CTIPilot

Threat graph

Start from an entity and see only what connects to it, nothing else is drawn. Pick a starting point (search, or an entity below); the graph renders its direct neighbourhood, and grows only where you take it: double-click any node to pull in that node's connections (or widen the reach to 2 hops / the full connected graph). Solid edges are curated relationships: typed, source-stated connections ("attributed to", "uses", "exploits", …), each citing the entry that establishes it. Dashed edges are derived: entities referenced by the same focused entry, or an entity and a CVE carried by the same entry (report roundups never create derived edges). Click a node for its detail panel; shift-click a second node to trace the shortest path between them.

1181 entities · 576 CVEs · 344 techniques · 179 curated relations · 3581 derived edges · edge model: docs/pipeline.md § Relationships

Start from a well-connected entity

Opens the graph seeded on that entity, its direct neighbourhood first; grow it node by node from there.