[ GHOST DEFENSE ] // GROUNDED HANDLING OF SOURCED THREAT-INTEL // ACTIVE

GHOST DEFENSE
CREW OPERATIONS

Grounded  Handling  Of  Sourced  Threat-intel

58 browser-based security tools for threat intelligence, vulnerability management, critical infrastructure monitoring, threat detection, and log analysis. No install required.

// Built with humans and AI — defending the homeland

🇺🇸

58 Tools
10 Free
9 AI-Powered
4 User Guides

Ghost Defense eliminates the gap between what defenders need and what they can afford. Enterprise-grade threat intelligence, incident response, situational awareness, and a live cyber battlefield picture — 58 tools, zero installation, always free to access. All data sources TLP:CLEAR. Built with humans and AI — defending the homeland 🇺🇸

📈
Command & Operations
3 tools
  • Executive COP Dashboard — 16 CI sector reports
  • OSINT Morning Brief — 8 intel feeds
  • Asset Inventory — CVE exposure tracking
🔍
Threat Intelligence
10 tools
  • Nation-state actor profiles & APT mapping
  • Ransomware group tracker
  • IP Intel, Link Verifier, Credential Monitor
  • AI deepfake & video detection
  • Submarine cable threat tracker
  • CI Threat Map — all 16 CISA sectors
🔒
Vulnerability Management
7 tools
  • CISA KEV catalog — live search
  • SSVC/EPSS patch priority ranker
  • Attack surface mapper (passive)
  • Port scanner + historical comparison
  • DNSSEC validator (BOD 18-01)
  • F5, Nessus, hardware & EOL checks
🚨
Detection & Response
10 tools
  • Real-time IDS — 32 MITRE ATT&CK rules
  • AI IR playbooks (NIST/SANS/ATT&CK)
  • Log analyzer + PCAP — 100% local
  • Phishing email + attachment sandbox
  • KEV detection signatures (Sigma/Snort/YARA)
  • Botnet IOC, DNSSEC, Hardware ID, ATG map
🌊
Situational Awareness
5 tools
  • Maritime AIS — shadow fleet, 12 chokepoints
  • Aircraft tracker — emergency squawk alerts
  • Satellite status — 9 constellations
  • Telecom grid monitor — carrier health
  • Radio frequency + live SDR (111 freqs)
🎓
Training & Awareness
1 tool
  • AI phishing simulations — 10 templates
  • 4 difficulty levels (Basic → Nation-state)
  • Red flag analysis with severity ratings
  • Interactive awareness quiz
  • Authorized training programs only
// Operational Use Cases
⚔️ Global Threat Picture
Tools 36, 33, 10
Battlefield Map shows live attack arcs from 12 nation-state actors. COP Dashboard: 16 CI sector threat reports. Morning Brief: 8 feeds in 60 seconds.
🔒 Ransomware Response
Tools 29, 31, 24, 01, 13
IR playbook in 30 seconds. Real-time IDS on logs. PCAP analysis. Attacker IP enrichment. Ransomware group identification. NIST SP 800-61r2 aligned.
📋 KEV Patch Prioritization
Tools 02, 06, 32, 18
KEV check. SSVC/EPSS priority rank. Asset exposure scan via Shodan. Deploy Sigma/Snort/YARA compensating controls while patches stage.
🎬 Deepfake Investigation
Tools 35, 14, 34
AI video analysis with local frame extraction. Photo identity forensics. Malicious link verification of media source URL. CEO fraud / synthetic media detection.
🌊 Maritime Threat Monitoring
Tools 36, 07, 15, 25, 26
Battlefield Map: chokepoints and cable routes. AIS live tracking. Shadow fleet detection. Submarine cable threats. Satellite and telecom comms resilience.
🎣 Security Awareness Campaign
Tools 30, 19, 34
AI phishing simulation with red flag analysis and quiz. Email forensic analysis. Link verification. 10 templates, 4 difficulty levels including nation-state quality.
// Sector-Specific Value
Sector / Role Primary Tools Key Value
Government / SLTT10, 02, 06, 17, 20, 29Morning brief auto-generated. BOD 18-01 DNSSEC compliance. CI Threat Map for leadership. IR playbooks before incidents.
Healthcare / Hospital02, 06, 19, 22, 24, 29KEV patching for medical devices. Ransomware IR playbooks. Phishing defence. Log analysis for HIPAA incident detection.
