THREATHUBGLOBAL CYBER THREAT INTELLIGENCE
LIVE
LOADINGChecking sources…
TH
ThreatHubIntelligence Console
THREATHUB · GLOBAL CYBER THREAT INTELLIGENCE

See the threat. Understand the context. Act on evidence.

An evidence-led analyst workspace for ransomware, exploited vulnerabilities, threat actors, malware, IOCs and emerging cyber activity. Every assessment preserves source provenance, confidence and collection context.

ANALYST WORKSPACE

Global cyber situation picture

Evidence-backed priority, exploitation, ransomware, Pulse and collection health in one operational view.

LIVEWaiting for intelligence…

Highest-priority evidence-backed developments

Ranked from loaded CTI, ransomware and Pulse intelligence

CALCULATING

Evidence confidence —
/100

Key judgement, confidence & intelligence gaps

Separates source-backed facts from analytical judgement and collection limitations
CALCULATING
KEY JUDGEMENT

Building assessment from current source snapshots…

Waiting for correlated intelligence.

Confidence basis
ANALYST PRIORITIES
INTELLIGENCE GAPS
ASSESSMENT ≠ FACT Analytical judgements are derived from the loaded source set.CONFIDENCE ≠ PROBABILITY Confidence reflects evidence quality and collection coverage.

Geolocated threat activity & live intelligence

Building global intelligence view…
AUTO60s sync
ScopeGLOBAL
Signal
Window
Highest activityElevatedObservedActor / ransomware lensLatest ≤24h Waiting for first render…

Latest intelligence

All signals · 30D
LIVE
Published ransomware snapshot checked every 60s · full intelligence refresh every 6 hours

Evidence-backed relationship chains

Only relationships supported by the currently loaded source set are shown
TRACEABLE

Actor concentration

30D
claims

Exploit pressure

LIVE
Known Exploited
EPSS > 50%
Ransomware KEV
Total KEVs

Ransomware claim geography

30D

Most active groups

7D

Enrichment coverage

30D
enriched
ransomware claims matched to seeded organization intelligenceLoading organization seed…
Domains
Industries
ZoomInfo IDs

Enriched victim sectors

30D
Seed-backed classification only · no inferred industries

Employee exposure

ENRICHMENT
Populates when employee-size fields are available from an approved enrichment source

Revenue profile

ENRICHMENT
Populates when revenue fields are available from an approved enrichment source
INTELLIGENCE ENGINE
— sourcesPulse —Ransomware —KEV —
THREATHUB INVESTIGATION · ENTITY CORRELATION

Follow the evidence across entities.

Search loaded CTI for a CVE, ATT&CK technique, campaign, ransomware group, victim, country, malware family or IOC. Direct evidence is separated from contextual relationships.

EVIDENCE-FIRST
SEARCH EXAMPLES
Investigation workspace ready

Enter an entity above or use the global search. ThreatHub will show source-backed matches, direct relationships, contextual links and collection gaps.

INTELLIGENCE · CAMPAIGN CORRELATION

Campaign Intelligence

Separate the official ATT&CK campaign profile from the latest ThreatHub observations. Direct ATT&CK relationships remain distinct from contextual Pulse evidence, with visible freshness and provenance.

ATT&CK —
CAMPAIGN OBJECTSOfficial ATT&CK
ATTRIBUTEDLinked threat groups
TECHNIQUESUnique mapped behavior
SOFTWAREMalware / tools
LOCAL CONTEXTCampaigns with exact-name Pulse context
PROFILE ≠ LIVE ACTIVITYMITRE ATT&CK defines campaign identity and direct relationships. ThreatHub Pulse adds separately labelled recent context; a recent mention does not by itself prove that the campaign is currently active.

Structured adversary operations

Waiting for MITRE ATT&CK…
Run the MITRE ATT&CK collector to populate campaign intelligence.
EXECUTIVE INTELLIGENCE

Management situation brief

A concise, evidence-based summary generated from the five live intelligence sources.

Generating briefing…

Waiting for correlated intelligence.

Confidence —

What changed

What to watch

Top KEV watchlist

Regional picture

Source confidence

MALAYSIA & ASEAN

Regional Threat Intelligence

Malaysia-focused cyber signals with ASEAN ransomware activity from the currently loaded public intelligence feed.

REGIONAL LENS

National cyber signal picture

ASSESSING
MY

Waiting for Malaysia intelligence.

Derived OSINT signal. Not an official national threat level.
≤24h
≤7d
≤30d
Top group

Regional ransomware activity

11 MEMBERS
claims in loaded feed
≤24h
≤7d
Active countries
Top country

ASEAN claim concentration

Latest-feed sample

Regional threat groups

Targeted sectors

Latest MyCERT advisories

National advisory feed
MyCERT ↗
THREATHUB PULSE · CYBER SIGNAL DISCOVERY

See what is gaining momentum across the cyber world.

ThreatHub Pulse correlates ransomware, vulnerabilities, malware, breaches, IOCs and threat research from trusted public sources, then ranks what is trending, emerging and corroborated.

