Get Malware Intelligence
get_malware_intelligencePivot on a malware family name to retrieve its type, prevalence, associated threats and actors, and common ATT&CK techniques.
Instructions
Pivot on a malware FAMILY by name (e.g. LockBit, Vidar, Emotet). Returns the canonical family + type, prevalence (threat/actor counts, first/last seen), the threats deploying it, the actors using it, and its most-common ATT&CK techniques. For an offensive TOOL (Cobalt Strike, Mimikatz) use get_tool_intelligence. Use resolve_entity first if unsure of the canonical name.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Malware family name (e.g. LockBit, Vidar) |