APT reports → MITRE ATT&CK, powered by the Joinable API
Every threat report below is a real, public-domain government advisory (CISA · FBI · NSA · ACSC), mapped to MITRE ATT&CK techniques so you can explore, verify, and compare adversary behaviour.
Each bar is one ATT&CK tactic (an attacker goal), left→right in kill-chain order. Height = how many distinct techniques across the whole library serve that goal.
Techniques seen across the most reports — the shared playbook.
Where to watch first — ATT&CK data sources that cover the most mapped techniques.
Open any profile to inspect its techniques, evidence, coverage and source report.
Where each adversary concentrates. Darker = more techniques mapped in that tactic. Hover a cell for the count.
Compare trusted demo advisories with each other—or with your own analyses—to see shared tradecraft, unique techniques, and detection priorities.
Choose one report or upload a new one. We prepare it, map the behaviors, validate the ATT&CK techniques, and save the result for you.
Most people can leave this alone. Switch or create a Joinable collection only when you need a separate document workspace.
Manage reports already uploaded to the active private collection.
Editable RAG queries with ATT&CK tactic ownership. The default sweep is read-only — duplicate it to edit.
Every analysis is persisted (local file store by default). Open a profile, or preview its source report.