Ghost Defense is a zero-install, zero-cost, browser-based defensive-cyber toolkit built for the operators who need enterprise-grade capability but cannot fund enterprise-grade platforms: SLTT governments, rural utilities, hospitals, school districts, small critical-infrastructure operators, and any team whose scale sits below the price floor of commercial cyber tooling. The suite complements — never replaces — CISA, MITRE, NIST, and vendor advisories, and treats them as the authoritative upstream sources it filters, prioritizes, and puts in front of an operator in one place.
The current build ships 53 tools organized across 12 capability domains. 38 of the 53 require no API key. The remaining 15 use optional Anthropic AI enrichment. Every tool is a single self-contained HTML file served from Cloudflare Pages; there is no server to maintain, no telemetry, no vendor lock-in. Sensitive analysis (log parsing, PCAP inspection, video frame extraction, credential hashing) runs client-side and never leaves the browser.
The design principle throughout is defender-first honesty: every tool names its data source, its rescan cadence, its false-positive posture, and the questions it cannot answer. A tool that says "no hits in screened sources" says exactly that — not "safe." A tool that shows exposure ranks says "exposure ≠ exploitability." This is why the toolkit is defensible in front of leadership: the reasoning chain from source to verdict is visible in every screen.
The browser tools rely on a small set of Cloudflare Workers that provide server-side API-key handling, upstream mirroring, and CORS bridging for sources that cannot be reached directly from a browser.
Ghost Defense ships alongside a matched set of position papers and reference documents. Each is honest about what binds whom (BODs are FCEB-mandatory, SLTT-voluntary) and about the tool’s scope (advisory, human-in-the-loop, outside the OT safety loop).