Threat intelligence you can read in five minutes.
Know which groups are likely to come after you, hear early when your organisation is mentioned on the dark web, and see which of your passwords are already in criminal hands. APOLLOSEC Intel is built into the platform.
Know your adversary
The portal profiles the advanced persistent threat (APT) groups and ransomware gangs that are active right now: who they are, what motivates them, the names they go by, the tools and techniques they rely on, and who they have hit recently.
Scroll through them all, or filter by your sector and country to see the handful that would realistically come after an organisation like yours. That short list tells you what to test for and what to defend against first.
- Lazarus GroupAPT · North Korea
Targets: Finance, crypto, defence
- Scattered SpidereCrime · UK and US
Targets: Retail, telecoms, insurance
- AkiraRansomware · Russian-speaking
Targets: Manufacturing, education, professional services
- APT29APT · Russia
Targets: Government, technology, think tanks
- QilinRansomware · Russian-speaking
Targets: Healthcare, local government
- Volt TyphoonAPT · China
Targets: Energy, water, communications
- LockBitRansomware · Affiliate network
Targets: Any sector with exposed remote access
- SandwormAPT · Russia
Targets: Energy and critical infrastructure
Examples of the kind of groups profiled. Scroll sideways for more.
Dark web monitoring and alerts
Attackers talk before they act. Access to networks is advertised for sale, stolen data is posted on ransomware leak sites, and targets are discussed on forums and channels most organisations never see.
We watch those places for your organisation, your domains and your key suppliers, and alert you when you appear. An early warning that your VPN access is for sale, or that a supplier holding your data has been listed by a ransomware group, gives you time to act before it becomes an incident.
Password breach monitoring
Stolen logins are behind a large share of break-ins, and most of them were taken somewhere else: a breached third-party site, or malware on a personal laptop that copied every saved password.
We monitor your company domains in breach data and infostealer logs, so you can see exactly which accounts are exposed, what was taken with them, and whether they have been reset. Fix them before someone tries them against your email, VPN or cloud.
Everything above is in the portal for platform clients, alongside your attack surface and test findings.
Far more intelligence sits behind it, and we use it for bespoke engagements: threat models built around the groups that target you, red team operations that emulate their techniques step by step, and tabletop scenarios taken from their real campaigns.
Recent research
Longer analysis is published in Savount.