LIVE RANKINGDISCOVER · INVESTIGATE · VERIFY
Discover important signals earlier.Pulse measures momentum, source diversity, credibility and cross-source corroboration so you can prioritize what deserves attention, investigate the relationships and verify every finding against its original evidence.
SIGNALS ANALYZEDLoaded source-backed records
ACTIVE SOURCESHealthy collectors
CORRELATED TOPICSClustered · deduplicated · ranked
EMERGING SIGNALSStrict multi-source acceleration
CORROBORATED TOPICSAuthoritative / cross-source

Ranked discovery queue

Priority ordered by signal score, momentum, credibility, evidence and recency
— topics
RankTopicCategoryScoreMomentumSignalsLatestActions
DISCOVERY · GLOBAL THREAT MAP

Global Threat Landscape

Explore geolocated ransomware and threat-actor activity across the world. Vulnerability signals remain global unless the upstream source provides defensible geography.

LIVE GEOSPATIAL INTELLIGENCE

Building map…

ScopeGLOBAL
Signal
Window

Geolocated threat activity

Waiting for render…
Highest activityElevatedObservedActor / ransomware lensLatest ≤24h
RANSOMWARE INTELLIGENCE

Victims, Groups, Targeting & Evidence

Investigate public ransomware and extortion claims across the retained historical archive, from global activity and actor concentration down to victim, country, sector and source traceability.

Open ransomware.live ↗
FEED STATUSCHECKINGSelecting freshest public feed…
LAST COLLECTOR CHECKGitHub Actions
LATEST SOURCE CLAIMWaiting for source data
NEW THIS CHECKCompared with previous collection
LIVE RANSOMWARE PULSEVictim-claim intelligence · browser auto-sync every 60 seconds · source collector every 6 hours
LATEST CLAIMWaiting for source data
CLAIMS ≤24HCurrent live window
COUNTRIES ≤24HMapped countries
ACTIVE GROUPS ≤24HObserved groups
MALAYSIA ≤24HMalaysia focus
Retained archiveRolling history
Claims · 90DSelected window
Claims ≤24hLatest activity
Active groupsIn current view
CountriesWith mapped claims

Find and narrow ransomware intelligence

Search victim, domain, ransomware group, country or sector. Filters update the map, analytics and claim explorer together.
No investigation filters applied
Loading intelligence…

Where ransomware claims are appearing now

LIVE · last 24 hours
LowHighLatest ≤24hAUTO SYNC · 60s
Colourful base map = visual geography. Bright heat colours = claim volume in the selected window. Pulsing markers = latest claims discovered within 24 hours.Mapping retained claims…

Claim trend

Selected history window
LIVE

Most active groups

Click a group for profile
DRILL-DOWN

Targeted countries

Click to inspect claims

Targeted sectors

Selected window

Recent victim claims

Click for evidence view
OSINT

Investigate retained ransomware claims

Every row preserves the victim → group → country → sector → discovery time → source-evidence path.
— MATCHES
VictimGroupCountrySectorDiscoveredVerificationEvidence
Loading retained ransomware intelligence…

Ransomware group profiles

Activity, countries, sectors and any TTP/CVE/tool metadata exposed by the public source.
— GROUPS
INTELLIGENCE · THREAT ACTORS

Threat Actor Intelligence 4.0

Canonical actor dossiers that consolidate approved aliases across ransomware claims, Pulse, IOC and MITRE ATT&CK evidence while preserving every observed source label and attribution guardrail.

ENRICHED ACTOR LENSWaiting for actor intelligence…
ACTIVE GROUPS · 30DGroups with observed victim claims
ϟ
ACTIVE GROUPS · 7DRecent operational activity
STRONG EVIDENCEEvidence completeness — not attribution probability
PULSE OBSERVEDExplicit ransomware-group topic entities
ASEAN RELEVANTObserved ASEAN claims ≤90D
MOST ACTIVE · 30DWaiting for data

Most active actor

Building actor profile from retained claims…
THREAT ACTOR
30D CLAIMS
7D ACTIVITY
TOP COUNTRY
TOP SECTOR
Actor activity is derived from source-backed ransomware victim claims; ThreatHub does not infer attribution beyond the loaded source metadata.

Most active groups

30-day claim volume with 7-day activity context
30D

Observed ransomware & extortion groups

Search, compare and investigate current actor activity.
— ACTORS
Evidence-backed enrichment
ACTOR / EVIDENCE30D7DMOMENTUMINTELLIGENCEASEANTOP TARGET

Geographic concentration

Countries appearing most often across 30-day actor claims

Sector concentration

Industries with the highest observed claim volume

Recent victim claims

Newest retained ransomware disclosures
INTELLIGENCE · INFOSTEALERS

Infostealer Intelligence

Track source-backed stealer family activity, malware samples, IOC observations and supporting research from the intelligence already collected by ThreatHub.

