APT India Reference
Complete database of APT groups targeting Indian government, defence, and critical infrastructure with TTPs and campaigns.
View database →TTP Heatmap
Visual frequency heatmap of MITRE ATT&CK techniques used by India-targeting APTs. Prioritise your detection engineering.
View heatmap →MITRE Comparison
Side-by-side ATT&CK technique comparison across up to three APT groups. Find shared techniques for highest-value detection rules.
Compare groups →Malware Reference
APT-attributed malware families, capabilities, and detection indicators relevant to Indian sector organisations.
View reference →LOLBin Reference
Living-off-the-land binaries used by APTs targeting India. Includes detection queries and defence guidance.
View LOLBins →Credential Theft Reference
APT credential stealing techniques with MITRE mapping, detection indicators, and mitigation guidance.
View reference →Persistence Encyclopedia
All APT persistence mechanisms catalogued with examples, registry paths, and SIEM detection queries.
Browse encyclopedia →Hunt Query Builder
Build threat hunt queries targeting specific APT TTPs. Outputs SPL and KQL ready to run against your SIEM.
Build hunt queries →CTI to SIEM Converter
Convert threat intelligence IOCs and TTPs directly into SIEM detection rules in SPL or KQL format.
Convert CTI →APT Recon Scanner
Detect APT reconnaissance activity patterns in logs. Identifies discovery TTPs used before lateral movement.
Scan for recon →Memory Forensics Reference
APT memory-resident malware indicators and forensic artefacts. Guidance for memory acquisition and analysis.
View reference →STIX Explorer
Browse structured APT threat intelligence in STIX format. Filter by group, sector, and technique.
Explore STIX →Diamond Model Builder
Build a Diamond Model of intrusion analysis for incident investigation and threat intelligence structuring.
Build model →Purple Team Mapper
Map APT TTPs to red team test cases and blue team detection requirements for joint exercises.
Map exercises →Red Team Mapper
Map your red team engagements to specific APT TTPs relevant to Indian sector threats.
Map TTPs →APT Scenario Generator
Generate realistic APT attack scenarios for tabletop exercises, based on actual campaigns targeting India.
Generate scenario →Attack Surface Analyser
Identify attack surface elements most relevant to APTs targeting your sector. Prioritise hardening efforts.
Analyse surface →TI Maturity Assessment
Assess your threat intelligence programme maturity. Get a scored level with specific improvement recommendations.
Assess maturity →Spearphish Profiler
Profile APT spearphishing campaigns targeting Indian sectors. Lure themes, infrastructure patterns, and detection.
Profile campaigns →IOC vs IOA Reference
Understand the difference between indicators of compromise and indicators of attack. Guidance on when to use each.
Read reference →Exfiltration Reference
APT data exfiltration techniques with MITRE mapping, volume estimates, and detection SPL/KQL queries.
View reference →Dropper Reference
APT dropper and loader techniques — stager chains, persistence, and evasion used in India-targeting campaigns.
View reference →C2 Reference
APT command and control techniques and infrastructure patterns. Detection guidance for each C2 category.
View reference →Watering Hole Reference
APT watering hole attacks targeting Indian government and sector websites. Detection and mitigation guidance.
View reference →Protocol Abuse Reference
APT protocol abuse and tunnelling techniques — DNS, HTTPS, SMB, and custom protocols used for C2 and exfil.
View reference →APT vs Cybercrime
Distinguish targeted APT activity from commodity cybercrime. Decision framework for triage and attribution.
Read guide →