Framework Threat Intel APT Encyclopedia Blog

Get Notified

Receive updates about new features and track development progress.

Support Development

Your contribution supports infrastructure, server costs, and ongoing development. Get priority beta access. Estimated release: September 2026

Overview of your agents, running campaigns and detection results

Dashboard

Agents built on the fly by binary patching, no compiling needed

Agents

Browse APT groups with their techniques, intel sources and references

APT Groups

See which techniques each APT uses and what you've already run

APT Matrix

Run real attack chains the way threat intel reported them

APT Campaigns

Detection coverage mapped onto the ATT&CK matrix

MITRE ATT&CK

Correlate each run with Splunk, Sentinel, AWS Security Hub or GCP to see what was detected

Detection gap analysis

Cloud TTPs for AWS, Azure and GCP, with audit-log correlation

Cloud TTPs (AWS / Azure / GCP)

Kubernetes and Docker techniques: pod escape, RBAC abuse, breakout

Container techniques (Kubernetes / Docker)

The report cover and summary, with the detection rate

Campaign report — executive summary

Per-technique detail: MITRE mapping, expected events and evidence

Campaign report — technique detail

Write your own techniques and import TTP packs as YAML

Custom TTP editor / Packs

Campaign templates for FIN7, APT29, Lazarus and more, sorted by difficulty

Campaign templates

Agent, agentless (WinRM/SSH) and cloud execution

Execution Modes

Webhook notifications to outside systems

Webhooks

Schedule campaigns to run on a calendar

Scheduler

Server, agent and audit logs

Logs