Skip to content

Threat actor

Travizory

Last fetched

Travizory is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Travizory is a Swiss company that develops advanced border and surveillance technology. Its primary product, the API-PNR Targeting System, utilizes real-time traveler data, including Advance Passenger Information (API) and Passenger Name Records (PNR), to assess "risks" and identify individuals of interest before they cross borders. The system integrates AI-powered profiling and automated alerts for use by border officials, connecting governments with transport operators, and uses its AI for decision-making on which passengers to prevent from entering a country. According to a report by Wired, Travizory uses its algorithms to analyze up to 150 variables, including travel patterns, connections to known persons of interest, and anomalies in behavior. For example, the system can flag travelers whose behavior deviates from typical patterns, such as short visits with excessive luggage or unusual spending habits. These assessments are used to generate risk classifications, which are shared with government agencies, including customs, immigration, and intelligence services. Currently operational in Kenya and the Seychelles, Travizory is also in discussions to expand its system to 20 other African countries.

Techniques by tactic

No ATT&CK techniques are recorded for Travizory in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Travizory today — this states the absence of a published link, not that Travizory has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Travizory into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.