DISCOVERY → INVESTIGATE → VERIFY

Waiting for Pulse data…

ACTIVE FAMILIES · 30DObserved in loaded Pulse evidence
IOC OBSERVATIONSDomains · IPs · URLs · hashes
SAMPLE SIGNALSMalware sample records
ACTIVE ≤24HFamilies with fresh evidence
EVIDENCE SOURCESIndependent loaded sources

Family activity watch

Building family intelligence…
SOURCE-BACKED

Observed infostealer families

Derived from loaded MalwareBazaar, ThreatFox and other source-backed Pulse records.
— FAMILIES
FamilyActivityMomentumSamplesIOCsSourcesFirst seenLast seen

Recent infostealer observations

What this workspace means

ThreatHub Infostealer Intelligence V1 shows malware-family, sample, IOC and research evidence already present in the loaded intelligence. It does not claim stolen credentials, compromised organizations or account exposure unless a future approved exposure source explicitly supports that relationship.

INTELLIGENCE · INDICATORS OF COMPROMISE

IOC Intelligence

Investigate source-backed indicators with validated first/last-seen timing, type-specific TTL, expiry, revocation and lifecycle-aware confidence decay.

OBSERVE → CORRELATE → VALIDATE

Waiting for IOC snapshot…

INDICATORSUnique loaded IOC objects
OPERATIONALActive or aging; eligible for current-risk views
HIGH CONFIDENCEStrict evidence threshold — not maliciousness probability
SIGHTINGSSource observation records
MALWARE LINKEDDirect source-backed family relationship
IOC SOURCESIndependent loaded IOC feeds

Enforced IOC lifecycle queue

Expired and revoked indicators remain auditable but are excluded from the default operational view and current-risk relationships.
— MATCHES
IndicatorTypeConfidenceLifecycleSightingsSourcesLast seen / expiryContext
Page —

Recent source observations

Click an observation to inspect the IOC, evidence chain and related entities.
SOURCE-BACKED
Dark Web Intelligence
Dark-web operational details are intentionally obscured in the public ThreatHub view.
PUBLIC VIEW · DETAILS HIDDEN
VULNERABILITY INTELLIGENCE

Exploit Intelligence 3.0

Turn CISA KEV seeds into enriched exploit intelligence by correlating NVD, FIRST EPSS, Pulse observations, MyCERT regional advisories and explicit IOC relationships — without inventing actor attribution.

PRESSURE

Assessing exploit signals

ASSESSING

Correlating actively exploited KEVs, CVSS severity, EPSS probability and ransomware association.

CVSS CoverageNVD enriched
EPSS CoverageFIRST scored

What the KEV seed tells us beyond severity

Cross-source observation, regional relevance and evidence completeness are kept separate from the existing ThreatHub priority score.
LOADING ENRICHMENT
Cross-source CVEsPulse evidence
MyCERT relevanceMalaysia advisory references
Strong evidenceEvidence completeness · not probability
Fresh evidence · 7DLatest source-backed observation
IOC-linked CVEsExplicit source relationships only
Building a stable enrichment snapshot from the loaded intelligence sources…

Filter, prioritise and verify known exploited vulnerabilities

CISA KEV confirms exploitation. ThreatHub enriches each seed with technical severity, exploit probability, cross-source observations, regional advisories, IOC relationships and evidence strength.
CISA KEV · EXPLOITATION CONFIRMED
No investigation filters applied
Loading correlated vulnerability intelligence…
PRIORITY WATCHLIST

Top vulnerabilities to watch now

Click a card to open enriched evidence, Pulse observations, regional relevance and authoritative source links.

CVSS × EPSS × CTI Priority

Upper-right means severe + highly likely exploitation. Click a point for evidence.
CriticalHighMedium

Severity & exploit probability

scored
Critical High Medium Low
FIRST EPSS probability bands
Coverage
EPSS ≥10%
Top 1%

New exploited vulnerabilities

CISA KEV additions vs ransomware-associated additions
LIVE DATA
KEV additionsRansomware-related

Most represented vendors

Click a vendor to filter the live KEV table

KEV-seeded exploit intelligence

Loading…
CVEVendor / ProductCVSSEPSSRansomwareCTIIntelligenceEvidence
UNIFIED INTELLIGENCE

Live operational feed

A focused triage timeline of the newest source-backed intelligence. Open any row for full context, evidence and source links.

LIVEUpdated
SIGNALS · 24HTimestamped observations
CRITICALHighest-priority signals
RANSOMWAREExtortion activity
MALAYSIAMalaysia-relevant signals
ACTIVE SOURCESCollectors currently ready

Newest correlated intelligence

Building signals…
Latest source
Feed = triage · open a row for investigation
Collection freshnessCollector recency and source healthView details ↓
Feed Operations
Collector health and operational telemetry are intentionally obscured in the public ThreatHub view.
PUBLIC VIEW · DETAILS HIDDEN
Intelligence Sources
Detailed source inventory and collection telemetry are intentionally obscured in the public ThreatHub view.
PUBLIC VIEW · DETAILS HIDDEN
Data caveat: ransomware victim entries are public claims and not automatically independently verified incidents. Ransomware map and ASEAN counts use the retained Ransomware.live historical mirror when available and fall back to recent public-claim data; they are OSINT claims, not complete national incident totals. The Malaysia signal score is dashboard-derived OSINT. EPSS is provided by FIRST. This product uses NVD data but is not endorsed or certified by NVD.