AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Equation
Aliases: None listed
Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
OSINT & Reconnaissance · tactic-routeModule 5 — Cloud, containers, and Kubernetes
Red Team & Offensive Security · tactic-routeData classification, storage, cryptography, keys, backup, and deletion
Cloud Security · tactic-routeControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · tactic-routeModule 4 — Detection engineering and detection as code
Blue Team & Defensive Security · tactic-routeDisk, file-system, and persistence forensics
Digital Forensics & Incident Response (DFIR) · tactic-route