// SOVEREIGN THREAT INTELLIGENCE

We don't just flagthreats. We find theone control thatbreaks them.

Free, automated intelligence that scores every campaign's chokepoint with hard math, projects the adversary's next move, and hands you the detection to stop it. Twice a day.

Access the feed ›How it works
TWICE DAILY · EVIDENCE-ANCHORED · DEFANGED · FREE
CENTER OF GRAVITY
T1112
Modify Registry
38 CAMPAIGNS
// HOW IT WORKS

From raw telemetry to the one control that breaks the attack.

01

Ingest

200+ open-source pulses a day, ground truth extracted, never invented.

02

Score

Graph centrality finds each campaign's chokepoint, the one control worth breaking.

03

Project BETA

The Flame Cell anticipates the adversary's next move, with the counter.

04

Ship

Defanged brief plus a deployable detection pack. Twice daily. Free.

// LIVE FEED

Latest briefs

// CENTER OF GRAVITY

Where the threats converge.

The techniques attackers most depend on across everything we score. Break these controls and you disrupt the most operations at once. Aggregated from 278 campaigns.

T1112 Modify Registry38 · 13%
T1547.001 Registry Run Keys / Startup Folder37 · 13%
T1078 Valid Accounts34 · 12%
T1566 Phishing34 · 12%
T1190 Exploit Public-Facing Application21 · 7%
T1566.001 Spearphishing Attachment11 · 3%
T1505.003 Web Shell10 · 3%
T1059 Command and Scripting Interpreter9 · 3%

◈ Each percentage is a direct count of campaigns whose decisive control point falls here, nothing modelled. Per-sector coverage boards arrive as the corpus deepens.

// WEEKLY DIGEST · STRATEGIC

Week 29 Threat Digest

2026-07-19 · 107 UNIQUE CAMPAIGNS · 106 CRITICAL/HIGH · TLP:GREEN

Defensive priority // recurring chokepoints

TECHNIQUECONTROL POINTCAMPAIGNS
T1547.001Registry Run Keys / Startup Folder19
T1112Modify Registry18
T1078Valid Accounts9
T1566Phishing9
T1190Exploit Public-Facing Application5
T1195.002Compromise Software Supply Chain5

What we observed this week, by sector

Most common chokepoint per sector this week; the count is out of that sector's campaigns. A description of what we saw, not a coverage guarantee.

SECTORTECHNIQUECONTROL POINTSEEN
TechnologyT1547.001Registry Run Keys / Startup Folder4/25
GovernmentT1547.001Registry Run Keys / Startup Folder10/25
FinanceT1547.001Registry Run Keys / Startup Folder5/17
EducationT1566Phishing3/12
HealthcareT1547.001Registry Run Keys / Startup Folder4/11
DefenseT1112Modify Registry4/9
SECTORS
Technology25
Government25
Finance17
Education12
Healthcare11
Defense9
ACTORS
The Gentlemen5
APT373
Gamaredon3
DragonForce2
SilverFox2
GOLD PRELUDE2
CVEs IN PLAY
CVE-2025-80884
CVE-2025-57772
CVE-2024-555912
CVE-2026-507511
CVE-2026-507521
CVE-2023-522711
Download PDF ›
// METHODOLOGY

The math, in the open.

Every score is deterministic and auditable. The model writes prose; it is never allowed to invent a fact or a number. Here is how the engine decides what matters, and what it deliberately refuses to claim.

Chokepoint · eigenvector centrality

We build a graph of each campaign's techniques and run eigenvector centrality to find the single most disruptable one, the control worth breaking first.

Criticality · kill-chain reach

A transparent convex combination of kill-chain reach, structural centrality and path coherence, with published weights. Severity is never merged with attribution.

Co-occurrence · lift over 170 groups

Across 170 documented ATT&CK groups we count which techniques actually pair, ranked by conditional probability and lift above base rate.

Evidence-anchoring · numeric validator

The writer may only narrate facts the source data holds, and a validator rejects any figure the math did not produce.

What we deliberately do not claim

No Chi-Squared "attribution", no forced transition matrices. Behavioural resemblance is telemetry, not identity; the source-named actor is authoritative. The Flame Cell is a hypothetical tabletop projection, not a prediction.

// DETECTION PACKS

Deployable detection, defanged by default.

Every brief ships detection content you can act on, hosted here and mirrored to GitHub. Indicators are defanged and pass a pre-publish check that fails closed on any live URL. Verify before use.

Recent packs

DATECAMPAIGNARTIFACTSIOCs
2026-08-27Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers…IOC · SNORT · STIX · YARA4
2026-08-27Dark Caracal Reloaded: New Malware, Same Hunting GroundsIOC · SNORT · STIX · YARA39
2026-08-23Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast AsiaIOC · SNORT · STIX · YARA20
2026-08-23Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver…IOC · SNORT · STIX · YARA45
2026-08-20MacSync StealerIOC · SNORT · STIX · YARA22
2026-08-19Fraudulent Employment OperationsIOC · SNORT · STIX · YARA18
2026-08-19Clop Returns with Custom Implant in Mass-Extortion CampaignIOC · SNORT · STIX · YARA6
2026-08-17UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise…IOC · SNORT · STIX · YARA60

Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers… — pack

DEFANGED IOCs
0da123adf9251957a4b850a3f6bd6a753dd4892be176a84a18450e899534cc5e 338662fd0c4d750a0ba203a32b59f081 17e771c78430cc67e71d4547f8996a1a488e9d3f hxxp://83[.]138[.]53[.]110/service/save[.]php
SURICATA
alert dns any any -> any any ( msg:"SALACTI C2 lookup"; dns.query; content:"hxxp://83[.]138[.]53[.]110/service/save[.]php"; sid:20260715;)
View on GitHub ›
SECURITY-FIRST

All indicators are defanged at the boundary and pass a pre-publish check that fails closed on any live URL. Every artifact is for defensive detection only; we never keep a live, harmful link collection.

// ABOUT & LEGAL

About & Legal

About

Salamander CTI is a free, automated threat-intelligence service for the small European teams that cannot justify an enterprise platform. It turns open-source telemetry into ranked, evidence-anchored briefs twice a day. The automation writes the prose; it is not permitted to invent the facts.

Contact

[email protected]

PRIVACY

Static and privacy-first. We set no cookies and collect no personal data. No accounts, trackers, analytics or advertising.

TERMS

Provided free and on an "as-is" basis, without warranty. Aggregated open-source intelligence does not guarantee protection or completeness; verify indicators before use. The Flame Cell is a clearly-labelled experimental projection, not a prediction.