Skip to content

Hide Navigation Hide TOC

MISP Galaxy Statistics

Cluster statistics

Number of clusters

Here you can find the total number of clusters including public and private clusters.The number of public clusters has been calculated based on the number of unique Clusters in the MISP galaxy JSON files. The number of private clusters could only be approximated based on the number of relations to non-existing clusters. Therefore the number of private clusters is not accurate and only an approximation.

No. Type Count
1 Public clusters 30413
2 Private clusters 77

Galaxy statistics

Galaxies with the most clusters

No. Galaxy Count
1 Firearms 5953
2 Tidal References 3848
3 Malpedia 3039
4 Sigma-Rules 2873
5 NAICS 2125
6 Ransomware 1705
7 Tidal Software 1386
8 Attack Pattern 1124
9 Malware 671
10 Threat Actor 652
11 Tidal Technique 625
12 Tool 596
13 Tidal Groups 441
14 Intelligence Agencies 436
15 Android 433
16 Ammunitions 410
17 Techniques 376
18 Course of Action 280
19 SoD Matrix 276
20 RAT 266

Galaxies with the least clusters

No. Galaxy Count
1 online-service 1
2 Levels 3
3 Cryptominers 5
4 Cert EU GovSector 6
5 Assets 7
6 Tea Matrix 7
7 Tactics 9
8 Groups 10
9 TDS 11
10 Branded Vulnerability 14
11 Tidal Tactic 14
12 Producer 15
13 Stealer 16
14 Software 17
15 MITRE ATLAS Course of Action 19
16 Dark Patterns 19
17 Preventive Measure 20
18 FIRST DNS Abuse Techniques Matrix 21
19 Election guidelines 23
20 Backdoor 24

Relation statistics

Here you can find the total number of relations including public and private relations. The number includes relations between public clusters and relations between public and private clusters. Therefore relatons between private clusters are not included in the statistics.

Number of relations

No. Type Count
1 Public relations 1364798
2 Private relations 12414

Average number of relations per cluster: 45

Cluster with the most relations

No. Cluster Count
1 Mimikatz 5734
2 net.exe - Associated Software 5654
3 Net 5654
4 cmd.exe - Associated Software 4832
5 cmd 4832
6 Rundll32.exe - Associated Software 4245
7 Rundll32 4245
8 PsExec 3694
9 Cobalt Strike 3486
10 netsh.exe - Associated Software 3016
11 netsh 3016
12 Impacket 2746
13 Tasklist 2733
14 certutil.exe - Associated Software 2589
15 certutil 2589
16 PowerSploit 2563
17 Systeminfo 2559
18 Mshta.exe - Associated Software 2554
19 Mshta 2554
20 ipconfig 2422

Cluster with the least relations

No. Cluster Count
1 CIA - APT-C-39 0
2 黄金鼠 - APT-C-27 0
3 黄金雕 - APT-C-34 0
4 盲眼鹰 - APT-C-36 0
5 毒针 - APT-C-31 0
6 ArmaRat - APT-C-33 0
7 军刀狮 - APT-C-38 0
8 拍拍熊 - APT-C-37 0
9 人面狮 - APT-C-15 0
10 美人鱼 - APT-C-07 0
11 双尾蝎 - APT-C-23 0
12 蓝宝菇 - APT-C-12 0
13 毒云藤 - APT-C-01 0
14 肚脑虫 - APT-C-35 0
15 蔓灵花 - APT-C-08 0
16 潜行者 - APT-C-30 0
17 Turla - APT-C-29 0
18 飞鲨 - APT-C-17 0
19 方程式 - APT-C-40 0
20 腾云蛇 - APT-C-61 0

Synonym statistics

Cluster with the most synonyms

No. Cluster Count
1 Lazarus Group 39
2 Turla 25
3 APT28 24
4 APT29 17
5 ENERGETIC BEAR 17
6 DarkHotel 16
7 APT32 16
8 APT41 16
9 APT29 - G0016 15
10 JCrypt 15
11 APT15 15
12 APT37 15
13 APT19 14
14 APT27 14
15 APT40 14
16 APT10 13
17 Sandworm 13
18 OilRig 13
19 Gamaredon Group 13
20 APT28 - G0007 12