Independent Threat Intelligence Research

Open frameworks
for the infrastructure
of adversary work.

Malwarebox is an independent research initiative building the frameworks, methodology and tooling that modern threat intelligence is missing. Three components, one analytical loop, partially open, designed to outlast any single campaign.

Components 3 active
Focus Infrastructure
Model Partially open
Origin Europe 🇪🇺 / Germany 🇩🇪
01 - THE IDEA

Threat intelligence has a shape problem.

The field produces more data than ever - indicators, reports, feeds, detections and less clarity per unit of data than a decade ago. Not because the data is bad. Because the structures to hold it were never built.

Adversaries operate as systems.
Most frameworks treat them as events.

Indicators decay within days. Behavioral taxonomies describe endpoints but stay silent on infrastructure. Risk models quantify impact but ignore adversary intent. Between these layers sits the operational reality - how campaigns are actually composed, delivered, routed and defended against.

Malwarebox exists to build what is missing in this space: structured models, explicit methodology and continuous observation, all released openly, designed to compose with existing standards rather than replace them.

"Threat intelligence doesn't need more data. It needs shape."
02 - COMPONENTS

Three components. One loop.

Malwarebox publicly holds three independent but complementary projects - a platform, a framework and a methodology. Each functions on its own. Together they form a closed analytical loop: observation produces structure, structure produces priority and priority drives further observation.

03 - THE LOOP

Each component is incomplete alone.

Kraken without IIM is a graph of disconnected observations. IIM without Kraken is a grammar nobody uses. ACDP without both is scoring numbers pulled from air. Together they form a single analytical loop where each component produces exactly what the next one needs.

Analytical Loop

Observation. Structure. Priority.

Three components, three flows between them, one coherent way to go from raw infrastructure signals to justified defensive decisions.

actor-centric explicit-first K · PLATFORM Kraken CONTINUOUS OBSERVATION Tracks rotations, maintains graph I · FRAMEWORK IIM STRUCTURAL MODEL Roles, relations, patterns A · METHODOLOGY ACDP DEFENSIVE TRANSLATION Converts intent to priority OBSERVATIONS → STRUCTURE STRUCTURE → PRIORITY PRIORITY → COLLECTION
04 - PRINCIPLES

How we build.

Six principles that run through every component. They are not promises. They are constraints we accept, because without them the work collapses into the same noise it tries to replace.

Actor-Centric

Indicators rotate. Actors don't.

Everything we build currently organizes around adversaries, not artifacts. Infrastructure, patterns, priorities - all of it connects back to the operators behind the activity. The artifact view is tactical and short-lived. The actor view outlives any single campaign.

Explicit-First

Implicit assumptions rot.

Every model, weighting and scoring decision is documented and contestable. If a judgment can't be written down, it can't be reviewed and if it can't be reviewed, it degrades silently. We choose the discomfort of explicit decisions over the comfort of implicit ones.

Open Where It Matters

The frameworks belong to everyone. The lab doesn't.

IIM, ACDP, the schemas, the reference implementations - everything the community needs to reason, review and build on top of - is released openly. Kraken is the working environment behind it, and for now it stays closed. Access is granted through vetting. Research that shapes public frameworks has to mature somewhere private first, that somewhere is Kraken.

European

Sovereign infrastructure matters.

Europe has historically depended on US commercial feeds and fragmented bilateral exchanges for threat intelligence. That dependence is a strategic weakness. Malwarebox builds open, federated, sovereign alternatives.

Patient

No rush to be adopted.

This is the standard We use across my own ecosystem. I'm sharing it because it might be useful to others working on the same problems. Things that become useful to many people tend to do so slowly, and I'd rather get it right than get it noticed.

Composable

Complement, don't replace.

We do not intend to replace ATT&CK, STIX, NIST, or any mature framework. Every component of Malwarebox is designed to compose with existing standards and fill specific gaps.

05 - RESEARCH

The work in motion.

Malwarebox publishes continuous threat intelligence research through the Synaptic Security Blog - deep analyses of active adversaries, infrastructure patterns and defensive approaches. The research informs the frameworks. The frameworks sharpen the research.

The current focus is on adversaries targeting Europe and especially Ukraine - state-aligned operators whose campaigns rotate infrastructure faster than most feeds can keep up with. Gamaredon is the clearest example: a group that has been active for over a decade, shifts infrastructure on a near-daily basis, and keeps returning to the same structural patterns underneath the rotation. Understanding how they operate as a system - rather than through isolated samples - is what most of the recent work has been about.

New analysis is published approximately every one to two weeks. The approach stays the same across actors: treat them as systems, describe the infrastructure structurally, and assume the specific IOCs will be gone by the time anyone reads the post.

Visit the Blog
Active Coverage 7+ APTs
Published Analyses 17+
Publication Cadence Monthly


An open position.

Malwarebox is research infrastructure, released as it is built. Use what is useful, critique what is weak, contribute what is missing. The work is better when more people touch it.