groups/G0059/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Magic Hound. Magic Hound actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0059",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0059/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0060",
      "title": "BRONZE BUTLER",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0060/",
      "source_url": "https://attack.mitre.org/groups/G0060/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BRONZE BUTLER. BRONZE BUTLER actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0060",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0060/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0061",
      "title": "FIN8",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0061/",
      "source_url": "https://attack.mitre.org/groups/G0061/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN8. FIN8 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0061",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0061/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0062",
      "title": "TA459",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0062/",
      "source_url": "https://attack.mitre.org/groups/G0062/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA459. TA459 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0062",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0062/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0063",
      "title": "BlackOasis",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0063/",
      "source_url": "https://attack.mitre.org/groups/G0063/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BlackOasis. BlackOasis actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0063",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0063/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0064",
      "title": "APT33",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0064/",
      "source_url": "https://attack.mitre.org/groups/G0064/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT33. APT33 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0064",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0064/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0065",
      "title": "Leviathan",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0065/",
      "source_url": "https://attack.mitre.org/groups/G0065/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Leviathan. Leviathan actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0065",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0065/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0066",
      "title": "Elderwood",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0066/",
      "source_url": "https://attack.mitre.org/groups/G0066/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Elderwood. Elderwood actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0066",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0066/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0067",
      "title": "APT37",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0067/",
      "source_url": "https://attack.mitre.org/groups/G0067/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT37. APT37 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0067",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0067/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0068",
      "title": "PLATINUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0068/",
      "source_url": "https://attack.mitre.org/groups/G0068/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PLATINUM. PLATINUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0068",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0068/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0069",
      "title": "MuddyWater",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0069/",
      "source_url": "https://attack.mitre.org/groups/G0069/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "MuddyWater. MuddyWater actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0069",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0069/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0070",
      "title": "Dark Caracal",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0070/",
      "source_url": "https://attack.mitre.org/groups/G0070/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dark Caracal. Dark Caracal actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0070",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0070/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0071",
      "title": "Orangeworm",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0071/",
      "source_url": "https://attack.mitre.org/groups/G0071/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Orangeworm. Orangeworm actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0071",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0071/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0073",
      "title": "APT19",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0073/",
      "source_url": "https://attack.mitre.org/groups/G0073/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT19. APT19 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0073",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0073/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0075",
      "title": "Rancor",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0075/",
      "source_url": "https://attack.mitre.org/groups/G0075/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rancor. Rancor actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0075",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0075/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0076",
      "title": "Thrip",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0076/",
      "source_url": "https://attack.mitre.org/groups/G0076/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Thrip. Thrip actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0076",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0076/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0077",
      "title": "Leafminer",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0077/",
      "source_url": "https://attack.mitre.org/groups/G0077/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Leafminer. Leafminer actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0077",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0077/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0078",
      "title": "Gorgon Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0078/",
      "source_url": "https://attack.mitre.org/groups/G0078/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gorgon Group. Gorgon Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0078",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0078/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0079",
      "title": "DarkHydrus",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0079/",
      "source_url": "https://attack.mitre.org/groups/G0079/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DarkHydrus. DarkHydrus actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0079",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0079/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0080",
      "title": "Cobalt Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0080/",
      "source_url": "https://attack.mitre.org/groups/G0080/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cobalt Group. Cobalt Group actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0080",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0080/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0081",
      "title": "Tropic Trooper",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0081/",
      "source_url": "https://attack.mitre.org/groups/G0081/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Tropic Trooper. Tropic Trooper actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0081",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0081/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0082",
      "title": "APT38",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0082/",
      "source_url": "https://attack.mitre.org/groups/G0082/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT38. APT38 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0082",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0082/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0083",
      "title": "SilverTerrier",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0083/",
      "source_url": "https://attack.mitre.org/groups/G0083/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SilverTerrier. SilverTerrier actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0083",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0083/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0084",
      "title": "Gallmaker",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0084/",
      "source_url": "https://attack.mitre.org/groups/G0084/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gallmaker. Gallmaker actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0084",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0084/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0085",
      "title": "FIN4",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0085/",
      "source_url": "https://attack.mitre.org/groups/G0085/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN4. FIN4 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0085",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0085/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0087",
      "title": "APT39",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0087/",
      "source_url": "https://attack.mitre.org/groups/G0087/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT39. APT39 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0087",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0087/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0088",
      "title": "TEMP.Veles",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0088/",
      "source_url": "https://attack.mitre.org/groups/G0088/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TEMP.Veles. TEMP.Veles actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0088",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0088/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0089",
      "title": "The White Company",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0089/",
      "source_url": "https://attack.mitre.org/groups/G0089/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "The White Company. The White Company actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0089",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0089/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0090",
      "title": "WIRTE",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0090/",
      "source_url": "https://attack.mitre.org/groups/G0090/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "WIRTE. WIRTE actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0090",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0090/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0091",
      "title": "Silence",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0091/",
      "source_url": "https://attack.mitre.org/groups/G0091/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Silence. Silence actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0091",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0091/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0092",
      "title": "TA505",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0092/",
      "source_url": "https://attack.mitre.org/groups/G0092/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA505. TA505 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0092",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0092/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0093",
      "title": "GALLIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0093/",
      "source_url": "https://attack.mitre.org/groups/G0093/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GALLIUM. GALLIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0093",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0093/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0094",
      "title": "Kimsuky",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0094/",
      "source_url": "https://attack.mitre.org/groups/G0094/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Kimsuky. Kimsuky actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0094",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0094/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0095",
      "title": "Machete",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0095/",
      "source_url": "https://attack.mitre.org/groups/G0095/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Machete. Machete actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0095",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0095/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0096",
      "title": "APT41",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0096/",
      "source_url": "https://attack.mitre.org/groups/G0096/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT41. APT41 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0096",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0096/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0097",
      "title": "Bouncing Golf",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0097/",
      "source_url": "https://attack.mitre.org/groups/G0097/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bouncing Golf. Bouncing Golf actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0097",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0097/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0098",
      "title": "BlackTech",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0098/",
      "source_url": "https://attack.mitre.org/groups/G0098/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BlackTech. BlackTech actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0098",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0098/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0099",
      "title": "APT-C-36",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0099/",
      "source_url": "https://attack.mitre.org/groups/G0099/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT-C-36. APT-C-36 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0099",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0099/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0100",
      "title": "Inception",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0100/",
      "source_url": "https://attack.mitre.org/groups/G0100/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Inception. Inception actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0100",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0100/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0102",
      "title": "Wizard Spider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0102/",
      "source_url": "https://attack.mitre.org/groups/G0102/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Wizard Spider. Wizard Spider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0102",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0102/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0103",
      "title": "Mofang",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0103/",
      "source_url": "https://attack.mitre.org/groups/G0103/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mofang. Mofang actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0103",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0103/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0105",
      "title": "DarkVishnya",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0105/",
      "source_url": "https://attack.mitre.org/groups/G0105/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DarkVishnya. DarkVishnya actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0105",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0105/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0106",
      "title": "Rocke",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0106/",
      "source_url": "https://attack.mitre.org/groups/G0106/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rocke. Rocke actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0106",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0106/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0107",
      "title": "Whitefly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0107/",
      "source_url": "https://attack.mitre.org/groups/G0107/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Whitefly. Whitefly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0107",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0107/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0108",
      "title": "Blue Mockingbird",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0108/",
      "source_url": "https://attack.mitre.org/groups/G0108/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Blue Mockingbird. Blue Mockingbird actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0108",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0108/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0112",
      "title": "Windshift",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0112/",
      "source_url": "https://attack.mitre.org/groups/G0112/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windshift. Windshift actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0112",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0112/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0114",
      "title": "Chimera",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0114/",
      "source_url": "https://attack.mitre.org/groups/G0114/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Chimera. Chimera actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0114",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0114/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0115",
      "title": "GOLD SOUTHFIELD",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0115/",
      "source_url": "https://attack.mitre.org/groups/G0115/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GOLD SOUTHFIELD. GOLD SOUTHFIELD actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0115",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0115/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0117",
      "title": "Fox Kitten",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0117/",
      "source_url": "https://attack.mitre.org/groups/G0117/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Fox Kitten. Fox Kitten actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0117",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0117/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0119",
      "title": "Indrik Spider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0119/",
      "source_url": "https://attack.mitre.org/groups/G0119/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Indrik Spider. Indrik Spider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0119",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0119/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0120",
      "title": "Evilnum",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0120/",
      "source_url": "https://attack.mitre.org/groups/G0120/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Evilnum. Evilnum actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0120",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0120/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0121",
      "title": "Sidewinder",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0121/",
      "source_url": "https://attack.mitre.org/groups/G0121/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sidewinder. Sidewinder actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0121",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0121/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0122",
      "title": "Silent Librarian",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0122/",
      "source_url": "https://attack.mitre.org/groups/G0122/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Silent Librarian. Silent Librarian actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0122",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0122/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0123",
      "title": "Volatile Cedar",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0123/",
      "source_url": "https://attack.mitre.org/groups/G0123/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Volatile Cedar. Volatile Cedar actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0123",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0123/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0124",
      "title": "Windigo",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0124/",
      "source_url": "https://attack.mitre.org/groups/G0124/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windigo. Windigo actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0124",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0124/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0125",
      "title": "HAFNIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0125/",
      "source_url": "https://attack.mitre.org/groups/G0125/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "HAFNIUM. HAFNIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0125",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0125/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0126",
      "title": "Higaisa",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0126/",
      "source_url": "https://attack.mitre.org/groups/G0126/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Higaisa. Higaisa actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0126",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0126/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0127",
      "title": "TA551",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0127/",
      "source_url": "https://attack.mitre.org/groups/G0127/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA551. TA551 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0127",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0127/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0128",
      "title": "ZIRCONIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0128/",
      "source_url": "https://attack.mitre.org/groups/G0128/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ZIRCONIUM. ZIRCONIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0128",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0128/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0129",
      "title": "Mustang Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0129/",
      "source_url": "https://attack.mitre.org/groups/G0129/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mustang Panda. Mustang Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0129",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0129/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0130",
      "title": "Ajax Security Team",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0130/",
      "source_url": "https://attack.mitre.org/groups/G0130/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ajax Security Team. Ajax Security Team actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting…",
      "tags": [
        "g0130",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0130/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0131",
      "title": "Tonto Team",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0131/",
      "source_url": "https://attack.mitre.org/groups/G0131/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Tonto Team. Tonto Team actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0131",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0131/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0133",
      "title": "Nomadic Octopus",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0133/",
      "source_url": "https://attack.mitre.org/groups/G0133/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Nomadic Octopus. Nomadic Octopus actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0133",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0133/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0134",
      "title": "Transparent Tribe",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0134/",
      "source_url": "https://attack.mitre.org/groups/G0134/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Transparent Tribe. Transparent Tribe actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0134",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0134/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0135",
      "title": "BackdoorDiplomacy",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0135/",
      "source_url": "https://attack.mitre.org/groups/G0135/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BackdoorDiplomacy. BackdoorDiplomacy actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0135",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0135/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0136",
      "title": "IndigoZebra",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0136/",
      "source_url": "https://attack.mitre.org/groups/G0136/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "IndigoZebra. IndigoZebra actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0136",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0136/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0137",
      "title": "Ferocious Kitten",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0137/",
      "source_url": "https://attack.mitre.org/groups/G0137/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ferocious Kitten. Ferocious Kitten actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0137",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0137/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0138",
      "title": "Andariel",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0138/",
      "source_url": "https://attack.mitre.org/groups/G0138/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Andariel. Andariel actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0138",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0138/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0139",
      "title": "TeamTNT",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0139/",
      "source_url": "https://attack.mitre.org/groups/G0139/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TeamTNT. TeamTNT actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0139",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0139/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0140",
      "title": "LazyScripter",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0140/",
      "source_url": "https://attack.mitre.org/groups/G0140/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LazyScripter. LazyScripter actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0140",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0140/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0142",
      "title": "Confucius",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0142/",
      "source_url": "https://attack.mitre.org/groups/G0142/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Confucius. Confucius actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0142",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0142/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g0143",
      "title": "Aquatic Panda",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G0143/",
      "source_url": "https://attack.mitre.org/groups/G0143/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Aquatic Panda. Aquatic Panda actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g0143",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G0143/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1001",
      "title": "HEXANE",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1001/",
      "source_url": "https://attack.mitre.org/groups/G1001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "HEXANE. HEXANE actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1001",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1002",
      "title": "BITTER",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1002/",
      "source_url": "https://attack.mitre.org/groups/G1002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BITTER. BITTER actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1002",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1003",
      "title": "Ember Bear",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1003/",
      "source_url": "https://attack.mitre.org/groups/G1003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ember Bear. Ember Bear actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1003",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1004",
      "title": "LAPSUS$",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1004/",
      "source_url": "https://attack.mitre.org/groups/G1004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LAPSUS$. LAPSUS$ actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1004",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1005",
      "title": "POLONIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1005/",
      "source_url": "https://attack.mitre.org/groups/G1005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "POLONIUM. POLONIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1005",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1006",
      "title": "Earth Lusca",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1006/",
      "source_url": "https://attack.mitre.org/groups/G1006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Earth Lusca. Earth Lusca actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1006",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1007",
      "title": "Aoqin Dragon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1007/",
      "source_url": "https://attack.mitre.org/groups/G1007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Aoqin Dragon. Aoqin Dragon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "ai-security",
        "g1007",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1008",
      "title": "SideCopy",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1008/",
      "source_url": "https://attack.mitre.org/groups/G1008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SideCopy. SideCopy actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1008",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1009",
      "title": "Moses Staff",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1009/",
      "source_url": "https://attack.mitre.org/groups/G1009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Moses Staff. Moses Staff actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1009",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1011",
      "title": "EXOTIC LILY",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1011/",
      "source_url": "https://attack.mitre.org/groups/G1011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "EXOTIC LILY. EXOTIC LILY actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1011",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1012",
      "title": "CURIUM",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1012/",
      "source_url": "https://attack.mitre.org/groups/G1012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "CURIUM. CURIUM actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1012",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1013",
      "title": "Metador",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1013/",
      "source_url": "https://attack.mitre.org/groups/G1013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Metador. Metador actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1013",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1014",
      "title": "LuminousMoth",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1014/",
      "source_url": "https://attack.mitre.org/groups/G1014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LuminousMoth. LuminousMoth actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1014",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1015",
      "title": "Scattered Spider",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1015/",
      "source_url": "https://attack.mitre.org/groups/G1015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scattered Spider. Scattered Spider actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1015",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1016",
      "title": "FIN13",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1016/",
      "source_url": "https://attack.mitre.org/groups/G1016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "FIN13. FIN13 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1016",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1017",
      "title": "Volt Typhoon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1017/",
      "source_url": "https://attack.mitre.org/groups/G1017/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Volt Typhoon. Volt Typhoon actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1017",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1018",
      "title": "TA2541",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1018/",
      "source_url": "https://attack.mitre.org/groups/G1018/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA2541. TA2541 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1018",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1019",
      "title": "MoustachedBouncer",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1019/",
      "source_url": "https://attack.mitre.org/groups/G1019/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "MoustachedBouncer. MoustachedBouncer actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1019",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1019/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1020",
      "title": "Mustard Tempest",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1020/",
      "source_url": "https://attack.mitre.org/groups/G1020/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mustard Tempest. Mustard Tempest actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1020",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1020/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1021",
      "title": "Cinnamon Tempest",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1021/",
      "source_url": "https://attack.mitre.org/groups/G1021/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cinnamon Tempest. Cinnamon Tempest actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1021",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1021/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1022",
      "title": "ToddyCat",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1022/",
      "source_url": "https://attack.mitre.org/groups/G1022/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ToddyCat. ToddyCat actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1022",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1022/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1023",
      "title": "APT5",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1023/",
      "source_url": "https://attack.mitre.org/groups/G1023/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT5. APT5 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1023",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1023/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1024",
      "title": "Akira",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1024/",
      "source_url": "https://attack.mitre.org/groups/G1024/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Akira. Akira actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1024",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1024/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1026",
      "title": "Malteiro",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1026/",
      "source_url": "https://attack.mitre.org/groups/G1026/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malteiro. Malteiro actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1026",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1026/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1028",
      "title": "APT-C-23",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1028/",
      "source_url": "https://attack.mitre.org/groups/G1028/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "APT-C-23. APT-C-23 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1028",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1028/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1030",
      "title": "Agrius",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1030/",
      "source_url": "https://attack.mitre.org/groups/G1030/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Agrius. Agrius actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1030",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1030/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1031",
      "title": "Saint Bear",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1031/",
      "source_url": "https://attack.mitre.org/groups/G1031/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Saint Bear. Saint Bear actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1031",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1031/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1032",
      "title": "INC Ransom",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1032/",
      "source_url": "https://attack.mitre.org/groups/G1032/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "INC Ransom. INC Ransom actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1032",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1032/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1033",
      "title": "Star Blizzard",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1033/",
      "source_url": "https://attack.mitre.org/groups/G1033/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Star Blizzard. Star Blizzard actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1033",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1033/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1034",
      "title": "Daggerfly",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1034/",
      "source_url": "https://attack.mitre.org/groups/G1034/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Daggerfly. Daggerfly actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1034",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1034/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1035",
      "title": "Winter Vivern",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1035/",
      "source_url": "https://attack.mitre.org/groups/G1035/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Winter Vivern. Winter Vivern actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1035",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1035/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1036",
      "title": "Moonstone Sleet",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1036/",
      "source_url": "https://attack.mitre.org/groups/G1036/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Moonstone Sleet. Moonstone Sleet actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1036",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1036/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1037",
      "title": "TA577",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1037/",
      "source_url": "https://attack.mitre.org/groups/G1037/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA577. TA577 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1037",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1037/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1038",
      "title": "TA578",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1038/",
      "source_url": "https://attack.mitre.org/groups/G1038/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TA578. TA578 actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1038",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1038/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1039",
      "title": "RedCurl",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1039/",
      "source_url": "https://attack.mitre.org/groups/G1039/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "RedCurl. RedCurl actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1039",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1039/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1040",
      "title": "Play",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1040/",
      "source_url": "https://attack.mitre.org/groups/G1040/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Play. Play actor profile, aliases, ATT&CK techniques, correlated CTI reports, detection and threat-hunting pivots.",
      "tags": [
        "g1040",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1040/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1041",
      "title": "Sea Turtle",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1041/",
      "source_url": "https://attack.mitre.org/groups/G1041/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Sea Turtle (G1041): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1041",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1041/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1042",
      "title": "RedEcho",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1042/",
      "source_url": "https://attack.mitre.org/groups/G1042/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "RedEcho (G1042): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1042",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1042/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1043",
      "title": "BlackByte",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1043/",
      "source_url": "https://attack.mitre.org/groups/G1043/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "BlackByte (G1043): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1043",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1043/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1044",
      "title": "APT42",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1044/",
      "source_url": "https://attack.mitre.org/groups/G1044/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "APT42 (G1044): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1044",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1044/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1045",
      "title": "Salt Typhoon",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1045/",
      "source_url": "https://attack.mitre.org/groups/G1045/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Salt Typhoon (G1045): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1045",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1045/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1046",
      "title": "Storm-1811",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1046/",
      "source_url": "https://attack.mitre.org/groups/G1046/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Storm-1811 (G1046): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1046",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1046/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1047",
      "title": "Velvet Ant",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1047/",
      "source_url": "https://attack.mitre.org/groups/G1047/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Velvet Ant (G1047): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1047",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1047/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1048",
      "title": "UNC3886",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1048/",
      "source_url": "https://attack.mitre.org/groups/G1048/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "UNC3886 (G1048): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1048",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1048/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1049",
      "title": "AppleJeus",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1049/",
      "source_url": "https://attack.mitre.org/groups/G1049/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "AppleJeus (G1049): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1049",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1049/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1050",
      "title": "Water Galura",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1050/",
      "source_url": "https://attack.mitre.org/groups/G1050/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Water Galura (G1050): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1050",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1050/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1051",
      "title": "Medusa Group",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1051/",
      "source_url": "https://attack.mitre.org/groups/G1051/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Medusa Group (G1051): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1051",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1051/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1052",
      "title": "Contagious Interview",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1052/",
      "source_url": "https://attack.mitre.org/groups/G1052/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Contagious Interview (G1052): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1052",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1052/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1053",
      "title": "Storm-0501",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1053/",
      "source_url": "https://attack.mitre.org/groups/G1053/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "Storm-0501 (G1053): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1053",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1053/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1054",
      "title": "MirrorFace",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1054/",
      "source_url": "https://attack.mitre.org/groups/G1054/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "MirrorFace (G1054): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1054",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1054/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:actors:g1055",
      "title": "VOID MANTICORE",
      "primary_type": "reference-entity",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/actors/G1055/",
      "source_url": "https://attack.mitre.org/groups/G1055/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "VOID MANTICORE (G1055): aliases, ATT&CK techniques, and Cyber Knowledge routes.",
      "tags": [
        "g1055",
        "mitre-attack",
        "reference-entity",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/groups/G1055/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001.001",
      "title": "Junk Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001.001/",
      "source_url": "https://attack.mitre.org/techniques/T1001/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Junk Data. T1001.001 Junk Data: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001.002",
      "title": "Steganography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001.002/",
      "source_url": "https://attack.mitre.org/techniques/T1001/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Steganography. T1001.002 Steganography: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001.003",
      "title": "Protocol or Service Impersonation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001.003/",
      "source_url": "https://attack.mitre.org/techniques/T1001/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Protocol or Service Impersonation. T1001.003 Protocol or Service Impersonation: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1001",
      "title": "Data Obfuscation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1001/",
      "source_url": "https://attack.mitre.org/techniques/T1001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Obfuscation. T1001 Data Obfuscation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.001",
      "title": "LSASS Memory",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.001/",
      "source_url": "https://attack.mitre.org/techniques/T1003/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LSASS Memory. T1003.001 LSASS Memory: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.002",
