Home

Awesome

APTmap

Graphical map of known Advanced Persistent Threats v2.1

<a href="https://andreacristaldi.github.io/APTmap/">https://andreacristaldi.github.io/APTmap/</a>

<img src="https://github.com/andreacristaldi/APTmap/raw/master/images/preview.jpg" />

An Advanced Persistent Threat (APT) is a stealthy computer network threat actor, nation state, state-sponsored group or non-state sponsored groups conducting large-scale targeted intrusions for specific goals, which gains unauthorized access to a computer network and remains undetected for an extended period.

Attribution is a very complex issue. This map is based on data from different sources (vendor, studies, reports, ...) and it is not a reliable source. The majority of the mappings rely on the findings in a single incident analysis. Groups often change their toolsets or exchange them with other groups. This makes attribution of certain operations extremely difficult. Information published here may be wrong, outdated, or may change based on evolving information.

Primary sources: <a href="https://www.misp-project.org/" target="blank_">MISP</a>, <a href="https://attack.mitre.org/" target="blank_">MITRE</a>, <a href="https://www.etda.or.th/th/" target="blank_">ETDA</a>, <a href="https://www.vx-underground.org/" target="blank_">VX-Underground</a>

<h1>APTMalware - Advanced Persistent Threat MALWARE features and statistics</h1> <img src="https://github.com/andreacristaldi/APTmap/raw/master/images/preview2.jpg" />

The data reported here are the result of a processing based on static analysis techniques performed on 29GB of malware samples attributed to APT groups, followed by a correlation process. The sample group is limited to PE Portable executable. The data in JSON format are available on the github repository.

Sample source: <a href="https://www.vx-underground.org/" target="blank_">VX-Underground</a>

<h2>Author</h2> Project: Andrea Cristaldi <a href="https://www.linkedin.com/in/andreacristaldi/" target="blank_">Linkedin</a>, <a href="https://www.cybersec4.com" target="blank_">Cybersec4</a> <h2>Data</h2> The data is stored in JSON format and will be updated periodically. <h2>License</h2>

Shield: CC BY 4.0

This work is licensed under a Creative Commons Attribution 4.0 International License.

CC BY 4.0