Intelligence Packages

Integrated packages that combine CVEs, malware, threat actors, ATT&CK techniques, research and mitigation into one consumable unit.

Publication policy

AI drafts and gathers evidence for intelligence packages. An AI never auto-publishes: the published state is set only by a human analyst after review.

Review workflow

  • Draft AI reachable — AI-generated draft — the only state AI can create.
  • Evidence AI reachable — Gathered citations added; still AI-authored.
  • Review Human-only — Human analyst verification; AI cannot advance here.
  • Published Human-only — Published only by a human after review — never auto-published.

AI reaches only draft and evidence. Review and published are set by humans; AI never auto-publishes.

Ransomware Intelligence Package

published CVE-2021-44228

An integrated view of active ransomware operations: campaigns, indicators, tooling, techniques and mitigation.

  • CVE — Log4Shell (CVE-2021-44228)Common initial-access vector in ransomware campaigns.
  • Malware — LockBit / Cl0p / ALPHVActive ransomware families under observation.
  • Threat Actor — Financially motivated groupsAttribution varies; low to medium confidence.
  • ATT&CK — T1203 / T1486 / T1078Exploitation, data encryption, valid accounts.
  • Research — Ransomware landscape researchTooling and initial-access trend shifts.
  • Mitigation — Backup, segmentation, MFAPriority defensive countermeasures.

Sources: MITRE ATT&CK, NVD, CISA, OpenTrojan Research

Software Supply Chain Intelligence Package

review CVE-2021-44228, CVE-2017-0144

Vulnerabilities and threats in software supply chains, from source to production dependency.

  • CVE — Embedded dependency riskCVEs reaching production via third-party bundling.
  • ATT&CK — T1195 / T1195.002Supply-chain compromise techniques.
  • Research — Supply-chain exposure researchUnder peer review.
  • Mitigation — SBOM, dependency scanningInventory and continuous scanning.

Sources: OpenTrojan Research, Vendor advisories

Cloud Identity & Access Intelligence Package

evidence No CVE reference

Configuration and identity risks affecting cloud IAM, with detection and hardening guidance.

  • Threat Actor — Cloud-focused actorsAbuse of misconfigured identity.
  • ATT&CK — T1078 / T1098Valid accounts and account manipulation.
  • Mitigation — Least privilege, conditional accessReduce identity attack surface.

Sources: OpenTrojan Threat Team, Vendor advisory

AI-Assisted Detection Methods (Draft)

draft No CVE reference

Early AI-assisted draft exploring automated zero-day RCE detection patterns — research only, not yet published.

  • Research — Automated detection researchBeing drafted; no external claims yet.
  • Mitigation — Detection engineeringExploratory, not production guidance.

Sources: OpenTrojan Research

Related: Asset Marketplace · Subscriptions & Collections · Intelligence Feeds