{"repo":"Mickinthemiddle/CLOAK","free":true,"listed":false,"github":"https://github.com/Mickinthemiddle/CLOAK","clone":"git clone https://github.com/Mickinthemiddle/CLOAK.git","description":"Knowledge base on cybercriminal concealment techniques","language":"HTML","stars":246,"topics":["attribution","cybercrime","concealment","knowledge-base"],"license":"GPL-2.0","category":"productivity","readme_excerpt":"Concealment Layers for Online Anonymity and Knowledge (CLOAK) CLOAK is the first publicly available knowledge base on cybercriminal concealment measures. CLOAK is the result of qualitative scientific research and has been inspired by the famous MITRE ATT&CK™ framework. CLOAK has been developed by analyzing over 200 Operational Security (OpSec) guides from both the clear- and darkweb. CLOAK's main objective is to contribute to combating cybercrime better and has been made publicly available to allow improvements to be made together with the cybersecurity community. CLOAK's initial version (January 2025) already identified 13 tactics, 109 techniques, 679 sub-techniques, and 586 procedures. Which comes down to a total of 1.387 unique TTP's! For an interactive version of CLOAK please see https://opsectechniques.com. Technical TTPs have been marked red, Behavioral TTPs orange, and Physical TTPs Blue. Unfold the tactics (TA) and discover how they relate to techniques (TE), subtechniques (ST), and procedures, and vice versa. Recording of the talk about CLOAK at SANS DFIR Summit Prague 2025 (slides) The problem Cybercrime is a global growing problem and concealment measures make attribution of cybercrime hard or impossible, because they provide threat actors anonymity. We tend to focus on tactics, techniques, and procedures (TTPs) with respect to cyberattacks, but focus very little on adversarial concealment measures which preserve their anonymity through and in cyberspace. Concealme","default_branch":null,"files":null,"tree":[],"storefront":"/r/Mickinthemiddle","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Mickinthemiddle/CLOAK/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}