We track criminal infrastructure, expose adversarial tradecraft, and publish the research that keeps defenders ahead of the next breach.
18 adversarial tactics · 310+ techniques · 4,800+ criminal procedures mapped against real incident data.
Explore Documentation →2,100+ validated adversarial prompts for red-teaming LLM deployments — jailbreaks, injection chains, and alignment bypasses.
View Playbook →87 curated intelligence sources covering criminal forums, paste sites, leak channels, and infrastructure registries.
Download Framework →Passive reconnaissance engine with criminal infrastructure enrichment — maps actor clusters, bulletproof hosting, and C2 pivot chains.
View on GitHub →Automated attack surface discovery — identifies exposed assets, misconfigured cloud resources, and shadow IT before adversaries do.
View on GitHub →Adversarial red-team CLI for LLM deployments — tests prompt injection, context manipulation, and alignment boundary erosion.
View on GitHub →UMBRASEC is an independent threat intelligence collective tracking cybercriminal ecosystems, nation-state intrusion sets, and emerging adversarial techniques across AI, cloud, and traditional infrastructure.
We operate without vendor or institutional affiliation. Our research is funded entirely by the community — which means we report what we find, not what's convenient to find.
All findings are published openly. We believe defenders deserve the same quality of intelligence that adversaries are already sharing among themselves.
Our complete methodology for tracking criminal infrastructure: from initial indicator to full actor attribution. No paywall, no email gate.
Download Free →