[Country] Quick Knowledge
Overview
A country-centric dashboard covering active threats, campaigns, malware, ATT&CK techniques, exploited vulnerabilities, targeted sectors, and related reports/indicators. Built for quick situational awareness and briefing.
Quick Knowledge is a custom OpenCTI dashboard view tailored to the Country entity type, built to give analysts and stakeholders an at-a-glance understanding of the threat landscape affecting a specific country, without needing to navigate through multiple tabs.
The layout is organized into three thematic sections:
- High Level Indicators & Active Threats: instant counters covering reports about the country, threat actors/intrusion sets and campaigns targeting it, malware count, and related indicators, paired with ranked visualizations of the top 20 threats and top 20 malware targeting the country, a radar chart of the most-used MITRE ATT&CK techniques, and a breakdown of the top vulnerabilities exploited against it.
- Recent Activities: a chronological timeline of the most recent campaigns targeting the country, alongside a list of the latest related indicators, giving a sense of how active and current the threat picture is.
- Technical Information: a deeper look at reporting and context, including donut and bar-chart views of reports referencing the country, a word cloud of the top labels appearing in those reports, the most correlated indicators, and the top sectors within the country being targeted.
This view is designed to be used as a quick-reference briefing tool for country-level threat landscape assessments. It's ideal for Analysts or Customer-facing teams who need to rapidly understand who is threatening a given country, with what tools and techniques, and how recently, during demos, investigations, or executive briefings.