CTI Workbench
Enterprise Infiltration Console
Forensic timelines, indicators of compromise, and remediation logs for active adversary groups.
Campaign Threat Assessment
Observed Indicators (IOCs)Campaign Scope
Remediation & Hardening Actions
- ✓LNK File Execution Blocking:
Configured Group Policy Objects (GPO) to block execution of shortcut LNK files from public folders.
- ✓Accounting Access Hardening:
Enforced strict MFA constraints for all access points to corporate payroll and accounting web interfaces.
Active Campaign & Infrastructure Radar
OPERATIONAL INTEL RADARReal-Time Threat Actor Campaign Progression, Live C2 Infrastructure & SOC Telemetry
Focuses on WHAT adversaries are doing right now—live C2 IPs/domains, active intrusion steps, detection trigger rates, and real-time IOC feeds.
Focuses on WHO adversaries are—country origin, threat group aliases, targeted industries, historical breach catalog, and MITRE ATT&CK technique mapping.
UNC6671 (BlackFile)
Perimeter SSL-VPN breaches, credential dumping, and dual-extortion ransomware targeting global banks.
Void Blizzard (Fancy Bear)
Abusing M365 OAuth consent applications & edge VPN zero-days for financial access.
LockBit 3.0 Supporter Cluster
Active double-extortion ransomware targeting regional banks & core payment infrastructure.
Lazarus / BlueNoroff
Spearphishing financial engineers with ClickFix fake update kits & browser malware.