      "title": "Security Account Manager",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.002/",
      "source_url": "https://attack.mitre.org/techniques/T1003/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Security Account Manager. T1003.002 Security Account Manager: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.003",
      "title": "NTDS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.003/",
      "source_url": "https://attack.mitre.org/techniques/T1003/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "NTDS. T1003.003 NTDS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.004",
      "title": "LSA Secrets",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.004/",
      "source_url": "https://attack.mitre.org/techniques/T1003/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LSA Secrets. T1003.004 LSA Secrets: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.005",
      "title": "Cached Domain Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.005/",
      "source_url": "https://attack.mitre.org/techniques/T1003/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cached Domain Credentials. T1003.005 Cached Domain Credentials: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.006",
      "title": "DCSync",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.006/",
      "source_url": "https://attack.mitre.org/techniques/T1003/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DCSync. T1003.006 DCSync: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.007",
      "title": "Proc Filesystem",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.007/",
      "source_url": "https://attack.mitre.org/techniques/T1003/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Proc Filesystem. T1003.007 Proc Filesystem: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003.008",
      "title": "/etc/passwd and /etc/shadow",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003.008/",
      "source_url": "https://attack.mitre.org/techniques/T1003/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "/etc/passwd and /etc/shadow. T1003.008 /etc/passwd and /etc/shadow: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1003",
      "title": "OS Credential Dumping",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1003/",
      "source_url": "https://attack.mitre.org/techniques/T1003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "OS Credential Dumping. T1003 OS Credential Dumping: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1005",
      "title": "Data from Local System",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1005/",
      "source_url": "https://attack.mitre.org/techniques/T1005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data from Local System. T1005 Data from Local System: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1006",
      "title": "Direct Volume Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1006/",
      "source_url": "https://attack.mitre.org/techniques/T1006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Direct Volume Access. T1006 Direct Volume Access: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1007",
      "title": "System Service Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1007/",
      "source_url": "https://attack.mitre.org/techniques/T1007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Service Discovery. T1007 System Service Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1008",
      "title": "Fallback Channels",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1008/",
      "source_url": "https://attack.mitre.org/techniques/T1008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Fallback Channels. T1008 Fallback Channels: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1010",
      "title": "Application Window Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1010/",
      "source_url": "https://attack.mitre.org/techniques/T1010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Application Window Discovery. T1010 Application Window Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1011.001",
      "title": "Exfiltration Over Bluetooth",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1011.001/",
      "source_url": "https://attack.mitre.org/techniques/T1011/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Bluetooth. T1011.001 Exfiltration Over Bluetooth: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1011.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1011/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1011",
      "title": "Exfiltration Over Other Network Medium",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1011/",
      "source_url": "https://attack.mitre.org/techniques/T1011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Other Network Medium. T1011 Exfiltration Over Other Network Medium: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1012",
      "title": "Query Registry",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1012/",
      "source_url": "https://attack.mitre.org/techniques/T1012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Query Registry. T1012 Query Registry: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1014",
      "title": "Rootkit",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1014/",
      "source_url": "https://attack.mitre.org/techniques/T1014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rootkit. T1014 Rootkit: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1016.001",
      "title": "Internet Connection Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1016.001/",
      "source_url": "https://attack.mitre.org/techniques/T1016/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Internet Connection Discovery. T1016.001 Internet Connection Discovery: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1016.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1016/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1016.002",
      "title": "Wi-Fi Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1016.002/",
      "source_url": "https://attack.mitre.org/techniques/T1016/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Wi-Fi Discovery. T1016.002 Wi-Fi Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1016.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1016/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1016",
      "title": "System Network Configuration Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1016/",
      "source_url": "https://attack.mitre.org/techniques/T1016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Network Configuration Discovery. T1016 System Network Configuration Discovery: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1016",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1018",
      "title": "Remote System Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1018/",
      "source_url": "https://attack.mitre.org/techniques/T1018/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote System Discovery. T1018 Remote System Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1018",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1020.001",
      "title": "Traffic Duplication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1020.001/",
      "source_url": "https://attack.mitre.org/techniques/T1020/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Traffic Duplication. T1020.001 Traffic Duplication: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1020.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1020/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1020",
      "title": "Automated Exfiltration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1020/",
      "source_url": "https://attack.mitre.org/techniques/T1020/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Automated Exfiltration. T1020 Automated Exfiltration: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1020",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1020/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.001",
      "title": "Remote Desktop Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.001/",
      "source_url": "https://attack.mitre.org/techniques/T1021/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote Desktop Protocol. T1021.001 Remote Desktop Protocol: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.002",
      "title": "SMB/Windows Admin Shares",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.002/",
      "source_url": "https://attack.mitre.org/techniques/T1021/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SMB/Windows Admin Shares. T1021.002 SMB/Windows Admin Shares: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.003",
      "title": "Distributed Component Object Model",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.003/",
      "source_url": "https://attack.mitre.org/techniques/T1021/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Distributed Component Object Model. T1021.003 Distributed Component Object Model: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.004",
      "title": "SSH",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.004/",
      "source_url": "https://attack.mitre.org/techniques/T1021/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SSH. T1021.004 SSH: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.005",
      "title": "VNC",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.005/",
      "source_url": "https://attack.mitre.org/techniques/T1021/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "VNC. T1021.005 VNC: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.006",
      "title": "Windows Remote Management",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.006/",
      "source_url": "https://attack.mitre.org/techniques/T1021/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows Remote Management. T1021.006 Windows Remote Management: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.007",
      "title": "Cloud Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.007/",
      "source_url": "https://attack.mitre.org/techniques/T1021/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Services. T1021.007 Cloud Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1021.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021.008",
      "title": "Direct Cloud VM Connections",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021.008/",
      "source_url": "https://attack.mitre.org/techniques/T1021/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Direct Cloud VM Connections. T1021.008 Direct Cloud VM Connections: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1021.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1021",
      "title": "Remote Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1021/",
      "source_url": "https://attack.mitre.org/techniques/T1021/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote Services. T1021 Remote Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1021",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1021/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1025",
      "title": "Data from Removable Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1025/",
      "source_url": "https://attack.mitre.org/techniques/T1025/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data from Removable Media. T1025 Data from Removable Media: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1025",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1025/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.001",
      "title": "Binary Padding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.001/",
      "source_url": "https://attack.mitre.org/techniques/T1027/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Binary Padding. T1027.001 Binary Padding: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.002",
      "title": "Software Packing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.002/",
      "source_url": "https://attack.mitre.org/techniques/T1027/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Software Packing. T1027.002 Software Packing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.003",
      "title": "Steganography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.003/",
      "source_url": "https://attack.mitre.org/techniques/T1027/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Steganography. T1027.003 Steganography: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.004",
      "title": "Compile After Delivery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.004/",
      "source_url": "https://attack.mitre.org/techniques/T1027/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compile After Delivery. T1027.004 Compile After Delivery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.005",
      "title": "Indicator Removal from Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.005/",
      "source_url": "https://attack.mitre.org/techniques/T1027/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Indicator Removal from Tools. T1027.005 Indicator Removal from Tools: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.006",
      "title": "HTML Smuggling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.006/",
      "source_url": "https://attack.mitre.org/techniques/T1027/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "HTML Smuggling. T1027.006 HTML Smuggling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.007",
      "title": "Dynamic API Resolution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.007/",
      "source_url": "https://attack.mitre.org/techniques/T1027/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dynamic API Resolution. T1027.007 Dynamic API Resolution: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.008",
      "title": "Stripped Payloads",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.008/",
      "source_url": "https://attack.mitre.org/techniques/T1027/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Stripped Payloads. T1027.008 Stripped Payloads: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.009",
      "title": "Embedded Payloads",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.009/",
      "source_url": "https://attack.mitre.org/techniques/T1027/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Embedded Payloads. T1027.009 Embedded Payloads: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1027.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.010",
      "title": "Command Obfuscation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.010/",
      "source_url": "https://attack.mitre.org/techniques/T1027/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Command Obfuscation. T1027.010 Command Obfuscation: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.011",
      "title": "Fileless Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.011/",
      "source_url": "https://attack.mitre.org/techniques/T1027/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Fileless Storage. T1027.011 Fileless Storage: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1027.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.012",
      "title": "LNK Icon Smuggling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.012/",
      "source_url": "https://attack.mitre.org/techniques/T1027/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LNK Icon Smuggling. T1027.012 LNK Icon Smuggling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.013",
      "title": "Encrypted/Encoded File",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.013/",
      "source_url": "https://attack.mitre.org/techniques/T1027/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Encrypted/Encoded File. T1027.013 Encrypted/Encoded File: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.014",
      "title": "Polymorphic Code",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.014/",
      "source_url": "https://attack.mitre.org/techniques/T1027/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Polymorphic Code. T1027.014 Polymorphic Code: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.015",
      "title": "Compression",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.015/",
      "source_url": "https://attack.mitre.org/techniques/T1027/015/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.015 Compression: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.016",
      "title": "Junk Code Insertion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.016/",
      "source_url": "https://attack.mitre.org/techniques/T1027/016/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.016 Junk Code Insertion: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.016",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.017",
      "title": "SVG Smuggling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.017/",
      "source_url": "https://attack.mitre.org/techniques/T1027/017/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.017 SVG Smuggling: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.017",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027.018",
      "title": "Invisible Unicode",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027.018/",
      "source_url": "https://attack.mitre.org/techniques/T1027/018/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1027.018 Invisible Unicode: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027.018",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1027",
      "title": "Obfuscated Files or Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1027/",
      "source_url": "https://attack.mitre.org/techniques/T1027/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Obfuscated Files or Information. T1027 Obfuscated Files or Information: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1027",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1027/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1029",
      "title": "Scheduled Transfer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1029/",
      "source_url": "https://attack.mitre.org/techniques/T1029/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scheduled Transfer. T1029 Scheduled Transfer: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1029",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1029/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1030",
      "title": "Data Transfer Size Limits",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1030/",
      "source_url": "https://attack.mitre.org/techniques/T1030/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Transfer Size Limits. T1030 Data Transfer Size Limits: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1030",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1030/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1033",
      "title": "System Owner/User Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1033/",
      "source_url": "https://attack.mitre.org/techniques/T1033/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Owner/User Discovery. T1033 System Owner/User Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1033",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1033/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.001",
      "title": "Invalid Code Signature",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.001/",
      "source_url": "https://attack.mitre.org/techniques/T1036/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Invalid Code Signature. T1036.001 Invalid Code Signature: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.002",
      "title": "Right-to-Left Override",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.002/",
      "source_url": "https://attack.mitre.org/techniques/T1036/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Right-to-Left Override. T1036.002 Right-to-Left Override: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.003",
      "title": "Rename System Utilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.003/",
      "source_url": "https://attack.mitre.org/techniques/T1036/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rename System Utilities. T1036.003 Rename System Utilities: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.004",
      "title": "Masquerade Task or Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.004/",
      "source_url": "https://attack.mitre.org/techniques/T1036/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Masquerade Task or Service. T1036.004 Masquerade Task or Service: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.005",
      "title": "Match Legitimate Name or Location",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.005/",
      "source_url": "https://attack.mitre.org/techniques/T1036/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Match Legitimate Name or Location. T1036.005 Match Legitimate Name or Location: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.006",
      "title": "Space after Filename",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.006/",
      "source_url": "https://attack.mitre.org/techniques/T1036/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Space after Filename. T1036.006 Space after Filename: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.007",
      "title": "Double File Extension",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.007/",
      "source_url": "https://attack.mitre.org/techniques/T1036/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Double File Extension. T1036.007 Double File Extension: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.008",
      "title": "Masquerade File Type",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.008/",
      "source_url": "https://attack.mitre.org/techniques/T1036/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Masquerade File Type. T1036.008 Masquerade File Type: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.009",
      "title": "Break Process Trees",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.009/",
      "source_url": "https://attack.mitre.org/techniques/T1036/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Break Process Trees. T1036.009 Break Process Trees: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.010",
      "title": "Masquerade Account Name",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.010/",
      "source_url": "https://attack.mitre.org/techniques/T1036/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Masquerade Account Name. T1036.010 Masquerade Account Name: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.011",
      "title": "Overwrite Process Arguments",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.011/",
      "source_url": "https://attack.mitre.org/techniques/T1036/011/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1036.011 Overwrite Process Arguments: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036.012",
      "title": "Browser Fingerprint",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036.012/",
      "source_url": "https://attack.mitre.org/techniques/T1036/012/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1036.012 Browser Fingerprint: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1036",
      "title": "Masquerading",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1036/",
      "source_url": "https://attack.mitre.org/techniques/T1036/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Masquerading. T1036 Masquerading: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1036",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1036/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.001",
      "title": "Logon Script (Windows)",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.001/",
      "source_url": "https://attack.mitre.org/techniques/T1037/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Logon Script (Windows). T1037.001 Logon Script (Windows): description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.002",
      "title": "Login Hook",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.002/",
      "source_url": "https://attack.mitre.org/techniques/T1037/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Login Hook. T1037.002 Login Hook: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.003",
      "title": "Network Logon Script",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.003/",
      "source_url": "https://attack.mitre.org/techniques/T1037/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Logon Script. T1037.003 Network Logon Script: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.004",
      "title": "RC Scripts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.004/",
      "source_url": "https://attack.mitre.org/techniques/T1037/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "RC Scripts. T1037.004 RC Scripts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037.005",
      "title": "Startup Items",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037.005/",
      "source_url": "https://attack.mitre.org/techniques/T1037/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Startup Items. T1037.005 Startup Items: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1037",
      "title": "Boot or Logon Initialization Scripts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1037/",
      "source_url": "https://attack.mitre.org/techniques/T1037/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Boot or Logon Initialization Scripts. T1037 Boot or Logon Initialization Scripts: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1037",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1037/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1039",
      "title": "Data from Network Shared Drive",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1039/",
      "source_url": "https://attack.mitre.org/techniques/T1039/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data from Network Shared Drive. T1039 Data from Network Shared Drive: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1039",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1039/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1040",
      "title": "Network Sniffing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1040/",
      "source_url": "https://attack.mitre.org/techniques/T1040/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Sniffing. T1040 Network Sniffing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1040",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1040/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1041",
      "title": "Exfiltration Over C2 Channel",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1041/",
      "source_url": "https://attack.mitre.org/techniques/T1041/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over C2 Channel. T1041 Exfiltration Over C2 Channel: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1041",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1041/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1046",
      "title": "Network Service Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1046/",
      "source_url": "https://attack.mitre.org/techniques/T1046/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Service Discovery. T1046 Network Service Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1046",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1046/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1047",
      "title": "Windows Management Instrumentation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1047/",
      "source_url": "https://attack.mitre.org/techniques/T1047/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows Management Instrumentation. T1047 Windows Management Instrumentation: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1047",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1047/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048.001",
      "title": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048.001/",
      "source_url": "https://attack.mitre.org/techniques/T1048/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol. T1048.001 Exfiltration Over Symmetric Encrypted…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048.002",
      "title": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048.002/",
      "source_url": "https://attack.mitre.org/techniques/T1048/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol. T1048.002 Exfiltration Over Asymmetric…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048.003",
      "title": "Exfiltration Over Unencrypted Non-C2 Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048.003/",
      "source_url": "https://attack.mitre.org/techniques/T1048/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Unencrypted Non-C2 Protocol. T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1048",
      "title": "Exfiltration Over Alternative Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1048/",
      "source_url": "https://attack.mitre.org/techniques/T1048/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Alternative Protocol. T1048 Exfiltration Over Alternative Protocol: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1048",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1048/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1049",
      "title": "System Network Connections Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1049/",
      "source_url": "https://attack.mitre.org/techniques/T1049/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Network Connections Discovery. T1049 System Network Connections Discovery: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1049",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1049/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1052.001",
      "title": "Exfiltration over USB",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1052.001/",
      "source_url": "https://attack.mitre.org/techniques/T1052/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration over USB. T1052.001 Exfiltration over USB: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1052.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1052/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1052",
      "title": "Exfiltration Over Physical Medium",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1052/",
      "source_url": "https://attack.mitre.org/techniques/T1052/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Physical Medium. T1052 Exfiltration Over Physical Medium: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1052",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1052/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.002",
      "title": "At",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.002/",
      "source_url": "https://attack.mitre.org/techniques/T1053/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "At. T1053.002 At: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.003",
      "title": "Cron",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.003/",
      "source_url": "https://attack.mitre.org/techniques/T1053/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cron. T1053.003 Cron: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.005",
      "title": "Scheduled Task",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.005/",
      "source_url": "https://attack.mitre.org/techniques/T1053/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scheduled Task. T1053.005 Scheduled Task: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.006",
      "title": "Systemd Timers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.006/",
      "source_url": "https://attack.mitre.org/techniques/T1053/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Systemd Timers. T1053.006 Systemd Timers: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053.007",
      "title": "Container Orchestration Job",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053.007/",
      "source_url": "https://attack.mitre.org/techniques/T1053/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Container Orchestration Job. T1053.007 Container Orchestration Job: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1053.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1053",
      "title": "Scheduled Task/Job",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1053/",
      "source_url": "https://attack.mitre.org/techniques/T1053/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scheduled Task/Job. T1053 Scheduled Task/Job: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1053",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1053/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.001",
      "title": "Dynamic-link Library Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.001/",
      "source_url": "https://attack.mitre.org/techniques/T1055/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dynamic-link Library Injection. T1055.001 Dynamic-link Library Injection: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.002",
      "title": "Portable Executable Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.002/",
      "source_url": "https://attack.mitre.org/techniques/T1055/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Portable Executable Injection. T1055.002 Portable Executable Injection: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.003",
      "title": "Thread Execution Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.003/",
      "source_url": "https://attack.mitre.org/techniques/T1055/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Thread Execution Hijacking. T1055.003 Thread Execution Hijacking: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.004",
      "title": "Asynchronous Procedure Call",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.004/",
      "source_url": "https://attack.mitre.org/techniques/T1055/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Asynchronous Procedure Call. T1055.004 Asynchronous Procedure Call: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.005",
      "title": "Thread Local Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.005/",
      "source_url": "https://attack.mitre.org/techniques/T1055/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Thread Local Storage. T1055.005 Thread Local Storage: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1055.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.008",
      "title": "Ptrace System Calls",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.008/",
      "source_url": "https://attack.mitre.org/techniques/T1055/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ptrace System Calls. T1055.008 Ptrace System Calls: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.009",
      "title": "Proc Memory",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.009/",
      "source_url": "https://attack.mitre.org/techniques/T1055/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Proc Memory. T1055.009 Proc Memory: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.011",
      "title": "Extra Window Memory Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.011/",
      "source_url": "https://attack.mitre.org/techniques/T1055/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Extra Window Memory Injection. T1055.011 Extra Window Memory Injection: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.012",
      "title": "Process Hollowing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.012/",
      "source_url": "https://attack.mitre.org/techniques/T1055/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Process Hollowing. T1055.012 Process Hollowing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "malware-behavior",
        "mitre-attack",
        "t1055.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.013",
      "title": "Process Doppelgänging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.013/",
      "source_url": "https://attack.mitre.org/techniques/T1055/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Process Doppelgänging. T1055.013 Process Doppelgänging: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.014",
      "title": "VDSO Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.014/",
      "source_url": "https://attack.mitre.org/techniques/T1055/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "VDSO Hijacking. T1055.014 VDSO Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055.015",
      "title": "ListPlanting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055.015/",
      "source_url": "https://attack.mitre.org/techniques/T1055/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ListPlanting. T1055.015 ListPlanting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1055",
      "title": "Process Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1055/",
      "source_url": "https://attack.mitre.org/techniques/T1055/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Process Injection. T1055 Process Injection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1055",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1055/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.001",
      "title": "Keylogging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.001/",
      "source_url": "https://attack.mitre.org/techniques/T1056/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Keylogging. T1056.001 Keylogging: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "malware-behavior",
        "mitre-attack",
        "t1056.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.002",
      "title": "GUI Input Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.002/",
      "source_url": "https://attack.mitre.org/techniques/T1056/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "GUI Input Capture. T1056.002 GUI Input Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.003",
      "title": "Web Portal Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.003/",
      "source_url": "https://attack.mitre.org/techniques/T1056/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Portal Capture. T1056.003 Web Portal Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056.004",
      "title": "Credential API Hooking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056.004/",
      "source_url": "https://attack.mitre.org/techniques/T1056/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credential API Hooking. T1056.004 Credential API Hooking: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1056",
      "title": "Input Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1056/",
      "source_url": "https://attack.mitre.org/techniques/T1056/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Input Capture. T1056 Input Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1056",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1056/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1057",
      "title": "Process Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1057/",
      "source_url": "https://attack.mitre.org/techniques/T1057/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Process Discovery. T1057 Process Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1057",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1057/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.001",
      "title": "PowerShell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.001/",
      "source_url": "https://attack.mitre.org/techniques/T1059/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PowerShell. T1059.001 PowerShell: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.002",
      "title": "AppleScript",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.002/",
      "source_url": "https://attack.mitre.org/techniques/T1059/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "AppleScript. T1059.002 AppleScript: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.003",
      "title": "Windows Command Shell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.003/",
      "source_url": "https://attack.mitre.org/techniques/T1059/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows Command Shell. T1059.003 Windows Command Shell: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.004",
      "title": "Unix Shell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.004/",
      "source_url": "https://attack.mitre.org/techniques/T1059/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Unix Shell. T1059.004 Unix Shell: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.005",
      "title": "Visual Basic",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.005/",
      "source_url": "https://attack.mitre.org/techniques/T1059/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Visual Basic. T1059.005 Visual Basic: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.006",
      "title": "Python",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.006/",
      "source_url": "https://attack.mitre.org/techniques/T1059/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Python. T1059.006 Python: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.007",
      "title": "JavaScript",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.007/",
      "source_url": "https://attack.mitre.org/techniques/T1059/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "JavaScript. T1059.007 JavaScript: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.008",
      "title": "Network Device CLI",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.008/",
      "source_url": "https://attack.mitre.org/techniques/T1059/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Device CLI. T1059.008 Network Device CLI: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.009",
      "title": "Cloud API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.009/",
      "source_url": "https://attack.mitre.org/techniques/T1059/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud API. T1059.009 Cloud API: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1059.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.010",
      "title": "AutoHotKey & AutoIT",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.010/",
      "source_url": "https://attack.mitre.org/techniques/T1059/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "AutoHotKey & AutoIT. T1059.010 AutoHotKey & AutoIT: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.011",
      "title": "Lua",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.011/",
      "source_url": "https://attack.mitre.org/techniques/T1059/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lua. T1059.011 Lua: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.012",
      "title": "Hypervisor CLI",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.012/",
      "source_url": "https://attack.mitre.org/techniques/T1059/012/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1059.012 Hypervisor CLI: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059.013",
      "title": "Container CLI/API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059.013/",
      "source_url": "https://attack.mitre.org/techniques/T1059/013/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1059.013 Container CLI/API: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1059.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1059",
      "title": "Command and Scripting Interpreter",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1059/",
      "source_url": "https://attack.mitre.org/techniques/T1059/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Command and Scripting Interpreter. T1059 Command and Scripting Interpreter: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1059",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1059/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1068",
      "title": "Exploitation for Privilege Escalation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1068/",
      "source_url": "https://attack.mitre.org/techniques/T1068/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploitation for Privilege Escalation. T1068 Exploitation for Privilege Escalation: description, detection logic…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "mitre-attack",
        "offensive-security",
        "t1068",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1068/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069.001",
      "title": "Local Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069.001/",
      "source_url": "https://attack.mitre.org/techniques/T1069/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Local Groups. T1069.001 Local Groups: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1069.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069.002",
      "title": "Domain Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069.002/",
      "source_url": "https://attack.mitre.org/techniques/T1069/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Groups. T1069.002 Domain Groups: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1069.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069.003",
      "title": "Cloud Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069.003/",
      "source_url": "https://attack.mitre.org/techniques/T1069/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Groups. T1069.003 Cloud Groups: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1069.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1069",
      "title": "Permission Groups Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1069/",
      "source_url": "https://attack.mitre.org/techniques/T1069/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Permission Groups Discovery. T1069 Permission Groups Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1069",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1069/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.001",
      "title": "Clear Windows Event Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.001/",
      "source_url": "https://attack.mitre.org/techniques/T1070/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clear Windows Event Logs. T1070.001 Clear Windows Event Logs: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.002",
      "title": "Clear Linux or Mac System Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.002/",
      "source_url": "https://attack.mitre.org/techniques/T1070/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clear Linux or Mac System Logs. T1070.002 Clear Linux or Mac System Logs: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.003",
      "title": "Clear Command History",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.003/",
      "source_url": "https://attack.mitre.org/techniques/T1070/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clear Command History. T1070.003 Clear Command History: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.004",
      "title": "File Deletion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.004/",
      "source_url": "https://attack.mitre.org/techniques/T1070/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "File Deletion. T1070.004 File Deletion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.005",
      "title": "Network Share Connection Removal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.005/",
      "source_url": "https://attack.mitre.org/techniques/T1070/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Share Connection Removal. T1070.005 Network Share Connection Removal: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.006",
      "title": "Timestomp",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.006/",
      "source_url": "https://attack.mitre.org/techniques/T1070/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Timestomp. T1070.006 Timestomp: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.007",
      "title": "Clear Network Connection History and Configurations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.007/",
      "source_url": "https://attack.mitre.org/techniques/T1070/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clear Network Connection History and Configurations. T1070.007 Clear Network Connection History and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.008",
      "title": "Clear Mailbox Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.008/",
      "source_url": "https://attack.mitre.org/techniques/T1070/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clear Mailbox Data. T1070.008 Clear Mailbox Data: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.009",
      "title": "Clear Persistence",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.009/",
      "source_url": "https://attack.mitre.org/techniques/T1070/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clear Persistence. T1070.009 Clear Persistence: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070.010",
      "title": "Relocate Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070.010/",
      "source_url": "https://attack.mitre.org/techniques/T1070/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Relocate Malware. T1070.010 Relocate Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "t1070.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1070",
      "title": "Indicator Removal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1070/",
      "source_url": "https://attack.mitre.org/techniques/T1070/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Indicator Removal. T1070 Indicator Removal: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1070",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1070/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.001",
