v1.0.0 · Open Source · MIT

THEORY

Analyst-grade threat actor dossiers, generated from seven public intelligence sources. Free, open, and built for the people running detection engineering, IR, and hunts.

7
Sources
35
Actors
275
Aliases
9
Output Formats
Actor APT28 / Fancy Bear
Technique T1566.001 HIGH
IOC · sha256 a3f9c1b8…4d7e
Format STIX 2.1
theory · zsh

Nine ways to use the intelligence

Every dossier opens with an LLM-synthesized executive overview. Export to whatever your workflow needs.

--output dossier
Terminal + Markdown
Rich terminal output with a saved markdown file. The default.
--output html
HTML Dossier
Self-contained, shareable intelligence report. Opens in any browser, works offline.
--output navigator
ATT&CK Navigator
Confidence-colored heatmap layer. Import directly into MITRE Navigator.
--output playbook
IR Playbook
Detection checklists, IOC blocks, hunt hypotheses, containment steps. Markdown or Jira.
--output stix
STIX 2.1 Bundle
Import into MISP, OpenCTI, Splunk ES, or Microsoft Sentinel.
--output json
JSON Profile
Raw unified profile. Build your own integrations.
--output csv
IOC CSV
Raw indicator values for SIEM lookup tables and blocklists.
--output exec
Executive Summary
Non-technical BLUF briefing with sector context. Hand it to leadership.
--detection-path
Coverage Gap Report
Compare actor TTPs against your local detection rules. Find what you're missing.

Seven sources, one unified profile

Each source feeds into a common schema. The deduplicator merges everything and assigns confidence scores. Nothing downstream knows which source the data came from.

Source Key Auth Cache
MITRE ATT&CK mitre none 7 days
CISA Advisories + KEV cisa none per request
Malpedia malpedia none per request
AlienVault OTX otx OTX_API_KEY per request
SigmaHQ detection rules sigma none 7 days
ThreatFox IOCs threatfox none 24 hours
Vendor intel synthesis vendor LLM API key 7 days

Running in under a minute

Python 3.11+, a virtual environment, and one free API key. That's it.

01 · Install
# clone and set up the environment git clone https://github.com/threatcraft-co/theory cd theory && python -m venv venv && source venv/bin/activate pip install -e .
02 · Configure & Run
# download the ATT&CK bundle theory --update-bundles # add API keys (OTX is free at otx.alienvault.com) cp .env.example .env # run your first dossier theory --actor APT28