APT knowledge graph
The same curated dataset as the feed, visualized as connections: which threat actors are reported operating from which regions, and targeting which sectors and regions β drawn only from what each source post actually states. Drag nodes, scroll to zoom, click a node to see its posts.
Browse the same data as a filterable feed βNode size reflects how many sourced connections a threat actor, origin, sector or region has in this dataset β not a measure of real-world activity or severity. Edges are drawn only from fields the original source post explicitly states; nothing here is inferred attribution.
Frequently asked questions
What connects the nodes in this graph?
Every edge comes from a real, sourced threat-intel post: a threat actor connects to a suspected origin, target sector, or target region only when the original vendor post explicitly states that fact. There is no inferred or estimated attribution in the graph.
Why does a threat actor not appear on the graph?
Only posts naming a specific threat actor contribute nodes and edges here. A post covering general malware or ransomware trends without naming an actor wonβt show up in the graph β it still appears in the filterable feed.
Does node size mean the actor is more dangerous?
No. Node size reflects how many sourced connections that node has in this specific dataset β a curation artifact, not a severity or threat-level ranking.
Is this the same data as the APT feed?
Yes β the graph and the feed are built from the exact same curated dataset, just visualized two different ways. Click a node here to see its underlying posts, or browse everything with filters on the feed page.