Skip to content

Threat actor

NotionTag

Last fetched

NotionTag is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

NotionTag is the developer of FaceTagr, an advanced facial recognition application designed for identity verification and video analytics. Adopted by the Chennai police since 2017, it uses computer vision to analyze CCTV footage for real-time object detection, zone monitoring, and suspect identification. In addition, the company developed CoBuddy, a facial recognition app which was used by Tamil Nadu police during the COVID-19 pandemic to monitor individuals under quarantine, according to MediaNama. The app combined GPS geofencing and facial verification to ensure quarantined individuals remained within designated areas. The app also sent random prompts for face verification multiple times a day, alerting authorities if someone left the geofenced zone. It featured a centralized dashboard for real-time monitoring and heat maps of quarantined individuals.

Techniques by tactic

No ATT&CK techniques are recorded for NotionTag in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to NotionTag today — this states the absence of a published link, not that NotionTag has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from NotionTag into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.