Editorial standards
Methodology
Scope
APT Notes covers publicly documented threat actors and the operations, entities and behaviours needed to understand them. Inclusion requires a durable research purpose and sufficient public sourcing.
Inclusion criteria
Profiles require a stable identifier, meaningful summary, review date, confidence statement and normalized sources. Drafts and placeholders are never published.
Naming and aliases
Threat actor names are analytical constructs. Different organisations may use different names for overlapping, broader or narrower sets of activity.
Aliases are source-mapped and assigned a relationship type. A vendor tracking cluster is not treated as an automatic one-to-one equivalent.
Sources and attribution
Claims retain their publisher, date and source type. Government, vendor, academic and other reporting are not blended into a single unattributed conclusion. Source reporting, APT Notes assessment, disputed attribution and unresolved attribution are clearly separated.
Inclusion in APT Notes does not independently confirm every public attribution claim associated with an actor.
Confidence
- Low
- Limited or weakly corroborated public evidence; the assessment may change materially.
- Moderate
- Credible evidence with some corroboration, but important gaps or alternative explanations remain.
- High
- Strong, independently corroborated evidence with limited plausible alternatives.
Confidence is qualitative and never presented as a numeric probability.
Updates and corrections
Substantive changes are written to the structured update collection. Corrections identify what changed without silently rewriting analytical history.
Limitations
Public reporting is incomplete, collection access is unequal, and actor boundaries change. A profile is a reviewed representation of available evidence, not a claim of omniscience or a live operational feed.
Privacy
APT Notes uses no analytics, advertising cookies, fingerprinting or external search telemetry. Theme preference is stored locally in the browser. Search is generated and executed locally.