Islamic State in the Sahel Province (IS Sahel) is an Islamic State affiliate operating in the central Sahel, particularly in the Burkina Faso-Mali-Niger theater. It emerged as part of the broader expansion of Islamic State-linked insurgency from neighboring Mali into Burkina Faso and has been active in the country’s conflict since at least 2016. IS Sahel has expanded its area of operations in Burkina Faso alongside other jihadist actors and has carried out attacks against government security forces as well as civilians. The group is associated with armed insurgent activity intended to contest state control and intimidate local populations in areas where it operates. High-confidence reporting in the available material supports its role in violent attacks in Burkina Faso, but does not provide sufficient corroborated detail here on specific sub-groups, leadership, or a fuller attack tradecraft profile beyond armed assaults on security forces and the population. IS Sahel is widely referred to as IS Sahel and as Islamic State in the Sahel Province.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Islamist armed group active in Burkina Faso’s Sahel region, described as carrying out attacks against security forces and civilians and operating in areas where communities were later targeted by Burkinabè forces or VDPs.
Islamic State affiliate operating in the Sahel, particularly northern and eastern Burkina Faso, with a stronghold in Niger’s Tillabéri region. The content describes it as carrying out large-scale attacks against civilians and military forces and competing violently with JNIM for territorial control and ideological dominance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.