Energy / Utilities04, 17, 22, 25, 26, 29ATG exposure map. ICS/OT IR playbook. Comms resilience monitoring. Nation-state threat tracking for energy sector.
Maritime / Port Security07, 25, 26, 28, 15Live AIS vessel tracking. Shadow fleet detection. Submarine cable threats. Emergency comms backup monitoring.
SOC / MSSP Analyst36, 10, 02, 31, 18, 32Daily brief in one click. Detection rule generation. Log and PCAP analysis. Attack surface enumeration for clients.
Incident Responder29, 24, 01, 19, 22, 13IR playbook in 30 seconds. Log and PCAP analysis. IP enrichment. Phishing forensics. Ransomware group ID.
CISO / Security Manager36, 33, 10, 17, 29, 32Executive morning brief. CI Threat Map for leadership reporting. Patch priority decisions. Exposure trend tracking.
Emergency Management25, 26, 27, 28, 07, 10Telecom outage detection. Satellite comms status. Aircraft situational awareness. Radio frequency monitoring.
Small / Underfunded TeamAll 45 toolsEnterprise-grade capability at zero cost. Deploy in 30 seconds. No installation, no licensing, no ongoing cost.
// Key Differentiators
Zero installation — browser only Free to deploy on Cloudflare Pages All sources TLP:CLEAR 100% local for PCAP, logs & video NIST · MITRE · CISA · BOD 18-01 aligned No telemetry · No tracking · No vendor No server to maintain AI optional — 33 tools need no API key Live sourced intel — CISA ICS advisories, MITRE ATT&CK, IODA outages Deepfake detection — local frame analysis
// Deploy in 30 Seconds
1Go to pages.cloudflare.com → Create → Upload assets
2Drag and drop ghost2210-toolkit.zip into the upload box
3Click Deploy site — live in under 30 seconds
4Share the *.pages.dev URL with your team — done
Cost: $0
Cloudflare Pages free tier
Unlimited requests/month
HTTPS by default
Global CDN — no server
AI Tools (optional)
Anthropic API key
~$10–20/month for teams
console.anthropic.com
DEFEND ALWAYS 🛡️
AI Tools require an Anthropic API key
Paste your key in the top-right of any AI tool · ~$10–20/month for a small team
Get API Key →
4 tools · Battlefield Map · COP · Morning Brief · Assets
33LIVE
📈
Executive COP Dashboard
Full-screen Common Operating Picture. Threat level meter, KEV patch ticker, 16 CI sector cards (click for detailed reports), live intel feed, detection alerts, asset exposure, comms status. Auto-refreshes every 5 minutes. Built for the wall screen.
10AI
☀️
OSINT Morning Brief
Daily threat intelligence brief aggregating CISA, FBI, NSA, US-CERT, ThreatFox, Exploit-DB, GitHub, and MITRE ATT&CK. AI synthesis with executive summary, scorecard, nation-state tracker, live IOC feed, and immediate action items. Print/PDF and HTML export.
32Free
🗂️
Asset Inventory Tracker
Browser-based CMDB with live CVE exposure tracking. Scans IPs via Shodan InternetDB (free, no key). Cross-references CVEs against CISA KEV. Risk score per asset. Dashboard, CSV import/export, print report. 100% local storage.
21 tools · Nation-State · APT · Ransomware · IOC · Deepfake · Credential · Trending CVE Radar · ICS Exposure · Regional Survey
11AI
🏴
Threat Actor Profiles
12 nation-state and criminal APT group profiles with AI-updated intelligence on TTPs, recent campaigns, targeted sectors, and IOCs. Covers Salt Typhoon, Volt Typhoon, APT29, Lazarus, CyberAv3ngers, Scattered Spider, and more.
12AI
🗺️
APT Exposure Map
Visualizes APT group targeting by sector and geography. Select your industry and region to get an AI-generated exposure assessment showing which threat actors target you and recommended mitigations.
13AI
🔒
Ransomware Group Tracker
Tracks 12 active ransomware groups with AI-updated activity reports, victim counts, ransom demands, TTPs, targeted sectors, and decryptor availability. Identifies groups by attack patterns and ransom note characteristics.
