AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Sowbug
Aliases: None listed
Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idCloud, SaaS, identity, container, and Kubernetes forensics
Digital Forensics & Incident Response (DFIR) · topic-matchTimeline reconstruction, ATT CK mapping, CTI, and confidence
Digital Forensics & Incident Response (DFIR) · topic-matchPrompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchEvidence integrity, order of volatility, and chain of custody
Digital Forensics & Incident Response (DFIR) · topic-matchEndpoint live response and volatile acquisition
Digital Forensics & Incident Response (DFIR) · topic-matchNetwork, DNS, proxy, VPN, and email forensics
Digital Forensics & Incident Response (DFIR) · topic-matchInfrastructure as code, CI/CD, artifact provenance, and policy as code
Cloud Security · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-match