MALWAREBOX / PLATFORM
"Indicators rotate constantly. Tracking actors is more stable."
KRAKEN WHITEPAPER

Kraken is Malwarebox's observation platform: it brings collection, processing, modeling and visualization into one continuous workflow, instead of five separate tools passing data back and forth.

Kraken dashboard: entity counts, intelligence growth, entity composition, service health
FIG 01 KRAKEN 1.0-EVAL "HADAL" · OPERATIONAL OVERVIEW
THE PROBLEM

Classical CTI work is spread across passive-DNS tools, sandbox systems, OSINT sources and manual correlation that don't talk to each other. A lot of analyst time goes into exporting, reformatting and merging, while the infrastructure being tracked has already moved on.

THE APPROACH

An entity graph, not a flat list

Every edge carries evidence, every relation is traceable rather than merely asserted. Repeated observations strengthen an existing entity instead of fragmenting the dataset with duplicates.

Domain → resolves_to → IP Address
URL → hosted_on → Domain
Malware → communicates_with → Infrastructure
Campaign → uses → Infrastructure
Threat Actor → operates → Campaign
Kraken threat graph view: entities and relations drawn as a radial graph
FIG 02 THREAT GRAPH · ENTITIES AND RELATIONS
CASE: MB-0001 IN KRAKEN

Gamaredon, from one account to a cluster

Tracking starts from a single known entity, in this case a Telegram or blog account used as a dead drop. A collection module reads its content on a cycle and extracts embedded domains, IPs and URLs. Each signal passes through normalization and import rules into the graph. Across cycles, new domains resolve to previously unseen IPs, which host further domains from the same campaign. One indicator exposes a full infrastructure cluster, rotation pattern included.

CYCLE 1
A single dead-drop account: the only known entity.
CYCLE 2
Embedded domains extracted from its posts.
CYCLE 3
Those domains resolve to previously unseen IPs.
CYCLE 4
Those IPs host further campaign domains: the rotation cluster is visible.
Published infrastructure chain for the Gamaredon Gamma matryoshka campaign, shown as a role-based chain map with a node inspector
FIG 03 THE SAME CASE AS AN IIM CHAIN · ENTRY, STAGING, REDIRECTOR, C2, PAYLOAD
Open the full MB-0001 Gamaredon dossier
MANTIS

The analysis bench next to the graph

Mantis is where a single sample is worked through: hashes, entropy, strings, sections, imports, disassembly and YARA matches in one workspace. Findings move into Kraken as entities instead of staying in a local report.

Mantis analysis workspace for a sample: format, file size, entropy, YARA matches, file identity hashes, entropy curve
FIG 04 SAMPLE WORKSPACE
Mantis sandbox view: Podman connected, apply a container to this sample, saved profiles and run history
FIG 05 SANDBOX · CONTAINERS RUN AGAINST A SAMPLE

Repetitive work is handed to rules: a tag or a YARA hit can trigger a container profile or notify a webhook and the extracted entities are imported back automatically.

Mantis automation rules: rules reacting to tags and YARA hits, running Podman profiles or notifying webhooks
FIG 06 AUTOMATION RULES
FROM KRAKEN TO IIM

Kraken stores raw observations as an entity graph. IIM takes those observations and interprets them into role chains, entry, staging, payload, c2. Kraken is the observation layer, IIM is the interpretation layer. See how IIM structures this on the Research page

6
Core services
3
Databases
26
IIM techniques in active use
100%
Evidence-trail coverage
Kraken 1.0-eval "Hadal": restricted access, granted only after analyst vetting. Not a freely available product.
Full platform tour Technical whitepaper MB-0001 Gamaredon dossier