NORSESTAR
DarkWatch Platform · Yggdrasil Graph

Every indicator,
connected.

Yggdrasil is the attribution layer of the DarkWatch platform. Every indicator we see is a node; Yggdrasil connects them — domains, certs, ASNs, wallets, and operators — so one alert unfolds into the whole adversary tree.

6.4Bindicators (nodes)
28Brelationships (edges)
9pivot types
<48 hmedian time to attribution
One alert, the whole tree

Pivot across the adversary's infrastructure

Start from a single indicator surfaced in DarkWatch Live or Valkyrie, and let Yggdrasil walk the edges — passive DNS, TLS certificates, WHOIS history, ASNs, and on-chain wallets — until the campaign's whole estate is on screen.

  • Pivot across passive DNS, TLS, and WHOIS history
  • Actor and campaign attribution scoring with evidence
  • Wallet and operator links from on-chain cash-out infrastructure
  • Shareable graph exports (PNG, JSON, STIX 2.1) for threat reports
Request a demo ▸
Capabilities

Attribution you can defend

Every link is sourced and every score is explainable — so the conclusion holds up in a report, a briefing, or a courtroom.

Multi-source pivots

Walk edges across passive DNS, TLS certificates, and historical WHOIS without leaving the graph.

Attribution scoring

Actor- and campaign-level confidence scores, each with the evidence trail that produced them.

Certificate & ASN layers

Surface shared certs and hosting fingerprints that quietly tie separate operations together.

Wallet & operator links

Connect on-chain cash-out infrastructure and operator handles to the campaigns that use them.

Shareable exports

Export any view as PNG, JSON, or a STIX 2.1 bundle — drop it straight into a threat report.

Editions

For the analyst and the org

A single-seat explorer for investigators, or an org-wide graph with unlimited history and shared cases.

Analyst

Single seat

CustomPer analyst / year
  • Interactive graph explorer
  • Passive DNS / TLS / WHOIS pivots
  • Attribution scoring with evidence
  • PNG / JSON / STIX exports
Request a demo ▸
Release notes

Yggdrasil changelog

Currently shipping Yggdrasil 4.1. Highlights from recent releases.

4.1June 2026

Wallet & operator pivots

  • Wallet and operator pivots link on-chain cash-out infrastructure to campaigns
  • Attribution scoring v2 with a full evidence breakdown
  • Graph exports add STIX 2.1 bundles
4.0January 2026

New graph engine

  • New distributed graph engine — billions of nodes at interactive speed
  • Passive DNS, TLS, and WHOIS pivots unified in one explorer
  • Shareable, read-only graph snapshots
3.5September 2025

Certificate & ASN layers

  • Certificate and ASN graph layers
  • Saved pivots and investigation folders
  • PNG / JSON export
The DarkWatch suite

Yggdrasil completes the picture

Attribution is the last mile. These products collect, render, enrich, and triage the activity Yggdrasil attributes.

DarkWatch Live

The global attack map

Renders every attack the sensor grid sees, in real time, with AI-attack fingerprinting — the screen on the SOC wall.

Explore DarkWatch Live ▸

Bifrost Sensor Network

Global collection grid

Passive sensors, honeypots, and dark-IP listeners that capture attack traffic before it reaches a customer network.

Explore Bifrost ▸

RuneFeed Intelligence

Curated threat feeds & API

Enriched indicators and AI-attack signatures delivered as STIX/TAXII, a REST API, or native SIEM connectors.

Explore RuneFeed ▸

Valkyrie AI

Analyst copilot & triage

Clusters campaigns, flags machine-generated attacks, and drafts the investigation so analysts act instead of sift.

Explore Valkyrie ▸
Follow the whole tree

See Yggdrasil attribute a campaign

Thirty minutes with a NorseStar intelligence engineer and a live pivot through the infrastructure behind a real campaign our sensors are tracking.

Request a demo ▸