MISP Galaxy threat-actor record
A Cyber Av3ngers threat-actor update was accepted into the public MISP Galaxy repository.
Boundary: upstream merge evidence; no downstream deployment or usage claim.
External validation / publications
A reviewer-facing evidence register led by verified public records and accepted upstream work. Reproducible validation, releases, point-in-time metrics, and open submissions follow in decreasing evidentiary strength; open submissions are never presented as adoption or acceptance.
These records prove upstream acceptance only. They do not establish production deployment, active users, operational effectiveness, or endorsement. Publication rules are defined in the adoption-evidence model.
A Cyber Av3ngers threat-actor update was accepted into the public MISP Galaxy repository.
Boundary: upstream merge evidence; no downstream deployment or usage claim.
Threat Matrix and the CTI Analyst Field Manual passed external review for an upstream detection-engineering resource list.
Boundary: curation evidence; not evidence of production SOC deployment.
AIDebug passed upstream review for inclusion in a public YARA resource collection.
Boundary: external curation only; not package-use or active-user evidence.
AdversaryGraph passed upstream review for inclusion in a public SOC resource collection.
Boundary: third-party curation evidence; not a production-deployment claim.
AdversaryGraph passed upstream review for inclusion in a public AI/GPT security resource collection.
Boundary: third-party curation evidence; not a production-deployment claim.
Merged into public third-party repositories. Closed-unmerged and open submissions are excluded.
5 GitHub PRs and 0 GitLab MRs submitted for maintainer review across CTI, malware, detection, cloud, AI, mobile, and lab lists.
Markdown files preserved in the maintained Medium export archive; this is not a live Medium publication count.
GitHub release, PyPI package, wheel/sdist artifacts, CI, tests, Kali request text, and docs.
Merged and CI-validated on main, matching the latest published immutable GitHub release v7.0.0.
Live public portfolio total across 82 GitHub repositories, including 37 forked repositories, 23 repository forks, 35 GitHub followers, and 40 combined stars for AIDebug plus AdversaryGraph.
Live public GitHub follower count for the anpa1200 account at verification time.
GitHub clone events summed across 45 daily-tracked source repositories (Aug 29–Sep 11 2026). The 667 GitHub-reported unique values are summed per repository and are not globally deduplicated people, users, or deployments.
Cumulative GitHub clone events across 45 daily-tracked source repositories (Jun 13–Sep 11 2026). The 5,869 GitHub-reported unique values are summed per repository/day and are not globally deduplicated people, users, or deployments.
Accepted and pending upstream pull requests are tracked separately so open submissions are not presented as accepted validation.
GitLab merge requests are included from authenticated GitLab data plus public MR verification for known upstream requests.
Public GitHub footprint at snapshot time, including source repositories and forked repositories.
Repository traction and release evidence for the self-hosted CTI platform.
Repository traction and release evidence for the malware-analysis and reverse-engineering debugger.
1 of 5 open GitHub PRs have no maintainer comments or reviews yet. 0 are draft PRs.
Main reason for the backlog: external maintainer review latency. Actionable technical items at this snapshot: 1 behind, 0 blocked, 0 unstable.
Highest-star public repositories visible under the GitHub account at snapshot time.
Repository metrics are point-in-time public GitHub/GitLab observations. Stars, forks, issues, and review status can change after the snapshot.
