Source-linked entries
Every event carries a link to its origin. One click takes an analyst — or an auditor — straight to the report it's based on.
Platform · Evidence Timeline
The Evidence Timeline is a chronological, source-linked record of what an adversary has actually done. Every entry ties back to the exact report it came from — so your intelligence holds up whether it's feeding a hunt or a board briefing.
threatspire / actors / SILVERSCALE-117 / timeline
Evidence Timeline
26 May 2026
· TodayPhishing campaign targeting Nordic logistics with weaponized ISO attachments.
18 May 2026
· 8d agoBeaconing to fastflux .top domain cluster; TLS JA3 matches prior campaign.
11 May 2026
· 15d agoRansomware deployment observed at two manufacturing subsidiaries.
03 May 2026
· 23d agoStolen credentials posted on darkforum thread tied to actor alias.
22 Apr 2026
· 34d agoRegistry run key modification detected on compromised endpoints.
The problem
When a finding can't be traced to a source, it can't be defended. Analysts paste claims from a dozen feeds with no link back to the original, duplicates pile up, and the moment someone asks “how do we know this?” the answer is a shrug. Unsourced intel erodes trust exactly when decisions depend on it.
Pain
Intel arrives as bullet points with no way to verify where they came from.
Cost
The moment a finding is questioned, the team has nothing to stand on.
How it works
Continuously pulls in reporting from across the web — security news, vendor research, and disclosure feeds.
Turns raw articles and reports into discrete, dated activity events instead of walls of text.
Binds every event to the exact source it came from, with publisher and date preserved.
Assembles events into a clean, deduplicated, recency-ranked timeline per actor.
What you get
Every event carries a link to its origin. One click takes an analyst — or an auditor — straight to the report it's based on.
News, vendor reporting, and ransomware/disclosure feeds flow into one timeline, so the picture isn't dependent on a single source.
Events are typed (initial access, C2, impact, disclosure, and more) and aligned to MITRE ATT&CK so behavior is searchable, not buried.
Near-duplicate reporting is collapsed and the freshest, most relevant activity rises to the top — signal over noise.
Entries are weighted by the quality of the source, so a vendor advisory and an unverified post aren't treated as equals.
Why it's different
ThreatSpire won't surface a claim it can't attribute. Source-linking isn't a feature you turn on — it's how the timeline is built.
From any finding, trace the full chain back to the original report. Defensible to a hunt lead, a customer, or a regulator.
The timeline refreshes as new reporting lands, so what your team sees reflects the latest known activity — not last quarter's snapshot.
It feeds everything
The Evidence Timeline is the spine of every actor profile, priority question, and decision trace in ThreatSpire.
Pick an actor — we'll show you the sourced timeline ThreatSpire builds.