Al-Qaeda is a Sunni jihadist terrorist organization founded by Osama bin Laden and senior associates including Muhammed Atef. It emerged from the Afghan jihad milieu and developed into a transnational network responsible for mass-casualty terrorism, most notably the 11 September 2001 attacks in the United States and the 1998 bombings of the U.S. embassies in Kenya and Tanzania. The organization has maintained a near-global network of affiliates, facilitators, media arms, and regional branches, including Al-Qaeda in the Arabian Peninsula and other Africa- and Syria-based aligned groups. Al-Qaeda’s primary objective is violent jihad against the United States, its allies, and governments and societies it considers adversaries. Its activity spans terrorist plotting, propaganda, recruitment, facilitation, and financing. The group and its affiliates have used social media, encrypted communications, and online publications to radicalize supporters and encourage attacks, including calls for homegrown violent extremists to conduct local attacks and assassinations. It has also been linked to cyber-enabled terrorist financing, including the use of Telegram and other social platforms to solicit cryptocurrency donations and launder funds through layered transactions, sometimes under the cover of charitable fundraising. Operationally, Al-Qaeda has demonstrated reconnaissance, target surveillance, clandestine logistics, international facilitation, and coordinated attack planning. Historical operations show use of safe houses, covert support networks, and bomb-making expertise. The organization has also shown interest in cyber capabilities and electronic security, including recruitment of technically skilled supporters and use of encryption tools to protect communications. Al-Qaeda has competed with the Islamic State for leadership of the global jihadist movement since their formal split in 2014, while retaining influence through regional affiliates and long-standing ideological appeal. Known aliases include al Qaeda, al-Qaida, AQ, and The Base. Important branches and aligned entities include Al-Qaeda in the Arabian Peninsula and the former Islamic Emirate of the Caucasus as an al-Qaeda affiliate prior to defections to the Islamic State. Al-Qaeda remains best characterized as a transnational terrorist organization motivated by terrorism rather than a conventional cyber threat actor, though it has repeatedly incorporated cyber-enabled fundraising, propaganda, and communications security into its broader operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A terrorist network led by Usama bin Laden that conducted the September 11 attacks. The referenced Abbottabad correspondence indicates that after the Taliban regime's collapse it faced financial, operational, and mobility constraints and was no longer effectively mounting international terrorist operations.
Mentioned as a foreign terrorist organization likely to exploit developments from the Iran War for recruitment and radicalization of US homegrown violent extremists.
Discussed as a long-standing jihadist network with affiliates active in the Sahel and historical roots in Africa dating back to the 1990s. The content notes that many current groups stem from al-Qaeda roots and that its affiliates often focus attacks on security forces.
Referenced as a terrorist organization with senior financial leadership targeted by U.S. operations and financial intelligence efforts after 9/11.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.