      "title": "Web Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.001/",
      "source_url": "https://attack.mitre.org/techniques/T1071/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Protocols. T1071.001 Web Protocols: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.002",
      "title": "File Transfer Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.002/",
      "source_url": "https://attack.mitre.org/techniques/T1071/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "File Transfer Protocols. T1071.002 File Transfer Protocols: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.003",
      "title": "Mail Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.003/",
      "source_url": "https://attack.mitre.org/techniques/T1071/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mail Protocols. T1071.003 Mail Protocols: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.004",
      "title": "DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.004/",
      "source_url": "https://attack.mitre.org/techniques/T1071/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DNS. T1071.004 DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071.005",
      "title": "Publish/Subscribe Protocols",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071.005/",
      "source_url": "https://attack.mitre.org/techniques/T1071/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Publish/Subscribe Protocols. T1071.005 Publish/Subscribe Protocols: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1071",
      "title": "Application Layer Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1071/",
      "source_url": "https://attack.mitre.org/techniques/T1071/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Application Layer Protocol. T1071 Application Layer Protocol: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1071",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1071/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1072",
      "title": "Software Deployment Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1072/",
      "source_url": "https://attack.mitre.org/techniques/T1072/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Software Deployment Tools. T1072 Software Deployment Tools: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1072",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1072/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1074.001",
      "title": "Local Data Staging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1074.001/",
      "source_url": "https://attack.mitre.org/techniques/T1074/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Local Data Staging. T1074.001 Local Data Staging: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1074.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1074/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1074.002",
      "title": "Remote Data Staging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1074.002/",
      "source_url": "https://attack.mitre.org/techniques/T1074/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote Data Staging. T1074.002 Remote Data Staging: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1074.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1074/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1074",
      "title": "Data Staged",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1074/",
      "source_url": "https://attack.mitre.org/techniques/T1074/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Staged. T1074 Data Staged: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1074",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1074/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.001",
      "title": "Default Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.001/",
      "source_url": "https://attack.mitre.org/techniques/T1078/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Default Accounts. T1078.001 Default Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.002",
      "title": "Domain Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.002/",
      "source_url": "https://attack.mitre.org/techniques/T1078/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Accounts. T1078.002 Domain Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.003",
      "title": "Local Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.003/",
      "source_url": "https://attack.mitre.org/techniques/T1078/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Local Accounts. T1078.003 Local Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078.004",
      "title": "Cloud Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078.004/",
      "source_url": "https://attack.mitre.org/techniques/T1078/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Accounts. T1078.004 Cloud Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1078.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1078",
      "title": "Valid Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1078/",
      "source_url": "https://attack.mitre.org/techniques/T1078/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Valid Accounts. T1078 Valid Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1078",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1078/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1080",
      "title": "Taint Shared Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1080/",
      "source_url": "https://attack.mitre.org/techniques/T1080/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Taint Shared Content. T1080 Taint Shared Content: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1080",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1080/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1082",
      "title": "System Information Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1082/",
      "source_url": "https://attack.mitre.org/techniques/T1082/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Information Discovery. T1082 System Information Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1082",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1082/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1083",
      "title": "File and Directory Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1083/",
      "source_url": "https://attack.mitre.org/techniques/T1083/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "File and Directory Discovery. T1083 File and Directory Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1083",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1083/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.001",
      "title": "Local Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.001/",
      "source_url": "https://attack.mitre.org/techniques/T1087/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Local Account. T1087.001 Local Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.002",
      "title": "Domain Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.002/",
      "source_url": "https://attack.mitre.org/techniques/T1087/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Account. T1087.002 Domain Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.003",
      "title": "Email Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.003/",
      "source_url": "https://attack.mitre.org/techniques/T1087/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Account. T1087.003 Email Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087.004",
      "title": "Cloud Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087.004/",
      "source_url": "https://attack.mitre.org/techniques/T1087/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Account. T1087.004 Cloud Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1087.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1087",
      "title": "Account Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1087/",
      "source_url": "https://attack.mitre.org/techniques/T1087/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Account Discovery. T1087 Account Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1087",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1087/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.001",
      "title": "Internal Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.001/",
      "source_url": "https://attack.mitre.org/techniques/T1090/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Internal Proxy. T1090.001 Internal Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.002",
      "title": "External Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.002/",
      "source_url": "https://attack.mitre.org/techniques/T1090/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "External Proxy. T1090.002 External Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.003",
      "title": "Multi-hop Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.003/",
      "source_url": "https://attack.mitre.org/techniques/T1090/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Multi-hop Proxy. T1090.003 Multi-hop Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090.004",
      "title": "Domain Fronting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090.004/",
      "source_url": "https://attack.mitre.org/techniques/T1090/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Fronting. T1090.004 Domain Fronting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1090",
      "title": "Proxy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1090/",
      "source_url": "https://attack.mitre.org/techniques/T1090/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Proxy. T1090 Proxy: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1090",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1090/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1091",
      "title": "Replication Through Removable Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1091/",
      "source_url": "https://attack.mitre.org/techniques/T1091/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Replication Through Removable Media. T1091 Replication Through Removable Media: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1091",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1091/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1092",
      "title": "Communication Through Removable Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1092/",
      "source_url": "https://attack.mitre.org/techniques/T1092/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Communication Through Removable Media. T1092 Communication Through Removable Media: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1092",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1092/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1095",
      "title": "Non-Application Layer Protocol",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1095/",
      "source_url": "https://attack.mitre.org/techniques/T1095/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Non-Application Layer Protocol. T1095 Non-Application Layer Protocol: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1095",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1095/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.001",
      "title": "Additional Cloud Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.001/",
      "source_url": "https://attack.mitre.org/techniques/T1098/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Additional Cloud Credentials. T1098.001 Additional Cloud Credentials: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1098.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.002",
      "title": "Additional Email Delegate Permissions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.002/",
      "source_url": "https://attack.mitre.org/techniques/T1098/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Additional Email Delegate Permissions. T1098.002 Additional Email Delegate Permissions: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.003",
      "title": "Additional Cloud Roles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.003/",
      "source_url": "https://attack.mitre.org/techniques/T1098/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Additional Cloud Roles. T1098.003 Additional Cloud Roles: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1098.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.004",
      "title": "SSH Authorized Keys",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.004/",
      "source_url": "https://attack.mitre.org/techniques/T1098/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SSH Authorized Keys. T1098.004 SSH Authorized Keys: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.005",
      "title": "Device Registration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.005/",
      "source_url": "https://attack.mitre.org/techniques/T1098/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Device Registration. T1098.005 Device Registration: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.006",
      "title": "Additional Container Cluster Roles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.006/",
      "source_url": "https://attack.mitre.org/techniques/T1098/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Additional Container Cluster Roles. T1098.006 Additional Container Cluster Roles: description, detection logic, threat…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1098.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098.007",
      "title": "Additional Local or Domain Groups",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098.007/",
      "source_url": "https://attack.mitre.org/techniques/T1098/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Additional Local or Domain Groups. T1098.007 Additional Local or Domain Groups: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1098",
      "title": "Account Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1098/",
      "source_url": "https://attack.mitre.org/techniques/T1098/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Account Manipulation. T1098 Account Manipulation: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1098",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1098/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102.001",
      "title": "Dead Drop Resolver",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102.001/",
      "source_url": "https://attack.mitre.org/techniques/T1102/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dead Drop Resolver. T1102.001 Dead Drop Resolver: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102.002",
      "title": "Bidirectional Communication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102.002/",
      "source_url": "https://attack.mitre.org/techniques/T1102/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bidirectional Communication. T1102.002 Bidirectional Communication: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102.003",
      "title": "One-Way Communication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102.003/",
      "source_url": "https://attack.mitre.org/techniques/T1102/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "One-Way Communication. T1102.003 One-Way Communication: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1102",
      "title": "Web Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1102/",
      "source_url": "https://attack.mitre.org/techniques/T1102/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Service. T1102 Web Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1102",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1102/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1104",
      "title": "Multi-Stage Channels",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1104/",
      "source_url": "https://attack.mitre.org/techniques/T1104/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Multi-Stage Channels. T1104 Multi-Stage Channels: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1104",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1104/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1105",
      "title": "Ingress Tool Transfer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1105/",
      "source_url": "https://attack.mitre.org/techniques/T1105/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ingress Tool Transfer. T1105 Ingress Tool Transfer: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1105",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1105/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1106",
      "title": "Native API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1106/",
      "source_url": "https://attack.mitre.org/techniques/T1106/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Native API. T1106 Native API: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1106",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1106/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.001",
      "title": "Password Guessing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.001/",
      "source_url": "https://attack.mitre.org/techniques/T1110/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Password Guessing. T1110.001 Password Guessing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.002",
      "title": "Password Cracking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.002/",
      "source_url": "https://attack.mitre.org/techniques/T1110/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Password Cracking. T1110.002 Password Cracking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.003",
      "title": "Password Spraying",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.003/",
      "source_url": "https://attack.mitre.org/techniques/T1110/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Password Spraying. T1110.003 Password Spraying: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110.004",
      "title": "Credential Stuffing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110.004/",
      "source_url": "https://attack.mitre.org/techniques/T1110/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credential Stuffing. T1110.004 Credential Stuffing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1110",
      "title": "Brute Force",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1110/",
      "source_url": "https://attack.mitre.org/techniques/T1110/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Brute Force. T1110 Brute Force: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1110",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1110/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1111",
      "title": "Multi-Factor Authentication Interception",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1111/",
      "source_url": "https://attack.mitre.org/techniques/T1111/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Multi-Factor Authentication Interception. T1111 Multi-Factor Authentication Interception: description, detection…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1111",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1111/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1112",
      "title": "Modify Registry",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1112/",
      "source_url": "https://attack.mitre.org/techniques/T1112/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Modify Registry. T1112 Modify Registry: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1112",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1112/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1113",
      "title": "Screen Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1113/",
      "source_url": "https://attack.mitre.org/techniques/T1113/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Screen Capture. T1113 Screen Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1113",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1113/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114.001",
      "title": "Local Email Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114.001/",
      "source_url": "https://attack.mitre.org/techniques/T1114/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Local Email Collection. T1114.001 Local Email Collection: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114.002",
      "title": "Remote Email Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114.002/",
      "source_url": "https://attack.mitre.org/techniques/T1114/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote Email Collection. T1114.002 Remote Email Collection: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114.003",
      "title": "Email Forwarding Rule",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114.003/",
      "source_url": "https://attack.mitre.org/techniques/T1114/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Forwarding Rule. T1114.003 Email Forwarding Rule: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1114",
      "title": "Email Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1114/",
      "source_url": "https://attack.mitre.org/techniques/T1114/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Collection. T1114 Email Collection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1114",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1114/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1115",
      "title": "Clipboard Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1115/",
      "source_url": "https://attack.mitre.org/techniques/T1115/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Clipboard Data. T1115 Clipboard Data: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1115",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1115/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1119",
      "title": "Automated Collection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1119/",
      "source_url": "https://attack.mitre.org/techniques/T1119/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Automated Collection. T1119 Automated Collection: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1119",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1119/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1120",
      "title": "Peripheral Device Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1120/",
      "source_url": "https://attack.mitre.org/techniques/T1120/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Peripheral Device Discovery. T1120 Peripheral Device Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1120",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1120/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1123",
      "title": "Audio Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1123/",
      "source_url": "https://attack.mitre.org/techniques/T1123/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Audio Capture. T1123 Audio Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1123",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1123/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1124",
      "title": "System Time Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1124/",
      "source_url": "https://attack.mitre.org/techniques/T1124/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Time Discovery. T1124 System Time Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1124",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1124/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1125",
      "title": "Video Capture",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1125/",
      "source_url": "https://attack.mitre.org/techniques/T1125/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Video Capture. T1125 Video Capture: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1125",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1125/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127.001",
      "title": "MSBuild",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127.001/",
      "source_url": "https://attack.mitre.org/techniques/T1127/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "MSBuild. T1127.001 MSBuild: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127.002",
      "title": "ClickOnce",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127.002/",
      "source_url": "https://attack.mitre.org/techniques/T1127/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ClickOnce. T1127.002 ClickOnce: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127.003",
      "title": "JamPlus",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127.003/",
      "source_url": "https://attack.mitre.org/techniques/T1127/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1127.003 JamPlus: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1127",
      "title": "Trusted Developer Utilities Proxy Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1127/",
      "source_url": "https://attack.mitre.org/techniques/T1127/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Trusted Developer Utilities Proxy Execution. T1127 Trusted Developer Utilities Proxy Execution: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1127",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1127/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1129",
      "title": "Shared Modules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1129/",
      "source_url": "https://attack.mitre.org/techniques/T1129/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Shared Modules. T1129 Shared Modules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1129",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1129/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1132.001",
      "title": "Standard Encoding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1132.001/",
      "source_url": "https://attack.mitre.org/techniques/T1132/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Standard Encoding. T1132.001 Standard Encoding: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1132.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1132/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1132.002",
      "title": "Non-Standard Encoding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1132.002/",
      "source_url": "https://attack.mitre.org/techniques/T1132/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Non-Standard Encoding. T1132.002 Non-Standard Encoding: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1132.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1132/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1132",
      "title": "Data Encoding",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1132/",
      "source_url": "https://attack.mitre.org/techniques/T1132/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Encoding. T1132 Data Encoding: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1132",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1132/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1133",
      "title": "External Remote Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1133/",
      "source_url": "https://attack.mitre.org/techniques/T1133/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "External Remote Services. T1133 External Remote Services: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1133",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1133/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.001",
      "title": "Token Impersonation/Theft",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.001/",
      "source_url": "https://attack.mitre.org/techniques/T1134/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Token Impersonation/Theft. T1134.001 Token Impersonation/Theft: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.002",
      "title": "Create Process with Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.002/",
      "source_url": "https://attack.mitre.org/techniques/T1134/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Create Process with Token. T1134.002 Create Process with Token: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.003",
      "title": "Make and Impersonate Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.003/",
      "source_url": "https://attack.mitre.org/techniques/T1134/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Make and Impersonate Token. T1134.003 Make and Impersonate Token: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.004",
      "title": "Parent PID Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.004/",
      "source_url": "https://attack.mitre.org/techniques/T1134/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Parent PID Spoofing. T1134.004 Parent PID Spoofing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134.005",
      "title": "SID-History Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134.005/",
      "source_url": "https://attack.mitre.org/techniques/T1134/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SID-History Injection. T1134.005 SID-History Injection: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1134.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1134",
      "title": "Access Token Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1134/",
      "source_url": "https://attack.mitre.org/techniques/T1134/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Access Token Manipulation. T1134 Access Token Manipulation: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "mitre-attack",
        "t1134",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1134/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1135",
      "title": "Network Share Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1135/",
      "source_url": "https://attack.mitre.org/techniques/T1135/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Share Discovery. T1135 Network Share Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1135",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1135/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136.001",
      "title": "Local Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136.001/",
      "source_url": "https://attack.mitre.org/techniques/T1136/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Local Account. T1136.001 Local Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1136.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136.002",
      "title": "Domain Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136.002/",
      "source_url": "https://attack.mitre.org/techniques/T1136/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Account. T1136.002 Domain Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1136.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136.003",
      "title": "Cloud Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136.003/",
      "source_url": "https://attack.mitre.org/techniques/T1136/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Account. T1136.003 Cloud Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1136.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1136",
      "title": "Create Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1136/",
      "source_url": "https://attack.mitre.org/techniques/T1136/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Create Account. T1136 Create Account: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1136",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1136/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.001",
      "title": "Office Template Macros",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.001/",
      "source_url": "https://attack.mitre.org/techniques/T1137/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Office Template Macros. T1137.001 Office Template Macros: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.002",
      "title": "Office Test",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.002/",
      "source_url": "https://attack.mitre.org/techniques/T1137/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Office Test. T1137.002 Office Test: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.003",
      "title": "Outlook Forms",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.003/",
      "source_url": "https://attack.mitre.org/techniques/T1137/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Outlook Forms. T1137.003 Outlook Forms: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.004",
      "title": "Outlook Home Page",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.004/",
      "source_url": "https://attack.mitre.org/techniques/T1137/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Outlook Home Page. T1137.004 Outlook Home Page: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.005",
      "title": "Outlook Rules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.005/",
      "source_url": "https://attack.mitre.org/techniques/T1137/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Outlook Rules. T1137.005 Outlook Rules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137.006",
      "title": "Add-ins",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137.006/",
      "source_url": "https://attack.mitre.org/techniques/T1137/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Add-ins. T1137.006 Add-ins: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1137",
      "title": "Office Application Startup",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1137/",
      "source_url": "https://attack.mitre.org/techniques/T1137/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Office Application Startup. T1137 Office Application Startup: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1137",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1137/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1140",
      "title": "Deobfuscate/Decode Files or Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1140/",
      "source_url": "https://attack.mitre.org/techniques/T1140/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Deobfuscate/Decode Files or Information. T1140 Deobfuscate/Decode Files or Information: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1140",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1140/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1176.001",
      "title": "Browser Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1176.001/",
      "source_url": "https://attack.mitre.org/techniques/T1176/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1176.001 Browser Extensions: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1176.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1176/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1176.002",
      "title": "IDE Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1176.002/",
      "source_url": "https://attack.mitre.org/techniques/T1176/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1176.002 IDE Extensions: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1176.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1176/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1176",
      "title": "Browser Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1176/",
      "source_url": "https://attack.mitre.org/techniques/T1176/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Browser Extensions. T1176 Browser Extensions: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1176",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1176/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1185",
      "title": "Browser Session Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1185/",
      "source_url": "https://attack.mitre.org/techniques/T1185/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Browser Session Hijacking. T1185 Browser Session Hijacking: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1185",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1185/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1187",
      "title": "Forced Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1187/",
      "source_url": "https://attack.mitre.org/techniques/T1187/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Forced Authentication. T1187 Forced Authentication: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1187",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1187/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1189",
      "title": "Drive-by Compromise",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1189/",
      "source_url": "https://attack.mitre.org/techniques/T1189/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Drive-by Compromise. T1189 Drive-by Compromise: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1189",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1189/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1190",
      "title": "Exploit Public-Facing Application",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1190/",
      "source_url": "https://attack.mitre.org/techniques/T1190/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploit Public-Facing Application. T1190 Exploit Public-Facing Application: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1190",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1190/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195.001",
      "title": "Compromise Software Dependencies and Development Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195.001/",
      "source_url": "https://attack.mitre.org/techniques/T1195/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compromise Software Dependencies and Development Tools. T1195.001 Compromise Software Dependencies and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1195.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195.002",
      "title": "Compromise Software Supply Chain",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195.002/",
      "source_url": "https://attack.mitre.org/techniques/T1195/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compromise Software Supply Chain. T1195.002 Compromise Software Supply Chain: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1195.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195.003",
      "title": "Compromise Hardware Supply Chain",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195.003/",
      "source_url": "https://attack.mitre.org/techniques/T1195/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compromise Hardware Supply Chain. T1195.003 Compromise Hardware Supply Chain: description, detection logic, threat actors…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1195.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1195",
      "title": "Supply Chain Compromise",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1195/",
      "source_url": "https://attack.mitre.org/techniques/T1195/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Supply Chain Compromise. T1195 Supply Chain Compromise: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1195",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1195/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1197",
      "title": "BITS Jobs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1197/",
      "source_url": "https://attack.mitre.org/techniques/T1197/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "BITS Jobs. T1197 BITS Jobs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1197",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1197/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1199",
      "title": "Trusted Relationship",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1199/",
      "source_url": "https://attack.mitre.org/techniques/T1199/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Trusted Relationship. T1199 Trusted Relationship: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1199",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1199/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1200",
      "title": "Hardware Additions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1200/",
      "source_url": "https://attack.mitre.org/techniques/T1200/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hardware Additions. T1200 Hardware Additions: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1200",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1200/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1201",
      "title": "Password Policy Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1201/",
      "source_url": "https://attack.mitre.org/techniques/T1201/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Password Policy Discovery. T1201 Password Policy Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1201",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1201/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1202",
      "title": "Indirect Command Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1202/",
      "source_url": "https://attack.mitre.org/techniques/T1202/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Indirect Command Execution. T1202 Indirect Command Execution: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1202",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1202/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1203",
      "title": "Exploitation for Client Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1203/",
      "source_url": "https://attack.mitre.org/techniques/T1203/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploitation for Client Execution. T1203 Exploitation for Client Execution: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1203",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1203/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.001",
      "title": "Malicious Link",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.001/",
      "source_url": "https://attack.mitre.org/techniques/T1204/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malicious Link. T1204.001 Malicious Link: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.002",
      "title": "Malicious File",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.002/",
      "source_url": "https://attack.mitre.org/techniques/T1204/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malicious File. T1204.002 Malicious File: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.003",
      "title": "Malicious Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.003/",
      "source_url": "https://attack.mitre.org/techniques/T1204/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malicious Image. T1204.003 Malicious Image: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.004",
      "title": "Malicious Copy and Paste",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.004/",
      "source_url": "https://attack.mitre.org/techniques/T1204/004/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1204.004 Malicious Copy and Paste: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204.005",
      "title": "Malicious Library",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204.005/",
      "source_url": "https://attack.mitre.org/techniques/T1204/005/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1204.005 Malicious Library: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1204",
      "title": "User Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1204/",
      "source_url": "https://attack.mitre.org/techniques/T1204/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "User Execution. T1204 User Execution: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1204",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1204/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1205.001",
      "title": "Port Knocking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1205.001/",
      "source_url": "https://attack.mitre.org/techniques/T1205/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Port Knocking. T1205.001 Port Knocking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1205.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1205/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1205.002",
      "title": "Socket Filters",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1205.002/",
      "source_url": "https://attack.mitre.org/techniques/T1205/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Socket Filters. T1205.002 Socket Filters: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1205.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1205/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1205",
      "title": "Traffic Signaling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1205/",
      "source_url": "https://attack.mitre.org/techniques/T1205/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Traffic Signaling. T1205 Traffic Signaling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1205",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1205/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1207",
      "title": "Rogue Domain Controller",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1207/",
      "source_url": "https://attack.mitre.org/techniques/T1207/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rogue Domain Controller. T1207 Rogue Domain Controller: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1207",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1207/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1210",
      "title": "Exploitation of Remote Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1210/",
      "source_url": "https://attack.mitre.org/techniques/T1210/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploitation of Remote Services. T1210 Exploitation of Remote Services: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1210",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1210/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1211",
      "title": "Exploitation for Defense Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1211/",
      "source_url": "https://attack.mitre.org/techniques/T1211/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploitation for Defense Evasion. T1211 Exploitation for Defense Evasion: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1211",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1211/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1212",
      "title": "Exploitation for Credential Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1212/",
      "source_url": "https://attack.mitre.org/techniques/T1212/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploitation for Credential Access. T1212 Exploitation for Credential Access: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1212",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1212/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.001",
      "title": "Confluence",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.001/",
      "source_url": "https://attack.mitre.org/techniques/T1213/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Confluence. T1213.001 Confluence: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.002",
      "title": "Sharepoint",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.002/",
      "source_url": "https://attack.mitre.org/techniques/T1213/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sharepoint. T1213.002 Sharepoint: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.003",
      "title": "Code Repositories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.003/",
      "source_url": "https://attack.mitre.org/techniques/T1213/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Code Repositories. T1213.003 Code Repositories: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.004",
      "title": "Customer Relationship Management Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.004/",
      "source_url": "https://attack.mitre.org/techniques/T1213/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Customer Relationship Management Software. T1213.004 Customer Relationship Management Software: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.005",
      "title": "Messaging Applications",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.005/",
      "source_url": "https://attack.mitre.org/techniques/T1213/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Messaging Applications. T1213.005 Messaging Applications: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213.006",
      "title": "Databases",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213.006/",
      "source_url": "https://attack.mitre.org/techniques/T1213/006/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1213.006 Databases: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1213",
      "title": "Data from Information Repositories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1213/",
      "source_url": "https://attack.mitre.org/techniques/T1213/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data from Information Repositories. T1213 Data from Information Repositories: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1213",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1213/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1216.001",
      "title": "PubPrn",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1216.001/",
      "source_url": "https://attack.mitre.org/techniques/T1216/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PubPrn. T1216.001 PubPrn: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1216.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1216/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1216.002",
      "title": "SyncAppvPublishingServer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1216.002/",