17AI
🏛️
CI Threat Map
16 CISA critical infrastructure sectors with threat actor mapping and current threat levels. AI generates a leadership briefing report for your sector. Includes recent incidents, threat actors, and recommended defensive actions.
01Free
🌐
IP Intelligence Checker
IP geolocation, ISP, ASN, Shodan open ports and CVEs, threat tags (TOR, VPN, scanner, CDN, botnet), risk score 0–100. GIS map visualization. Identifies attacker infrastructure and checks C2 IPs from incident logs.
34Free
🔗
Malicious Link Verifier
15-point heuristic engine plus URLScan.io, PhishTank, VirusTotal, and Google Safe Browsing. Detects phishing, payload delivery, typosquatting, brand impersonation, URL shorteners, punycode, double extensions. Verdict: PHISHING / MALWARE / SUSPICIOUS / CLEAN. Bulk URL support.
09Free
🔑
DarkWatch Credential Monitor
Credential breach monitoring via HaveIBeenPwned k-Anonymity API. Check email addresses for breach exposure. Password check via partial SHA-1 hash — passwords never transmitted. Bulk email checking supported.
14AI
📷
Photo Identity Analyzer
AI forensic analysis of images for identity theft detection, metadata extraction, and authenticity assessment. Identifies manipulation, deepfakes, and suspicious characteristics. For authorized investigative use only.
35AI
🎬
AI Video & Deepfake Checker
Detects AI-generated video, deepfakes, face swaps, and synthetic media. Local frame extraction via Canvas API — video never transmitted. Heuristic analysis: facial boundary artifacts, lighting inconsistencies, GAN fingerprints, edge anomalies, metadata forensics. Claude AI visual analysis of extracted frames with structured deepfake verdict. Supports MP4, MOV, AVI, WEBM, JPG, PNG. Text report export.
15AI
🌊
Submarine Cable Tracker
Global submarine cable status and incident intelligence with AI analysis. Maps active and cut cables, landing stations, and high-risk segments. Critical for maritime and telecommunications operators monitoring infrastructure threats.
46HYBRID
⚙️
Configuration Audit Framework
Identify weak configurations threat actors exploit. Live endpoint analysis (TLS, headers), hardening checklists (app defaults, AD, cloud), weaponization context. What default configs are in active campaigns? Cross-referenced with CISA KEV.
47FREE
🎯
BOD 26-04 Decision Lane
Merges KEV lookup, CISA SSVC, and compensating-controls into one continuous BOD 26-04 workflow. Enter a CVE: pulls KEV status and CVSS+CWE from NVD via the Ghost Worker, walks the four SSVC decision points to ACT/ATTEND/TRACK, maps CWE to NIST/CIS controls when you can’t patch in the window. Every input tagged by provenance. Flags the 3-day forensic-triage top tier.
48FREE
📡
SNMP Exposure Scanner
Passive discovery of internet-exposed SNMP agents via the Shodan Search API. Search by ASN, IP/CIDR, country+sector; reports SNMP version(s) per host from Shodan data, sysDescr, org/location, CVEs. Flags plaintext-auth v1/v2c and mixed-version hosts. Sends no packets; version filtering client-side and labeled per-page. NIST/CIS hardening reference + CLI recipes.
49FREE
🔌
Exposure Intelligence
Three intelligence cuts on internet exposure via Shodan. By Port — find every host exposing a port. By CVE — vuln: filter surfaces flagged hosts (honest banner-detection caveat). By Product — search a vendor/product, highlight affected version ranges. Facet summary across ALL matches (top countries/products/orgs). Scope by country/ASN/CIDR/sector. Passive; exposure ≠ exploitability.
50FREE
🛰️
Netblock Watch
Monitors the IP ranges and individual hosts you own for services that appear. Paste CIDRs or single IPs, take a baseline of what Shodan currently sees, and every later check shows what is newly exposed and what has gone away — the change view a point-in-time search cannot give you. Also manages Shodan network alerts server-side (create, list, delete, enable the new_service trigger) so Shodan notifies you between checks. Passive: sends no packets. Detection follows Shodan’s rescan cadence, so this is change awareness, not intrusion detection. Baseline is stored in your browser, never uploaded. Pairs with Tools 49, 32 and 23.
