KRAKEN
Continuous observation substrate for actor-centric infrastructure tracking, enrichment and graph context.
Malwarebox is an independent research initiative from Germany/Europe 🇩🇪🇪🇺 building the frameworks, methodology and tooling that modern threat intelligence is missing. Seven components, one analytical loop, partially open, designed to outlast any single campaign.
The field produces more indicators, reports and feeds than ever. The missing part is not more data. The missing part is structure: how campaigns are composed, how infrastructure is routed, how actors make recurring decisions, and how defenders should prioritize what matters.
Models, schemas, query concepts and defensive methodology can be open. Continuous operational evidence, private actor notes and decision substrates remain controlled where needed.
A clean split → operationalize → prioritize model: KRAKEN produces evidence, IIM and Modus interpret different layers, IIMQL, Search, Workbench and Feeds make the model operational and shareable, MB-RM selects the actors that matter, and ACDP decides what to do first.
Continuous observation substrate for actor-centric infrastructure tracking, enrichment and graph context.
Infrastructure Intelligence Model. Structural grammar for adversary infrastructure roles, relations, chains and patterns.
Query language for adversary infrastructure. Lets analysts express structural searches across IIM data.
Fast lookup across IIM infrastructure data. Pivot from an indicator, role or pattern to the chains and actors it belongs to.
Sanitized, consumable IIM feeds. Structured chains and patterns published as safe, machine-readable intelligence for downstream tooling.
Analyst workspace for building, validating, visualizing and exporting IIM chains and patterns.
Adversary fingerprinting via decision-pattern profiles. Captures stable choices beyond tooling and infrastructure rotation.
Malwarebox Relevance Mapper. Maps organization-specific exposure to actor relevance and analyst-readable rationale.
Actor-Centric Defensive Prioritization. Converts actor relevance and intelligence context into ranked defensive controls.
Public analyst layer for actor overviews, Malwarebox actor IDs, malware references, IIM feeds and defensive articles.
Research output that feeds the ecosystem and documents campaigns, infrastructure patterns and defensive thinking.
Collects and relates infrastructure, campaigns, sightings and graph context.
Turns infrastructure into roles, relations, chains, techniques and reusable patterns.
Models stable adversary choices through versioned decision events and actor profiles.
Query, look up, inspect, validate and export the structured model — and publish it as sanitized IIM Feeds.
Ranks which actors matter for a specific defender and why.
Ranks the defensive controls that matter first against the relevant actors.
KRAKEN.evidence[] → IIM.chain { roles, relations, techniques } → IIM.pattern { reusable structure } → IIMQL.result { matched chains } → IIM Search.hit { indicator → chain } → Workbench.validation { analyst reviewed } → IIM Feeds.published { sanitized intel } → Modus.profile { decision distributions } → MB-RM.ranking { actor relevance } → ACDP.controls { prioritized defense } → KRAKEN.collection_tasks { next cycle }
Indicators rotate. Actors persist. Infrastructure, decisions and priorities connect back to the operator view.
Assumptions, weights, models and interpretations must be visible, contestable and reproducible.
Frameworks, schemas, methodology and reference tooling can be public. Sensitive substrates stay controlled.
Built with a strong European sovereignty angle and designed to reduce dependency on closed external CTI ecosystems.
Designed to complement ATT&CK, STIX, NIST, Sigma, YARA, Suricata and existing CTI workflows, not replace them.
The end goal is not another feed. The end goal is better defensive decisions and clearer analyst workflows.
Useful for analysts, readers and partners without exposing operationally harmful details.
Operational material stays private or partner-gated when publication would help adversaries adapt.