      "source_url": "https://attack.mitre.org/techniques/T1216/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SyncAppvPublishingServer. T1216.002 SyncAppvPublishingServer: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1216.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1216/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1216",
      "title": "System Script Proxy Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1216/",
      "source_url": "https://attack.mitre.org/techniques/T1216/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Script Proxy Execution. T1216 System Script Proxy Execution: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1216",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1216/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1217",
      "title": "Browser Information Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1217/",
      "source_url": "https://attack.mitre.org/techniques/T1217/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Browser Information Discovery. T1217 Browser Information Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1217",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1217/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.001",
      "title": "Compiled HTML File",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.001/",
      "source_url": "https://attack.mitre.org/techniques/T1218/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compiled HTML File. T1218.001 Compiled HTML File: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.002",
      "title": "Control Panel",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.002/",
      "source_url": "https://attack.mitre.org/techniques/T1218/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Control Panel. T1218.002 Control Panel: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.003",
      "title": "CMSTP",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.003/",
      "source_url": "https://attack.mitre.org/techniques/T1218/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "CMSTP. T1218.003 CMSTP: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.004",
      "title": "InstallUtil",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.004/",
      "source_url": "https://attack.mitre.org/techniques/T1218/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "InstallUtil. T1218.004 InstallUtil: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.005",
      "title": "Mshta",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.005/",
      "source_url": "https://attack.mitre.org/techniques/T1218/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mshta. T1218.005 Mshta: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.007",
      "title": "Msiexec",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.007/",
      "source_url": "https://attack.mitre.org/techniques/T1218/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Msiexec. T1218.007 Msiexec: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.008",
      "title": "Odbcconf",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.008/",
      "source_url": "https://attack.mitre.org/techniques/T1218/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Odbcconf. T1218.008 Odbcconf: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.009",
      "title": "Regsvcs/Regasm",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.009/",
      "source_url": "https://attack.mitre.org/techniques/T1218/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Regsvcs/Regasm. T1218.009 Regsvcs/Regasm: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.010",
      "title": "Regsvr32",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.010/",
      "source_url": "https://attack.mitre.org/techniques/T1218/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Regsvr32. T1218.010 Regsvr32: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.011",
      "title": "Rundll32",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.011/",
      "source_url": "https://attack.mitre.org/techniques/T1218/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Rundll32. T1218.011 Rundll32: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.012",
      "title": "Verclsid",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.012/",
      "source_url": "https://attack.mitre.org/techniques/T1218/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Verclsid. T1218.012 Verclsid: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.013",
      "title": "Mavinject",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.013/",
      "source_url": "https://attack.mitre.org/techniques/T1218/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mavinject. T1218.013 Mavinject: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.014",
      "title": "MMC",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.014/",
      "source_url": "https://attack.mitre.org/techniques/T1218/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "MMC. T1218.014 MMC: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218.015",
      "title": "Electron Applications",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218.015/",
      "source_url": "https://attack.mitre.org/techniques/T1218/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Electron Applications. T1218.015 Electron Applications: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1218",
      "title": "System Binary Proxy Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1218/",
      "source_url": "https://attack.mitre.org/techniques/T1218/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Binary Proxy Execution. T1218 System Binary Proxy Execution: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1218",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1218/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219.001",
      "title": "IDE Tunneling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219.001/",
      "source_url": "https://attack.mitre.org/techniques/T1219/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1219.001 IDE Tunneling: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1219.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219.002",
      "title": "Remote Desktop Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219.002/",
      "source_url": "https://attack.mitre.org/techniques/T1219/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1219.002 Remote Desktop Software: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1219.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219.003",
      "title": "Remote Access Hardware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219.003/",
      "source_url": "https://attack.mitre.org/techniques/T1219/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1219.003 Remote Access Hardware: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1219.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1219",
      "title": "Remote Access Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1219/",
      "source_url": "https://attack.mitre.org/techniques/T1219/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote Access Software. T1219 Remote Access Software: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1219",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1219/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1220",
      "title": "XSL Script Processing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1220/",
      "source_url": "https://attack.mitre.org/techniques/T1220/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "XSL Script Processing. T1220 XSL Script Processing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1220",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1220/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1221",
      "title": "Template Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1221/",
      "source_url": "https://attack.mitre.org/techniques/T1221/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Template Injection. T1221 Template Injection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1221",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1221/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1222.001",
      "title": "Windows File and Directory Permissions Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1222.001/",
      "source_url": "https://attack.mitre.org/techniques/T1222/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows File and Directory Permissions Modification. T1222.001 Windows File and Directory Permissions…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1222.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1222/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1222.002",
      "title": "Linux and Mac File and Directory Permissions Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1222.002/",
      "source_url": "https://attack.mitre.org/techniques/T1222/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Linux and Mac File and Directory Permissions Modification. T1222.002 Linux and Mac File and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1222.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1222/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1222",
      "title": "File and Directory Permissions Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1222/",
      "source_url": "https://attack.mitre.org/techniques/T1222/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "File and Directory Permissions Modification. T1222 File and Directory Permissions Modification: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1222",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1222/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1480.001",
      "title": "Environmental Keying",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1480.001/",
      "source_url": "https://attack.mitre.org/techniques/T1480/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Environmental Keying. T1480.001 Environmental Keying: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1480.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1480/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1480.002",
      "title": "Mutual Exclusion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1480.002/",
      "source_url": "https://attack.mitre.org/techniques/T1480/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mutual Exclusion. T1480.002 Mutual Exclusion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1480.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1480/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1480",
      "title": "Execution Guardrails",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1480/",
      "source_url": "https://attack.mitre.org/techniques/T1480/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Execution Guardrails. T1480 Execution Guardrails: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1480",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1480/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1482",
      "title": "Domain Trust Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1482/",
      "source_url": "https://attack.mitre.org/techniques/T1482/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Trust Discovery. T1482 Domain Trust Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1482",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1482/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1484.001",
      "title": "Group Policy Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1484.001/",
      "source_url": "https://attack.mitre.org/techniques/T1484/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Group Policy Modification. T1484.001 Group Policy Modification: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1484.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1484/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1484.002",
      "title": "Trust Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1484.002/",
      "source_url": "https://attack.mitre.org/techniques/T1484/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Trust Modification. T1484.002 Trust Modification: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1484.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1484/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1484",
      "title": "Domain or Tenant Policy Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1484/",
      "source_url": "https://attack.mitre.org/techniques/T1484/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain or Tenant Policy Modification. T1484 Domain or Tenant Policy Modification: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1484",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1484/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1485.001",
      "title": "Lifecycle-Triggered Deletion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1485.001/",
      "source_url": "https://attack.mitre.org/techniques/T1485/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lifecycle-Triggered Deletion. T1485.001 Lifecycle-Triggered Deletion: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1485.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1485/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1485",
      "title": "Data Destruction",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1485/",
      "source_url": "https://attack.mitre.org/techniques/T1485/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Destruction. T1485 Data Destruction: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1485",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1485/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1486",
      "title": "Data Encrypted for Impact",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1486/",
      "source_url": "https://attack.mitre.org/techniques/T1486/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Encrypted for Impact. T1486 Data Encrypted for Impact: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1486",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1486/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1489",
      "title": "Service Stop",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1489/",
      "source_url": "https://attack.mitre.org/techniques/T1489/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Service Stop. T1489 Service Stop: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1489",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1489/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1490",
      "title": "Inhibit System Recovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1490/",
      "source_url": "https://attack.mitre.org/techniques/T1490/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Inhibit System Recovery. T1490 Inhibit System Recovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1490",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1490/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1491.001",
      "title": "Internal Defacement",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1491.001/",
      "source_url": "https://attack.mitre.org/techniques/T1491/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Internal Defacement. T1491.001 Internal Defacement: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1491.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1491/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1491.002",
      "title": "External Defacement",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1491.002/",
      "source_url": "https://attack.mitre.org/techniques/T1491/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "External Defacement. T1491.002 External Defacement: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1491.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1491/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1491",
      "title": "Defacement",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1491/",
      "source_url": "https://attack.mitre.org/techniques/T1491/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Defacement. T1491 Defacement: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1491",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1491/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1495",
      "title": "Firmware Corruption",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1495/",
      "source_url": "https://attack.mitre.org/techniques/T1495/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Firmware Corruption. T1495 Firmware Corruption: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "hardware-security",
        "mitre-attack",
        "t1495",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1495/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.001",
      "title": "Compute Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.001/",
      "source_url": "https://attack.mitre.org/techniques/T1496/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compute Hijacking. T1496.001 Compute Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.002",
      "title": "Bandwidth Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.002/",
      "source_url": "https://attack.mitre.org/techniques/T1496/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bandwidth Hijacking. T1496.002 Bandwidth Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.003",
      "title": "SMS Pumping",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.003/",
      "source_url": "https://attack.mitre.org/techniques/T1496/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SMS Pumping. T1496.003 SMS Pumping: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496.004",
      "title": "Cloud Service Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496.004/",
      "source_url": "https://attack.mitre.org/techniques/T1496/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Service Hijacking. T1496.004 Cloud Service Hijacking: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1496.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1496",
      "title": "Resource Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1496/",
      "source_url": "https://attack.mitre.org/techniques/T1496/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Resource Hijacking. T1496 Resource Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1496",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1496/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497.001",
      "title": "System Checks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497.001/",
      "source_url": "https://attack.mitre.org/techniques/T1497/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Checks. T1497.001 System Checks: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1497.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497.002",
      "title": "User Activity Based Checks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497.002/",
      "source_url": "https://attack.mitre.org/techniques/T1497/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "User Activity Based Checks. T1497.002 User Activity Based Checks: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1497.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497.003",
      "title": "Time Based Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497.003/",
      "source_url": "https://attack.mitre.org/techniques/T1497/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Time Based Evasion. T1497.003 Time Based Evasion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1497.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1497",
      "title": "Virtualization/Sandbox Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1497/",
      "source_url": "https://attack.mitre.org/techniques/T1497/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Virtualization/Sandbox Evasion. T1497 Virtualization/Sandbox Evasion: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "mitre-attack",
        "t1497",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1497/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1498.001",
      "title": "Direct Network Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1498.001/",
      "source_url": "https://attack.mitre.org/techniques/T1498/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Direct Network Flood. T1498.001 Direct Network Flood: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1498.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1498/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1498.002",
      "title": "Reflection Amplification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1498.002/",
      "source_url": "https://attack.mitre.org/techniques/T1498/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Reflection Amplification. T1498.002 Reflection Amplification: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1498.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1498/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1498",
      "title": "Network Denial of Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1498/",
      "source_url": "https://attack.mitre.org/techniques/T1498/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Denial of Service. T1498 Network Denial of Service: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1498",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1498/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.001",
      "title": "OS Exhaustion Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.001/",
      "source_url": "https://attack.mitre.org/techniques/T1499/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "OS Exhaustion Flood. T1499.001 OS Exhaustion Flood: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.002",
      "title": "Service Exhaustion Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.002/",
      "source_url": "https://attack.mitre.org/techniques/T1499/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Service Exhaustion Flood. T1499.002 Service Exhaustion Flood: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.003",
      "title": "Application Exhaustion Flood",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.003/",
      "source_url": "https://attack.mitre.org/techniques/T1499/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Application Exhaustion Flood. T1499.003 Application Exhaustion Flood: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499.004",
      "title": "Application or System Exploitation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499.004/",
      "source_url": "https://attack.mitre.org/techniques/T1499/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Application or System Exploitation. T1499.004 Application or System Exploitation: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1499.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1499",
      "title": "Endpoint Denial of Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1499/",
      "source_url": "https://attack.mitre.org/techniques/T1499/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Endpoint Denial of Service. T1499 Endpoint Denial of Service: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1499",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1499/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.001",
      "title": "SQL Stored Procedures",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.001/",
      "source_url": "https://attack.mitre.org/techniques/T1505/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SQL Stored Procedures. T1505.001 SQL Stored Procedures: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.002",
      "title": "Transport Agent",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.002/",
      "source_url": "https://attack.mitre.org/techniques/T1505/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Transport Agent. T1505.002 Transport Agent: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.003",
      "title": "Web Shell",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.003/",
      "source_url": "https://attack.mitre.org/techniques/T1505/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Shell. T1505.003 Web Shell: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.004",
      "title": "IIS Components",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.004/",
      "source_url": "https://attack.mitre.org/techniques/T1505/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "IIS Components. T1505.004 IIS Components: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.005",
      "title": "Terminal Services DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.005/",
      "source_url": "https://attack.mitre.org/techniques/T1505/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Terminal Services DLL. T1505.005 Terminal Services DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505.006",
      "title": "vSphere Installation Bundles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505.006/",
      "source_url": "https://attack.mitre.org/techniques/T1505/006/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1505.006 vSphere Installation Bundles: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1505",
      "title": "Server Software Component",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1505/",
      "source_url": "https://attack.mitre.org/techniques/T1505/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Server Software Component. T1505 Server Software Component: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1505",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1505/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1518.001",
      "title": "Security Software Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1518.001/",
      "source_url": "https://attack.mitre.org/techniques/T1518/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Security Software Discovery. T1518.001 Security Software Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1518.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1518/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1518.002",
      "title": "Backup Software Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1518.002/",
      "source_url": "https://attack.mitre.org/techniques/T1518/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1518.002 Backup Software Discovery: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1518.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1518/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1518",
      "title": "Software Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1518/",
      "source_url": "https://attack.mitre.org/techniques/T1518/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Software Discovery. T1518 Software Discovery: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1518",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1518/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1525",
      "title": "Implant Internal Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1525/",
      "source_url": "https://attack.mitre.org/techniques/T1525/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Implant Internal Image. T1525 Implant Internal Image: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1525",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1525/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1526",
      "title": "Cloud Service Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1526/",
      "source_url": "https://attack.mitre.org/techniques/T1526/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Service Discovery. T1526 Cloud Service Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1526",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1526/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1528",
      "title": "Steal Application Access Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1528/",
      "source_url": "https://attack.mitre.org/techniques/T1528/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Steal Application Access Token. T1528 Steal Application Access Token: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "mitre-attack",
        "t1528",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1528/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1529",
      "title": "System Shutdown/Reboot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1529/",
      "source_url": "https://attack.mitre.org/techniques/T1529/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Shutdown/Reboot. T1529 System Shutdown/Reboot: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1529",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1529/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1530",
      "title": "Data from Cloud Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1530/",
      "source_url": "https://attack.mitre.org/techniques/T1530/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data from Cloud Storage. T1530 Data from Cloud Storage: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "ai-security",
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1530",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1530/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1531",
      "title": "Account Access Removal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1531/",
      "source_url": "https://attack.mitre.org/techniques/T1531/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Account Access Removal. T1531 Account Access Removal: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1531",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1531/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1534",
      "title": "Internal Spearphishing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1534/",
      "source_url": "https://attack.mitre.org/techniques/T1534/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Internal Spearphishing. T1534 Internal Spearphishing: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1534",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1534/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1535",
      "title": "Unused/Unsupported Cloud Regions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1535/",
      "source_url": "https://attack.mitre.org/techniques/T1535/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Unused/Unsupported Cloud Regions. T1535 Unused/Unsupported Cloud Regions: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1535",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1535/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1537",
      "title": "Transfer Data to Cloud Account",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1537/",
      "source_url": "https://attack.mitre.org/techniques/T1537/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Transfer Data to Cloud Account. T1537 Transfer Data to Cloud Account: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1537",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1537/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1538",
      "title": "Cloud Service Dashboard",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1538/",
      "source_url": "https://attack.mitre.org/techniques/T1538/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Service Dashboard. T1538 Cloud Service Dashboard: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1538",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1538/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1539",
      "title": "Steal Web Session Cookie",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1539/",
      "source_url": "https://attack.mitre.org/techniques/T1539/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Steal Web Session Cookie. T1539 Steal Web Session Cookie: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1539",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1539/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.001",
      "title": "System Firmware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.001/",
      "source_url": "https://attack.mitre.org/techniques/T1542/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Firmware. T1542.001 System Firmware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "hardware-security",
        "mitre-attack",
        "t1542.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.002",
      "title": "Component Firmware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.002/",
      "source_url": "https://attack.mitre.org/techniques/T1542/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Component Firmware. T1542.002 Component Firmware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "hardware-security",
        "mitre-attack",
        "t1542.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.003",
      "title": "Bootkit",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.003/",
      "source_url": "https://attack.mitre.org/techniques/T1542/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bootkit. T1542.003 Bootkit: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.004",
      "title": "ROMMONkit",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.004/",
      "source_url": "https://attack.mitre.org/techniques/T1542/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ROMMONkit. T1542.004 ROMMONkit: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542.005",
      "title": "TFTP Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542.005/",
      "source_url": "https://attack.mitre.org/techniques/T1542/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TFTP Boot. T1542.005 TFTP Boot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1542",
      "title": "Pre-OS Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1542/",
      "source_url": "https://attack.mitre.org/techniques/T1542/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Pre-OS Boot. T1542 Pre-OS Boot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1542",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1542/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.001",
      "title": "Launch Agent",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.001/",
      "source_url": "https://attack.mitre.org/techniques/T1543/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Launch Agent. T1543.001 Launch Agent: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.002",
      "title": "Systemd Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.002/",
      "source_url": "https://attack.mitre.org/techniques/T1543/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Systemd Service. T1543.002 Systemd Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.003",
      "title": "Windows Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.003/",
      "source_url": "https://attack.mitre.org/techniques/T1543/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows Service. T1543.003 Windows Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.003",
        "threat-intelligence",
        "windows-internals"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.004",
      "title": "Launch Daemon",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.004/",
      "source_url": "https://attack.mitre.org/techniques/T1543/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Launch Daemon. T1543.004 Launch Daemon: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543.005",
      "title": "Container Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543.005/",
      "source_url": "https://attack.mitre.org/techniques/T1543/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Container Service. T1543.005 Container Service: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1543.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1543",
      "title": "Create or Modify System Process",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1543/",
      "source_url": "https://attack.mitre.org/techniques/T1543/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Create or Modify System Process. T1543 Create or Modify System Process: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1543",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1543/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.001",
      "title": "Change Default File Association",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.001/",
      "source_url": "https://attack.mitre.org/techniques/T1546/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Change Default File Association. T1546.001 Change Default File Association: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.002",
      "title": "Screensaver",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.002/",
      "source_url": "https://attack.mitre.org/techniques/T1546/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Screensaver. T1546.002 Screensaver: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.003",
      "title": "Windows Management Instrumentation Event Subscription",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.003/",
      "source_url": "https://attack.mitre.org/techniques/T1546/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows Management Instrumentation Event Subscription. T1546.003 Windows Management Instrumentation…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.004",
      "title": "Unix Shell Configuration Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.004/",
      "source_url": "https://attack.mitre.org/techniques/T1546/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Unix Shell Configuration Modification. T1546.004 Unix Shell Configuration Modification: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.005",
      "title": "Trap",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.005/",
      "source_url": "https://attack.mitre.org/techniques/T1546/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Trap. T1546.005 Trap: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.006",
      "title": "LC_LOAD_DYLIB Addition",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.006/",
      "source_url": "https://attack.mitre.org/techniques/T1546/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LC_LOAD_DYLIB Addition. T1546.006 LC_LOAD_DYLIB Addition: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.007",
      "title": "Netsh Helper DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.007/",
      "source_url": "https://attack.mitre.org/techniques/T1546/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Netsh Helper DLL. T1546.007 Netsh Helper DLL: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.008",
      "title": "Accessibility Features",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.008/",
      "source_url": "https://attack.mitre.org/techniques/T1546/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Accessibility Features. T1546.008 Accessibility Features: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.009",
      "title": "AppCert DLLs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.009/",
      "source_url": "https://attack.mitre.org/techniques/T1546/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "AppCert DLLs. T1546.009 AppCert DLLs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.010",
      "title": "AppInit DLLs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.010/",
      "source_url": "https://attack.mitre.org/techniques/T1546/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "AppInit DLLs. T1546.010 AppInit DLLs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.011",
      "title": "Application Shimming",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.011/",
      "source_url": "https://attack.mitre.org/techniques/T1546/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Application Shimming. T1546.011 Application Shimming: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.012",
      "title": "Image File Execution Options Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.012/",
      "source_url": "https://attack.mitre.org/techniques/T1546/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Image File Execution Options Injection. T1546.012 Image File Execution Options Injection: description, detection…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.013",
      "title": "PowerShell Profile",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.013/",
      "source_url": "https://attack.mitre.org/techniques/T1546/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "PowerShell Profile. T1546.013 PowerShell Profile: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.014",
      "title": "Emond",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.014/",
      "source_url": "https://attack.mitre.org/techniques/T1546/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Emond. T1546.014 Emond: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.015",
      "title": "Component Object Model Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.015/",
      "source_url": "https://attack.mitre.org/techniques/T1546/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Component Object Model Hijacking. T1546.015 Component Object Model Hijacking: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.016",
      "title": "Installer Packages",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.016/",
      "source_url": "https://attack.mitre.org/techniques/T1546/016/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Installer Packages. T1546.016 Installer Packages: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.016",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/016/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.017",
      "title": "Udev Rules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.017/",
      "source_url": "https://attack.mitre.org/techniques/T1546/017/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Udev Rules. T1546.017 Udev Rules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.017",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/017/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546.018",
      "title": "Python Startup Hooks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546.018/",
      "source_url": "https://attack.mitre.org/techniques/T1546/018/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1546.018 Python Startup Hooks: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546.018",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/018/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1546",
      "title": "Event Triggered Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1546/",
      "source_url": "https://attack.mitre.org/techniques/T1546/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Event Triggered Execution. T1546 Event Triggered Execution: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1546",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1546/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.001",
      "title": "Registry Run Keys / Startup Folder",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.001/",
      "source_url": "https://attack.mitre.org/techniques/T1547/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Registry Run Keys / Startup Folder. T1547.001 Registry Run Keys / Startup Folder: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.002",
      "title": "Authentication Package",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.002/",
      "source_url": "https://attack.mitre.org/techniques/T1547/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Authentication Package. T1547.002 Authentication Package: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.003",
      "title": "Time Providers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.003/",
      "source_url": "https://attack.mitre.org/techniques/T1547/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Time Providers. T1547.003 Time Providers: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.004",
      "title": "Winlogon Helper DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.004/",
      "source_url": "https://attack.mitre.org/techniques/T1547/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Winlogon Helper DLL. T1547.004 Winlogon Helper DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.005",
      "title": "Security Support Provider",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.005/",
      "source_url": "https://attack.mitre.org/techniques/T1547/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Security Support Provider. T1547.005 Security Support Provider: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.006",
      "title": "Kernel Modules and Extensions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.006/",
      "source_url": "https://attack.mitre.org/techniques/T1547/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Kernel Modules and Extensions. T1547.006 Kernel Modules and Extensions: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.007",
      "title": "Re-opened Applications",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.007/",
      "source_url": "https://attack.mitre.org/techniques/T1547/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Re-opened Applications. T1547.007 Re-opened Applications: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.008",
      "title": "LSASS Driver",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.008/",
      "source_url": "https://attack.mitre.org/techniques/T1547/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LSASS Driver. T1547.008 LSASS Driver: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.009",
      "title": "Shortcut Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.009/",
      "source_url": "https://attack.mitre.org/techniques/T1547/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Shortcut Modification. T1547.009 Shortcut Modification: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.010",
      "title": "Port Monitors",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.010/",
      "source_url": "https://attack.mitre.org/techniques/T1547/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Port Monitors. T1547.010 Port Monitors: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.012",
      "title": "Print Processors",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.012/",
      "source_url": "https://attack.mitre.org/techniques/T1547/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Print Processors. T1547.012 Print Processors: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.013",
      "title": "XDG Autostart Entries",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.013/",
      "source_url": "https://attack.mitre.org/techniques/T1547/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "XDG Autostart Entries. T1547.013 XDG Autostart Entries: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.014",
      "title": "Active Setup",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.014/",
      "source_url": "https://attack.mitre.org/techniques/T1547/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Active Setup. T1547.014 Active Setup: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547.015",
      "title": "Login Items",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547.015/",
      "source_url": "https://attack.mitre.org/techniques/T1547/015/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Login Items. T1547.015 Login Items: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547.015",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/015/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1547",
      "title": "Boot or Logon Autostart Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1547/",
      "source_url": "https://attack.mitre.org/techniques/T1547/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Boot or Logon Autostart Execution. T1547 Boot or Logon Autostart Execution: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1547",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1547/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.001",
      "title": "Setuid and Setgid",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.001/",
      "source_url": "https://attack.mitre.org/techniques/T1548/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Setuid and Setgid. T1548.001 Setuid and Setgid: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.002",
      "title": "Bypass User Account Control",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.002/",
      "source_url": "https://attack.mitre.org/techniques/T1548/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bypass User Account Control. T1548.002 Bypass User Account Control: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.003",
      "title": "Sudo and Sudo Caching",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.003/",
      "source_url": "https://attack.mitre.org/techniques/T1548/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Sudo and Sudo Caching. T1548.003 Sudo and Sudo Caching: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.004",
      "title": "Elevated Execution with Prompt",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.004/",
      "source_url": "https://attack.mitre.org/techniques/T1548/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Elevated Execution with Prompt. T1548.004 Elevated Execution with Prompt: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.005",
      "title": "Temporary Elevated Cloud Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.005/",
      "source_url": "https://attack.mitre.org/techniques/T1548/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Temporary Elevated Cloud Access. T1548.005 Temporary Elevated Cloud Access: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1548.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548.006",
