// SOVEREIGN THREAT INTELLIGENCE

We don't just flagthreats. We find theone control thatbreaks them.

Free, automated intelligence that scores every campaign's chokepoint with hard math, projects the adversary's next move, and hands you the detection to stop it. Twice a day.

Access the feed ›How it works
TWICE DAILY · EVIDENCE-ANCHORED · DEFANGED · FREE
CENTER OF GRAVITY
T1112
Modify Registry
31 CAMPAIGNS
// HOW IT WORKS

From raw telemetry to the one control that breaks the attack.

01

Ingest

200+ open-source pulses a day, ground truth extracted, never invented.

02

Score

Graph centrality finds each campaign's chokepoint, the one control worth breaking.

03

Project BETA

The Flame Cell anticipates the adversary's next move, with the counter.

04

Ship

Defanged brief plus a deployable detection pack. Twice daily. Free.

// LIVE FEED

Latest briefs

// CENTER OF GRAVITY

Where the threats converge.

The techniques attackers most depend on across everything we score. Break these controls and you disrupt the most operations at once. Aggregated from 204 campaigns.

T1112 Modify Registry31 · 15%
T1547.001 Registry Run Keys / Startup Folder30 · 14%
T1566 Phishing27 · 13%
T1078 Valid Accounts18 · 8%
T1190 Exploit Public-Facing Application13 · 6%
T1505.003 Web Shell8 · 3%
T1566.001 Spearphishing Attachment8 · 3%
T1199 Trusted Relationship6 · 2%

◈ Each percentage is a direct count of campaigns whose decisive control point falls here, nothing modelled. Per-sector coverage boards arrive as the corpus deepens.

// WEEKLY DIGEST · STRATEGIC

Week 29 Threat Digest

2026-07-19 · 107 UNIQUE CAMPAIGNS · 106 CRITICAL/HIGH · TLP:GREEN

Defensive priority // recurring chokepoints

TECHNIQUECONTROL POINTCAMPAIGNS
T1547.001Registry Run Keys / Startup Folder19
T1112Modify Registry18
T1078Valid Accounts9
T1566Phishing9
T1190Exploit Public-Facing Application5
T1195.002Compromise Software Supply Chain5

What we observed this week, by sector

Most common chokepoint per sector this week; the count is out of that sector's campaigns. A description of what we saw, not a coverage guarantee.

SECTORTECHNIQUECONTROL POINTSEEN
TechnologyT1547.001Registry Run Keys / Startup Folder4/25
GovernmentT1547.001Registry Run Keys / Startup Folder10/25
FinanceT1547.001Registry Run Keys / Startup Folder5/17
EducationT1566Phishing3/12
HealthcareT1547.001Registry Run Keys / Startup Folder4/11
DefenseT1112Modify Registry4/9
SECTORS
Technology25
Government25
Finance17
Education12
Healthcare11
Defense9
ACTORS
The Gentlemen5
APT373
Gamaredon3
DragonForce2
SilverFox2
GOLD PRELUDE2
CVEs IN PLAY
CVE-2025-80884
CVE-2025-57772
CVE-2024-555912
CVE-2026-507511
CVE-2026-507521
CVE-2023-522711
Download PDF ›
// METHODOLOGY

The math, in the open.

Every score is deterministic and auditable. The model writes prose; it is never allowed to invent a fact or a number. Here is how the engine decides what matters, and what it deliberately refuses to claim.

Chokepoint · eigenvector centrality

We build a graph of each campaign's techniques and run eigenvector centrality to find the single most disruptable one, the control worth breaking first.

Criticality · kill-chain reach

A transparent convex combination of kill-chain reach, structural centrality and path coherence, with published weights. Severity is never merged with attribution.

Co-occurrence · lift over 170 groups

Across 170 documented ATT&CK groups we count which techniques actually pair, ranked by conditional probability and lift above base rate.

Evidence-anchoring · numeric validator

The writer may only narrate facts the source data holds, and a validator rejects any figure the math did not produce.

What we deliberately do not claim

No Chi-Squared "attribution", no forced transition matrices. Behavioural resemblance is telemetry, not identity; the source-named actor is authoritative. The Flame Cell is a hypothetical tabletop projection, not a prediction.

// DETECTION PACKS

Deployable detection, defanged by default.

Every brief ships detection content you can act on, hosted here and mirrored to GitHub. Indicators are defanged and pass a pre-publish check that fails closed on any live URL. Verify before use.

Recent packs

DATECAMPAIGNARTIFACTSIOCs
2026-07-28Phishing on the Edge of the Web and Mobile Using QR CodesIOC · SNORT · STIX · YARA41
2026-07-28Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer ConnectionIOC · SNORT · STIX · YARA42
2026-07-28Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site…IOC · SNORT · STIX · YARA10
2026-07-28Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC BackdoorIOC · SNORT · STIX · YARA34
2026-07-28Mirage Kitten targets Middle East and Africa region with new malwareIOC · SNORT · STIX · YARA23
2026-07-28SilabRAT, What's Your Power?IOC · SNORT · STIX · YARA4
2026-07-28Sniper's Nest: From Brand Impersonation to Browser Hijacking and CPA FraudIOC · SNORT · STIX · YARA3
2026-07-28Threat Actors Achieve Persistence After SQL InjectionIOC · SNORT · STIX · YARA2

Phishing on the Edge of the Web and Mobile Using QR Codes — pack

DEFANGED IOCs
xx[.]com gui[.]snitch-dev[.]site kzeva2010[.]sbs gui[.]snitch-dev[.]online snitch-dev[.]space
SURICATA
alert dns any any -> any any ( msg:"SALACTI C2 lookup"; dns.query; content:"xx[.]com"; sid:20260715;)
View on GitHub ›
SECURITY-FIRST

All indicators are defanged at the boundary and pass a pre-publish check that fails closed on any live URL. Every artifact is for defensive detection only; we never keep a live, harmful link collection.

// ABOUT & LEGAL

About & Legal

About

Salamander CTI is a free, automated threat-intelligence service for the small European teams that cannot justify an enterprise platform. It turns open-source telemetry into ranked, evidence-anchored briefs twice a day. The automation writes the prose; it is not permitted to invent the facts.

Contact

[email protected]

PRIVACY

Static and privacy-first. We set no cookies and collect no personal data. No accounts, trackers, analytics or advertising.

TERMS

Provided free and on an "as-is" basis, without warranty. Aggregated open-source intelligence does not guarantee protection or completeness; verify indicators before use. The Flame Cell is a clearly-labelled experimental projection, not a prediction.