Intelligence Packages
Integrated packages that combine CVEs, malware, threat actors, ATT&CK techniques, research and mitigation into one consumable unit.
Publication policy
AI drafts and gathers evidence for intelligence packages. An AI never auto-publishes: the published state is set only by a human analyst after review.
Review workflow
- Draft AI reachable — AI-generated draft — the only state AI can create.
- Evidence AI reachable — Gathered citations added; still AI-authored.
- Review Human-only — Human analyst verification; AI cannot advance here.
- Published Human-only — Published only by a human after review — never auto-published.
AI reaches only draft and evidence. Review and published are set by humans; AI never auto-publishes.
Ransomware Intelligence Package
An integrated view of active ransomware operations: campaigns, indicators, tooling, techniques and mitigation.
- CVE — Log4Shell (CVE-2021-44228)Common initial-access vector in ransomware campaigns.
- Malware — LockBit / Cl0p / ALPHVActive ransomware families under observation.
- Threat Actor — Financially motivated groupsAttribution varies; low to medium confidence.
- ATT&CK — T1203 / T1486 / T1078Exploitation, data encryption, valid accounts.
- Research — Ransomware landscape researchTooling and initial-access trend shifts.
- Mitigation — Backup, segmentation, MFAPriority defensive countermeasures.
Sources: MITRE ATT&CK, NVD, CISA, OpenTrojan Research
Software Supply Chain Intelligence Package
Vulnerabilities and threats in software supply chains, from source to production dependency.
- CVE — Embedded dependency riskCVEs reaching production via third-party bundling.
- ATT&CK — T1195 / T1195.002Supply-chain compromise techniques.
- Research — Supply-chain exposure researchUnder peer review.
- Mitigation — SBOM, dependency scanningInventory and continuous scanning.
Sources: OpenTrojan Research, Vendor advisories
Cloud Identity & Access Intelligence Package
Configuration and identity risks affecting cloud IAM, with detection and hardening guidance.
- Threat Actor — Cloud-focused actorsAbuse of misconfigured identity.
- ATT&CK — T1078 / T1098Valid accounts and account manipulation.
- Mitigation — Least privilege, conditional accessReduce identity attack surface.
Sources: OpenTrojan Threat Team, Vendor advisory
AI-Assisted Detection Methods (Draft)
Early AI-assisted draft exploring automated zero-day RCE detection patterns — research only, not yet published.
- Research — Automated detection researchBeing drafted; no external claims yet.
- Mitigation — Detection engineeringExploratory, not production guidance.
Sources: OpenTrojan Research
Related: Asset Marketplace · Subscriptions & Collections · Intelligence Feeds