The actors that actually target the Gulf.
Not an encyclopedia. 9 dossiers on the threat actors with recorded victimology in the UAE, Saudi Arabia, Qatar, Kuwait, Oman and Bahrain — each one written as a detection plan rather than a description, with its tooling purpose-mapped, its sourcing graded and its gaps published.
- Dossiers
- 9 Gulf victimology, reviewed monthly
- Detection behaviours
- 137 ranked by durability, not novelty
- Tools mapped
- 134 each with a derived purpose
- Techniques
- 477 ATT&CK, unplaced ones counted
Why these read differently
We publish the gaps, the grades and the weights
An actor profile that only lists what is known is unusable for defence: you cannot tell whether a quiet actor is dormant or simply unobserved. Every dossier here carries four things the category leaves out — a ranked detection plan with the reason each behaviour survives retooling, a toolkit split into what identifies the actor and what does not, Admiralty grades separating primary research from the outlets repeating it, and an explicit statement of what we do not know.
Tiers
Pyramid-of-Pain tier for each behaviour. Tier 1–2 costs the actor an afternoon to change; tier 5–6 costs them their tradecraft. We rank by tier, not by how recent the reporting is.
Admiralty grades
A letter for source reliability, a number for the credibility of the claim. B2 is primary vendor research; C3 is an outlet reporting on someone else's work. Ten C3s are not a corroboration.
ICD 203 language
ALMOST CERTAIN, LIKELY, UNLIKELY — the US intelligence community's estimative lexicon, with confidence stated separately from likelihood. No "may potentially".
The library
9 dossiers
Ordered by depth of technique coverage. Reviewed monthly; the review date is on every page.
Credential phishing at scale against Gulf government and academic mail.
The Gulf energy and telecom operator-set, worked continuously for a decade.
Gulf government and telecom, via the helpdesk tools your admins already trust.
Travel, telecom and personal-movement data across Kuwait and Saudi Arabia.
Maritime and research targets, Saudi Arabia included.
UAE targets inside a wide Chinese espionage and for-profit remit.
VPN and edge-appliance exploitation into Kuwaiti and Saudi networks.
Middle East oil, gas and telecom — built for one region.
Saudi aviation and petrochemical, with a wiper in the toolkit.
The same method, on your estate
Your coverage against all nine, measured.
The library is the part we can publish. The platform runs the same detection plan against your own estate, tells you which of these behaviours you already cover, and retro-hunts the rest — on your hardware, with nothing leaving the building.