Skip to content

Threat actor

Silicon Forensics

Last fetched

Silicon Forensics is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Silicon Forensics provides digital forensics and surveillance tools used by law enforcement, military, and enterprise security teams to extract and analyze data from digital devices. Their products include tools like Hancom MD-LIVE, which enables rapid data acquisition from smartphones. They also distribute Tableau hardware for write-blocked data acquisition. Additionally, Silicon Forensics supplies password recovery and decryption tools, chip-off and JTAG extraction systems, and cloud forensics kits. These tools are used to bypass device locks, recover deleted content, extract data from encrypted sources, and monitor communication platforms.

Techniques by tactic

No ATT&CK techniques are recorded for Silicon Forensics in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Silicon Forensics today — this states the absence of a published link, not that Silicon Forensics has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Silicon Forensics into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.