Joinable Threat Mapper

APT reports → MITRE ATT&CK, powered by the Joinable API

Interactive product demo

See how the world's top adversaries attack — mapped to ATT&CK

Every threat report below is a real, public-domain government advisory (CISA · FBI · NSA · ACSC), mapped to MITRE ATT&CK techniques so you can explore, verify, and compare adversary behaviour.

🎯 Techniques across the attack kill-chain

Each bar is one ATT&CK tactic (an attacker goal), left→right in kill-chain order. Height = how many distinct techniques across the whole library serve that goal.

🔁 Most common techniques

Techniques seen across the most reports — the shared playbook.

🛰 Best detection data sources

Where to watch first — ATT&CK data sources that cover the most mapped techniques.

🗂 Demo advisory library

Open any profile to inspect its techniques, evidence, coverage and source report.

🌡 Adversaries × ATT&CK tactics

Where each adversary concentrates. Darker = more techniques mapped in that tactic. Hover a cell for the count.

⚖️ Compare two adversaries

Compare trusted demo advisories with each other—or with your own analyses—to see shared tradecraft, unique techniques, and detection priorities.

Find common controlsShared techniques reveal detections and mitigations that cover both threats.
Spot what is uniqueSee where one report adds exposure that the other does not document.
Benchmark your reportCompare a private analysis with a trusted public advisory without mixing the libraries.
Choose two threat profilesDemo advisories are ready to compare.
VS