      "title": "TCC Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548.006/",
      "source_url": "https://attack.mitre.org/techniques/T1548/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "TCC Manipulation. T1548.006 TCC Manipulation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1548",
      "title": "Abuse Elevation Control Mechanism",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1548/",
      "source_url": "https://attack.mitre.org/techniques/T1548/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Abuse Elevation Control Mechanism. T1548 Abuse Elevation Control Mechanism: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1548",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1548/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.001",
      "title": "Application Access Token",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.001/",
      "source_url": "https://attack.mitre.org/techniques/T1550/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Application Access Token. T1550.001 Application Access Token: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "mitre-attack",
        "t1550.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.002",
      "title": "Pass the Hash",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.002/",
      "source_url": "https://attack.mitre.org/techniques/T1550/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Pass the Hash. T1550.002 Pass the Hash: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.003",
      "title": "Pass the Ticket",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.003/",
      "source_url": "https://attack.mitre.org/techniques/T1550/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Pass the Ticket. T1550.003 Pass the Ticket: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550.004",
      "title": "Web Session Cookie",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550.004/",
      "source_url": "https://attack.mitre.org/techniques/T1550/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Session Cookie. T1550.004 Web Session Cookie: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1550",
      "title": "Use Alternate Authentication Material",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1550/",
      "source_url": "https://attack.mitre.org/techniques/T1550/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Use Alternate Authentication Material. T1550 Use Alternate Authentication Material: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1550",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1550/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.001",
      "title": "Credentials In Files",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.001/",
      "source_url": "https://attack.mitre.org/techniques/T1552/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credentials In Files. T1552.001 Credentials In Files: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.002",
      "title": "Credentials in Registry",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.002/",
      "source_url": "https://attack.mitre.org/techniques/T1552/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credentials in Registry. T1552.002 Credentials in Registry: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.003",
      "title": "Bash History",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.003/",
      "source_url": "https://attack.mitre.org/techniques/T1552/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Bash History. T1552.003 Bash History: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.004",
      "title": "Private Keys",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.004/",
      "source_url": "https://attack.mitre.org/techniques/T1552/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Private Keys. T1552.004 Private Keys: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.005",
      "title": "Cloud Instance Metadata API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.005/",
      "source_url": "https://attack.mitre.org/techniques/T1552/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Instance Metadata API. T1552.005 Cloud Instance Metadata API: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1552.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.006",
      "title": "Group Policy Preferences",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.006/",
      "source_url": "https://attack.mitre.org/techniques/T1552/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Group Policy Preferences. T1552.006 Group Policy Preferences: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.007",
      "title": "Container API",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.007/",
      "source_url": "https://attack.mitre.org/techniques/T1552/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Container API. T1552.007 Container API: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1552.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552.008",
      "title": "Chat Messages",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552.008/",
      "source_url": "https://attack.mitre.org/techniques/T1552/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Chat Messages. T1552.008 Chat Messages: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1552",
      "title": "Unsecured Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1552/",
      "source_url": "https://attack.mitre.org/techniques/T1552/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Unsecured Credentials. T1552 Unsecured Credentials: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1552",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1552/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.001",
      "title": "Gatekeeper Bypass",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.001/",
      "source_url": "https://attack.mitre.org/techniques/T1553/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gatekeeper Bypass. T1553.001 Gatekeeper Bypass: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.002",
      "title": "Code Signing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.002/",
      "source_url": "https://attack.mitre.org/techniques/T1553/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Code Signing. T1553.002 Code Signing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.003",
      "title": "SIP and Trust Provider Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.003/",
      "source_url": "https://attack.mitre.org/techniques/T1553/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SIP and Trust Provider Hijacking. T1553.003 SIP and Trust Provider Hijacking: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.004",
      "title": "Install Root Certificate",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.004/",
      "source_url": "https://attack.mitre.org/techniques/T1553/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Install Root Certificate. T1553.004 Install Root Certificate: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.005",
      "title": "Mark-of-the-Web Bypass",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.005/",
      "source_url": "https://attack.mitre.org/techniques/T1553/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Mark-of-the-Web Bypass. T1553.005 Mark-of-the-Web Bypass: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553.006",
      "title": "Code Signing Policy Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553.006/",
      "source_url": "https://attack.mitre.org/techniques/T1553/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Code Signing Policy Modification. T1553.006 Code Signing Policy Modification: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1553",
      "title": "Subvert Trust Controls",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1553/",
      "source_url": "https://attack.mitre.org/techniques/T1553/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Subvert Trust Controls. T1553 Subvert Trust Controls: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1553",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1553/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1554",
      "title": "Compromise Host Software Binary",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1554/",
      "source_url": "https://attack.mitre.org/techniques/T1554/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compromise Host Software Binary. T1554 Compromise Host Software Binary: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1554",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1554/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.001",
      "title": "Keychain",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.001/",
      "source_url": "https://attack.mitre.org/techniques/T1555/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Keychain. T1555.001 Keychain: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.002",
      "title": "Securityd Memory",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.002/",
      "source_url": "https://attack.mitre.org/techniques/T1555/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Securityd Memory. T1555.002 Securityd Memory: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.003",
      "title": "Credentials from Web Browsers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.003/",
      "source_url": "https://attack.mitre.org/techniques/T1555/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credentials from Web Browsers. T1555.003 Credentials from Web Browsers: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.004",
      "title": "Windows Credential Manager",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.004/",
      "source_url": "https://attack.mitre.org/techniques/T1555/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Windows Credential Manager. T1555.004 Windows Credential Manager: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.005",
      "title": "Password Managers",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.005/",
      "source_url": "https://attack.mitre.org/techniques/T1555/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Password Managers. T1555.005 Password Managers: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555.006",
      "title": "Cloud Secrets Management Stores",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555.006/",
      "source_url": "https://attack.mitre.org/techniques/T1555/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Secrets Management Stores. T1555.006 Cloud Secrets Management Stores: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1555.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1555",
      "title": "Credentials from Password Stores",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1555/",
      "source_url": "https://attack.mitre.org/techniques/T1555/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credentials from Password Stores. T1555 Credentials from Password Stores: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1555",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1555/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.001",
      "title": "Domain Controller Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.001/",
      "source_url": "https://attack.mitre.org/techniques/T1556/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Controller Authentication. T1556.001 Domain Controller Authentication: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.002",
      "title": "Password Filter DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.002/",
      "source_url": "https://attack.mitre.org/techniques/T1556/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Password Filter DLL. T1556.002 Password Filter DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.003",
      "title": "Pluggable Authentication Modules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.003/",
      "source_url": "https://attack.mitre.org/techniques/T1556/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Pluggable Authentication Modules. T1556.003 Pluggable Authentication Modules: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.004",
      "title": "Network Device Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.004/",
      "source_url": "https://attack.mitre.org/techniques/T1556/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Device Authentication. T1556.004 Network Device Authentication: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.005",
      "title": "Reversible Encryption",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.005/",
      "source_url": "https://attack.mitre.org/techniques/T1556/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Reversible Encryption. T1556.005 Reversible Encryption: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.006",
      "title": "Multi-Factor Authentication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.006/",
      "source_url": "https://attack.mitre.org/techniques/T1556/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Multi-Factor Authentication. T1556.006 Multi-Factor Authentication: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.007",
      "title": "Hybrid Identity",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.007/",
      "source_url": "https://attack.mitre.org/techniques/T1556/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hybrid Identity. T1556.007 Hybrid Identity: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "t1556.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.008",
      "title": "Network Provider DLL",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.008/",
      "source_url": "https://attack.mitre.org/techniques/T1556/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Provider DLL. T1556.008 Network Provider DLL: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556.009",
      "title": "Conditional Access Policies",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556.009/",
      "source_url": "https://attack.mitre.org/techniques/T1556/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Conditional Access Policies. T1556.009 Conditional Access Policies: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1556",
      "title": "Modify Authentication Process",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1556/",
      "source_url": "https://attack.mitre.org/techniques/T1556/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Modify Authentication Process. T1556 Modify Authentication Process: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1556",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1556/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.001",
      "title": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.001/",
      "source_url": "https://attack.mitre.org/techniques/T1557/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "LLMNR/NBT-NS Poisoning and SMB Relay. T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.002",
      "title": "ARP Cache Poisoning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.002/",
      "source_url": "https://attack.mitre.org/techniques/T1557/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "ARP Cache Poisoning. T1557.002 ARP Cache Poisoning: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.003",
      "title": "DHCP Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.003/",
      "source_url": "https://attack.mitre.org/techniques/T1557/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DHCP Spoofing. T1557.003 DHCP Spoofing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557.004",
      "title": "Evil Twin",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557.004/",
      "source_url": "https://attack.mitre.org/techniques/T1557/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Evil Twin. T1557.004 Evil Twin: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1557",
      "title": "Adversary-in-the-Middle",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1557/",
      "source_url": "https://attack.mitre.org/techniques/T1557/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Adversary-in-the-Middle. T1557 Adversary-in-the-Middle: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1557",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1557/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.001",
      "title": "Golden Ticket",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.001/",
      "source_url": "https://attack.mitre.org/techniques/T1558/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Golden Ticket. T1558.001 Golden Ticket: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.002",
      "title": "Silver Ticket",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.002/",
      "source_url": "https://attack.mitre.org/techniques/T1558/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Silver Ticket. T1558.002 Silver Ticket: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.003",
      "title": "Kerberoasting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.003/",
      "source_url": "https://attack.mitre.org/techniques/T1558/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Kerberoasting. T1558.003 Kerberoasting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.004",
      "title": "AS-REP Roasting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.004/",
      "source_url": "https://attack.mitre.org/techniques/T1558/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "AS-REP Roasting. T1558.004 AS-REP Roasting: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558.005",
      "title": "Ccache Files",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558.005/",
      "source_url": "https://attack.mitre.org/techniques/T1558/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ccache Files. T1558.005 Ccache Files: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1558.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1558",
      "title": "Steal or Forge Kerberos Tickets",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1558/",
      "source_url": "https://attack.mitre.org/techniques/T1558/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Steal or Forge Kerberos Tickets. T1558 Steal or Forge Kerberos Tickets: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "t1558",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1558/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559.001",
      "title": "Component Object Model",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559.001/",
      "source_url": "https://attack.mitre.org/techniques/T1559/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Component Object Model. T1559.001 Component Object Model: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559.002",
      "title": "Dynamic Data Exchange",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559.002/",
      "source_url": "https://attack.mitre.org/techniques/T1559/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dynamic Data Exchange. T1559.002 Dynamic Data Exchange: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559.003",
      "title": "XPC Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559.003/",
      "source_url": "https://attack.mitre.org/techniques/T1559/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "XPC Services. T1559.003 XPC Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1559",
      "title": "Inter-Process Communication",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1559/",
      "source_url": "https://attack.mitre.org/techniques/T1559/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Inter-Process Communication. T1559 Inter-Process Communication: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1559",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1559/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560.001",
      "title": "Archive via Utility",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560.001/",
      "source_url": "https://attack.mitre.org/techniques/T1560/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Archive via Utility. T1560.001 Archive via Utility: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560.002",
      "title": "Archive via Library",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560.002/",
      "source_url": "https://attack.mitre.org/techniques/T1560/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Archive via Library. T1560.002 Archive via Library: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560.003",
      "title": "Archive via Custom Method",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560.003/",
      "source_url": "https://attack.mitre.org/techniques/T1560/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Archive via Custom Method. T1560.003 Archive via Custom Method: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1560",
      "title": "Archive Collected Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1560/",
      "source_url": "https://attack.mitre.org/techniques/T1560/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Archive Collected Data. T1560 Archive Collected Data: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1560",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1560/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1561.001",
      "title": "Disk Content Wipe",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1561.001/",
      "source_url": "https://attack.mitre.org/techniques/T1561/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disk Content Wipe. T1561.001 Disk Content Wipe: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1561.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1561/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1561.002",
      "title": "Disk Structure Wipe",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1561.002/",
      "source_url": "https://attack.mitre.org/techniques/T1561/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disk Structure Wipe. T1561.002 Disk Structure Wipe: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1561.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1561/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1561",
      "title": "Disk Wipe",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1561/",
      "source_url": "https://attack.mitre.org/techniques/T1561/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disk Wipe. T1561 Disk Wipe: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1561",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1561/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.001",
      "title": "Disable or Modify Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.001/",
      "source_url": "https://attack.mitre.org/techniques/T1562/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable or Modify Tools. T1562.001 Disable or Modify Tools: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.002",
      "title": "Disable Windows Event Logging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.002/",
      "source_url": "https://attack.mitre.org/techniques/T1562/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable Windows Event Logging. T1562.002 Disable Windows Event Logging: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.003",
      "title": "Impair Command History Logging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.003/",
      "source_url": "https://attack.mitre.org/techniques/T1562/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Impair Command History Logging. T1562.003 Impair Command History Logging: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.004",
      "title": "Disable or Modify System Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.004/",
      "source_url": "https://attack.mitre.org/techniques/T1562/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable or Modify System Firewall. T1562.004 Disable or Modify System Firewall: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.006",
      "title": "Indicator Blocking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.006/",
      "source_url": "https://attack.mitre.org/techniques/T1562/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Indicator Blocking. T1562.006 Indicator Blocking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.007",
      "title": "Disable or Modify Cloud Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.007/",
      "source_url": "https://attack.mitre.org/techniques/T1562/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable or Modify Cloud Firewall. T1562.007 Disable or Modify Cloud Firewall: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1562.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.008",
      "title": "Disable or Modify Cloud Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.008/",
      "source_url": "https://attack.mitre.org/techniques/T1562/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable or Modify Cloud Logs. T1562.008 Disable or Modify Cloud Logs: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1562.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.009",
      "title": "Safe Mode Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.009/",
      "source_url": "https://attack.mitre.org/techniques/T1562/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Safe Mode Boot. T1562.009 Safe Mode Boot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.010",
      "title": "Downgrade Attack",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.010/",
      "source_url": "https://attack.mitre.org/techniques/T1562/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Downgrade Attack. T1562.010 Downgrade Attack: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.011",
      "title": "Spoof Security Alerting",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.011/",
      "source_url": "https://attack.mitre.org/techniques/T1562/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spoof Security Alerting. T1562.011 Spoof Security Alerting: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562.012",
      "title": "Disable or Modify Linux Audit System",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562.012/",
      "source_url": "https://attack.mitre.org/techniques/T1562/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable or Modify Linux Audit System. T1562.012 Disable or Modify Linux Audit System: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1562",
      "title": "Impair Defenses",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1562/",
      "source_url": "https://attack.mitre.org/techniques/T1562/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Impair Defenses. T1562 Impair Defenses: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1562",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1562/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1563.001",
      "title": "SSH Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1563.001/",
      "source_url": "https://attack.mitre.org/techniques/T1563/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SSH Hijacking. T1563.001 SSH Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1563.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1563/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1563.002",
      "title": "RDP Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1563.002/",
      "source_url": "https://attack.mitre.org/techniques/T1563/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "RDP Hijacking. T1563.002 RDP Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1563.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1563/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1563",
      "title": "Remote Service Session Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1563/",
      "source_url": "https://attack.mitre.org/techniques/T1563/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Remote Service Session Hijacking. T1563 Remote Service Session Hijacking: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1563",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1563/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.001",
      "title": "Hidden Files and Directories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.001/",
      "source_url": "https://attack.mitre.org/techniques/T1564/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hidden Files and Directories. T1564.001 Hidden Files and Directories: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.002",
      "title": "Hidden Users",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.002/",
      "source_url": "https://attack.mitre.org/techniques/T1564/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hidden Users. T1564.002 Hidden Users: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.003",
      "title": "Hidden Window",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.003/",
      "source_url": "https://attack.mitre.org/techniques/T1564/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hidden Window. T1564.003 Hidden Window: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.004",
      "title": "NTFS File Attributes",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.004/",
      "source_url": "https://attack.mitre.org/techniques/T1564/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "NTFS File Attributes. T1564.004 NTFS File Attributes: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.005",
      "title": "Hidden File System",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.005/",
      "source_url": "https://attack.mitre.org/techniques/T1564/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hidden File System. T1564.005 Hidden File System: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.006",
      "title": "Run Virtual Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.006/",
      "source_url": "https://attack.mitre.org/techniques/T1564/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Run Virtual Instance. T1564.006 Run Virtual Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.007",
      "title": "VBA Stomping",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.007/",
      "source_url": "https://attack.mitre.org/techniques/T1564/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "VBA Stomping. T1564.007 VBA Stomping: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.008",
      "title": "Email Hiding Rules",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.008/",
      "source_url": "https://attack.mitre.org/techniques/T1564/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Hiding Rules. T1564.008 Email Hiding Rules: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.009",
      "title": "Resource Forking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.009/",
      "source_url": "https://attack.mitre.org/techniques/T1564/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Resource Forking. T1564.009 Resource Forking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.010",
      "title": "Process Argument Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.010/",
      "source_url": "https://attack.mitre.org/techniques/T1564/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Process Argument Spoofing. T1564.010 Process Argument Spoofing: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.011",
      "title": "Ignore Process Interrupts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.011/",
      "source_url": "https://attack.mitre.org/techniques/T1564/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Ignore Process Interrupts. T1564.011 Ignore Process Interrupts: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.012",
      "title": "File/Path Exclusions",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.012/",
      "source_url": "https://attack.mitre.org/techniques/T1564/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "File/Path Exclusions. T1564.012 File/Path Exclusions: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.013",
      "title": "Bind Mounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.013/",
      "source_url": "https://attack.mitre.org/techniques/T1564/013/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1564.013 Bind Mounts: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564.014",
      "title": "Extended Attributes",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564.014/",
      "source_url": "https://attack.mitre.org/techniques/T1564/014/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1564.014 Extended Attributes: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1564",
      "title": "Hide Artifacts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1564/",
      "source_url": "https://attack.mitre.org/techniques/T1564/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hide Artifacts. T1564 Hide Artifacts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1564",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1564/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565.001",
      "title": "Stored Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565.001/",
      "source_url": "https://attack.mitre.org/techniques/T1565/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Stored Data Manipulation. T1565.001 Stored Data Manipulation: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565.002",
      "title": "Transmitted Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565.002/",
      "source_url": "https://attack.mitre.org/techniques/T1565/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Transmitted Data Manipulation. T1565.002 Transmitted Data Manipulation: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565.003",
      "title": "Runtime Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565.003/",
      "source_url": "https://attack.mitre.org/techniques/T1565/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Runtime Data Manipulation. T1565.003 Runtime Data Manipulation: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1565",
      "title": "Data Manipulation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1565/",
      "source_url": "https://attack.mitre.org/techniques/T1565/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data Manipulation. T1565 Data Manipulation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1565",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1565/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.001",
      "title": "Spearphishing Attachment",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.001/",
      "source_url": "https://attack.mitre.org/techniques/T1566/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Attachment. T1566.001 Spearphishing Attachment: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.002",
      "title": "Spearphishing Link",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.002/",
      "source_url": "https://attack.mitre.org/techniques/T1566/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Link. T1566.002 Spearphishing Link: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.003",
      "title": "Spearphishing via Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.003/",
      "source_url": "https://attack.mitre.org/techniques/T1566/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing via Service. T1566.003 Spearphishing via Service: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566.004",
      "title": "Spearphishing Voice",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566.004/",
      "source_url": "https://attack.mitre.org/techniques/T1566/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Voice. T1566.004 Spearphishing Voice: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1566",
      "title": "Phishing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1566/",
      "source_url": "https://attack.mitre.org/techniques/T1566/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Phishing. T1566 Phishing: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1566",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1566/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.001",
      "title": "Exfiltration to Code Repository",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.001/",
      "source_url": "https://attack.mitre.org/techniques/T1567/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration to Code Repository. T1567.001 Exfiltration to Code Repository: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1567.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.002",
      "title": "Exfiltration to Cloud Storage",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.002/",
      "source_url": "https://attack.mitre.org/techniques/T1567/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration to Cloud Storage. T1567.002 Exfiltration to Cloud Storage: description, detection logic, threat actors, correlated…",
      "tags": [
        "ai-security",
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1567.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.003",
      "title": "Exfiltration to Text Storage Sites",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.003/",
      "source_url": "https://attack.mitre.org/techniques/T1567/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration to Text Storage Sites. T1567.003 Exfiltration to Text Storage Sites: description, detection logic, threat…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1567.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567.004",
      "title": "Exfiltration Over Webhook",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567.004/",
      "source_url": "https://attack.mitre.org/techniques/T1567/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Webhook. T1567.004 Exfiltration Over Webhook: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1567.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1567",
      "title": "Exfiltration Over Web Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1567/",
      "source_url": "https://attack.mitre.org/techniques/T1567/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exfiltration Over Web Service. T1567 Exfiltration Over Web Service: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1567",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1567/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568.001",
      "title": "Fast Flux DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568.001/",
      "source_url": "https://attack.mitre.org/techniques/T1568/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Fast Flux DNS. T1568.001 Fast Flux DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568.002",
      "title": "Domain Generation Algorithms",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568.002/",
      "source_url": "https://attack.mitre.org/techniques/T1568/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Generation Algorithms. T1568.002 Domain Generation Algorithms: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568.003",
      "title": "DNS Calculation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568.003/",
      "source_url": "https://attack.mitre.org/techniques/T1568/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DNS Calculation. T1568.003 DNS Calculation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1568",
      "title": "Dynamic Resolution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1568/",
      "source_url": "https://attack.mitre.org/techniques/T1568/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dynamic Resolution. T1568 Dynamic Resolution: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1568",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1568/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569.001",
      "title": "Launchctl",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569.001/",
      "source_url": "https://attack.mitre.org/techniques/T1569/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Launchctl. T1569.001 Launchctl: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569.002",
      "title": "Service Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569.002/",
      "source_url": "https://attack.mitre.org/techniques/T1569/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Service Execution. T1569.002 Service Execution: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569.003",
      "title": "Systemctl",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569.003/",
      "source_url": "https://attack.mitre.org/techniques/T1569/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1569.003 Systemctl: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1569",
      "title": "System Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1569/",
      "source_url": "https://attack.mitre.org/techniques/T1569/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Services. T1569 System Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1569",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1569/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1570",
      "title": "Lateral Tool Transfer",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1570/",
      "source_url": "https://attack.mitre.org/techniques/T1570/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Lateral Tool Transfer. T1570 Lateral Tool Transfer: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1570",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1570/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1571",
      "title": "Non-Standard Port",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1571/",
      "source_url": "https://attack.mitre.org/techniques/T1571/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Non-Standard Port. T1571 Non-Standard Port: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1571",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1571/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1572",
      "title": "Protocol Tunneling",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1572/",
      "source_url": "https://attack.mitre.org/techniques/T1572/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Protocol Tunneling. T1572 Protocol Tunneling: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1572",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1572/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1573.001",
      "title": "Symmetric Cryptography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1573.001/",
      "source_url": "https://attack.mitre.org/techniques/T1573/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Symmetric Cryptography. T1573.001 Symmetric Cryptography: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1573.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1573/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1573.002",
      "title": "Asymmetric Cryptography",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1573.002/",
      "source_url": "https://attack.mitre.org/techniques/T1573/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Asymmetric Cryptography. T1573.002 Asymmetric Cryptography: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1573.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1573/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1573",
      "title": "Encrypted Channel",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1573/",
      "source_url": "https://attack.mitre.org/techniques/T1573/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Encrypted Channel. T1573 Encrypted Channel: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1573",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1573/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.001",
      "title": "DLL Search Order Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.001/",
      "source_url": "https://attack.mitre.org/techniques/T1574/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DLL Search Order Hijacking. T1574.001 DLL Search Order Hijacking: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.002",
      "title": "DLL Side-Loading",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.002/",
      "source_url": "https://attack.mitre.org/techniques/T1574/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DLL Side-Loading. T1574.002 DLL Side-Loading: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.004",
      "title": "Dylib Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.004/",
      "source_url": "https://attack.mitre.org/techniques/T1574/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dylib Hijacking. T1574.004 Dylib Hijacking: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.005",
      "title": "Executable Installer File Permissions Weakness",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.005/",
      "source_url": "https://attack.mitre.org/techniques/T1574/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Executable Installer File Permissions Weakness. T1574.005 Executable Installer File Permissions Weakness…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.006",
      "title": "Dynamic Linker Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.006/",
      "source_url": "https://attack.mitre.org/techniques/T1574/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Dynamic Linker Hijacking. T1574.006 Dynamic Linker Hijacking: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.007",
      "title": "Path Interception by PATH Environment Variable",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.007/",
      "source_url": "https://attack.mitre.org/techniques/T1574/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Path Interception by PATH Environment Variable. T1574.007 Path Interception by PATH Environment Variable…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.008",
      "title": "Path Interception by Search Order Hijacking",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.008/",
      "source_url": "https://attack.mitre.org/techniques/T1574/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Path Interception by Search Order Hijacking. T1574.008 Path Interception by Search Order Hijacking: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.009",
      "title": "Path Interception by Unquoted Path",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.009/",
      "source_url": "https://attack.mitre.org/techniques/T1574/009/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Path Interception by Unquoted Path. T1574.009 Path Interception by Unquoted Path: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.009",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/009/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.010",
      "title": "Services File Permissions Weakness",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.010/",
      "source_url": "https://attack.mitre.org/techniques/T1574/010/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Services File Permissions Weakness. T1574.010 Services File Permissions Weakness: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.010",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/010/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.011",
      "title": "Services Registry Permissions Weakness",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.011/",
      "source_url": "https://attack.mitre.org/techniques/T1574/011/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Services Registry Permissions Weakness. T1574.011 Services Registry Permissions Weakness: description, detection…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.011",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/011/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.012",
      "title": "COR_PROFILER",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.012/",
      "source_url": "https://attack.mitre.org/techniques/T1574/012/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "COR_PROFILER. T1574.012 COR_PROFILER: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.012",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/012/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.013",
      "title": "KernelCallbackTable",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.013/",
      "source_url": "https://attack.mitre.org/techniques/T1574/013/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "KernelCallbackTable. T1574.013 KernelCallbackTable: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.013",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/013/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574.014",
      "title": "AppDomainManager",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574.014/",
      "source_url": "https://attack.mitre.org/techniques/T1574/014/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "AppDomainManager. T1574.014 AppDomainManager: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574.014",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/014/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1574",
      "title": "Hijack Execution Flow",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1574/",
      "source_url": "https://attack.mitre.org/techniques/T1574/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hijack Execution Flow. T1574 Hijack Execution Flow: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1574",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1574/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.001",
      "title": "Create Snapshot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.001/",
      "source_url": "https://attack.mitre.org/techniques/T1578/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Create Snapshot. T1578.001 Create Snapshot: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1578.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.002",
