Actor-centric, not IOC-centric. Our own models for infrastructure, attribution and defensive prioritization, built in the gaps that ATT&CK, STIX, NIST and FAIR leave open on purpose.
Each framework closes a gap that ATT&CK, STIX, the Diamond Model, NIST CSF or FAIR leave open by design. The analyses and the IIM feed below are evidence: proof these models hold up against real campaigns, not the main event.
A structural grammar for adversary infrastructure, positioned between short-lived IOCs and the deliberately abstract ATT&CK. Five layers: Entities (raw observation) to Relations to Roles (5 types: entry, redirector, staging, payload, c2) to Techniques (26, across 5 categories: Hosting, Resolution, Routing, Gating, Composition) to Chains and Patterns. Complementary to ATT&CK, to STIX 2.1 (lossless export) and to the Diamond Model, for which it supplies the missing grammar for the Infrastructure vertex. Technique catalog v1.0 released.
GhostShell (MB-0009): a standalone EC-P-256 mTLS implant with per-implant client certificates and a self-named CA, tracked after publication by Zscaler ThreatLabz and the Belgian CCB. IIM techniques also carry longitudinal cases such as Gamaredon’s BITS-downloading (MB-0001) and the GIFTEDCROOK tooling evolution across UAC-0226 (MB-0004).
A query language for IIM data, drawing on Cypher's graph pattern matching and SQL's filtering, built for the IIM v1.1 data model: MATCH (e:entry)-[:download]->(s:staging)-->(p:payload)-[:connect]->(c:c2) WHERE ... RETURN ... Ships as CLI, REPL and Python API, with no runtime dependencies beyond stdlib. 25 end-to-end tests.
Six dimensions of evidence, weighted by forgeability rather than treated as equal: Technical (easiest to fake) to Infrastructure to Linguistic to Behavioral to Operational to Strategic (hardest to fake: cui bono). A divergence between surface and deep dimensions reads as a false-flag signal, not noise to discard.
Sits above ATT&CK, NIST CSF and FAIR: takes their output and produces a reasoned order for which control comes first, against a specific actor. Four axes (ADV, IRR, CC, DDT), weighted per actor rather than generically. A worked example against a Sandworm profile puts immutable backups in Tier 1 and awareness training in Tier 4, against that actor, not in general.
Community-submitted chains are accepted after review. A verifiable source link is required, capped at 1,000 submissions per day.
IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA…
ENKI-attributed Kimsuky lane. Fake Webex page based on a legitimate meeting schedule downloads an ALZip archive containing fix-camera.jse, which drops meeting.html and mTSTCv8.mdxm/loadDll.dll. The downloader retrieves engine.dat/spyInster.dll, which installs…
WithSecure-attributed GREYVIBE PhantomMail lane. April 2026 spear-phishing likely impersonated Ukraine’s State Service of Special Communications and Information Protection, delivered Google Drive-hosted RAR archives, ran TEASOUP-obfuscated JavaScript loaders,…
IIM chain built from the original Rapid7 report published on 2026-05-29 and included here as an accepted follow-up for the 2026-05-31 request. Rapid7 observed exploitation of CVE-2026-0257 against PAN-OS / Prisma Access GlobalProtect deployments where…
IIM chain built from an original reverse-engineering report published on 2026-05-31. The report analyzes a Mach-O universal binary associated with Atomic macOS Stealer (AMOS). The sample uses a rolling XOR routine keyed by 7M43mJx9I0GwjslSA2oKSgkqsUo to hide…
IIM chain for a targeted spear-phishing campaign reported via The Hacker News (Joe Security analysis) against the Punjab Safe Cities Authority and PPIC3 in Pakistan. The email used legitimate-sounding government infrastructure projects as lures and carried…
Pick what you want to hear about. One address, no cadence you did not ask for.