Skip to content

Threat actor

Kaseware

Last fetched

Kaseware is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Kaseware is a Denver-based software company that facilitates surveillance activities for law enforcement and other agencies. Its co-founders helped build the FBI’s investigation management solution in the U.S. Partnered with ShadowDragon and Microsoft, Kaseware provides a centralized investigative platform that integrates diverse data sources, including open-source intelligence (OSINT) from social media, websites, and other online platforms. This platform supports activities such as behavior analysis, predictive policing, and mapping the social graph and relationships of targets. Kaseware’s platform is used alongside ShadowDragon tools like SocialNet and OIMonitor, which allow for real-time monitoring of individuals across over 120 online platforms, including social media, dating apps, and the dark web.

Techniques by tactic

No ATT&CK techniques are recorded for Kaseware in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Kaseware today — this states the absence of a published link, not that Kaseware has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Kaseware into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.