Threat Intelligence

Adversary Heatmap

Aggregate MITRE ATT&CK coverage across 20 tracked threat actors. Identify which kill-chain phases are most heavily targeted and what controls provide coverage.

20 actors in scope

Kill Chain Tactic Density

How many threat actors in scope are active in each ATT&CK phase.

01
Reconnaissance
0
actors
02
Resource Development
0
actors
03
Initial Access
19
actors
04
Execution
5
actors
05
Persistence
9
actors
06
Privilege Escalation
1
actors
07
Defence Evasion
10
actors
08
Credential Access
4
actors
09
Discovery
0
actors
10
Lateral Movement
2
actors
11
Collection
6
actors
12
Exfiltration
12
actors
13
Impact
17
actors
Initial Access
19 actors
AP
AP
AP
AP
FA
+14
Impact
17 actors
AP
AP
VO
LO
RA
+12
Exfiltration
12 actors
AP
AP
LO
RA
AL
+7
Defence Evasion
10 actors
AP
AP
AP
FA
VO
+5
Persistence
9 actors
AP
AP
AP
FA
RA
+4
Collection
6 actors
AP
AP
FA
LA
IN
+1
Execution
5 actors
AP
LO
RH
BI
QI
Credential Access
4 actors
VO
SC
LA
IN
Lateral Movement
2 actors
SC
BL
Privilege Escalation
1 actors
AP
High density (≥75%)Elevated (≥50%)Moderate (≥25%)Low (<25%)No actors in scope

Top Techniques by Actor Frequency

The most commonly used individual techniques across all actors in scope. Click a technique to view defensive controls.

Sector Exposure Matrix

How many tracked threat actors actively target each industry sector.

Government & Defence
15
75%
Critical Infrastructure
9
45%
Healthcare
14
70%
Financial Services
14
70%
Technology & SaaS
9
45%
Telecommunications
7
35%
Research & Universities
6
30%
Legal & Professional Services
8
40%
Maritime & Shipping
2
10%
Mining & Resources
2
10%
Retail
3
15%
Gaming & Hospitality
4
20%
Political Organisations
1
5%
Cryptocurrency Exchanges
1
5%

ATT&CK Heatmap Timeline Scrubber

30 days of an APT campaign.

Drag the timeline. Cells light from orange/red (active adversary) to cyan (detected & blocked by Aloupa AI). Hover any active cell for the technique, its ISM controls, and the recommended detection rule.

Campaign Day
01 / 30
Day 1 · BreachDay 15Day 30 · Contained
Active adversary Blocked by Aloupa AI No activity19 active · 0 blocked
Initial Access
T1566.002Spearphishing Link● active
T1190Exploit Public-Facing App● active
T1133External Remote Services● active
Execution
T1059.001PowerShell● active
T1059.003Windows Command Shell● active
T1569.002Service Execution● active
Persistence
T1505.003Web Shell● active
T1543.003Windows Service● active
Credential Access
T1003.001LSASS Memory● active
T1558.001Golden Ticket● active
T1110.001Password Guessing● active
Lateral Movement
T1021.001RDP● active
T1550.002Pass the Hash● active
T1070Indicator Removal● active
Exfiltration
T1048Exfil Over Alt Protocol● active
T1567Exfil to Cloud Storage● active
Impact
T1486Data Encrypted for Impact● active
T1490Inhibit System Recovery● active
T1499Endpoint DoS● active

Drag the timeline to watch Aloupa AI progressively detect and neutralise the campaign across the kill chain.

Commission a Bespoke Assessment

Understand your specific exposure surface

Map the threat actors most likely to target your organisation to a prioritised remediation roadmap.

Feisty Fox LogoFeisty Fox Security

© 2026 Feisty Fox Security. All rights reserved.