See the threat. Understand the context. Act on evidence.
An evidence-led analyst workspace for ransomware, exploited vulnerabilities, threat actors, malware, IOCs and emerging cyber activity. Every assessment preserves source provenance, confidence and collection context.
Global cyber situation picture
Evidence-backed priority, exploitation, ransomware, Pulse and collection health in one operational view.
CALCULATING
Key judgement, confidence & intelligence gaps
Separates source-backed facts from analytical judgement and collection limitationsBuilding assessment from current source snapshots…
Waiting for correlated intelligence.
Geolocated threat activity & live intelligence
Building global intelligence view…Latest intelligence
All signals · 30DEvidence-backed relationship chains
Only relationships supported by the currently loaded source set are shownActor concentration
Exploit pressure
Ransomware claim geography
Most active groups
Enrichment coverage
Enriched victim sectors
Employee exposure
Revenue profile
Follow the evidence across entities.
Search loaded CTI for a CVE, ATT&CK technique, campaign, ransomware group, victim, country, malware family or IOC. Direct evidence is separated from contextual relationships.
Enter an entity above or use the global search. ThreatHub will show source-backed matches, direct relationships, contextual links and collection gaps.
Observed adversary behavior
Technique and tactic relationships come from the official Enterprise ATT&CK dataset or an explicit ATT&CK ID in loaded source evidence.Correlated intelligence
Solid links are directly present in loaded source data. Dashed/context labels indicate analyst context, not incident attribution.Source-backed observations
Campaign Intelligence
Separate the official ATT&CK campaign profile from the latest ThreatHub observations. Direct ATT&CK relationships remain distinct from contextual Pulse evidence, with visible freshness and provenance.
Structured adversary operations
Waiting for MITRE ATT&CK…Management situation brief
A concise, evidence-based summary generated from the five live intelligence sources.
Generating briefing…
Waiting for correlated intelligence.
What changed
LATEST SIGNALSWhat to watch
NEXT ACTIONTop KEV watchlist
CLICK TO DRILL DOWNRegional picture
Source confidence
—Regional Threat Intelligence
Malaysia-focused cyber signals with ASEAN ransomware activity from the currently loaded public intelligence feed.
National cyber signal picture
Waiting for Malaysia intelligence.
Derived OSINT signal. Not an official national threat level.Regional ransomware activity
ASEAN claim concentration
Regional threat groups
—Targeted sectors
OSINTLatest MyCERT advisories
National advisory feedSee what is gaining momentum across the cyber world.
ThreatHub Pulse correlates ransomware, vulnerabilities, malware, breaches, IOCs and threat research from trusted public sources, then ranks what is trending, emerging and corroborated.
Highest-significance cyber topics
Building ranking…Ranked discovery queue
Priority ordered by signal score, momentum, credibility, evidence and recency| Rank | Topic | Category | Score | Momentum | Signals | Latest | Actions |
|---|
Geolocated threat activity
Victims, Groups, Targeting & Evidence
Investigate public ransomware and extortion claims across the retained historical archive, from global activity and actor concentration down to victim, country, sector and source traceability.
Find and narrow ransomware intelligence
Search victim, domain, ransomware group, country or sector. Filters update the map, analytics and claim explorer together.Where ransomware claims are appearing now
LIVE · last 24 hoursClaim trend
Selected history windowMost active groups
Click a group for profileTargeted countries
Click to inspect claimsTargeted sectors
Selected windowRecent victim claims
Click for evidence viewInvestigate retained ransomware claims
Every row preserves the victim → group → country → sector → discovery time → source-evidence path.| Victim | Group | Country | Sector | Discovered | Verification | Evidence |
|---|---|---|---|---|---|---|
Loading retained ransomware intelligence… | ||||||
Ransomware group profiles
Activity, countries, sectors and any TTP/CVE/tool metadata exposed by the public source.Most active actor
Building actor profile from retained claims…Most active groups
30-day claim volume with 7-day activity contextObserved ransomware & extortion groups
Search, compare and investigate current actor activity.Geographic concentration
Countries appearing most often across 30-day actor claimsSector concentration
Industries with the highest observed claim volumeRecent victim claims
Newest retained ransomware disclosuresFamily activity watch
Building family intelligence…Observed infostealer families
Derived from loaded MalwareBazaar, ThreatFox and other source-backed Pulse records.| Family | Activity | Momentum | Samples | IOCs | Sources | First seen | Last seen |
|---|
Recent infostealer observations
What this workspace means
ThreatHub Infostealer Intelligence V1 shows malware-family, sample, IOC and research evidence already present in the loaded intelligence. It does not claim stolen credentials, compromised organizations or account exposure unless a future approved exposure source explicitly supports that relationship.
Enforced IOC lifecycle queue
Expired and revoked indicators remain auditable but are excluded from the default operational view and current-risk relationships.| Indicator | Type | Confidence | Lifecycle | Sightings | Sources | Last seen / expiry | Context |
|---|
Recent source observations
Click an observation to inspect the IOC, evidence chain and related entities.Exploit Intelligence 3.0
Turn CISA KEV seeds into enriched exploit intelligence by correlating NVD, FIRST EPSS, Pulse observations, MyCERT regional advisories and explicit IOC relationships — without inventing actor attribution.
Assessing exploit signals
ASSESSINGCorrelating actively exploited KEVs, CVSS severity, EPSS probability and ransomware association.
What the KEV seed tells us beyond severity
Cross-source observation, regional relevance and evidence completeness are kept separate from the existing ThreatHub priority score.Filter, prioritise and verify known exploited vulnerabilities
CISA KEV confirms exploitation. ThreatHub enriches each seed with technical severity, exploit probability, cross-source observations, regional advisories, IOC relationships and evidence strength.Top vulnerabilities to watch now
CVSS × EPSS × CTI Priority
Upper-right means severe + highly likely exploitation. Click a point for evidence.Severity & exploit probability
New exploited vulnerabilities
CISA KEV additions vs ransomware-associated additionsMost represented vendors
Click a vendor to filter the live KEV tableKEV-seeded exploit intelligence
Loading…| CVE | Vendor / Product | CVSS | EPSS | Ransomware | CTI | Intelligence | Evidence |
|---|
Live operational feed
A focused triage timeline of the newest source-backed intelligence. Open any row for full context, evidence and source links.