51FREE
🌐
Domain Discovery
Bootstraps Netblock Watch when you know your domain but not your IP ranges. Enter an apex domain — pulls every subdomain, A/AAAA/CNAME/MX/TXT record Shodan has indexed, extracts unique IPs, and detects when a record chains through a shared cloud/CDN provider (AWS, Cloudflare, Akamai, Fastly, Azure, GCP, GitHub Pages, and 17 more). Free InternetDB enrichment per IP surfaces ports, listed CVEs, and tags with zero query credits. One-click handoff writes selected IPs to Tool 50 — replace or merge with existing scope, deduplicated. Costs one Shodan query credit per Discover; everything downstream is free. Pairs with Tool 50.
52FREE
📊
Sector Peer Exposure
One Shodan query, one facet call, fanned across eight critical-infrastructure sectors and rendered as a briefing-ready peer chart with your sector highlighted. Answers the question a defender actually asks: are we in the hit population, and where do we rank? Enter a query (vuln:CVE-... or product:"..."), pick your sector or "All" to view without highlight, get a bar chart plus per-sector top-3 org receipts you can defend line by line. When a CVE is in the query, CVSS/EPSS/KEV/ransomware enrichment and a Shodan-suggested action pull from free CVEDB, and a detection-lag banner warns you when the CVE is under 30 days old. Optional custom sector override (org:, net:) measured by direct intersection instead of facet-bucketing. Print-clean layout. Costs 1 query credit per analyze (2 if custom). Pairs with Tools 43, 49 and 50.
53FREE
Crypto Address Tracker
Screens wallet addresses against OFAC sanctions, ransomware attribution, and on-chain activity — the fast triage a defender needs when a ransom note lands. Single-address mode for spot checks; bulk mode for lists (phishing campaigns, incident reports, threat feeds) with sortable table + filter buttons + CSV export. Four chains covered: BTC · ETH · LTC · XRP. Auto-detects chain from address format. Uses 0xB10C OFAC mirror (refreshed nightly), Ransomwhere bulk dataset (~25k crowdsourced payment records), and per-chain block explorer for balance + tx count (Blockstream, Ethplorer, SoChain, XRPScan). All free, no API key. Screening datasets bulk-load once per session; per-address checks are local. Verdict language is honest: "no hits in screened sources" is stated as such, not as a legitimacy certification. Print-clean layout for IR briefings.
54AI
📡
Trending CVE Impact Radar
Ranks CVEs by traction (rising attention), impact (reported severity), and sector attribution (targeting evidence) — surfaces what defenders should watch this week, not what the CVE database says. Traction score is arithmetic over objective signals from CISA KEV, FIRST EPSS, and CISA ICS-CERT (KEV recency, ransomware use, EPSS percentile band, ICS-CERT tagged, newly added since baseline). Sector attribution has three confidence tiers: hard (ICS-CERT direct tag or KEV vendor→sector), medium (threat-actor crosswalk from CISA-named campaigns: Volt Typhoon, CyberAv3ngers, Scattered Spider, Salt Typhoon, LockBit, and others), low (AI inference from advisory text). Filter by your CI sector (16 CISA sectors), impact type (RCE / cred theft / data exposure / lateral / DoS), and time window (7 / 30 / 90 day). Optional Anthropic API key adds one-line AI reasons per CVE and a daily executive summary — AI is augmentation, not verdict. Baseline stored locally for delta computation across runs. One-click handoff to Tools 06, 42, 43, 44, 47, 52. Print-clean.
57FREE
🏭
ICS Exposure Map
Surveys internet-exposed OT/ICS control protocols — Modbus, S7comm, EtherNet/IP, BACnet, Niagara Fox, IEC 60870-5-104, DNP3, CODESYS and nine more — and reports who and what, not just how many. Free facet queries return organization names, fingerprinted vendor/product strings and country distribution at zero query credits; a separate credit-gated step enumerates actual addresses with hostnames, banners and CVEs cross-referenced against the CISA KEV catalog. Built to be defensible: a query audit panel shows every search string sent to Shodan verbatim so any figure can be reproduced independently, facet coverage is stated as a percentage on every table so partial data is never read as complete, and country scope is enforced — records outside the selected country are discarded and counted, not silently included. Protocol filters are labelled wide (port-only, catches unrelated services) or fp (depends on Shodan fingerprinting, so a zero is not proof of nothing there). Print/PDF report leads with methodology and limitations rather than burying them. Sector attribution is keyword inference and is labelled as such throughout. Pairs with Tools 44, 49, 50 and 52.
