MISP Galaxy threat-actor record
A Cyber Av3ngers threat-actor update was accepted into the public MISP Galaxy repository.
Boundary: upstream merge evidence; no downstream deployment or usage claim.
External validation / publications
A reviewer-facing evidence register led by verified public records and accepted upstream work. Reproducible validation, releases, point-in-time metrics, and open submissions follow in decreasing evidentiary strength; open submissions are never presented as adoption or acceptance.
These records prove upstream acceptance only. They do not establish production deployment, active users, operational effectiveness, or endorsement. Publication rules are defined in the adoption-evidence model.
A Cyber Av3ngers threat-actor update was accepted into the public MISP Galaxy repository.
Boundary: upstream merge evidence; no downstream deployment or usage claim.
Threat Matrix and the CTI Analyst Field Manual passed external review for an upstream detection-engineering resource list.
Boundary: curation evidence; not evidence of production SOC deployment.
AIDebug passed upstream review for inclusion in a public YARA resource collection.
Boundary: external curation only; not package-use or active-user evidence.
AdversaryGraph passed upstream review for inclusion in a public SOC resource collection.
Boundary: third-party curation evidence; not a production-deployment claim.
Merged into public third-party repositories. Closed-unmerged and open submissions are excluded.
30 GitHub PRs and 1 GitLab MR submitted for maintainer review across CTI, malware, detection, cloud, AI, mobile, and lab lists.
Markdown files preserved in the maintained Medium export archive; this is not a live Medium publication count.
GitHub release, PyPI package, wheel/sdist artifacts, CI, tests, Kali request text, and docs.
Merged and CI-validated on main. The latest published immutable GitHub release remains v6.0.0 until the protected v6.5.0 tag workflow completes.
Live public portfolio total across 82 GitHub repositories, including 37 forked repositories, 20 repository forks, 26 GitHub followers, and 27 combined stars for AIDebug plus AdversaryGraph.
Live public GitHub follower count for the anpa1200 account at verification time.
GitHub clone events summed across 44 daily-tracked source repositories (Jul 13–Jul 26 2026). The 858 GitHub-reported unique values are summed per repository and are not globally deduplicated people, users, or deployments.
Cumulative GitHub clone events across 44 daily-tracked source repositories (Jun 13–Jul 26 2026). The 3,557 GitHub-reported unique values are summed per repository/day and are not globally deduplicated people, users, or deployments.
Accepted and pending upstream pull requests are tracked separately so open submissions are not presented as accepted validation.
GitLab merge requests are included from authenticated GitLab data plus public MR verification for known upstream requests.
Public GitHub footprint at snapshot time, including source repositories and forked repositories.
Repository traction and release evidence for the self-hosted CTI platform.
Repository traction and release evidence for the malware-analysis and reverse-engineering debugger.
25 of 30 open GitHub PRs have no maintainer comments or reviews yet. 0 are draft PRs.
Main reason for the backlog: external maintainer review latency. Actionable technical items at this snapshot: 0 behind, 1 blocked, 0 unstable.
Highest-star public repositories visible under the GitHub account at snapshot time.
Repository metrics are point-in-time public GitHub/GitLab observations. Stars, forks, issues, and review status can change after the snapshot.
| Project / Contribution | Status | Upstream | Evidence |
|---|---|---|---|
| 1200km Lab Work General cybersecurity lab portfolio submission. |
Approved | okhosting/awesome-cyber-security | PR #27 |
| AdversaryGraph AI-powered CTI and MITRE ATT&CK analysis platform submission. |
Approved | okhosting/awesome-cyber-security | PR #30 |
| 1200km Vulnerable Lab Projects Vulnerable application and lab portfolio submission. |
Approved | vavkamil/awesome-vulnerable-apps | PR #44 |
| AIDebug AI-assisted malware analysis and YARA-oriented reverse-engineering tool submission. |
Approved | pedramamini/awesome-yara | PR #78 |
| AdversaryGraph AI-powered CTI and MITRE ATT&CK analysis platform submission. |
Approved | cyb3rxp/awesome-soc | PR #20 |
| ThreatMapper and CTI Analyst Field Manual Detection engineering resource submission accepted by upstream maintainers. |
Approved | infosecB/awesome-detection-engineering | PR #28 |
| Cyber Av3ngers Threat Actor Update MISP Galaxy threat-actor contribution accepted by upstream maintainers. |
Approved | MISP/misp-galaxy | PR #1227 |
Submissions to threat intelligence, SOC, DFIR, MITRE ATT&CK, threat hunting, incident response, blue-team, and detection ecosystems. The MISP Galaxy and detection engineering submissions have moved to approved evidence.