      "title": "Create Cloud Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.002/",
      "source_url": "https://attack.mitre.org/techniques/T1578/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Create Cloud Instance. T1578.002 Create Cloud Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.003",
      "title": "Delete Cloud Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.003/",
      "source_url": "https://attack.mitre.org/techniques/T1578/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Delete Cloud Instance. T1578.003 Delete Cloud Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.004",
      "title": "Revert Cloud Instance",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.004/",
      "source_url": "https://attack.mitre.org/techniques/T1578/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Revert Cloud Instance. T1578.004 Revert Cloud Instance: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578.005",
      "title": "Modify Cloud Compute Configurations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578.005/",
      "source_url": "https://attack.mitre.org/techniques/T1578/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Modify Cloud Compute Configurations. T1578.005 Modify Cloud Compute Configurations: description, detection logic, threat…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1578",
      "title": "Modify Cloud Compute Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1578/",
      "source_url": "https://attack.mitre.org/techniques/T1578/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Modify Cloud Compute Infrastructure. T1578 Modify Cloud Compute Infrastructure: description, detection logic, threat…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1578",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1578/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1580",
      "title": "Cloud Infrastructure Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1580/",
      "source_url": "https://attack.mitre.org/techniques/T1580/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Infrastructure Discovery. T1580 Cloud Infrastructure Discovery: description, detection logic, threat actors, correlated…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1580",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1580/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.001",
      "title": "Domains",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.001/",
      "source_url": "https://attack.mitre.org/techniques/T1583/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domains. T1583.001 Domains: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.002",
      "title": "DNS Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.002/",
      "source_url": "https://attack.mitre.org/techniques/T1583/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DNS Server. T1583.002 DNS Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.003",
      "title": "Virtual Private Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.003/",
      "source_url": "https://attack.mitre.org/techniques/T1583/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Virtual Private Server. T1583.003 Virtual Private Server: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.004",
      "title": "Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.004/",
      "source_url": "https://attack.mitre.org/techniques/T1583/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Server. T1583.004 Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.005",
      "title": "Botnet",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.005/",
      "source_url": "https://attack.mitre.org/techniques/T1583/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Botnet. T1583.005 Botnet: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.006",
      "title": "Web Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.006/",
      "source_url": "https://attack.mitre.org/techniques/T1583/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Services. T1583.006 Web Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.007",
      "title": "Serverless",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.007/",
      "source_url": "https://attack.mitre.org/techniques/T1583/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Serverless. T1583.007 Serverless: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583.008",
      "title": "Malvertising",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583.008/",
      "source_url": "https://attack.mitre.org/techniques/T1583/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malvertising. T1583.008 Malvertising: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1583",
      "title": "Acquire Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1583/",
      "source_url": "https://attack.mitre.org/techniques/T1583/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Acquire Infrastructure. T1583 Acquire Infrastructure: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1583",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1583/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.001",
      "title": "Domains",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.001/",
      "source_url": "https://attack.mitre.org/techniques/T1584/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domains. T1584.001 Domains: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.002",
      "title": "DNS Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.002/",
      "source_url": "https://attack.mitre.org/techniques/T1584/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DNS Server. T1584.002 DNS Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.003",
      "title": "Virtual Private Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.003/",
      "source_url": "https://attack.mitre.org/techniques/T1584/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Virtual Private Server. T1584.003 Virtual Private Server: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.004",
      "title": "Server",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.004/",
      "source_url": "https://attack.mitre.org/techniques/T1584/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Server. T1584.004 Server: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.005",
      "title": "Botnet",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.005/",
      "source_url": "https://attack.mitre.org/techniques/T1584/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Botnet. T1584.005 Botnet: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.006",
      "title": "Web Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.006/",
      "source_url": "https://attack.mitre.org/techniques/T1584/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Services. T1584.006 Web Services: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.007",
      "title": "Serverless",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.007/",
      "source_url": "https://attack.mitre.org/techniques/T1584/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Serverless. T1584.007 Serverless: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584.008",
      "title": "Network Devices",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584.008/",
      "source_url": "https://attack.mitre.org/techniques/T1584/008/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Devices. T1584.008 Network Devices: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584.008",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/008/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1584",
      "title": "Compromise Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1584/",
      "source_url": "https://attack.mitre.org/techniques/T1584/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compromise Infrastructure. T1584 Compromise Infrastructure: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1584",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1584/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585.001",
      "title": "Social Media Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585.001/",
      "source_url": "https://attack.mitre.org/techniques/T1585/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Social Media Accounts. T1585.001 Social Media Accounts: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1585.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585.002",
      "title": "Email Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585.002/",
      "source_url": "https://attack.mitre.org/techniques/T1585/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Accounts. T1585.002 Email Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1585.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585.003",
      "title": "Cloud Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585.003/",
      "source_url": "https://attack.mitre.org/techniques/T1585/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Accounts. T1585.003 Cloud Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1585.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1585",
      "title": "Establish Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1585/",
      "source_url": "https://attack.mitre.org/techniques/T1585/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Establish Accounts. T1585 Establish Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1585",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1585/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586.001",
      "title": "Social Media Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586.001/",
      "source_url": "https://attack.mitre.org/techniques/T1586/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Social Media Accounts. T1586.001 Social Media Accounts: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1586.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586.002",
      "title": "Email Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586.002/",
      "source_url": "https://attack.mitre.org/techniques/T1586/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Accounts. T1586.002 Email Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1586.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586.003",
      "title": "Cloud Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586.003/",
      "source_url": "https://attack.mitre.org/techniques/T1586/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Accounts. T1586.003 Cloud Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1586.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1586",
      "title": "Compromise Accounts",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1586/",
      "source_url": "https://attack.mitre.org/techniques/T1586/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Compromise Accounts. T1586 Compromise Accounts: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1586",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1586/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.001",
      "title": "Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.001/",
      "source_url": "https://attack.mitre.org/techniques/T1587/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malware. T1587.001 Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "t1587.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.002",
      "title": "Code Signing Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.002/",
      "source_url": "https://attack.mitre.org/techniques/T1587/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Code Signing Certificates. T1587.002 Code Signing Certificates: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1587.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.003",
      "title": "Digital Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.003/",
      "source_url": "https://attack.mitre.org/techniques/T1587/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Digital Certificates. T1587.003 Digital Certificates: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1587.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587.004",
      "title": "Exploits",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587.004/",
      "source_url": "https://attack.mitre.org/techniques/T1587/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploits. T1587.004 Exploits: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1587.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1587",
      "title": "Develop Capabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1587/",
      "source_url": "https://attack.mitre.org/techniques/T1587/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Develop Capabilities. T1587 Develop Capabilities: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1587",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1587/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.001",
      "title": "Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.001/",
      "source_url": "https://attack.mitre.org/techniques/T1588/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Malware. T1588.001 Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "t1588.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.002",
      "title": "Tool",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.002/",
      "source_url": "https://attack.mitre.org/techniques/T1588/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Tool. T1588.002 Tool: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.003",
      "title": "Code Signing Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.003/",
      "source_url": "https://attack.mitre.org/techniques/T1588/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Code Signing Certificates. T1588.003 Code Signing Certificates: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.004",
      "title": "Digital Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.004/",
      "source_url": "https://attack.mitre.org/techniques/T1588/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Digital Certificates. T1588.004 Digital Certificates: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.005",
      "title": "Exploits",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.005/",
      "source_url": "https://attack.mitre.org/techniques/T1588/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Exploits. T1588.005 Exploits: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1588.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.006",
      "title": "Vulnerabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.006/",
      "source_url": "https://attack.mitre.org/techniques/T1588/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Vulnerabilities. T1588.006 Vulnerabilities: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588.007",
      "title": "Artificial Intelligence",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588.007/",
      "source_url": "https://attack.mitre.org/techniques/T1588/007/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Artificial Intelligence. T1588.007 Artificial Intelligence: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1588.007",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/007/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1588",
      "title": "Obtain Capabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1588/",
      "source_url": "https://attack.mitre.org/techniques/T1588/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Obtain Capabilities. T1588 Obtain Capabilities: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1588",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1588/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589.001",
      "title": "Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589.001/",
      "source_url": "https://attack.mitre.org/techniques/T1589/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Credentials. T1589.001 Credentials: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1589.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589.002",
      "title": "Email Addresses",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589.002/",
      "source_url": "https://attack.mitre.org/techniques/T1589/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Email Addresses. T1589.002 Email Addresses: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1589.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589.003",
      "title": "Employee Names",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589.003/",
      "source_url": "https://attack.mitre.org/techniques/T1589/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Employee Names. T1589.003 Employee Names: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1589.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1589",
      "title": "Gather Victim Identity Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1589/",
      "source_url": "https://attack.mitre.org/techniques/T1589/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gather Victim Identity Information. T1589 Gather Victim Identity Information: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "identity-security",
        "mitre-attack",
        "t1589",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1589/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.001",
      "title": "Domain Properties",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.001/",
      "source_url": "https://attack.mitre.org/techniques/T1590/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Domain Properties. T1590.001 Domain Properties: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.002",
      "title": "DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.002/",
      "source_url": "https://attack.mitre.org/techniques/T1590/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DNS. T1590.002 DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.003",
      "title": "Network Trust Dependencies",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.003/",
      "source_url": "https://attack.mitre.org/techniques/T1590/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Trust Dependencies. T1590.003 Network Trust Dependencies: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.004",
      "title": "Network Topology",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.004/",
      "source_url": "https://attack.mitre.org/techniques/T1590/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Topology. T1590.004 Network Topology: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.005",
      "title": "IP Addresses",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.005/",
      "source_url": "https://attack.mitre.org/techniques/T1590/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "IP Addresses. T1590.005 IP Addresses: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590.006",
      "title": "Network Security Appliances",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590.006/",
      "source_url": "https://attack.mitre.org/techniques/T1590/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Security Appliances. T1590.006 Network Security Appliances: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1590",
      "title": "Gather Victim Network Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1590/",
      "source_url": "https://attack.mitre.org/techniques/T1590/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gather Victim Network Information. T1590 Gather Victim Network Information: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1590",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1590/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.001",
      "title": "Determine Physical Locations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.001/",
      "source_url": "https://attack.mitre.org/techniques/T1591/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Determine Physical Locations. T1591.001 Determine Physical Locations: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.002",
      "title": "Business Relationships",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.002/",
      "source_url": "https://attack.mitre.org/techniques/T1591/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Business Relationships. T1591.002 Business Relationships: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.003",
      "title": "Identify Business Tempo",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.003/",
      "source_url": "https://attack.mitre.org/techniques/T1591/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Identify Business Tempo. T1591.003 Identify Business Tempo: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591.004",
      "title": "Identify Roles",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591.004/",
      "source_url": "https://attack.mitre.org/techniques/T1591/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Identify Roles. T1591.004 Identify Roles: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1591",
      "title": "Gather Victim Org Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1591/",
      "source_url": "https://attack.mitre.org/techniques/T1591/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gather Victim Org Information. T1591 Gather Victim Org Information: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1591",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1591/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.001",
      "title": "Hardware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.001/",
      "source_url": "https://attack.mitre.org/techniques/T1592/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hardware. T1592.001 Hardware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1592.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.002",
      "title": "Software",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.002/",
      "source_url": "https://attack.mitre.org/techniques/T1592/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Software. T1592.002 Software: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1592.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.003",
      "title": "Firmware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.003/",
      "source_url": "https://attack.mitre.org/techniques/T1592/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Firmware. T1592.003 Firmware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "embedded-security",
        "generated-reference",
        "hardware-security",
        "mitre-attack",
        "t1592.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592.004",
      "title": "Client Configurations",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592.004/",
      "source_url": "https://attack.mitre.org/techniques/T1592/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Client Configurations. T1592.004 Client Configurations: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1592.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1592",
      "title": "Gather Victim Host Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1592/",
      "source_url": "https://attack.mitre.org/techniques/T1592/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Gather Victim Host Information. T1592 Gather Victim Host Information: description, detection logic, threat actors, correlated…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1592",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1592/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593.001",
      "title": "Social Media",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593.001/",
      "source_url": "https://attack.mitre.org/techniques/T1593/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Social Media. T1593.001 Social Media: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593.002",
      "title": "Search Engines",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593.002/",
      "source_url": "https://attack.mitre.org/techniques/T1593/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Search Engines. T1593.002 Search Engines: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593.003",
      "title": "Code Repositories",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593.003/",
      "source_url": "https://attack.mitre.org/techniques/T1593/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Code Repositories. T1593.003 Code Repositories: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1593",
      "title": "Search Open Websites/Domains",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1593/",
      "source_url": "https://attack.mitre.org/techniques/T1593/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Search Open Websites/Domains. T1593 Search Open Websites/Domains: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1593",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1593/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1594",
      "title": "Search Victim-Owned Websites",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1594/",
      "source_url": "https://attack.mitre.org/techniques/T1594/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Search Victim-Owned Websites. T1594 Search Victim-Owned Websites: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1594",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1594/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595.001",
      "title": "Scanning IP Blocks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595.001/",
      "source_url": "https://attack.mitre.org/techniques/T1595/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scanning IP Blocks. T1595.001 Scanning IP Blocks: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595.002",
      "title": "Vulnerability Scanning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595.002/",
      "source_url": "https://attack.mitre.org/techniques/T1595/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Vulnerability Scanning. T1595.002 Vulnerability Scanning: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595.003",
      "title": "Wordlist Scanning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595.003/",
      "source_url": "https://attack.mitre.org/techniques/T1595/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Wordlist Scanning. T1595.003 Wordlist Scanning: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1595",
      "title": "Active Scanning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1595/",
      "source_url": "https://attack.mitre.org/techniques/T1595/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Active Scanning. T1595 Active Scanning: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1595",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1595/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.001",
      "title": "DNS/Passive DNS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.001/",
      "source_url": "https://attack.mitre.org/techniques/T1596/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "DNS/Passive DNS. T1596.001 DNS/Passive DNS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.002",
      "title": "WHOIS",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.002/",
      "source_url": "https://attack.mitre.org/techniques/T1596/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "WHOIS. T1596.002 WHOIS: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.003",
      "title": "Digital Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.003/",
      "source_url": "https://attack.mitre.org/techniques/T1596/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Digital Certificates. T1596.003 Digital Certificates: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.004",
      "title": "CDNs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.004/",
      "source_url": "https://attack.mitre.org/techniques/T1596/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "CDNs. T1596.004 CDNs: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem research.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596.005",
      "title": "Scan Databases",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596.005/",
      "source_url": "https://attack.mitre.org/techniques/T1596/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Scan Databases. T1596.005 Scan Databases: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1596",
      "title": "Search Open Technical Databases",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1596/",
      "source_url": "https://attack.mitre.org/techniques/T1596/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Search Open Technical Databases. T1596 Search Open Technical Databases: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1596",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1596/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1597.001",
      "title": "Threat Intel Vendors",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1597.001/",
      "source_url": "https://attack.mitre.org/techniques/T1597/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Threat Intel Vendors. T1597.001 Threat Intel Vendors: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1597.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1597/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1597.002",
      "title": "Purchase Technical Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1597.002/",
      "source_url": "https://attack.mitre.org/techniques/T1597/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Purchase Technical Data. T1597.002 Purchase Technical Data: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1597.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1597/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1597",
      "title": "Search Closed Sources",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1597/",
      "source_url": "https://attack.mitre.org/techniques/T1597/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Search Closed Sources. T1597 Search Closed Sources: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1597",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1597/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.001",
      "title": "Spearphishing Service",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.001/",
      "source_url": "https://attack.mitre.org/techniques/T1598/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Service. T1598.001 Spearphishing Service: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.002",
      "title": "Spearphishing Attachment",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.002/",
      "source_url": "https://attack.mitre.org/techniques/T1598/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Attachment. T1598.002 Spearphishing Attachment: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.003",
      "title": "Spearphishing Link",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.003/",
      "source_url": "https://attack.mitre.org/techniques/T1598/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Link. T1598.003 Spearphishing Link: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598.004",
      "title": "Spearphishing Voice",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598.004/",
      "source_url": "https://attack.mitre.org/techniques/T1598/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Spearphishing Voice. T1598.004 Spearphishing Voice: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1598",
      "title": "Phishing for Information",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1598/",
      "source_url": "https://attack.mitre.org/techniques/T1598/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Phishing for Information. T1598 Phishing for Information: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1598",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1598/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1599.001",
      "title": "Network Address Translation Traversal",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1599.001/",
      "source_url": "https://attack.mitre.org/techniques/T1599/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Address Translation Traversal. T1599.001 Network Address Translation Traversal: description, detection logic…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1599.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1599/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1599",
      "title": "Network Boundary Bridging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1599/",
      "source_url": "https://attack.mitre.org/techniques/T1599/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Boundary Bridging. T1599 Network Boundary Bridging: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1599",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1599/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1600.001",
      "title": "Reduce Key Space",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1600.001/",
      "source_url": "https://attack.mitre.org/techniques/T1600/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Reduce Key Space. T1600.001 Reduce Key Space: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1600.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1600/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1600.002",
      "title": "Disable Crypto Hardware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1600.002/",
      "source_url": "https://attack.mitre.org/techniques/T1600/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Disable Crypto Hardware. T1600.002 Disable Crypto Hardware: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "embedded-security",
        "generated-reference",
        "mitre-attack",
        "t1600.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1600/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1600",
      "title": "Weaken Encryption",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1600/",
      "source_url": "https://attack.mitre.org/techniques/T1600/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Weaken Encryption. T1600 Weaken Encryption: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1600",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1600/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1601.001",
      "title": "Patch System Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1601.001/",
      "source_url": "https://attack.mitre.org/techniques/T1601/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Patch System Image. T1601.001 Patch System Image: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1601.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1601/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1601.002",
      "title": "Downgrade System Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1601.002/",
      "source_url": "https://attack.mitre.org/techniques/T1601/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Downgrade System Image. T1601.002 Downgrade System Image: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1601.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1601/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1601",
      "title": "Modify System Image",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1601/",
      "source_url": "https://attack.mitre.org/techniques/T1601/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Modify System Image. T1601 Modify System Image: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1601",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1601/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1602.001",
      "title": "SNMP (MIB Dump)",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1602.001/",
      "source_url": "https://attack.mitre.org/techniques/T1602/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SNMP (MIB Dump). T1602.001 SNMP (MIB Dump): description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1602.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1602/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1602.002",
      "title": "Network Device Configuration Dump",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1602.002/",
      "source_url": "https://attack.mitre.org/techniques/T1602/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Network Device Configuration Dump. T1602.002 Network Device Configuration Dump: description, detection logic, threat…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1602.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1602/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1602",
      "title": "Data from Configuration Repository",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1602/",
      "source_url": "https://attack.mitre.org/techniques/T1602/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Data from Configuration Repository. T1602 Data from Configuration Repository: description, detection logic, threat actors…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1602",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1602/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1606.001",
      "title": "Web Cookies",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1606.001/",
      "source_url": "https://attack.mitre.org/techniques/T1606/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Web Cookies. T1606.001 Web Cookies: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1606.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1606/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1606.002",
      "title": "SAML Tokens",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1606.002/",
      "source_url": "https://attack.mitre.org/techniques/T1606/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SAML Tokens. T1606.002 SAML Tokens: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "identity-and-access",
        "mitre-attack",
        "t1606.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1606/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1606",
      "title": "Forge Web Credentials",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1606/",
      "source_url": "https://attack.mitre.org/techniques/T1606/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Forge Web Credentials. T1606 Forge Web Credentials: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1606",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1606/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.001",
      "title": "Upload Malware",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.001/",
      "source_url": "https://attack.mitre.org/techniques/T1608/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Upload Malware. T1608.001 Upload Malware: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "malware-analysis",
        "malware-behavior",
        "mitre-attack",
        "t1608.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.002",
      "title": "Upload Tool",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.002/",
      "source_url": "https://attack.mitre.org/techniques/T1608/002/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Upload Tool. T1608.002 Upload Tool: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.003",
      "title": "Install Digital Certificate",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.003/",
      "source_url": "https://attack.mitre.org/techniques/T1608/003/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Install Digital Certificate. T1608.003 Install Digital Certificate: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.004",
      "title": "Drive-by Target",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.004/",
      "source_url": "https://attack.mitre.org/techniques/T1608/004/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Drive-by Target. T1608.004 Drive-by Target: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.005",
      "title": "Link Target",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.005/",
      "source_url": "https://attack.mitre.org/techniques/T1608/005/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Link Target. T1608.005 Link Target: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608.006",
      "title": "SEO Poisoning",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608.006/",
      "source_url": "https://attack.mitre.org/techniques/T1608/006/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "SEO Poisoning. T1608.006 SEO Poisoning: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1608",
      "title": "Stage Capabilities",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1608/",
      "source_url": "https://attack.mitre.org/techniques/T1608/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Stage Capabilities. T1608 Stage Capabilities: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1608",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1608/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1609",
      "title": "Container Administration Command",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1609/",
      "source_url": "https://attack.mitre.org/techniques/T1609/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Container Administration Command. T1609 Container Administration Command: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1609",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1609/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1610",
      "title": "Deploy Container",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1610/",
      "source_url": "https://attack.mitre.org/techniques/T1610/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Deploy Container. T1610 Deploy Container: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1610",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1610/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1611",
      "title": "Escape to Host",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1611/",
      "source_url": "https://attack.mitre.org/techniques/T1611/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Escape to Host. T1611 Escape to Host: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1611",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1611/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1612",
      "title": "Build Image on Host",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1612/",
      "source_url": "https://attack.mitre.org/techniques/T1612/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Build Image on Host. T1612 Build Image on Host: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1612",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1612/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1613",
      "title": "Container and Resource Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1613/",
      "source_url": "https://attack.mitre.org/techniques/T1613/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Container and Resource Discovery. T1613 Container and Resource Discovery: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1613",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1613/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1614.001",
      "title": "System Language Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1614.001/",
      "source_url": "https://attack.mitre.org/techniques/T1614/001/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Language Discovery. T1614.001 System Language Discovery: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1614.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1614/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1614",
      "title": "System Location Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1614/",
      "source_url": "https://attack.mitre.org/techniques/T1614/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "System Location Discovery. T1614 System Location Discovery: description, detection logic, threat actors, correlated CTI reports…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1614",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1614/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1615",
      "title": "Group Policy Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1615/",
      "source_url": "https://attack.mitre.org/techniques/T1615/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Group Policy Discovery. T1615 Group Policy Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1615",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1615/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1619",
      "title": "Cloud Storage Object Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1619/",
      "source_url": "https://attack.mitre.org/techniques/T1619/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Storage Object Discovery. T1619 Cloud Storage Object Discovery: description, detection logic, threat actors, correlated…",
      "tags": [
        "ai-security",
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1619",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1619/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1620",
      "title": "Reflective Code Loading",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1620/",
      "source_url": "https://attack.mitre.org/techniques/T1620/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Reflective Code Loading. T1620 Reflective Code Loading: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1620",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1620/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1621",
      "title": "Multi-Factor Authentication Request Generation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1621/",
      "source_url": "https://attack.mitre.org/techniques/T1621/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Multi-Factor Authentication Request Generation. T1621 Multi-Factor Authentication Request Generation…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1621",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1621/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1622",
      "title": "Debugger Evasion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1622/",
      "source_url": "https://attack.mitre.org/techniques/T1622/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Debugger Evasion. T1622 Debugger Evasion: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1622",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1622/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1647",
      "title": "Plist File Modification",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1647/",
      "source_url": "https://attack.mitre.org/techniques/T1647/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Plist File Modification. T1647 Plist File Modification: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1647",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1647/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1648",
      "title": "Serverless Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1648/",
      "source_url": "https://attack.mitre.org/techniques/T1648/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Serverless Execution. T1648 Serverless Execution: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1648",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1648/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1649",
      "title": "Steal or Forge Authentication Certificates",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1649/",
      "source_url": "https://attack.mitre.org/techniques/T1649/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Steal or Forge Authentication Certificates. T1649 Steal or Forge Authentication Certificates: description…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1649",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1649/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1650",
      "title": "Acquire Access",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1650/",
      "source_url": "https://attack.mitre.org/techniques/T1650/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Acquire Access. T1650 Acquire Access: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1650",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1650/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1651",
      "title": "Cloud Administration Command",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1651/",
      "source_url": "https://attack.mitre.org/techniques/T1651/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Cloud Administration Command. T1651 Cloud Administration Command: description, detection logic, threat actors, correlated CTI…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1651",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1651/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1652",
      "title": "Device Driver Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1652/",
      "source_url": "https://attack.mitre.org/techniques/T1652/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Device Driver Discovery. T1652 Device Driver Discovery: description, detection logic, threat actors, correlated CTI reports, hunts…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1652",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1652/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1653",
      "title": "Power Settings",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1653/",
      "source_url": "https://attack.mitre.org/techniques/T1653/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Power Settings. T1653 Power Settings: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1653",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1653/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1654",
