AI Analysis
Upload PDF, DOCX, or TXT — or paste text — and get a streamed ATT&CK technique extraction with evidence snippets and confidence scores. Supports Claude, GPT-4o, and Gemini.
Read more →Map adversary behaviour to MITRE ATT&CK in seconds, compare against 174+ APT groups, and generate PDF reports — all running locally with your own LLM keys.
You give ThreatMapper a threat report — malware writeup, IR summary, vendor advisory, raw Slack thread. It gives you ATT&CK technique IDs, confidence scores, evidence snippets, and a ranked list of APT groups whose known TTP profile overlaps with what you observed. All computation is local. Nothing leaves your machine.
Upload PDF, DOCX, or TXT — or paste text — and get a streamed ATT&CK technique extraction with evidence snippets and confidence scores. Supports Claude, GPT-4o, and Gemini.
Read more →Interactive heatmap of the full ATT&CK matrix (Enterprise, Mobile, ICS). Build, save, reload, and export named TTP layers. Overlay any APT group for instant visual diff.
Read more →Automatic Jaccard similarity ranking against 174+ named threat groups and 56+ named campaigns. See exactly which techniques you share and what your detection gaps are.
Read more →DB 1 holds the full MITRE ATT&CK dataset including named campaigns. DB 2 stores every AI analysis you run — re-compare any past report without re-calling the LLM.
Read more →Generate multi-page formatted PDF reports from any analysis or Navigator layer. Includes cover page, executive summary, technique table, APT attribution, and tactic coverage.
Read more →Drive the entire workflow programmatically. Headless analysis, batch comparisons, layer management — all exposed as a documented REST API (Swagger at /docs).
Read more →Full walkthrough of every feature published on Medium: ThreatMapper: I Built a Self-Hosted AI Threat Intelligence Platform — Here's How to Use It
Professional CTI tradecraft from collection requirements to detection-ready outputs.
Visit →Structured intelligence product lifecycle as versioned code.
Visit →Deep-dive threat intelligence campaign analysis.
Visit →AI-augmented CTI delivery methodology for customer-facing teams.
Visit →