Threat intelligence that cites every claim, or makes none.
Signalis turns public CTI reporting into queryable reports, actors, CVEs, and indicators, all severity-ranked, cited, and honest about what the model assessed. Built for teams that read CTI daily. Free feed on a 7-day delay; real-time from $29/mo.
Kairos ransomware gang publishes LR Reed as victim
in the wild7d agoSouth Korea discloses data breach impacting diplomats worldwide
7d agoNova ransomware group publishes VNSO as new victim
in the wild7d agoBlacknevas ransomware claims Zuni Shopping Center, Inc.
in the wild7d agoFederal agencies broaden alert on Iran-linked OT attacks
in the wild7d agoDrupal Internationalization Single Sign-On Security Update (AV26-738)
7d agoSpeculo: cited, or refused.
Ask the corpus. Every claim carries a report citation, and when Signalis has nothing, it says so instead of guessing. No confident hallucinations.
apt28 is a Russia-aligned threat actor, also known as Forest Blizzard, Fancy Bear, Pawn Storm, Sednit, and GruesomeLarch #4223#3461#4163#5080. In Signalis reporting, the group first appears on 2024-11-22, with 20 reports in Signalis reporting to date [summary].
Primary Activities & Tactics:
apt28 specializes in espionage and infrastructure targeting, with a focus on government and critical infrastructure sectors [summary]. The group's primary attack techniques include exploiting public-facing applications [T1190], phishing [T1566], exfiltration over C2 channels [T1041], leveraging valid accounts [T1078], and deploying data-encrypting malware [T1486] [summary].
Notable Campaigns & Techniques:
Associated CVEs: CVE-2026-21509, CVE-2026-1340, CVE-2025-55182, CVE-2026-1281, CVE-2026-21513 [summary].
Signalis has no reporting on that.
No fabrication. The corpus is silent, so Speculo is too.
#id = grounded report citation (report detail is a member feature). Actor and CVE links are public.
Actor intelligence, at a glance.
Every actor gets a deterministic mark and a relationship graph of co-mentioned actors, exploited CVEs, targeted sectors, derived from the corpus, honestly labeled as co-mention, not confirmed collaboration.
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
A feed you can query. And an API.
Severity-ranked reports with structured extraction: CVEs, MITRE ATT&CK techniques, actors, and refanged indicators. Pull the actionable, attacker-role IOCs straight into MISP, OpenCTI, or your own tooling. API docs →
# attacker-role IOCs, cursor-paginated (Pro/Team key) curl -H "Authorization: Bearer $SIGNALIS_API_KEY" \ https://api.signalis.watch/api/feed/v1/iocs?type=domain
Watchlist alerts
Pin actors and CVEs; get one daily digest when they show new activity. Inbox respect is a feature.
Weekly briefing
A Monday digest of your watchlist plus the week's most-active actors and newly-exploited CVEs. Free tier included.
Honest by construction.
Severity and classification are model judgments, not measurements. And we say so. Extractions carry confidence; dates and counts describe Signalis's reporting window, not real-world ground truth. We'd rather show you a refusal than a confident guess. Read the methodology →
Plans
| Free | Pro $29/mo | Team $69/mo | |
|---|---|---|---|
| Feed | 7-day delayed | real-time | real-time |
| Report filters | 1 | unlimited | unlimited |
| Watchlist pins | 1 | 25 | 100 |
| Weekly digest | ✓ | ✓ | ✓ |
| Daily alerts | — | ✓ | ✓ |
| Analytics board | — | ✓ | ✓ |
| Speculo Q&A | — | 200/mo | 1,000/mo |
| IOC / feed API | — | 10k calls/mo | 100k calls/mo |