      "title": "Log Enumeration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1654/",
      "source_url": "https://attack.mitre.org/techniques/T1654/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Log Enumeration. T1654 Log Enumeration: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1654",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1654/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1656",
      "title": "Impersonation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1656/",
      "source_url": "https://attack.mitre.org/techniques/T1656/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Impersonation. T1656 Impersonation: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and ecosystem…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1656",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1656/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1657",
      "title": "Financial Theft",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1657/",
      "source_url": "https://attack.mitre.org/techniques/T1657/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Financial Theft. T1657 Financial Theft: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1657",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1657/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1659",
      "title": "Content Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1659/",
      "source_url": "https://attack.mitre.org/techniques/T1659/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Content Injection. T1659 Content Injection: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations, and…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1659",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1659/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1665",
      "title": "Hide Infrastructure",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1665/",
      "source_url": "https://attack.mitre.org/techniques/T1665/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Hide Infrastructure. T1665 Hide Infrastructure: description, detection logic, threat actors, correlated CTI reports, hunts, mitigations…",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1665",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1665/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1666",
      "title": "Modify Cloud Resource Hierarchy",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1666/",
      "source_url": "https://attack.mitre.org/techniques/T1666/",
      "published_at": null,
      "updated_at": "2026-06-27",
      "summary": "Modify Cloud Resource Hierarchy. T1666 Modify Cloud Resource Hierarchy: description, detection logic, threat actors…",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1666",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1666/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1667",
      "title": "Email Bombing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1667/",
      "source_url": "https://attack.mitre.org/techniques/T1667/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1667 Email Bombing: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1667",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1667/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1668",
      "title": "Exclusive Control",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1668/",
      "source_url": "https://attack.mitre.org/techniques/T1668/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1668 Exclusive Control: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1668",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1668/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1669",
      "title": "Wi-Fi Networks",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1669/",
      "source_url": "https://attack.mitre.org/techniques/T1669/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1669 Wi-Fi Networks: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1669",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1669/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1671",
      "title": "Cloud Application Integration",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1671/",
      "source_url": "https://attack.mitre.org/techniques/T1671/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1671 Cloud Application Integration: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1671",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1671/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1673",
      "title": "Virtual Machine Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1673/",
      "source_url": "https://attack.mitre.org/techniques/T1673/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1673 Virtual Machine Discovery: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1673",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1673/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1674",
      "title": "Input Injection",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1674/",
      "source_url": "https://attack.mitre.org/techniques/T1674/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1674 Input Injection: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1674",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1674/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1675",
      "title": "ESXi Administration Command",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1675/",
      "source_url": "https://attack.mitre.org/techniques/T1675/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1675 ESXi Administration Command: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1675",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1675/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1677",
      "title": "Poisoned Pipeline Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1677/",
      "source_url": "https://attack.mitre.org/techniques/T1677/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1677 Poisoned Pipeline Execution: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1677",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1677/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1678",
      "title": "Delay Execution",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1678/",
      "source_url": "https://attack.mitre.org/techniques/T1678/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1678 Delay Execution: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1678",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1678/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1679",
      "title": "Selective Exclusion",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1679/",
      "source_url": "https://attack.mitre.org/techniques/T1679/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1679 Selective Exclusion: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1679",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1679/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1680",
      "title": "Local Storage Discovery",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1680/",
      "source_url": "https://attack.mitre.org/techniques/T1680/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1680 Local Storage Discovery: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1680",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1680/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1681",
      "title": "Search Threat Vendor Data",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1681/",
      "source_url": "https://attack.mitre.org/techniques/T1681/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1681 Search Threat Vendor Data: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1681",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1681/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1682",
      "title": "Query Public AI Services",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1682/",
      "source_url": "https://attack.mitre.org/techniques/T1682/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1682 Query Public AI Services: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "ai-security",
        "generated-reference",
        "mitre-attack",
        "t1682",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1682/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1683.001",
      "title": "Written Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1683.001/",
      "source_url": "https://attack.mitre.org/techniques/T1683/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1683.001 Written Content: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1683.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1683/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1683.002",
      "title": "Audio-Visual Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1683.002/",
      "source_url": "https://attack.mitre.org/techniques/T1683/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1683.002 Audio-Visual Content: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1683.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1683/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1683",
      "title": "Generate Content",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1683/",
      "source_url": "https://attack.mitre.org/techniques/T1683/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1683 Generate Content: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1683",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1683/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1684.001",
      "title": "Impersonation",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1684.001/",
      "source_url": "https://attack.mitre.org/techniques/T1684/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1684.001 Impersonation: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1684.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1684/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1684.002",
      "title": "Email Spoofing",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1684.002/",
      "source_url": "https://attack.mitre.org/techniques/T1684/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1684.002 Email Spoofing: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1684.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1684/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1684",
      "title": "Social Engineering",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1684/",
      "source_url": "https://attack.mitre.org/techniques/T1684/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1684 Social Engineering: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1684",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1684/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.001",
      "title": "Disable or Modify Windows Event Log",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.001/",
      "source_url": "https://attack.mitre.org/techniques/T1685/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.001 Disable or Modify Windows Event Log: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.002",
      "title": "Disable or Modify Cloud Log",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.002/",
      "source_url": "https://attack.mitre.org/techniques/T1685/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.002 Disable or Modify Cloud Log: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1685.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.003",
      "title": "Modify or Spoof Tool UI",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.003/",
      "source_url": "https://attack.mitre.org/techniques/T1685/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.003 Modify or Spoof Tool UI: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.004",
      "title": "Disable or Modify Linux Audit System Log",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.004/",
      "source_url": "https://attack.mitre.org/techniques/T1685/004/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.004 Disable or Modify Linux Audit System Log: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.004",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/004/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.005",
      "title": "Clear Windows Event Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.005/",
      "source_url": "https://attack.mitre.org/techniques/T1685/005/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.005 Clear Windows Event Logs: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.005",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/005/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685.006",
      "title": "Clear Linux or Mac System Logs",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685.006/",
      "source_url": "https://attack.mitre.org/techniques/T1685/006/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685.006 Clear Linux or Mac System Logs: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685.006",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/006/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1685",
      "title": "Disable or Modify Tools",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1685/",
      "source_url": "https://attack.mitre.org/techniques/T1685/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1685 Disable or Modify Tools: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1685",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1685/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686.001",
      "title": "Cloud Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686.001/",
      "source_url": "https://attack.mitre.org/techniques/T1686/001/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686.001 Cloud Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "cloud-security",
        "generated-reference",
        "mitre-attack",
        "t1686.001",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/001/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686.002",
      "title": "Network Device Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686.002/",
      "source_url": "https://attack.mitre.org/techniques/T1686/002/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686.002 Network Device Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1686.002",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/002/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686.003",
      "title": "Windows Host Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686.003/",
      "source_url": "https://attack.mitre.org/techniques/T1686/003/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686.003 Windows Host Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1686.003",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/003/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1686",
      "title": "Disable or Modify System Firewall",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1686/",
      "source_url": "https://attack.mitre.org/techniques/T1686/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1686 Disable or Modify System Firewall: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1686",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1686/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1687",
      "title": "Exploitation for Defense Impairment",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1687/",
      "source_url": "https://attack.mitre.org/techniques/T1687/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1687 Exploitation for Defense Impairment: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "offensive-security",
        "t1687",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1687/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1688",
      "title": "Safe Mode Boot",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1688/",
      "source_url": "https://attack.mitre.org/techniques/T1688/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1688 Safe Mode Boot: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1688",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1688/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1689",
      "title": "Downgrade Attack",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1689/",
      "source_url": "https://attack.mitre.org/techniques/T1689/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1689 Downgrade Attack: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1689",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1689/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "site:threat-matrix:techniques:t1690",
      "title": "Prevent Command History Logging",
      "primary_type": "generated-reference",
      "primary_domain": "threat-intelligence",
      "audience": [
        "cti-analyst"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "current published 1200km content",
      "canonical_url": "https://1200km.com/threat-matrix/techniques/T1690/",
      "source_url": "https://attack.mitre.org/techniques/T1690/",
      "published_at": "2026-07-29",
      "updated_at": "2026-07-29",
      "summary": "T1690 Prevent Command History Logging: ATT&CK behavior, detection strategies, mitigations, groups, and Cyber Knowledge context.",
      "tags": [
        "generated-reference",
        "mitre-attack",
        "t1690",
        "threat-intelligence"
      ],
      "featured": false,
      "indexable": true,
      "source_platform": "MITRE ATT&CK",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://attack.mitre.org/techniques/T1690/",
      "canonical_owner": "1200km / Andrey Pautov",
      "collection_tier": "reference",
      "lifecycle": "stable-reference"
    },
    {
      "id": "github-com:anpa1200:aidebug",
      "title": "AIDebug",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer",
        "cti-analyst"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "1.1.0",
      "applies_to": "released malware triage and reverse-engineering assistant",
      "canonical_url": "https://github.com/anpa1200/AIDebug",
      "source_url": "https://pypi.org/project/1200km-aidebug/",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "AI-assisted malware triage and reverse-engineering tool with ATT&CK candidates, YARA seeds, IOC output, and analyst reports.",
      "tags": [
        "malware-analysis",
        "reverse-engineering",
        "tool",
        "yara"
      ],
      "featured": true,
      "indexable": false,
      "source_platform": "PyPI",
      "source_repository": "https://github.com/anpa1200/AIDebug",
      "original_publication": "https://pypi.org/project/1200km-aidebug/",
      "canonical_owner": "anpa1200",
      "collection_tier": "core",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:auditai",
      "title": "AuditAI",
      "primary_type": "tool",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "1.0.0",
      "applies_to": "authorized Linux host vulnerability assessment",
      "canonical_url": "https://github.com/anpa1200/AuditAI",
      "source_url": "https://pypi.org/project/1200km-auditai/",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Linux host vulnerability assessment tool with optional AI-assisted review.",
      "tags": [
        "linux",
        "offensive-security",
        "tool",
        "vulnerability-assessment"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "PyPI",
      "source_repository": "https://github.com/anpa1200/AuditAI",
      "original_publication": "https://pypi.org/project/1200km-auditai/",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:basic-file-information-gathering-script",
      "title": "FileInfo",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "current-development",
      "maturity": "beta",
      "evidence_level": "source-backed",
      "applies_to": "source repository; the advertised PyPI target was not published when verified",
      "canonical_url": "https://github.com/anpa1200/Basic-File-Information-Gathering-Script",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "First-pass file metadata, hashing, strings, entropy, YARA, and static-triage utility under development.",
      "tags": [
        "current-development",
        "file-triage",
        "malware-analysis",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Basic-File-Information-Gathering-Script",
      "original_publication": "https://github.com/anpa1200/Basic-File-Information-Gathering-Script",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "current-development"
    },
    {
      "id": "github-com:anpa1200:lpi",
      "title": "lpi",
      "primary_type": "tool",
      "primary_domain": "offensive-research",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/lpi",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical repository retained for reference and marked archived by GitHub.",
      "tags": [
        "archived",
        "offensive-security",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/lpi",
      "original_publication": "https://github.com/anpa1200/lpi",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:malware-analysis",
      "title": "Malware_analysis",
      "primary_type": "research",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/Malware_analysis",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical malware-analysis repository retained for reference and marked archived by GitHub.",
      "tags": [
        "archived",
        "malware-analysis",
        "research"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Malware_analysis",
      "original_publication": "https://github.com/anpa1200/Malware_analysis",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:networking",
      "title": "Networking",
      "primary_type": "research",
      "primary_domain": "network-security",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/Networking",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical networking repository retained for reference and marked archived by GitHub.",
      "tags": [
        "archived",
        "networking",
        "research"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Networking",
      "original_publication": "https://github.com/anpa1200/Networking",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:pe-import-analyzer",
      "title": "PE Import Analyzer",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "current-development",
      "maturity": "beta",
      "evidence_level": "source-backed",
      "applies_to": "source repository; the advertised PyPI target was not published when verified",
      "canonical_url": "https://github.com/anpa1200/PE-Import-Analyzer",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "PE import-table capability triage utility under development for malware analysts.",
      "tags": [
        "current-development",
        "malware-analysis",
        "pe",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/PE-Import-Analyzer",
      "original_publication": "https://github.com/anpa1200/PE-Import-Analyzer",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "current-development"
    },
    {
      "id": "github-com:anpa1200:stratus-ai",
      "title": "stratus-ai",
      "primary_type": "tool",
      "primary_domain": "cloud-security",
      "audience": [
        "security-engineer",
        "detection-engineer"
      ],
      "status": "maintained",
      "maturity": "stable",
      "evidence_level": "source-backed",
      "applies_to": "authorized AWS and GCP security assessment",
      "canonical_url": "https://github.com/anpa1200/stratus-ai",
      "published_at": null,
      "updated_at": null,
      "summary": "Multi-cloud security assessment and detection-coverage tool for authorized AWS and GCP environments.",
      "tags": [
        "aws",
        "cloud-security",
        "gcp",
        "tool"
      ],
      "featured": true,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/stratus-ai",
      "original_publication": "https://github.com/anpa1200/stratus-ai",
      "canonical_owner": "anpa1200",
      "collection_tier": "core",
      "lifecycle": "currentness-unknown"
    },
    {
      "id": "github-com:anpa1200:string-analyzer",
      "title": "String Analyzer",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "released",
      "maturity": "stable",
      "evidence_level": "release-evidence",
      "version": "2.0.0",
      "applies_to": "released binary-string triage utility",
      "canonical_url": "https://github.com/anpa1200/String-Analyzer",
      "source_url": "https://pypi.org/project/string-analyzer/",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Extracts strings, URLs, IP addresses, registry keys, APIs, and analyst prompts from binary files.",
      "tags": [
        "ioc",
        "malware-analysis",
        "static-analysis",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "PyPI",
      "source_repository": "https://github.com/anpa1200/String-Analyzer",
      "original_publication": "https://pypi.org/project/string-analyzer/",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "github-com:anpa1200:systemcheck",
      "title": "SystemCheck",
      "primary_type": "tool",
      "primary_domain": "application-security",
      "audience": [
        "security-engineer"
      ],
      "status": "archived",
      "maturity": "historical",
      "evidence_level": "source-backed",
      "applies_to": "historical repository",
      "canonical_url": "https://github.com/anpa1200/SystemCheck",
      "published_at": null,
      "updated_at": null,
      "summary": "Historical system-checking repository retained for reference and marked archived by GitHub.",
      "tags": [
        "application-security",
        "archived",
        "tool"
      ],
      "featured": false,
      "indexable": false,
      "archive_reason": "The repository is marked archived by GitHub and is not presented as maintained.",
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/SystemCheck",
      "original_publication": "https://github.com/anpa1200/SystemCheck",
      "canonical_owner": "anpa1200",
      "collection_tier": "archive",
      "lifecycle": "archived"
    },
    {
      "id": "github-com:anpa1200:unpacker",
      "title": "Unpacker",
      "primary_type": "tool",
      "primary_domain": "malware-analysis",
      "audience": [
        "security-engineer"
      ],
      "status": "current-development",
      "maturity": "beta",
      "evidence_level": "source-backed",
      "applies_to": "source repository; the advertised PyPI target was not published when verified",
      "canonical_url": "https://github.com/anpa1200/Unpacker",
      "published_at": null,
      "updated_at": "2026-07-21",
      "summary": "Packer detection and unpacking workflow under development for malware triage.",
      "tags": [
        "current-development",
        "malware-analysis",
        "tool",
        "unpacking"
      ],
      "featured": false,
      "indexable": false,
      "source_platform": "GitHub",
      "source_repository": "https://github.com/anpa1200/Unpacker",
      "original_publication": "https://github.com/anpa1200/Unpacker",
      "canonical_owner": "anpa1200",
      "collection_tier": "reference",
      "lifecycle": "current-development"
    },
    {
      "id": "trainsec-net:library:career-guides:cybersecurity-salaries",
      "title": "Cybersecurity Salaries: How Much Can You Earn in Different Roles?",
      "primary_type": "mirror",
      "primary_domain": "professional-profile",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/career-guides/cybersecurity-salaries/",
      "source_url": "https://trainsec.net/library/career-guides/cybersecurity-salaries/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/career-guides-cybersecurity-salaries.html"
      ],
      "published_at": "2026-05-04",
      "updated_at": "2026-09-04",
      "summary": "Cybersecurity is often seen as a high-paying field, and in many cases, that reputation is",
      "tags": [
        "author:Uriel Kosayev",
        "career",
        "career-development",
        "mirror",
        "professional-development",
        "professional-profile",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/career-guides/cybersecurity-salaries/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:career-guides:is-malware-analysis-right-for-you",
      "title": "Is Malware Analysis Right for You?",
      "primary_type": "mirror",
      "primary_domain": "professional-profile",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/career-guides/is-malware-analysis-right-for-you/",
      "source_url": "https://trainsec.net/library/career-guides/is-malware-analysis-right-for-you/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/career-guides-is-malware-analysis-right-for-you.html"
      ],
      "published_at": "2026-04-14",
      "updated_at": "2026-09-04",
      "summary": "A lot of people are drawn to malware analysis because it sounds advanced, technical, and",
      "tags": [
        "author:Uriel Kosayev",
        "career",
        "career-development",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "professional-development",
        "professional-profile",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/career-guides/is-malware-analysis-right-for-you/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:career-guides:malware-analysis-in-the-age-of-ai-what-still-requires-human-skill",
      "title": "Malware Analysis in the Age of AI: What Still Requires Human Skill?",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/career-guides/malware-analysis-in-the-age-of-ai-what-still-requires-human-skill/",
      "source_url": "https://trainsec.net/library/career-guides/malware-analysis-in-the-age-of-ai-what-still-requires-human-skill/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/career-guides-malware-analysis-in-the-age-of-ai-what-still-requires-human-skill.html"
      ],
      "published_at": "2026-06-25",
      "updated_at": "2026-09-04",
      "summary": "AI is starting to change malware analysis in ways that are hard to ignore. Some",
      "tags": [
        "ai-security",
        "author:Uriel Kosayev",
        "career-development",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/career-guides/malware-analysis-in-the-age-of-ai-what-still-requires-human-skill/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:career-guides:malware-analyst-roadmap",
      "title": "The Complete Malware Analyst Roadmap: Step-by-Step Guide",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/career-guides/malware-analyst-roadmap/",
      "source_url": "https://trainsec.net/library/career-guides/malware-analyst-roadmap/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/career-guides-malware-analyst-roadmap.html"
      ],
      "published_at": "2026-04-14",
      "updated_at": "2026-09-04",
      "summary": "If you want to become a Malware Analyst, the biggest mistake is trying to jump",
      "tags": [
        "author:Uriel Kosayev",
        "career-development",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/career-guides/malware-analyst-roadmap/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:career-guides:why-malware-analysts-need-to-think-like-attackers",
      "title": "Why Malware Analysts Need to Think Like Attackers",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/career-guides/why-malware-analysts-need-to-think-like-attackers/",
      "source_url": "https://trainsec.net/library/career-guides/why-malware-analysts-need-to-think-like-attackers/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/career-guides-why-malware-analysts-need-to-think-like-attackers.html"
      ],
      "published_at": "2026-06-25",
      "updated_at": "2026-09-04",
      "summary": "Malware analysts do not just need to understand what malicious code does. They also need",
      "tags": [
        "author:Uriel Kosayev",
        "career-development",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/career-guides/why-malware-analysts-need-to-think-like-attackers/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:hardware-hacking:best-starter-hardware-hacking-toolkit",
      "title": "Best starter Hardware Hacking Toolkit",
      "primary_type": "mirror",
      "primary_domain": "vulnerability-research",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/hardware-hacking/best-starter-hardware-hacking-toolkit/",
      "source_url": "https://trainsec.net/library/hardware-hacking/best-starter-hardware-hacking-toolkit/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/hardware-hacking-best-starter-hardware-hacking-toolkit.html"
      ],
      "published_at": "2024-07-30",
      "updated_at": "2026-09-04",
      "summary": "Best starter Hardware Hacking Toolkit by Amichai Yifrach, republished from TrainSec.net with permission.",
      "tags": [
        "author:Amichai Yifrach",
        "embedded",
        "embedded-security",
        "hardware-security",
        "mirror",
        "trainsec",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/hardware-hacking/best-starter-hardware-hacking-toolkit/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:hardware-hacking:the-hitchhikers-guide-to-breaking-secure-boot-jetson-orin-cves",
      "title": "The Hitchhiker's Guide to Breaking Secure Boot",
      "primary_type": "mirror",
      "primary_domain": "vulnerability-research",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/hardware-hacking/the-hitchhikers-guide-to-breaking-secure-boot-jetson-orin-cves/",
      "source_url": "https://trainsec.net/library/hardware-hacking/the-hitchhikers-guide-to-breaking-secure-boot-jetson-orin-cves/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/hardware-hacking-the-hitchhikers-guide-to-breaking-secure-boot-jetson-orin-cves.html"
      ],
      "published_at": "2026-04-19",
      "updated_at": "2026-09-04",
      "summary": "The Hitchhiker's Guide to Breaking Secure Boot by Amichai Yifrach, republished from TrainSec.net with permission.",
      "tags": [
        "author:Amichai Yifrach",
        "embedded",
        "embedded-security",
        "hardware-security",
        "mirror",
        "trainsec",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/hardware-hacking/the-hitchhikers-guide-to-breaking-secure-boot-jetson-orin-cves/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:hardware-hacking:trojan-horse-implementation-in-hardware",
      "title": "Trojan Horse Implementation in Hardware",
      "primary_type": "mirror",
      "primary_domain": "vulnerability-research",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/hardware-hacking/trojan-horse-implementation-in-hardware/",
      "source_url": "https://trainsec.net/library/hardware-hacking/trojan-horse-implementation-in-hardware/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/hardware-hacking-trojan-horse-implementation-in-hardware.html"
      ],
      "published_at": "2024-09-16",
      "updated_at": "2026-09-04",
      "summary": "Trojan Horse Implementation in Hardware by Amichai Yifrach, republished from TrainSec.net with permission.",
      "tags": [
        "author:Amichai Yifrach",
        "embedded",
        "embedded-security",
        "hardware-security",
        "malware-behavior",
        "mirror",
        "trainsec",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/hardware-hacking/trojan-horse-implementation-in-hardware/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:hardware-hacking:uart-security-the-parity-bit",
      "title": "Reinventing UART Security: Leveraging the Parity Bit for Robust Protection in OT Networks",
      "primary_type": "mirror",
      "primary_domain": "vulnerability-research",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/hardware-hacking/uart-security-the-parity-bit/",
      "source_url": "https://trainsec.net/library/hardware-hacking/uart-security-the-parity-bit/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/hardware-hacking-uart-security-the-parity-bit.html"
      ],
      "published_at": "2025-04-01",
      "updated_at": "2026-09-04",
      "summary": "Reinventing UART Security: Leveraging the Parity Bit for Robust Protection in OT Networks by Amichai Yifrach, republished from TrainSec.net with permission.",
      "tags": [
        "ai-security",
        "author:Amichai Yifrach",
        "embedded",
        "embedded-security",
        "hardware-security",
        "mirror",
        "trainsec",
        "vulnerability-research"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/hardware-hacking/uart-security-the-parity-bit/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:back-to-the-future-of-the-cyber-landscape",
      "title": "Back to the Future of the Cyber Landscape",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/back-to-the-future-of-the-cyber-landscape/",
      "source_url": "https://trainsec.net/library/malware-analysis/back-to-the-future-of-the-cyber-landscape/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-back-to-the-future-of-the-cyber-landscape.html"
      ],
      "published_at": "2024-10-02",
      "updated_at": "2026-09-04",
      "summary": "Back to the Future of the Cyber Landscape by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/back-to-the-future-of-the-cyber-landscape/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:can-document-files-be-trusted",
      "title": "Can Document Files Be Trusted?",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/can-document-files-be-trusted/",
      "source_url": "https://trainsec.net/library/malware-analysis/can-document-files-be-trusted/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-can-document-files-be-trusted.html"
      ],
      "published_at": "2025-06-02",
      "updated_at": "2026-09-04",
      "summary": "Can Document Files Be Trusted? by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "digital-forensics",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "security-operations",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/can-document-files-be-trusted/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:celebrate-uriel-kosayevs-birthday-with-crazy-price-cuts",
      "title": "Celebrate Uriel Kosayev's Birthday with crazy price cuts!",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/celebrate-uriel-kosayevs-birthday-with-crazy-price-cuts/",
      "source_url": "https://trainsec.net/library/malware-analysis/celebrate-uriel-kosayevs-birthday-with-crazy-price-cuts/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-celebrate-uriel-kosayevs-birthday-with-crazy-price-cuts.html"
      ],
      "published_at": "2024-10-29",
      "updated_at": "2026-09-04",
      "summary": "Celebrate Uriel Kosayev's Birthday with crazy price cuts!",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/celebrate-uriel-kosayevs-birthday-with-crazy-price-cuts/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:cyber-ai-friend-or-foe-lessons-from-the-orange-systems-inspiration-session",
      "title": "Cyber & AI – Friend or Foe? Lessons from the Orange Systems Inspiration Session",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/cyber-ai-friend-or-foe-lessons-from-the-orange-systems-inspiration-session/",
      "source_url": "https://trainsec.net/library/malware-analysis/cyber-ai-friend-or-foe-lessons-from-the-orange-systems-inspiration-session/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-cyber-ai-friend-or-foe-lessons-from-the-orange-systems-inspiration-session.html"
      ],
      "published_at": "2025-11-10",
      "updated_at": "2026-09-04",
      "summary": "Cyber & AI – Friend or Foe? Lessons from the Orange Systems Inspiration Session by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "ai-security",
        "author:Uriel Kosayev",
        "digital-forensics",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "security-operations",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/cyber-ai-friend-or-foe-lessons-from-the-orange-systems-inspiration-session/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:debugging-dll-files-with-ida-disassembler",
      "title": "Debugging DLL Files with IDA Disassembler",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/debugging-dll-files-with-ida-disassembler/",
      "source_url": "https://trainsec.net/library/malware-analysis/debugging-dll-files-with-ida-disassembler/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-debugging-dll-files-with-ida-disassembler.html"
      ],
      "published_at": "2024-11-10",
      "updated_at": "2026-09-04",
      "summary": "Debugging DLL Files with IDA Disassembler by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/debugging-dll-files-with-ida-disassembler/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:dissecting-ardamax-keylogger",
      "title": "Dissecting Ardamax Keylogger",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/dissecting-ardamax-keylogger/",
      "source_url": "https://trainsec.net/library/malware-analysis/dissecting-ardamax-keylogger/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-dissecting-ardamax-keylogger.html"
      ],
      "published_at": "2024-07-04",
      "updated_at": "2026-09-04",
      "summary": "Dissecting Ardamax Keylogger by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/dissecting-ardamax-keylogger/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:dissecting-blackbyte-ransomware",
      "title": "Dissecting the BlackByte Ransomware",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/dissecting-blackbyte-ransomware/",
      "source_url": "https://trainsec.net/library/malware-analysis/dissecting-blackbyte-ransomware/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-dissecting-blackbyte-ransomware.html"
      ],
      "published_at": "2025-01-09",
      "updated_at": "2026-09-04",
      "summary": "Dissecting the BlackByte Ransomware by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/dissecting-blackbyte-ransomware/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:how-malware-really-works-what-most-people-miss",
      "title": "How Malware Really Works (What Most People Miss)",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/how-malware-really-works-what-most-people-miss/",
      "source_url": "https://trainsec.net/library/malware-analysis/how-malware-really-works-what-most-people-miss/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-how-malware-really-works-what-most-people-miss.html"
      ],
      "published_at": "2025-12-28",
      "updated_at": "2026-09-04",
      "summary": "How Malware Really Works (What Most People Miss) by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/how-malware-really-works-what-most-people-miss/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:intel-audio-driver-unquoted-service-path-vulnerability",
      "title": "Intel® Audio Driver Unquoted Service Path Vulnerability",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/intel-audio-driver-unquoted-service-path-vulnerability/",
      "source_url": "https://trainsec.net/library/malware-analysis/intel-audio-driver-unquoted-service-path-vulnerability/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-intel-audio-driver-unquoted-service-path-vulnerability.html"
      ],
      "published_at": "2024-07-21",
      "updated_at": "2026-09-04",
      "summary": "Intel® Audio Driver Unquoted Service Path Vulnerability by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/intel-audio-driver-unquoted-service-path-vulnerability/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:join-our-live-workshop-attack-and-defense-remote-thread-injection-and-detection",
      "title": "Live Workshop: Attack and Defense: Remote Thread Injection and Detection (Recorded)",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/join-our-live-workshop-attack-and-defense-remote-thread-injection-and-detection/",
      "source_url": "https://trainsec.net/library/malware-analysis/join-our-live-workshop-attack-and-defense-remote-thread-injection-and-detection/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-join-our-live-workshop-attack-and-defense-remote-thread-injection-and-detection.html"
      ],
      "published_at": "2025-01-28",
      "updated_at": "2026-09-04",
      "summary": "Live Workshop: Attack and Defense: Remote Thread Injection and Detection (Recorded) by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "internals",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec",
        "windows"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/join-our-live-workshop-attack-and-defense-remote-thread-injection-and-detection/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:maos-malware-analysis-on-steroids-book",
      "title": "MAoS – Malware Analysis on Steroids book released",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/maos-malware-analysis-on-steroids-book/",
      "source_url": "https://trainsec.net/library/malware-analysis/maos-malware-analysis-on-steroids-book/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-maos-malware-analysis-on-steroids-book.html"
      ],
      "published_at": "2025-09-11",
      "updated_at": "2026-09-04",
      "summary": "MAoS – Malware Analysis on Steroids book released by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/maos-malware-analysis-on-steroids-book/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:meet-uriel-kosayev-def-con-34",
      "title": "Meet TrainSec Co-Founder Uriel Kosayev at DEF CON 34",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/meet-uriel-kosayev-def-con-34/",
      "source_url": "https://trainsec.net/library/malware-analysis/meet-uriel-kosayev-def-con-34/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-meet-uriel-kosayev-def-con-34.html"
      ],
      "published_at": "2026-07-20",
      "updated_at": "2026-09-04",
      "summary": "Meet TrainSec Co-Founder Uriel Kosayev at DEF CON 34 by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/meet-uriel-kosayev-def-con-34/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:microsoft-wslservice-unquoted-service-path-vulnerability",
      "title": "Microsoft WslService Unquoted Service Path Vulnerability",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/microsoft-wslservice-unquoted-service-path-vulnerability/",
      "source_url": "https://trainsec.net/library/malware-analysis/microsoft-wslservice-unquoted-service-path-vulnerability/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-microsoft-wslservice-unquoted-service-path-vulnerability.html"
      ],
      "published_at": "2024-07-08",
      "updated_at": "2026-09-04",
      "summary": "Microsoft WslService Unquoted Service Path Vulnerability by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/microsoft-wslservice-unquoted-service-path-vulnerability/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:msi-truecolor-unquoted-service-path",
      "title": "MSI TrueColor Unquoted Service Path",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/msi-truecolor-unquoted-service-path/",
      "source_url": "https://trainsec.net/library/malware-analysis/msi-truecolor-unquoted-service-path/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-msi-truecolor-unquoted-service-path.html"
      ],
      "published_at": "2024-07-21",
      "updated_at": "2026-09-04",
      "summary": "MSI TrueColor Unquoted Service Path by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/msi-truecolor-unquoted-service-path/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:muddywater-initial-access-trojan",
      "title": "MuddyWater Initial Access Trojan",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/muddywater-initial-access-trojan/",
      "source_url": "https://trainsec.net/library/malware-analysis/muddywater-initial-access-trojan/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-muddywater-initial-access-trojan.html"
      ],
      "published_at": "2024-09-29",
      "updated_at": "2026-09-04",
      "summary": "MuddyWater Initial Access Trojan by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/muddywater-initial-access-trojan/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:one-electron-to-rule-them-all",
      "title": "One Electron to Rule Them All",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/one-electron-to-rule-them-all/",
      "source_url": "https://trainsec.net/library/malware-analysis/one-electron-to-rule-them-all/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-one-electron-to-rule-them-all.html"
      ],
      "published_at": "2024-08-01",
      "updated_at": "2026-09-04",
      "summary": "One Electron to Rule Them All",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/one-electron-to-rule-them-all/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:reverse-engineering-arm-based-mirai-botnet",
      "title": "Reverse Engineering ARM based Mirai Botnet",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/reverse-engineering-arm-based-mirai-botnet/",
      "source_url": "https://trainsec.net/library/malware-analysis/reverse-engineering-arm-based-mirai-botnet/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-reverse-engineering-arm-based-mirai-botnet.html"
      ],
      "published_at": "2025-02-17",
      "updated_at": "2026-09-04",
      "summary": "Reverse Engineering ARM based Mirai Botnet by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/reverse-engineering-arm-based-mirai-botnet/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:the-malware-shlayer",
      "title": "The Malware Shlayer",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/the-malware-shlayer/",
