IntelFusions

Collections

Views that cut across industry and geography. Each one groups threat actors, vulnerabilities and malware families by something they share — a delivery mechanism, a class of exposed technology, a way of getting paid — and then renders what our graph currently holds for that set. The membership is chosen by hand; the numbers are not.

How to read these

A collection is an editorial judgement about which entities belong together, published so it can be argued with. Every count beside it is computed live from the same graph the rest of the site reads, so a group that stops being active stops showing incidents here without anyone editing the page. What does not update by itself is the membership — each page states, in its own words, how its list was chosen and what it leaves out.