Actor Tracking & Notebooks
Auto-built profiles for the adversaries that matter, seeded from the MITRE ATT&CK group catalog and refreshed continuously.
Learn more18 sensors. IT to grid.
ThreatSpire now impersonates real OT gear — Modicon PLCs, SIPROTEC relays, SIMATIC I/O, and power-grid personas — so attackers reveal intent before they touch production.

Built natively on the MITRE ATT&CK® framework
The problem
Reports are scattered across vendors and channels. Claims are made without sources. Findings rarely reach the people who decide what to hunt, block, or escalate — and by the time they do, the next campaign is already moving.
The platform
Auto-built profiles for the adversaries that matter, seeded from the MITRE ATT&CK group catalog and refreshed continuously.
Learn moreOne-click, CTID-style Threat Actor Profile Reports — executive summary, confidence-rated assessments, MITRE TTP tables, and evidence with clickable sources, drafted by AI and grounded in citations.
Charts that show who an actor is hitting and how — industries derived by AI from the evidence itself, techniques sourced from MITRE ATT&CK group data.
Turn your org's standing questions into tracked, signal-driven RFIs. The Requirement Agent drafts judgments and recommended actions for analyst review.
Learn moreEvery analyst gets their own workspace. Share requirements, cases, and IOCs at view, comment, or edit level — with comment threads and a full admin audit log.
Eighteen protocol sensors from IT to the plant floor: SSH, Telnet, HTTP/HTTPS, RDP, SMB, SIP/VoIP, MySQL, MSSQL, Redis, LDAPv3/AD, DNP3, Modbus/TCP, IEC 60870-5-104, IEC 61850 MMS, PROFINET, BACnet/IP, OPC-UA, and generic TCP/UDP.
Validate, enrich, and manage indicator lifecycle. Investigations become shareable cases with Diamond Model analysis.
Learn moreSSO, MFA, role-based access, and strict per-tenant isolation built in from day one.
Decoy personas
A generic ICS responder gives itself away the moment an attacker fingerprints it. Ask a real Modbus PLC who it is and it answers with a vendor and a model number. ThreatSpire's industrial sensors answer the same way — down to the identification objects operators actually query — so reconnaissance returns a plausible device instead of a tell.
Pick the persona that matches the plant you're defending. Changes are applied to your on-prem honeypot within about 30 seconds — no redeploy, no site visit, no SSH session.
The rest of the industrial sensors ship with fixed decoy identities modelled on equipment you'd actually find on a plant floor or in a substation.
Every sensor is capture-only. The decoys answer, log, and attribute — they never execute anything and never reach back into your network.

Evidence to leadership
How it works
Pull in reporting, vendor feeds, and internal signal.
Map activity to actors and MITRE ATT&CK techniques.
Surface priority questions and decision traces.
Hand analysts evidence-backed answers.
Built for teams



Why ThreatSpire
No unsourced claims. Every assertion in ThreatSpire links back to the report, feed, or telemetry it came from.
Not bolted on. Actors, techniques, and detections share one shared vocabulary from the ground up.
Drafts, gists, and report narratives generated with Amazon Bedrock stay grounded in cited sources — never hallucinated, always reviewable.
See ThreatSpire on your own actors and requirements.
Live · Signal Grid
Attacks logged
Unique adversaries
Countries of origin
Sensors live
Credentials captured
updated continuously