      "source_url": "https://trainsec.net/library/malware-analysis/the-malware-shlayer/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-the-malware-shlayer.html"
      ],
      "published_at": "2024-07-08",
      "updated_at": "2026-09-04",
      "summary": "The Malware Shlayer by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/the-malware-shlayer/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:two-sides-of-the-same-coin-from-dissected-malware-to-edr-evasion",
      "title": "Two Sides of The Same Coin - From Dissected Malware to EDR Evasion",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/two-sides-of-the-same-coin-from-dissected-malware-to-edr-evasion/",
      "source_url": "https://trainsec.net/library/malware-analysis/two-sides-of-the-same-coin-from-dissected-malware-to-edr-evasion/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-two-sides-of-the-same-coin-from-dissected-malware-to-edr-evasion.html"
      ],
      "published_at": "2025-08-10",
      "updated_at": "2026-09-04",
      "summary": "Two Sides of The Same Coin - From Dissected Malware to EDR Evasion by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "digital-forensics",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "security-operations",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/two-sides-of-the-same-coin-from-dissected-malware-to-edr-evasion/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:malware-analysis:wannacry-dropper-analysis-itsy-bitsy-tricks-that-break-your-tools",
      "title": "WannaCry Dropper Analysis: Itsy Bitsy Tricks That Break Your Tools",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/malware-analysis/wannacry-dropper-analysis-itsy-bitsy-tricks-that-break-your-tools/",
      "source_url": "https://trainsec.net/library/malware-analysis/wannacry-dropper-analysis-itsy-bitsy-tricks-that-break-your-tools/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/malware-analysis-wannacry-dropper-analysis-itsy-bitsy-tricks-that-break-your-tools.html"
      ],
      "published_at": "2026-06-10",
      "updated_at": "2026-09-04",
      "summary": "WannaCry Dropper Analysis: Itsy Bitsy Tricks That Break Your Tools by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "author:Uriel Kosayev",
        "malware",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "reverse-engineering",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/malware-analysis/wannacry-dropper-analysis-itsy-bitsy-tricks-that-break-your-tools/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:programming:rundll32",
      "title": "Understanding RunDLL32: Leveraging Dynamic Function Invocation",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/programming/rundll32/",
      "source_url": "https://trainsec.net/library/programming/rundll32/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/programming-rundll32.html"
      ],
      "published_at": "2025-01-13",
      "updated_at": "2026-09-04",
      "summary": "Understanding RunDLL32: Leveraging Dynamic Function Invocation by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "ai-security",
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/programming/rundll32/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:programming:sharing-kernel-objects-by-name-perks-and-perils",
      "title": "Sharing Kernel Objects by Name - Perks and Perils",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/programming/sharing-kernel-objects-by-name-perks-and-perils/",
      "source_url": "https://trainsec.net/library/programming/sharing-kernel-objects-by-name-perks-and-perils/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/programming-sharing-kernel-objects-by-name-perks-and-perils.html"
      ],
      "published_at": "2024-09-13",
      "updated_at": "2026-09-04",
      "summary": "Sharing Kernel Objects by Name - Perks and Perils by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/programming/sharing-kernel-objects-by-name-perks-and-perils/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:programming:shell-icon-handler-extension",
      "title": "Shell Icon Handler extension",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/programming/shell-icon-handler-extension/",
      "source_url": "https://trainsec.net/library/programming/shell-icon-handler-extension/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/programming-shell-icon-handler-extension.html"
      ],
      "published_at": "2025-01-09",
      "updated_at": "2026-09-04",
      "summary": "Shell Icon Handler extension by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/programming/shell-icon-handler-extension/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:programming:windows-system-programming-in-rust",
      "title": "Windows System Programming In Rust",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/programming/windows-system-programming-in-rust/",
      "source_url": "https://trainsec.net/library/programming/windows-system-programming-in-rust/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/programming-windows-system-programming-in-rust.html"
      ],
      "published_at": "2026-03-12",
      "updated_at": "2026-09-04",
      "summary": "Windows System Programming In Rust by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "rust",
        "trainsec",
        "windows"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/programming/windows-system-programming-in-rust/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:soc-and-dfir:reality-of-securing-modern-data-centers",
      "title": "You Can’t Sleep in the AI Era: The Brutal Reality of Securing Modern Data Centers",
      "primary_type": "mirror",
      "primary_domain": "incident-response",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/soc-and-dfir/reality-of-securing-modern-data-centers/",
      "source_url": "https://trainsec.net/library/soc-and-dfir/reality-of-securing-modern-data-centers/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/soc-and-dfir-reality-of-securing-modern-data-centers.html"
      ],
      "published_at": "2025-12-25",
      "updated_at": "2026-09-04",
      "summary": "You Can’t Sleep in the AI Era: The Brutal Reality of Securing Modern Data Centers by Uriel Kosayev, republished from TrainSec.net with permission.",
      "tags": [
        "ai-security",
        "author:Uriel Kosayev",
        "digital-forensics",
        "incident-response",
        "mirror",
        "security-operations",
        "trainsec"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/soc-and-dfir/reality-of-securing-modern-data-centers/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:anti-malware-scan-interface-c-sharp",
      "title": "AMSI Scanning in C#: P/Invoke, Memory-Mapped Files, and Safe Interop",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/anti-malware-scan-interface-c-sharp/",
      "source_url": "https://trainsec.net/library/windows-internals/anti-malware-scan-interface-c-sharp/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-anti-malware-scan-interface-c-sharp.html"
      ],
      "published_at": "2025-11-10",
      "updated_at": "2026-09-04",
      "summary": "AMSI Scanning in C#: P/Invoke, Memory-Mapped Files, and Safe Interop by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "internals",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/anti-malware-scan-interface-c-sharp/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:application-types-on-windows",
      "title": "“Application Types” on Windows",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/application-types-on-windows/",
      "source_url": "https://trainsec.net/library/windows-internals/application-types-on-windows/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-application-types-on-windows.html"
      ],
      "published_at": "2024-07-08",
      "updated_at": "2026-09-04",
      "summary": "“Application Types” on Windows by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/application-types-on-windows/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:blue-screen-of-death-a-practical-deep-dive",
      "title": "Exploring the Blue Screen of Death: A Practical Deep Dive",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/blue-screen-of-death-a-practical-deep-dive/",
      "source_url": "https://trainsec.net/library/windows-internals/blue-screen-of-death-a-practical-deep-dive/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-blue-screen-of-death-a-practical-deep-dive.html"
      ],
      "published_at": "2025-02-17",
      "updated_at": "2026-09-04",
      "summary": "Exploring the Blue Screen of Death: A Practical Deep Dive by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/blue-screen-of-death-a-practical-deep-dive/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:building-a-process-tree",
      "title": "Building a Process Tree",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/building-a-process-tree/",
      "source_url": "https://trainsec.net/library/windows-internals/building-a-process-tree/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-building-a-process-tree.html"
      ],
      "published_at": "2024-07-15",
      "updated_at": "2026-09-04",
      "summary": "Building a Process Tree",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "c-plus-plus",
        "mirror",
        "trainsec",
        "windows-internals",
        "windows-programming"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/building-a-process-tree/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:building-a-simple-rpc-client-and-server-a-step-by-step-guide",
      "title": "Building a Simple RPC Client and Server: A Step-by-Step Guide",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/building-a-simple-rpc-client-and-server-a-step-by-step-guide/",
      "source_url": "https://trainsec.net/library/windows-internals/building-a-simple-rpc-client-and-server-a-step-by-step-guide/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-building-a-simple-rpc-client-and-server-a-step-by-step-guide.html"
      ],
      "published_at": "2024-11-20",
      "updated_at": "2026-09-04",
      "summary": "Building a Simple RPC Client and Server: A Step-by-Step Guide by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/building-a-simple-rpc-client-and-server-a-step-by-step-guide/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:capture-etw-events-with-c-part-1",
      "title": "Capture ETW events with C++ (Part 1)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/capture-etw-events-with-c-part-1/",
      "source_url": "https://trainsec.net/library/windows-internals/capture-etw-events-with-c-part-1/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-capture-etw-events-with-c-part-1.html"
      ],
      "published_at": "2026-04-13",
      "updated_at": "2026-09-04",
      "summary": "Capture ETW events with C++ (Part 1) by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/capture-etw-events-with-c-part-1/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:capture-etw-events-with-c-part-2",
      "title": "Capture ETW events with C++ (Part 2)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/capture-etw-events-with-c-part-2/",
      "source_url": "https://trainsec.net/library/windows-internals/capture-etw-events-with-c-part-2/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-capture-etw-events-with-c-part-2.html"
      ],
      "published_at": "2026-04-13",
      "updated_at": "2026-09-04",
      "summary": "Capture ETW events with C++ (Part 2) by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/capture-etw-events-with-c-part-2/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:code-injection-with-image-file-execution-options",
      "title": "Code Injection with Image File Execution Options",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/code-injection-with-image-file-execution-options/",
      "source_url": "https://trainsec.net/library/windows-internals/code-injection-with-image-file-execution-options/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-code-injection-with-image-file-execution-options.html"
      ],
      "published_at": "2024-07-08",
      "updated_at": "2026-09-04",
      "summary": "Code Injection with Image File Execution Options by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "c-plus-plus",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "trainsec",
        "windows-internals",
        "windows-programming"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/code-injection-with-image-file-execution-options/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:creating-com-objects-with-the-class-moniker-cogetobject",
      "title": "Creating COM Objects with the Class Moniker (CoGetObject)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/creating-com-objects-with-the-class-moniker-cogetobject/",
      "source_url": "https://trainsec.net/library/windows-internals/creating-com-objects-with-the-class-moniker-cogetobject/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-creating-com-objects-with-the-class-moniker-cogetobject.html"
      ],
      "published_at": "2026-04-29",
      "updated_at": "2026-09-04",
      "summary": "Creating COM Objects with the Class Moniker (CoGetObject) by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/creating-com-objects-with-the-class-moniker-cogetobject/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:crowdstrike-and-the-formidable-bsod",
      "title": "CrowdStrike and the Formidable BSOD",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/crowdstrike-and-the-formidable-bsod/",
      "source_url": "https://trainsec.net/library/windows-internals/crowdstrike-and-the-formidable-bsod/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-crowdstrike-and-the-formidable-bsod.html"
      ],
      "published_at": "2024-07-21",
      "updated_at": "2026-09-04",
      "summary": "CrowdStrike and the Formidable BSOD",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "malware",
        "mirror",
        "reverse-engineering",
        "trainsec",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/crowdstrike-and-the-formidable-bsod/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:delete-a-file-in-windows",
      "title": "How to Delete a File in Windows (and What “Delete” Really Means)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/delete-a-file-in-windows/",
      "source_url": "https://trainsec.net/library/windows-internals/delete-a-file-in-windows/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-delete-a-file-in-windows.html"
      ],
      "published_at": "2026-02-08",
      "updated_at": "2026-09-04",
      "summary": "How to Delete a File in Windows (and What “Delete” Really Means)",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/delete-a-file-in-windows/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:dll-injection-with-windows-application-verifier",
      "title": "DLL Injection with Windows Application Verifier",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/dll-injection-with-windows-application-verifier/",
      "source_url": "https://trainsec.net/library/windows-internals/dll-injection-with-windows-application-verifier/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-dll-injection-with-windows-application-verifier.html"
      ],
      "published_at": "2026-06-22",
      "updated_at": "2026-09-04",
      "summary": "DLL Injection with Windows Application Verifier by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "internals",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/dll-injection-with-windows-application-verifier/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:exploring-ntfs-alternate-streams-a-hidden-gem-of-the-windows-file-system",
      "title": "Exploring NTFS Alternate Streams: A Hidden Gem of the Windows File System",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/exploring-ntfs-alternate-streams-a-hidden-gem-of-the-windows-file-system/",
      "source_url": "https://trainsec.net/library/windows-internals/exploring-ntfs-alternate-streams-a-hidden-gem-of-the-windows-file-system/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-exploring-ntfs-alternate-streams-a-hidden-gem-of-the-windows-file-system.html"
      ],
      "published_at": "2024-11-20",
      "updated_at": "2026-09-04",
      "summary": "Exploring NTFS Alternate Streams: A Hidden Gem of the Windows File System by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/exploring-ntfs-alternate-streams-a-hidden-gem-of-the-windows-file-system/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:hiding-a-service-with-c",
      "title": "Hiding a Service with C++",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/hiding-a-service-with-c/",
      "source_url": "https://trainsec.net/library/windows-internals/hiding-a-service-with-c/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-hiding-a-service-with-c.html"
      ],
      "published_at": "2026-03-16",
      "updated_at": "2026-09-04",
      "summary": "Hiding a Service with C++ by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/hiding-a-service-with-c/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:hiding-a-windows-service",
      "title": "Hiding A Windows Service From Enumeration",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/hiding-a-windows-service/",
      "source_url": "https://trainsec.net/library/windows-internals/hiding-a-windows-service/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-hiding-a-windows-service.html"
      ],
      "published_at": "2026-03-12",
      "updated_at": "2026-09-04",
      "summary": "Hiding A Windows Service From Enumeration by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/hiding-a-windows-service/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource",
      "title": "How to Embed and Extract Custom PE Resources in C++",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource/",
      "source_url": "https://trainsec.net/library/windows-internals/how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource.html"
      ],
      "published_at": "2026-06-01",
      "updated_at": "2026-09-04",
      "summary": "How to Embed and Extract Custom PE Resources in C++ by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:how-to-scan-files-with-the-anti-malware-scan-interface-in-windows",
      "title": "How to scan files with the Anti-Malware Scan Interface in Windows?",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/how-to-scan-files-with-the-anti-malware-scan-interface-in-windows/",
      "source_url": "https://trainsec.net/library/windows-internals/how-to-scan-files-with-the-anti-malware-scan-interface-in-windows/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-how-to-scan-files-with-the-anti-malware-scan-interface-in-windows.html"
      ],
      "published_at": "2025-11-10",
      "updated_at": "2026-09-04",
      "summary": "How to scan files with the Anti-Malware Scan Interface in Windows? by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "internals",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/how-to-scan-files-with-the-anti-malware-scan-interface-in-windows/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:how-windows-app-execution-aliases-work-and-how-to-read-them-in-c",
      "title": "How Windows App Execution Aliases Work (and How to Read Them in C++)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/how-windows-app-execution-aliases-work-and-how-to-read-them-in-c/",
      "source_url": "https://trainsec.net/library/windows-internals/how-windows-app-execution-aliases-work-and-how-to-read-them-in-c/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-how-windows-app-execution-aliases-work-and-how-to-read-them-in-c.html"
      ],
      "published_at": "2026-07-12",
      "updated_at": "2026-09-04",
      "summary": "How Windows App Execution Aliases Work (and How to Read Them in C++) by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/how-windows-app-execution-aliases-work-and-how-to-read-them-in-c/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:how-windows-pe-files-use-custom-resources-to-embed-anything",
      "title": "How Windows PE Files Use Custom Resources to Embed Anything",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/how-windows-pe-files-use-custom-resources-to-embed-anything/",
      "source_url": "https://trainsec.net/library/windows-internals/how-windows-pe-files-use-custom-resources-to-embed-anything/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-how-windows-pe-files-use-custom-resources-to-embed-anything.html"
      ],
      "published_at": "2026-05-25",
      "updated_at": "2026-09-04",
      "summary": "How Windows PE Files Use Custom Resources to Embed Anything by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/how-windows-pe-files-use-custom-resources-to-embed-anything/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:inside-the-windows-recycle-bin-what-really-happens-when-you-delete-a-file",
      "title": "Inside the Windows Recycle Bin - What Really Happens When You Delete a File?",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/inside-the-windows-recycle-bin-what-really-happens-when-you-delete-a-file/",
      "source_url": "https://trainsec.net/library/windows-internals/inside-the-windows-recycle-bin-what-really-happens-when-you-delete-a-file/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-inside-the-windows-recycle-bin-what-really-happens-when-you-delete-a-file.html"
      ],
      "published_at": "2025-08-13",
      "updated_at": "2026-09-04",
      "summary": "Inside the Windows Recycle Bin - What Really Happens When You Delete a File? by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/inside-the-windows-recycle-bin-what-really-happens-when-you-delete-a-file/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:inside-windows-sessions",
      "title": "Inside Windows Sessions: A Deep Dive with Pavel",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/inside-windows-sessions/",
      "source_url": "https://trainsec.net/library/windows-internals/inside-windows-sessions/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-inside-windows-sessions.html"
      ],
      "published_at": "2025-09-22",
      "updated_at": "2026-09-04",
      "summary": "Inside Windows Sessions: A Deep Dive with Pavel by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/inside-windows-sessions/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:introduction-to-the-windows-performance-analyzer",
      "title": "Introduction to the Windows Performance Analyzer (WPA)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/introduction-to-the-windows-performance-analyzer/",
      "source_url": "https://trainsec.net/library/windows-internals/introduction-to-the-windows-performance-analyzer/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-introduction-to-the-windows-performance-analyzer.html"
      ],
      "published_at": "2024-11-10",
      "updated_at": "2026-09-04",
      "summary": "Introduction to the Windows Performance Analyzer (WPA) by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/introduction-to-the-windows-performance-analyzer/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:introduction-to-windows-services",
      "title": "Introduction to Windows Services",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/introduction-to-windows-services/",
      "source_url": "https://trainsec.net/library/windows-internals/introduction-to-windows-services/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-introduction-to-windows-services.html"
      ],
      "published_at": "2024-11-10",
      "updated_at": "2026-09-04",
      "summary": "Introduction to Windows Services by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/introduction-to-windows-services/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:kernel-allocation-tags-in-windows-explained",
      "title": "Kernel Allocation Tags in Windows Explained",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/kernel-allocation-tags-in-windows-explained/",
      "source_url": "https://trainsec.net/library/windows-internals/kernel-allocation-tags-in-windows-explained/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-kernel-allocation-tags-in-windows-explained.html"
      ],
      "published_at": "2025-08-21",
      "updated_at": "2026-09-04",
      "summary": "Kernel Allocation Tags in Windows Explained by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/kernel-allocation-tags-in-windows-explained/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:kernel-debugging-windows-vms-a-practical-walk-through",
      "title": "Kernel Debugging Windows VMs – A Practical Walk-Through",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/kernel-debugging-windows-vms-a-practical-walk-through/",
      "source_url": "https://trainsec.net/library/windows-internals/kernel-debugging-windows-vms-a-practical-walk-through/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-kernel-debugging-windows-vms-a-practical-walk-through.html"
      ],
      "published_at": "2025-07-31",
      "updated_at": "2026-09-04",
      "summary": "Kernel Debugging Windows VMs – A Practical Walk-Through by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "internals",
        "malware-analysis",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/kernel-debugging-windows-vms-a-practical-walk-through/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:keyboard-hook-with-with-image-file-execution-options",
      "title": "Keyboard Hook with Image File Execution Options",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/keyboard-hook-with-with-image-file-execution-options/",
      "source_url": "https://trainsec.net/library/windows-internals/keyboard-hook-with-with-image-file-execution-options/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-keyboard-hook-with-with-image-file-execution-options.html"
      ],
      "published_at": "2024-08-25",
      "updated_at": "2026-09-04",
      "summary": "Keyboard hooking using Image File Execution Options and pretending to be a debugger.",
      "tags": [
        "author:Pavel Yosifovich",
        "c-plus-plus",
        "malware-analysis",
        "mirror",
        "trainsec",
        "windows-internals",
        "windows-programming"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/keyboard-hook-with-with-image-file-execution-options/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:live-windows-research-using-windbg",
      "title": "Windows Research with WinDBG - 4H Live (7th April) masterclass with Pavel",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/live-windows-research-using-windbg/",
      "source_url": "https://trainsec.net/library/windows-internals/live-windows-research-using-windbg/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-live-windows-research-using-windbg.html"
      ],
      "published_at": "2026-03-09",
      "updated_at": "2026-09-04",
      "summary": "Windows Research with WinDBG - 4H Live (7th April) masterclass with Pavel by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "reverse-engineering",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/live-windows-research-using-windbg/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:looking-into-windows-access-masks",
      "title": "Looking into Windows Access Masks",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/looking-into-windows-access-masks/",
      "source_url": "https://trainsec.net/library/windows-internals/looking-into-windows-access-masks/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-looking-into-windows-access-masks.html"
      ],
      "published_at": "2026-02-13",
      "updated_at": "2026-09-04",
      "summary": "Looking into Windows Access Masks by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/looking-into-windows-access-masks/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:maximum-handles-in-a-process",
      "title": "Maximum Handles in a process",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/maximum-handles-in-a-process/",
      "source_url": "https://trainsec.net/library/windows-internals/maximum-handles-in-a-process/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-maximum-handles-in-a-process.html"
      ],
      "published_at": "2024-08-13",
      "updated_at": "2026-09-04",
      "summary": "Maximum Handles in a process by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/maximum-handles-in-a-process/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:ntfs-transactions-in-windows-kernel-transaction-manager-createfiletransacted-and-process-doppelganging",
      "title": "NTFS Transactions in Windows: Kernel Transaction Manager, CreateFileTransacted, and Process Doppelganging",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/ntfs-transactions-in-windows-kernel-transaction-manager-createfiletransacted-and-process-doppelganging/",
      "source_url": "https://trainsec.net/library/windows-internals/ntfs-transactions-in-windows-kernel-transaction-manager-createfiletransacted-and-process-doppelganging/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-ntfs-transactions-in-windows-kernel-transaction-manager-createfiletransacted-and-process-doppelganging.html"
      ],
      "published_at": "2026-05-17",
      "updated_at": "2026-09-04",
      "summary": "NTFS Transactions in Windows: Kernel Transaction Manager, CreateFileTransacted, and Process Doppelganging by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/ntfs-transactions-in-windows-kernel-transaction-manager-createfiletransacted-and-process-doppelganging/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:process-memory-map-in-code-mapped-files-and-dos-paths-part-2",
      "title": "Process Memory Map in Code: Mapped Files and DOS Paths (Part 2)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-mapped-files-and-dos-paths-part-2/",
      "source_url": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-mapped-files-and-dos-paths-part-2/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-process-memory-map-in-code-mapped-files-and-dos-paths-part-2.html"
      ],
      "published_at": "2026-08-24",
      "updated_at": "2026-09-06",
      "summary": "Pavel Yosifovich extends his MemMap tool with GetMappedFileName, then converts raw NT device paths into ordinary drive-letter paths.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "c",
        "internals",
        "mapped-files",
        "mirror",
        "nt-paths",
        "trainsec",
        "virtual-memory",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-mapped-files-and-dos-paths-part-2/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:process-memory-map-in-code-thread-stacks-and-tebs-part-3",
      "title": "Process Memory Map in Code: Thread Stacks and TEBs (Part 3)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-thread-stacks-and-tebs-part-3/",
      "source_url": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-thread-stacks-and-tebs-part-3/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-process-memory-map-in-code-thread-stacks-and-tebs-part-3.html"
      ],
      "published_at": "2026-08-30",
      "updated_at": "2026-09-06",
      "summary": "Pavel Yosifovich extends his MemMap tool to enumerate threads, locate each Thread Environment Block, and read thread stack limits with ReadProcessMemory.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "c",
        "internals",
        "mirror",
        "teb",
        "threads",
        "trainsec",
        "virtual-memory",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-thread-stacks-and-tebs-part-3/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:process-memory-map-in-code-walking-virtualqueryex-and-finding-the-peb-part-1",
      "title": "Process Memory Map in Code (Part 1): Walking Process Virtual Address Space",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-walking-virtualqueryex-and-finding-the-peb-part-1/",
      "source_url": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-walking-virtualqueryex-and-finding-the-peb-part-1/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-process-memory-map-in-code-walking-virtualqueryex-and-finding-the-peb-part-1.html"
      ],
      "published_at": "2026-08-16",
      "updated_at": "2026-09-06",
      "summary": "Pavel Yosifovich writes a C++ tool that reads a Windows process's memory map with VirtualQueryEx, matching VMMap in code and locating the PEB.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "c",
        "internals",
        "mirror",
        "peb",
        "trainsec",
        "virtual-memory",
        "virtualqueryex",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/process-memory-map-in-code-walking-virtualqueryex-and-finding-the-peb-part-1/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:process-snapshotting-in-windows",
      "title": "How to Capture a Process Snapshot in Windows",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/process-snapshotting-in-windows/",
      "source_url": "https://trainsec.net/library/windows-internals/process-snapshotting-in-windows/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-process-snapshotting-in-windows.html"
      ],
      "published_at": "2025-09-16",
      "updated_at": "2026-09-04",
      "summary": "How to Capture a Process Snapshot in Windows by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "digital-forensics",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/process-snapshotting-in-windows/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:process-tree-in-windows",
      "title": "How to Build a Process Tree in Windows with Code",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/process-tree-in-windows/",
      "source_url": "https://trainsec.net/library/windows-internals/process-tree-in-windows/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-process-tree-in-windows.html"
      ],
      "published_at": "2025-09-05",
      "updated_at": "2026-09-04",
      "summary": "How to Build a Process Tree in Windows with Code by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "c-plus-plus",
        "mirror",
        "trainsec",
        "windows-internals",
        "windows-programming"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/process-tree-in-windows/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:protected-processes-ppl-keeping-windows-heart-safe",
      "title": "Protected Processes & PPL: keeping Windows’ heart safe",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/protected-processes-ppl-keeping-windows-heart-safe/",
      "source_url": "https://trainsec.net/library/windows-internals/protected-processes-ppl-keeping-windows-heart-safe/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-protected-processes-ppl-keeping-windows-heart-safe.html"
      ],
      "published_at": "2025-08-07",
      "updated_at": "2026-09-04",
      "summary": "Protected Processes & PPL: keeping Windows’ heart safe by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/protected-processes-ppl-keeping-windows-heart-safe/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:running-an-executable-as-system",
      "title": "Running an Executable as SYSTEM: Unlocking Windows Privilege Escalation Techniques",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/running-an-executable-as-system/",
      "source_url": "https://trainsec.net/library/windows-internals/running-an-executable-as-system/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-running-an-executable-as-system.html"
      ],
      "published_at": "2025-04-17",
      "updated_at": "2026-09-04",
      "summary": "Running an Executable as SYSTEM: Unlocking Windows Privilege Escalation Techniques by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "identity-and-access",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/running-an-executable-as-system/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:understanding-the-differences-between-createprocessasuser-and-createprocesswithtokenw-in-windows",
      "title": "Understanding the Differences Between CreateProcessAsUser and CreateProcessWithTokenW in Windows",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/understanding-the-differences-between-createprocessasuser-and-createprocesswithtokenw-in-windows/",
      "source_url": "https://trainsec.net/library/windows-internals/understanding-the-differences-between-createprocessasuser-and-createprocesswithtokenw-in-windows/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-understanding-the-differences-between-createprocessasuser-and-createprocesswithtokenw-in-windows.html"
      ],
      "published_at": "2024-12-17",
      "updated_at": "2026-09-04",
      "summary": "Understanding the Differences Between CreateProcessAsUser and CreateProcessWithTokenW in Windows by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/understanding-the-differences-between-createprocessasuser-and-createprocesswithtokenw-in-windows/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:understanding-uac-virtualization",
      "title": "Understanding UAC Virtualization: A Security Mechanism for Legacy Applications",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/understanding-uac-virtualization/",
      "source_url": "https://trainsec.net/library/windows-internals/understanding-uac-virtualization/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-understanding-uac-virtualization.html"
      ],
      "published_at": "2025-03-17",
      "updated_at": "2026-09-04",
      "summary": "Understanding UAC Virtualization: A Security Mechanism for Legacy Applications by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "c-plus-plus",
        "identity-and-access",
        "mirror",
        "trainsec",
        "windows-internals",
        "windows-programming"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/understanding-uac-virtualization/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:vmmap-basics-how-to-read-a-windows-processs-memory-layout",
      "title": "VMMap Basics: How to Read a Windows Process's Memory Layout",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/vmmap-basics-how-to-read-a-windows-processs-memory-layout/",
      "source_url": "https://trainsec.net/library/windows-internals/vmmap-basics-how-to-read-a-windows-processs-memory-layout/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-vmmap-basics-how-to-read-a-windows-processs-memory-layout.html"
      ],
      "published_at": "2026-08-02",
      "updated_at": "2026-09-04",
      "summary": "Pavel Yosifovich uses VMMap to break down a process's memory layout, for developers and researchers who want to see what memory a process really uses.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/vmmap-basics-how-to-read-a-windows-processs-memory-layout/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:when-process-hollowing-isnt-process-hollowing",
      "title": "When Process Hollowing Isn’t Process Hollowing",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/when-process-hollowing-isnt-process-hollowing/",
      "source_url": "https://trainsec.net/library/windows-internals/when-process-hollowing-isnt-process-hollowing/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-when-process-hollowing-isnt-process-hollowing.html"
      ],
      "published_at": "2026-01-27",
      "updated_at": "2026-09-04",
      "summary": "When Process Hollowing Isn’t Process Hollowing by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "internals",
        "malware-analysis",
        "malware-behavior",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/when-process-hollowing-isnt-process-hollowing/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:windows-logon-sessions-and-tokens",
      "title": "What Are Windows Logon Sessions and How Do They Relate to Tokens?",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/windows-logon-sessions-and-tokens/",
      "source_url": "https://trainsec.net/library/windows-internals/windows-logon-sessions-and-tokens/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-windows-logon-sessions-and-tokens.html"
      ],
      "published_at": "2026-06-21",
      "updated_at": "2026-09-04",
      "summary": "What Are Windows Logon Sessions and How Do They Relate to Tokens? by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/windows-logon-sessions-and-tokens/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:windows-management-instrumentation-wmi",
      "title": "Introduction to Windows Management Instrumentation (WMI)",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/windows-management-instrumentation-wmi/",
      "source_url": "https://trainsec.net/library/windows-internals/windows-management-instrumentation-wmi/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-windows-management-instrumentation-wmi.html"
      ],
      "published_at": "2025-07-20",
      "updated_at": "2026-09-04",
      "summary": "Introduction to Windows Management Instrumentation (WMI) by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/windows-management-instrumentation-wmi/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:windows-privileges-sedebugprivilege",
      "title": "Windows Privileges Explained: SeDebugPrivilege and AdjustTokenPrivileges in C++",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/windows-privileges-sedebugprivilege/",
      "source_url": "https://trainsec.net/library/windows-internals/windows-privileges-sedebugprivilege/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-windows-privileges-sedebugprivilege.html"
      ],
      "published_at": "2026-07-19",
      "updated_at": "2026-09-04",
      "summary": "Windows Privileges Explained: SeDebugPrivilege and AdjustTokenPrivileges in C++ by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "identity-and-access",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/windows-privileges-sedebugprivilege/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:windows-subsystem-for-linux",
      "title": "How does Windows Subsystem for Linux (Version 1) actually work?",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/windows-subsystem-for-linux/",
      "source_url": "https://trainsec.net/library/windows-internals/windows-subsystem-for-linux/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-windows-subsystem-for-linux.html"
      ],
      "published_at": "2025-08-27",
      "updated_at": "2026-09-04",
      "summary": "How does Windows Subsystem for Linux (Version 1) actually work? by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/windows-subsystem-for-linux/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:windows-tls-thread-local-storage-explained",
      "title": "Windows TLS (Thread-Local Storage) Explained",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/windows-tls-thread-local-storage-explained/",
      "source_url": "https://trainsec.net/library/windows-internals/windows-tls-thread-local-storage-explained/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-windows-tls-thread-local-storage-explained.html"
      ],
      "published_at": "2026-02-13",
      "updated_at": "2026-09-04",
      "summary": "Windows TLS (Thread-Local Storage) Explained by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "ai-security",
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/windows-tls-thread-local-storage-explained/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:write-windbg-extensions",
      "title": "Writing a WinDbg Extension: Streamline Your Debugging Workflow",
      "primary_type": "mirror",
      "primary_domain": "malware-analysis",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/write-windbg-extensions/",
      "source_url": "https://trainsec.net/library/windows-internals/write-windbg-extensions/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-write-windbg-extensions.html"
      ],
      "published_at": "2025-03-17",
      "updated_at": "2026-09-04",
      "summary": "Writing a WinDbg Extension: Streamline Your Debugging Workflow by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "author:Pavel Yosifovich",
        "c-plus-plus",
        "malware-analysis",
        "mirror",
        "reverse-engineering",
        "trainsec",
        "windows-internals",
        "windows-programming"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/write-windbg-extensions/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:writing-a-simple-key-logger",
      "title": "Writing a Simple Key Logger",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/writing-a-simple-key-logger/",
      "source_url": "https://trainsec.net/library/windows-internals/writing-a-simple-key-logger/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-writing-a-simple-key-logger.html"
      ],
      "published_at": "2025-06-02",
      "updated_at": "2026-09-04",
      "summary": "Writing a Simple Key Logger by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/writing-a-simple-key-logger/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:writing-a-windows-service",
      "title": "Writing a Windows Service",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/writing-a-windows-service/",
      "source_url": "https://trainsec.net/library/windows-internals/writing-a-windows-service/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-writing-a-windows-service.html"
      ],
      "published_at": "2024-11-10",
      "updated_at": "2026-09-04",
      "summary": "Writing a Windows Service by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/writing-a-windows-service/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-internals:writing-control-panel-applications",
      "title": "Writing Control Panel Applications",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-internals/writing-control-panel-applications/",
      "source_url": "https://trainsec.net/library/windows-internals/writing-control-panel-applications/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-internals-writing-control-panel-applications.html"
      ],
      "published_at": "2026-03-23",
      "updated_at": "2026-09-04",
      "summary": "Writing Control Panel Applications by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "internals",
        "mirror",
        "trainsec",
        "windows",
        "windows-internals"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-internals/writing-control-panel-applications/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-kernel:launch-wsl-applications-from-windows-with-wsllaunch",
      "title": "Launch WSL Applications from Windows with WslLaunch",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-kernel/launch-wsl-applications-from-windows-with-wsllaunch/",
      "source_url": "https://trainsec.net/library/windows-kernel/launch-wsl-applications-from-windows-with-wsllaunch/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-kernel-launch-wsl-applications-from-windows-with-wsllaunch.html"
      ],
      "published_at": "2026-04-21",
      "updated_at": "2026-09-04",
      "summary": "Launch WSL Applications from Windows with WslLaunch by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-kernel/launch-wsl-applications-from-windows-with-wsllaunch/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-kernel:linked-lists-in-the-windows-kernel",
      "title": "Linked Lists in the Windows Kernel",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-kernel/linked-lists-in-the-windows-kernel/",
      "source_url": "https://trainsec.net/library/windows-kernel/linked-lists-in-the-windows-kernel/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-kernel-linked-lists-in-the-windows-kernel.html"
      ],
      "published_at": "2026-03-25",
      "updated_at": "2026-09-04",
      "summary": "Linked Lists in the Windows Kernel by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-kernel/linked-lists-in-the-windows-kernel/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    },
    {
      "id": "trainsec-net:library:windows-kernel:windows-shell-links-in-c-how-to-read-and-write-lnk-files",
      "title": "Windows Shell Links in C++: How to Read and Write .lnk Files",
      "primary_type": "mirror",
      "primary_domain": "application-security",
      "audience": [
        "cti-analyst",
        "security-engineer",
        "developer"
      ],
      "status": "maintained",
      "maturity": "reference",
      "evidence_level": "source-backed",
      "applies_to": "permitted TrainSec Knowledge Library reproductions hosted by 1200km.com; each source remains canonical at TrainSec and technical currentness follows the original publication",
      "canonical_url": "https://trainsec.net/library/windows-kernel/windows-shell-links-in-c-how-to-read-and-write-lnk-files/",
      "source_url": "https://trainsec.net/library/windows-kernel/windows-shell-links-in-c-how-to-read-and-write-lnk-files/",
      "alternate_urls": [
        "https://1200km.com/articles/trainsec/windows-kernel-windows-shell-links-in-c-how-to-read-and-write-lnk-files.html"
      ],
      "published_at": "2026-05-10",
      "updated_at": "2026-09-04",
      "summary": "Windows Shell Links in C++: How to Read and Write .lnk Files by Pavel Yosifovich, republished from TrainSec.net with permission.",
      "tags": [
        "application-security",
        "author:Pavel Yosifovich",
        "kernel",
        "mirror",
        "trainsec",
        "windows",
        "windows-kernel"
      ],
      "featured": false,
      "indexable": false,
      "collection_id": "collection:trainsec-library",
      "source_platform": "TrainSec",
      "source_repository": "https://github.com/anpa1200/anpa1200.github.io",
      "original_publication": "https://trainsec.net/library/windows-kernel/windows-shell-links-in-c-how-to-read-and-write-lnk-files/",
      "canonical_owner": "TrainSec.net",
      "collection_tier": "reference",
      "lifecycle": "maintained"
    }
  ]
}