60FREE
🗺️
Ghost Regional Exposure Survey
Surveys internet-exposed devices across a whole CISA Region — one query per member state or territory, rolled up client-side so each member reports its own figure rather than disappearing into a regional total. Region scope is constructed from a dropdown, never typed, and territories are handled correctly: Puerto Rico, USVI, Guam, American Samoa and the Northern Marianas carry their own Shodan country codes, not country:US, so Regions 2 and 9 do not silently under-report. Five match modes — port, CVE, product fingerprint, raw banner text and free-form query — each with its own zero-result explanation naming the mode you should have used instead, because a silent zero in an exposure tool is a false-negative generator. A hardware-model guard catches part numbers like MicroLogix 1400 or PA-800 typed into product mode, where Shodan's vendor+service taxonomy guarantees a zero. Optional per-state denominator converts raw counts into an exposure rate so results are not simply ranked by population. The roll-up runs on free count queries; a separate credit-gated findings stage lists individual hosts with IP, port, product, org and Shodan-assigned location, sorted by KEV and ransomware association so the actionable rows surface first. Geolocation is labelled throughout as netblock-derived, not a physical site. Query audit prints every search string verbatim; CSV carries the same provenance. Pairs with Tools 49, 50, 52 and 57.
16 tools · KEV · EPSS · SSVC · CVE Bulk Calculator · Default Creds · Compensating Controls · ICS Advisories · Vendor Risk · EOL · Sector Intel · CSAF · VEX
02Free
🔴
KEV Scanner
Live CISA Known Exploited Vulnerabilities catalog search. Every CVE actively exploited in the wild with vendor, product, due date, and required action. Built-in Sigma, Snort/Suricata, and YARA detection signature generation per CVE.
06Free
📊
KEV Patch Priority Ranker
Paste CVE IDs from your scanner output. Tool ranks by EPSS exploitability score and SSVC decision tree, delivering ACT / ATTEND / TRACK+ / TRACK decisions. Tells you exactly which CVEs to fix first. CSV export.
21Free
🔌
Port Scanner + History
Passive port scanning via Shodan InternetDB — no active scanning, no noise. Historical snapshot comparison detects new port exposures since last scan. Bulk IP support. HTML, CSV, and PDF export.
23Free
🗺️
Attack Surface Mapper
Passive subdomain enumeration via CT logs, DNS brute force, and Shodan. Maps exposed services, tech stack fingerprinting, email security (SPF/DKIM/DMARC), security headers, and known CVEs. No active scanning.
05Free
EOL Checker
Device and software end-of-life status lookup. Identifies unsupported systems that cannot receive security patches. Covers OS, databases, frameworks, network devices, and embedded systems. Bulk checking supported.
03Free
F5 Vulnerability Scanner
CVE checker for F5 BIG-IP products covering 2020–2026. One of the most targeted enterprise platforms. Immediate risk assessment, patch links, and detection rules for every known F5 vulnerability including iControl REST RCE.
38Free
🏭
Sector CVE Intelligence
CVE intelligence filtered by CISA critical infrastructure sector. 10 sectors: Energy, Water, Comms, Healthcare, Financial, Government, Defense, Transport, Manufacturing, Emergency Services. Active threat actor overlay per sector. KEV cross-reference, EPSS scores, exploit indicators. AI sector brief. One-click integration with Tools 02, 06, 18, 29, 31, 33. Send CVE list directly to Patch Ranker. CSV export.
39FREE
📋
KEV + SSVC Catalog
Live CISA KEV catalog with SSVC v2.0 decision per entry — ACT / ATTEND / TRACK+ / TRACK. Filter by SSVC decision, vendor, year. Sortable columns. Click any CVE for full detail panel: exploitation status, automatable, mission impact, required action, rationale. Four export formats: CSV (spreadsheet), CSAF 2.0 (advisory), VEX (exploitability statements), OpenEoX (lifecycle). Select specific entries or export full filtered set.
40FREE
⚙️
ICS Advisory Command
CISA ICS-CERT advisory triage built to replace the Looker Studio dashboard. Live sync from the ICS Advisory Project CSV with KEV correlation and a transparent priority score — CVSS + in-the-wild exploitation + recency. Instant cross-filter by sector, vendor, year, and severity. 16-sector exposure heat grid, CVSS distribution, release timeline, and per-advisory detail with NVD/CISA deep-links. Pairs with Tools 38 and 39. CSV export of the filtered triage set.
