APT NOTES

Editorial standards

Methodology

Scope

APT Notes covers publicly documented threat actors and the operations, entities and behaviours needed to understand them. Inclusion requires a durable research purpose and sufficient public sourcing.

Inclusion criteria

Profiles require a stable identifier, meaningful summary, review date, confidence statement and normalized sources. Drafts and placeholders are never published.

Naming and aliases

Threat actor names are analytical constructs. Different organisations may use different names for overlapping, broader or narrower sets of activity.

Aliases are source-mapped and assigned a relationship type. A vendor tracking cluster is not treated as an automatic one-to-one equivalent.

Sources and attribution

Claims retain their publisher, date and source type. Government, vendor, academic and other reporting are not blended into a single unattributed conclusion. Source reporting, APT Notes assessment, disputed attribution and unresolved attribution are clearly separated.

Inclusion in APT Notes does not independently confirm every public attribution claim associated with an actor.

Confidence

Low
Limited or weakly corroborated public evidence; the assessment may change materially.
Moderate
Credible evidence with some corroboration, but important gaps or alternative explanations remain.
High
Strong, independently corroborated evidence with limited plausible alternatives.

Confidence is qualitative and never presented as a numeric probability.

Updates and corrections

Substantive changes are written to the structured update collection. Corrections identify what changed without silently rewriting analytical history.

Limitations

Public reporting is incomplete, collection access is unequal, and actor boundaries change. A profile is a reviewed representation of available evidence, not a claim of omniscience or a live operational feed.

Privacy

APT Notes uses no analytics, advertising cookies, fingerprinting or external search telemetry. Theme preference is stored locally in the browser. Search is generated and executed locally.