Skip to content

Threat actor

Sandvine Inc

Last fetched

Sandvine Inc is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Sandvine was originally founded in 2001 as Procera Networks, a company that developed deep packet inspection (DPI) technology for network. Procera Networks was a U.S.-based company that developed deep packet inspection (DPI) technology, which can be used for internet traffic management, censorship, and surveillance purposes. Procera's technology was also allegedly used for surveillance and censorship purposes in countries with authoritarian regimes, including Bahrain, Kuwait, Turkey, Syria and Egypt. Sandvine was acquired by Francisco Partners' affiliate and merged with Procera Networks. In February, 2024, the U.S. Commerce Department (DOC) added Sandvine to its Entity List, restricting its access to U.S. technology, specifically because it provided Egypt with surveillance technology used to target activists and dissidents. The DOC removed Sandvine from the Entity List in October, 2024, after the company promised to "undergo transformative changes." The company has since rebranded to AppLogic Networks.

Techniques by tactic

No ATT&CK techniques are recorded for Sandvine Inc in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Sandvine Inc today — this states the absence of a published link, not that Sandvine Inc has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Sandvine Inc into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.