| Project / Contribution | Status | Upstream | Evidence |
|---|---|---|---|
| 1200km Lab Work General cybersecurity lab portfolio submission. |
Approved | okhosting/awesome-cyber-security | PR #27 |
| AdversaryGraph AI-powered CTI and MITRE ATT&CK analysis platform submission. |
Approved | okhosting/awesome-cyber-security | PR #30 |
| 1200km Vulnerable Lab Projects Vulnerable application and lab portfolio submission. |
Approved | vavkamil/awesome-vulnerable-apps | PR #44 |
| AIDebug AI-assisted malware analysis and YARA-oriented reverse-engineering tool submission. |
Approved | pedramamini/awesome-yara | PR #78 |
| AdversaryGraph AI-powered CTI and MITRE ATT&CK analysis platform submission. |
Approved | cyb3rxp/awesome-soc | PR #20 |
| ThreatMapper and CTI Analyst Field Manual Detection engineering resource submission accepted by upstream maintainers. |
Approved | infosecB/awesome-detection-engineering | PR #28 |
| Cyber Av3ngers Threat Actor Update MISP Galaxy threat-actor contribution accepted by upstream maintainers. |
Approved | MISP/misp-galaxy | PR #1227 |
| AdversaryGraph AI-powered CTI and MITRE ATT&CK analysis platform submission. |
Approved | cckuailong/awesome-gpt-security | PR #50 |
Connector submission to the OpenCTI upstream platform adding Anthropic AI-powered enrichment to the connector ecosystem. Under active maintainer review.
Sigma detection rule submission covering Deno child-process and non-mail IMAP activity, under maintainer review.
Community guide index submission for the HexStrike AI documentation, under maintainer review.
Vulnerable AI Lab submission to a public LLM-security resource list, under maintainer review.
AIDebug submission to REMnux's provisioning states, adding it alongside the distribution's other malware-analysis tooling.
On 2026-08-05, 24 GitHub PRs and 1 GitLab MR with no maintainer comments or reviews were withdrawn and closed, narrowing this section to submissions with an active review signal. Open PRs are listed as review evidence, not as acceptance. Approved items move to the approved section only after upstream maintainer approval or acceptance.
| Tool | Request Status | Maintainer-Ready Contents | Evidence |
|---|---|---|---|
| AIDebug | Kali 2026.2 milestone | Tagged release, PyPI package, Debian metadata, man page, autopkgtest notes, dependency list, usage examples. | Kali request |
| AuditAI | Kali 2026.2 milestone | Linux host assessment scope, local CLI path, optional AI dependency, package metadata, CI and tests. | Kali request |
| String Analyzer | Kali 2026.2 milestone | Standard-library runtime, PyPI package, categorized malware/forensics triage output, tests and usage examples. | Kali request |
| RTSP Brute Force Tool | Prepared / request text | Authorized credential assessment scope, vendor presets, dry-run mode, JSON reports, Debian/Kali metadata. | Kali request |
| StratusAI | Prepared / request text | External/cloud assessment scope, no-AI mode, recommended external tools, package metadata, status notifications. | Kali request |
AI-assisted malware reverse-engineering debugger with ATT&CK mappings, YARA seed rules, IOC export, JSON output, TUI workflow, and analyst reports.
Self-hosted AI-assisted CTI platform for ATT&CK/ATLAS extraction, sector-aware actor relevance, IOC enrichment, MalwareGraph-backed malware analysis, asset attack surface mapping, APT comparison, D3.js Navigator workflows, STIX/OpenCTI export, and analyst-ready reporting.
Medium remains the public article source, while 1200km.com now provides internal navigation, Docusaurus pages, project pages, and ecosystem landing pages.
CTI workflows, detection engineering, malware analysis, OpenCTI, cloud and Kubernetes security, AI-assisted security tooling, reproducible labs, and technical guides.
Maintainer-ready because it has a tagged release, PyPI package, deterministic tests, GitHub Actions CI, release notes, screenshots, safety model, sample evidence, packaging metadata, and a clear non-exploit malware-analysis scope.
Maintainer-ready because the v7.0.0 source release is merged and CI-validated with the reproducible readiness gate, rollback guidance, source-backed workflows, case studies, governed Threat Hunting, Query Library, Unified RAG/MCP, asset exposure assessment, and SOC access groups. Attack Simulation and SIEM validation were introduced in the historical v5.0.0 line and remain part of the current platform. The latest published immutable GitHub release is v7.0.0, matching this source-release evidence.
Maintainer-ready because the labs are framed as authorized, reproducible education and validation environments with clear deployment paths, screenshots, documentation, and CTI/detection context.
Maintainer-ready because the work is organized around evidence handling, ATT&CK mapping, detection handoff, reproducibility, Sigma/MISP-compatible contribution patterns, and analyst-facing documentation.