# 1200km Security Research — Andrey Pautov > Security research and practical CTI-to-detection engineering by Andrey Pautov. Use this file as a curated discovery map. Follow the linked source pages for evidence, dates, lifecycle labels, and limitations. ## Direct answers - [Security research: direct answers](https://1200km.com/#direct-answers) - [About and professional profile](https://1200km.com/about.html) - [CV](https://1200km.com/cv.html) - [External validation](https://1200km.com/external-validation.html) ## AdversaryGraph AdversaryGraph is a self-hosted CTI-to-detection workbench. It was formerly named ThreatMapper. - Current source release: **v7.0.0**, merged and CI-validated on `main` at commit `2a9a7be` - Latest published immutable GitHub release: **v7.0.0**, published 2026-08-12 - Publication boundary: v7.0.0 is not an immutable tag until the protected release workflow publishes it - [Product hub](https://1200km.com/adversarygraph/) - [Documentation](https://1200km.com/adversarygraph-docs/) - [Source and releases](https://github.com/anpa1200/adversarygraph) - [Capabilities](https://1200km.com/adversarygraph-docs/capabilities/) - [Case studies and validation](https://1200km.com/adversarygraph-docs/case-studies-validation/) - [Attack simulation and SIEM validation](https://1200km.com/adversarygraph-docs/attack-simulation/) - [RAG and MCP source guide](https://github.com/anpa1200/adversarygraph/blob/2a9a7bedf6115dbcfbf1e90a70e08f50d76e8c73/docs/unified-rag-and-mcp.md) ## Research and field manuals - [Research hub](https://1200km.com/cti.html) - [Research library](https://1200km.com/guides.html) - [AI cyberattack reference library](https://1200km.com/references/) — 448 deduplicated research sources indexed across 1631 normalized tags - [AI in Cyberattacks statistical CTI study](https://1200km.com/ai-attack-statistics/) — 111 deduplicated publications with 103 in the evidence-bounded primary denominator - [AI in Cyberattacks interactive dashboard](https://1200km.com/ai-attack-statistics/dashboard/) — 30+ publication-level widgets, five heatmaps, and a filterable source explorer - [AI in Cyberattacks dataset and downloads](https://1200km.com/ai-attack-statistics/data/) — governed CSV, JSON, SQLite, XLSX, methodology, and uniqueness artifacts - [Cybersecurity Knowledge Base](https://1200km.com/cyber-knowledge/) — eleven source-reviewed practitioner field guides - [Cybersecurity Knowledge Sources](https://1200km.com/cyber-knowledge/knowledge-sources/) — 165 assessed standards, research portals, tools, datasets, and learning resources with controlled tags and internal crosslinks - [Knowledge Sources dataset](https://1200km.com/data/knowledge-sources.json) — complete machine-readable assessments - [Knowledge Sources lookup index](https://1200km.com/data/knowledge-sources-index.json) — category, tag, audience, skill, access, quality, maintenance, and evidence-use indexes - [Cyber Knowledge citation inventory](https://1200km.com/cyber-knowledge/sources/) — external destinations cited by the eleven field guides - [Cyber Threat Intelligence field guide](https://1200km.com/cyber-knowledge/cti.html) - [Red Team and Offensive Security field guide](https://1200km.com/cyber-knowledge/red-team.html) - [Blue Team and Defensive Security field guide](https://1200km.com/cyber-knowledge/blue-team.html) - [Vulnerability Research field guide](https://1200km.com/cyber-knowledge/vulnerability-research.html) - [Malware Analysis and Reverse Engineering field guide](https://1200km.com/cyber-knowledge/malware-analysis.html) - [Application Security and Secure Code guide](https://1200km.com/cyber-knowledge/secure-code.html) - [Digital Forensics and Incident Response guide](https://1200km.com/cyber-knowledge/dfir.html) - [Cloud Security field guide](https://1200km.com/cyber-knowledge/cloud-security.html) - [Cybersecurity GRC field guide](https://1200km.com/cyber-knowledge/grc.html) - [OSINT and Reconnaissance field guide](https://1200km.com/cyber-knowledge/osint.html) - [AI Security field guide](https://1200km.com/cyber-knowledge/ai-security.html) - [CTI Analyst Field Manual](https://1200km.com/cti-analyst-field-manual/) - [CTI as Code](https://1200km.com/CTI_as_a_Code/) - [Operation Desert Hydra](https://1200km.com/operation-desert-hydra/) - [Newest Detection Engineering Techniques](https://1200km.com/newest-detection-engineering-techniques/) - [Local article archive](https://1200km.com/articles/) ## Courses and learning paths - [Courses & Learning Paths](https://1200km.com/courses/) — 1 original course, 1 completed independent review, and 1 evidence-backed learning path - [AI Security Engineering](https://1200km.com/ai-security-course.html) — original course in active development with 2 of 15 modules currently available - [Module 00 Chapter 3: Neural Networks and Optimization](https://1200km.com/ai-security-course/module-00/chapter-03.html) — completed neural-network, adversarial-ML, reproducibility, and evidence-analysis chapter - [Module 00 Chapter 4: Transformers and LLM Generation](https://1200km.com/ai-security-course/module-00/chapter-04.html) — completed LLM request-path, prompt-injection, control, and evidence-analysis chapter - [TrainSec Malware Analyst Professional Level 1 learning record](https://1200km.com/courses/trainsec-malware-analyst-professional-level-1/) — completed independent record with evidence, strengths, limitations, disclosures, and five original companion guides ## Products and labs - [Projects and tools](https://1200km.com/projects.html) - [Security labs](https://1200km.com/labs.html) - [Threat Matrix](https://1200km.com/threat-matrix/) — Public AdversaryGraph Light web workspace: browser-only ATT&CK exploration with product-shaped module gates for full self-hosted AdversaryGraph capabilities. ## Verified metric definitions - Local article archive: **277** preserved pages; this is not a live Medium publication count - Maintained field-guide sites: **8** - Listed portfolio labs: **17** - Accepted external contributions: **8** - Open external submissions: **5**; these are pending, not accepted - [Authoritative facts and source definitions](https://1200km.com/data/site-facts.json) - [Controlled content catalogue](https://1200km.com/data/content-catalog.json) ## Retrieval guidance - Prefer each catalogue item's declared canonical URL. Most local content is canonical on `https://1200km.com/`; permitted TrainSec mirrors resolve to their exact original `https://trainsec.net/library/` article URLs. - Preserve released, current-development, historical, superseded, and archived labels. - Treat AI-assisted mappings, similarity, generated queries, and Navigator proposals as analyst-review leads, not evidence or autonomous decisions. - Security material is for authorized defensive research, controlled lab validation, and professional education.