πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
Threat Intel Β· free

APT knowledge graph

The same curated dataset as the feed, visualized as connections: which threat actors are reported operating from which regions, and targeting which sectors and regions β€” drawn only from what each source post actually states. Drag nodes, scroll to zoom, click a node to see its posts.

Browse the same data as a filterable feed β†’
Threat actorSuspected originTarget sectorTarget region

Node size reflects how many sourced connections a threat actor, origin, sector or region has in this dataset β€” not a measure of real-world activity or severity. Edges are drawn only from fields the original source post explicitly states; nothing here is inferred attribution.

Frequently asked questions

What connects the nodes in this graph?

Every edge comes from a real, sourced threat-intel post: a threat actor connects to a suspected origin, target sector, or target region only when the original vendor post explicitly states that fact. There is no inferred or estimated attribution in the graph.

Why does a threat actor not appear on the graph?

Only posts naming a specific threat actor contribute nodes and edges here. A post covering general malware or ransomware trends without naming an actor won’t show up in the graph β€” it still appears in the filterable feed.

Does node size mean the actor is more dangerous?

No. Node size reflects how many sourced connections that node has in this specific dataset β€” a curation artifact, not a severity or threat-level ranking.

Is this the same data as the APT feed?

Yes β€” the graph and the feed are built from the exact same curated dataset, just visualized two different ways. Click a node here to see its underlying posts, or browse everything with filters on the feed page.

APT Knowledge Graph β€” Visual Threat-Actor Explorer (Free) Β· PlayCISO