ThreatFusionAI™ by Craw Security

Every indicator, fully correlated.

A unified threat-intelligence platform that correlates and cross-references the indicators you already have — a hash, IP, domain, URL, CVE, email or phone — into the related IOCs, malware, threat actors, campaigns and MITRE ATT&CK techniques behind them.

Free to start 7 indicator types ATT&CK attribution

Three ways to turn one indicator into intelligence

Look it up, map its connections, and attribute the behaviour behind it — all from a single search.

Lookup & Enrichment

Resolve any indicator into a full report — verdicts, reputation, context and extracted IOCs.

  • Multi-engine verdicts & risk scoring
  • Sandbox behaviour & file identity
  • IOCs extracted from the artifact

IOC Cross-Reference

Pivot from one indicator to every hash, IP, domain, URL and file it connects to across the corpus.

  • Interactive relationship graph
  • Click any node to re-pivot
  • Export the connected IOC set

ATT&CK Attribution

Correlate a sample's observed techniques against the ATT&CK catalog to rank likely actors.

  • Observed technique extraction
  • Ranked actors, malware & campaigns
  • Rarity-weighted confidence

Start from anything you have

Seven indicator types, one correlation engine. Paste what you've got and follow the threads.

File Hash
AV verdicts, behaviour, IOCs, attribution
IP Address
Reputation, geo, linked infrastructure
Domain
Resolutions, related hosts & samples
URL
Scan verdicts & distribution links
CVE
CVSS, EPSS, exploit & KEV status
Email
Breach exposure & linked identity
Phone
Carrier, risk & linked accounts
Run a search
Pick a type and correlate
IOC Cross-Reference

One indicator in. Its whole network out.

Drop in a single hash, IP, domain or URL and the cross-reference engine maps every indicator it touches across the enriched corpus — then lets you pivot on any node to keep pulling the thread.

  • Relationship graph — hashes, IPs, domains, URLs and files, colour-coded and linked.
  • Pivot instantly — click any related indicator to re-run the correlation from there.
  • Export the set — take the connected IOCs straight into your tooling.
seed indicator
hash ip domain url
observed techniques
T1059 T1027 T1055 T1106 T1518 T1047
ranked against the ATT&CK catalog
likely threat actors
Mustang Panda42%
Gamaredon Group36%
Kimsuky33%
MITRE ATT&CK Attribution

From behaviour to a shortlist of actors

Give the engine a file hash and it extracts the ATT&CK techniques the sample was observed using, then ranks the threat actors, malware families and campaigns whose known behaviour lines up best.

  • Technique-driven — grounded in observed ATT&CK behaviour, not guesswork.
  • Rarity-weighted — discriminating techniques carry more signal.
  • Honest by design — behavioural correlation, clearly labelled as a lead, not a verdict.

How the correlation works

Every submission flows through the same pipeline — from raw indicator to connected intelligence.

01

Submit

Paste any indicator — hash, IP, domain, URL, CVE, email or phone.

02

Enrich

Verdicts, reputation and sandbox behaviour are gathered and normalised.

03

Index & correlate

Extracted IOCs are indexed and linked to everything else in the corpus.

04

Cross-reference

Pivot the graph and attribute the behaviour to actors, malware and campaigns.

Built on trusted intelligence
CRAW SECURITY
MITRE ATT&CK
MULTI-ENGINE AV
SANDBOX TELEMETRY
OSINT FEEDS

Simple, Scalable Pricing

Start free in seconds. Need more throughput? Request a higher tier — an admin reviews and grants access. No card required; paid tiers are request-only while we finalise pricing.

Threat Research & Blog

Security insights, platform updates, and playbook strategies from the Fusion team.

View all posts
Top Challenges in Domain Threat Analysis & How to Solve Them
Blog • Jul 27, 20

Top Challenges in Domain Threat Analysis & How to Solve Them

How to Choose the best Threat Intelligence Platform for Your Business?
Blog • Jul 26, 20

How to Choose the best Threat Intelligence Platform for Your Business?

What Is DNS Threat Intelligence and How Does It Work?
Threat Intelligence • Jul 22, 20

What Is DNS Threat Intelligence and How Does It Work?