Multi-source pivots
Walk edges across passive DNS, TLS certificates, and historical WHOIS without leaving the graph.
Yggdrasil is the attribution layer of the DarkWatch platform. Every indicator we see is a node; Yggdrasil connects them — domains, certs, ASNs, wallets, and operators — so one alert unfolds into the whole adversary tree.
Start from a single indicator surfaced in DarkWatch Live or Valkyrie, and let Yggdrasil walk the edges — passive DNS, TLS certificates, WHOIS history, ASNs, and on-chain wallets — until the campaign's whole estate is on screen.
Every link is sourced and every score is explainable — so the conclusion holds up in a report, a briefing, or a courtroom.
Walk edges across passive DNS, TLS certificates, and historical WHOIS without leaving the graph.
Actor- and campaign-level confidence scores, each with the evidence trail that produced them.
Surface shared certs and hosting fingerprints that quietly tie separate operations together.
Connect on-chain cash-out infrastructure and operator handles to the campaigns that use them.
Export any view as PNG, JSON, or a STIX 2.1 bundle — drop it straight into a threat report.
Jump in from DarkWatch Live or a Valkyrie campaign and enrich with RuneFeed.
A single-seat explorer for investigators, or an org-wide graph with unlimited history and shared cases.
Analyst
Single seat
Enterprise
Org-wide
Currently shipping Yggdrasil 4.1. Highlights from recent releases.
Attribution is the last mile. These products collect, render, enrich, and triage the activity Yggdrasil attributes.
The global attack map
Renders every attack the sensor grid sees, in real time, with AI-attack fingerprinting — the screen on the SOC wall.
Explore DarkWatch Live ▸Global collection grid
Passive sensors, honeypots, and dark-IP listeners that capture attack traffic before it reaches a customer network.
Explore Bifrost ▸Curated threat feeds & API
Enriched indicators and AI-attack signatures delivered as STIX/TAXII, a REST API, or native SIEM connectors.
Explore RuneFeed ▸Analyst copilot & triage
Clusters campaigns, flags machine-generated attacks, and drafts the investigation so analysts act instead of sift.
Explore Valkyrie ▸Thirty minutes with a NorseStar intelligence engineer and a live pivot through the infrastructure behind a real campaign our sensors are tracking.
Request a demo ▸