Submissions for reverse engineering, Python security, malware analysis, MalwareGraph standalone packaging, and threat intelligence lists. The YARA submission has moved to approved evidence.
Submissions to lab, vulnerable app, AI/LLM security, cloud security, mobile security, cyber range, blue-team, and detection collections.
Submissions for AI-assisted offensive security, audit, cloud assessment, CTI MCP, field manual, and HexStrike guide material.
Connector submission to the OpenCTI upstream platform adding Anthropic AI-powered enrichment to the connector ecosystem.
Open PRs are listed as review evidence, not as acceptance. Approved items move to the approved section only after upstream maintainer approval or acceptance.
| Tool | Request Status | Maintainer-Ready Contents | Evidence |
|---|---|---|---|
| AIDebug | Kali 2026.2 milestone | Tagged release, PyPI package, Debian metadata, man page, autopkgtest notes, dependency list, usage examples. | Kali request |
| AuditAI | Kali 2026.2 milestone | Linux host assessment scope, local CLI path, optional AI dependency, package metadata, CI and tests. | Kali request |
| String Analyzer | Kali 2026.2 milestone | Standard-library runtime, PyPI package, categorized malware/forensics triage output, tests and usage examples. | Kali request |
| RTSP Brute Force Tool | Prepared / request text | Authorized credential assessment scope, vendor presets, dry-run mode, JSON reports, Debian/Kali metadata. | Kali request |
| StratusAI | Prepared / request text | External/cloud assessment scope, no-AI mode, recommended external tools, package metadata, status notifications. | Kali request |
AI-assisted malware reverse-engineering debugger with ATT&CK mappings, YARA seed rules, IOC export, JSON output, TUI workflow, and analyst reports.
Self-hosted AI-assisted CTI platform for ATT&CK/ATLAS extraction, sector-aware actor relevance, IOC enrichment, MalwareGraph-backed malware analysis, asset attack surface mapping, APT comparison, D3.js Navigator workflows, STIX/OpenCTI export, and analyst-ready reporting.
Medium remains the public article source, while 1200km.com now provides internal navigation, Docusaurus pages, project pages, and ecosystem landing pages.
CTI workflows, detection engineering, malware analysis, OpenCTI, cloud and Kubernetes security, AI-assisted security tooling, reproducible labs, and technical guides.
Maintainer-ready because it has a tagged release, PyPI package, deterministic tests, GitHub Actions CI, release notes, screenshots, safety model, sample evidence, packaging metadata, and a clear non-exploit malware-analysis scope.
Maintainer-ready because the v6.5.0 source release is merged and CI-validated with the reproducible readiness gate, rollback guidance, source-backed workflows, case studies, governed Threat Hunting, Query Library, Unified RAG/MCP, asset exposure assessment, and SOC access groups. Attack Simulation and SIEM validation were introduced in the historical v5.0.0 line and remain part of the current platform. The latest published immutable GitHub release is still v6.0.0, so this source-release evidence does not claim that a v6.5.0 tag or container family has already been published.
Maintainer-ready because the labs are framed as authorized, reproducible education and validation environments with clear deployment paths, screenshots, documentation, and CTI/detection context.
Maintainer-ready because the work is organized around evidence handling, ATT&CK mapping, detection handoff, reproducibility, Sigma/MISP-compatible contribution patterns, and analyst-facing documentation.