Maintained products
Current supported software, led by AdversaryGraph and its associated public Threat Matrix workspace.
Canonical Public Footprint
This page is the public index for the 1200km security research ecosystem: flagship CTI platforms, malware-analysis tooling, PyPI packages, Docusaurus field guides, Medium research, labs, and community submission status.
Current supported software, led by AdversaryGraph and its associated public Threat Matrix workspace.
Question-led CTI and detection work with methods, evidence, findings, and stated limitations.
Installable utilities with registry and source links; availability is not presented as adoption.
Reproducible training and validation environments, separated from maintained product claims.
Accepted upstream work is separated from open submissions and backed by public records.
Superseded names, older version-specific material, and archived repositories remain available with lifecycle context.
Primary flagship: CTI-to-detection workbench, actor/TTP library, ATT&CK comparison, IOC investigation, MalwareGraph-backed malware analysis, hunting guidance, and report workflow.
Current source release: v6.5.0, merged and CI-validated on main. It includes governed hybrid retrieval across 12 platform source types, business-profile scoping, citation-grounded answers, persisted expiring Navigator advisory proposals that require analyst confirmation but do not save a layer, and a fixed four-tool stdio MCP surface. Exact matching and PostgreSQL full-text search are the default; private pgvector embeddings are optional. Published boundary: v6.0.0 remains the latest immutable GitHub release until v6.5.0 is tagged and published.
AI-assisted malware reverse-engineering debugger with ATT&CK candidates, YARA seeds, IOC extraction, JSON, and HTML reports.
Version-controlled CTI methodology and training lab with OpenCTI, TheHive, Elastic SIEM, evidence registers, and detection outputs.
MuddyWater CTI-to-detection pipeline with OpenCTI graph, detection atlas, Kibana validation, and reproducible lab evidence.
AdversaryGraph is the flagship self-hosted platform. Threat Matrix is its associated public, read-only browser ATT&CK workspace, not the full platform.
ThreatMapper is the historical name replaced by AdversaryGraph. AdversaryGraph Web is a superseded alias for Threat Matrix. Redirects and explicitly historical articles preserve old URLs.
GitHub currently marks lpi, Malware_analysis, Networking, and SystemCheck as archived. They are not presented as maintained products.
Definitions and source links are maintained in the authoritative fact model; content identity, lifecycle, and taxonomy are maintained in the content catalogue. Labs and research demonstrations are not automatically classified as products.
| Package | Availability | Purpose | Links |
|---|---|---|---|
| AIDebug | pip install 1200km-aidebug |
Malware debugger and reverse-engineering assistant. | PyPI · Repo |
| AuditAI | pip install 1200km-auditai |
Linux host vulnerability assessment with optional AI analysis. | PyPI · Repo |
| String Analyzer | pip install string-analyzer |
Extract strings, URLs, IPs, registry keys, APIs, and analyst prompts from binaries. | PyPI · Repo |
| Unpacker | Not published to PyPI | Packer detection and unpacking workflow for malware triage. | Source repository |
| PE Import Analyzer | Not published to PyPI | PE import-table capability triage for malware analysts. | Source repository |
| FileInfo | Not published to PyPI | First-pass file metadata, hashes, strings, entropy, YARA, and static triage. | Source repository |
AdversaryGraph, CTI Analyst Field Manual, CTI as a Code, Operation Desert Hydra, Israel Government Threat Actors CTI, CTI Detection Pack, threat-hunting hypotheses.
AIDebug, String Analyzer, Unpacker, PE Import Analyzer, Android Malware Analysis, Static Malware Analysis Orchestrator, Basic File Information Gathering Script.
HexStrike AI Guide, AI Offensive research, AI-PT-Lab, StratusAI, Vulnerable Cloud Lab, Vulnerable APK, DragonRx Lab, RTSP and password tooling.
Main site, start-here, local Article Archive, CV, About, project landing pages, and reading paths for different reviewer roles.
| Project | Status | Submitted To | Links |
|---|---|---|---|
| AdversaryGraph | Submitted | awesome-threat-intelligence, awesome-mitre-attack, awesome-detection-engineering, awesome_Threat-Hunting | PR · PR · PR · PR |
| AIDebug | Partially accepted | Accepted by awesome-yara; still under review for awesome-reversing, awesome-python-security, awesome-malware-analysis, REMnux, BlackArch | YARA merged · Reversing PR · REMnux · BlackArch |
| StratusAI | Submitted | awesome-gpt-security, Kali packaging tracker | PR · Tracker |
| AuditAI | Submitted | awesome-gpt-security, OWASP/Kali evaluation path | PR · Tracker |
| CTI Field Manual / MCP / Detections | Submitted | awesome-threat-intelligence, SigmaHQ, MISP Galaxy | Field Manual · CTI MCP · Sigma · MISP |
| HexStrike Guide | Submitted | Official HexStrike AI repository | PR #187 |
| Lab Portfolio | Submitted | Awesome Vulnerable Labs, vulnerable apps, AI/LLM security, cloud security, mobile security, threat detection, cyber range, blue team, general cybersecurity | Labs · Vulnerable apps · LLM · AI · Cloud · Cloud 2 · Mobile · Mobile 2 · Detection · Range · Blue team · General |
Status is intentionally conservative: items stay marked as submitted until an upstream maintainer merges, accepts, or explicitly rejects the contribution.
AdversaryGraph, CTI as a Code, Customer-Driven AI CTI, attribution methodology, ATT&CK usage, infrastructure pivoting, malware-to-CTI pivots, and detection handoff.
Historical AdversaryGraph v4 Malware Analysis coverage, the current Malware Analysis workflow, MalwareGraph standalone work, AIDebug, Android APK triage, strings, PE imports, unpacking, static orchestrator workflows, and YARA/IOC-ready analyst outputs.
HexStrike MCP, Cursor, Gemini, OpenAI Codex, local Ollama workflows, controlled labs, and defender takeaways.
StratusAI, vulnerable cloud labs, Kubernetes security, ITDR, UEBA, insider threat, anomaly detection, and CVSS prioritization.