DOE OSTI · 3364044
Evidence-based Graph Adversary Mapping (EGRAM) [Poster]
Abstract
Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Francis, Paul-Ann Shannon [Idaho National Laboratory (INL), Idaho Falls, ID (United States)]. 2025-08-02. Evidence-based Graph Adversary Mapping (EGRAM) [Poster]. https://doi.org/10.2172/3364044
Cite the original work for its findings. Save a collection to share your selection of sources.