41FREE
🏢
Vendor CVE & Advisory Aggregator
Vendor risk intelligence built on CISA KEV. Consolidates every vendor's actively-exploited advisories into one rollup and ranks vendors by a transparent risk score — KEV volume + ransomware linkage + recency + overdue remediation + EPSS lift. "My Vendors" watch-list scopes the scorecard to your estate; ransomware-linked and recent-activity panels; per-vendor advisory drill-down with NVD/CISA links; exec + CSV report export. Pairs with Tools 06 and 40.
42FREE
🌳
CISA SSVC Calculator
Stakeholder-Specific Vulnerability Categorization decision tree, encoding CISA Table 8 + Table 9 verbatim. Walks the four decision points to an ACT / ATTEND / TRACK* / TRACK outcome with a portable vector string. Exploitation auto-derived from KEV, Technical Impact suggested from CVSS, human judgment on Automatable / Mission / Well-being. Weaponization transition detection re-resolves saved assessments on KEV update and flags every escalation (e.g. Attend to Act). Per-asset mission reuse; register + CSV export. Pairs with Tools 06 and 41.
43FREE
🛡️
Compensating Controls Advisor
When you can't patch yet — no fix, budget-locked hardware, or blocked change window. Maps a vulnerability's weakness class (CWE) to control families, filters them by the CVSS attack path, and maps each to NIST 800-53 + CIS Controls. Prioritizes interim isolation for KEV / internet-facing cases, separates workarounds from detection from the real fix, and frames every control as human-confirms-feasibility. 31-CWE knowledge base; KEV context; exportable control plan. Pairs with Tools 06 and 42.
44FREE
🗺️
Shodan CVE Exposure Map
Query a CVE and plot every internet-exposed host Shodan observes as matching it, on a live world map. Defensive attack-surface intelligence: gauge global exposure scale, track your own ASN / org / net, or assess sector risk — scope filters (org:, asn:, net:, country:) narrow to what you defend. Capped sample by default with a pull-full-exposure option and a cheaper count-only mode. Your Shodan enterprise key is held server-side in the Ghost Worker (never in the page). Honest framing: exposure ≠ exploitability; verify before acting. Pairs with Tools 06 and 41.
45FREE
🌐
Internet Outage Map
Live BGP routing status and network-disruption awareness. Enter or pick an ASN (Lumen, AT&T, Comcast, Cloudflare, AWS, Azure, Meta…) and see its holder, announced prefixes, and RIPE RIS peer visibility straight from RIPEstat (RIPE NCC) — live, CORS-open, no key. Low visibility = potential disruption, labeled as a BGP signal not a verdict. Global outage detection via IODA (Georgia Tech/CAIDA, DHS-funded) and Cloudflare Radar routes through the Ghost Worker. ASN→operator is sourced RIR fact; service impact is shown as clearly-labeled inference, never a fabricated "app-down" list. Pairs with Tool 44.
58Free
🔑
Default Credential Auditor
Cross-checks your device inventory against known factory-default credentials — without ever contacting a device. Paste an inventory or import a Tool 49/50 exposure export; the tool resolves each vendor/product against a built-in offline set of ~20 CI/OT vendors (Axis, Hikvision, Dahua, Schneider, Siemens, Rockwell, Moxa, Advantech, Cisco, MikroTik and more) plus a live cirt.net lookup for anything outside the core set, shown attributed, nothing rehosted. It is a reference-and-audit tool by design: it tells you which of your assets ship with documented defaults and flags exposed ones to verify first — it sends no packets, attempts no logins, and makes no claim a credential still works. Rows carrying an IP sort to the top as "verify now". Remediation checkboxes persist. CSV export and print.
59Free
🧮
CVE Bulk Calculator
Scores the entire CVE universe outside KEV — the ~250,000 CVEs that never enter the KEV catalog but still need triage. Loads slim per-year bundles (all years 1999–present, selectable) built from the CVEProject/cvelistV5 data joined offline with EPSS probability and Exploit-DB availability. Four switchable scoring lenses: EPSS×CVSS, EPSS-only, CVSS-only, exploit-weighted. Runs the full four-factor CISA SSVC decision tree and emits the canonical CISAv1/E:/A:/T:/M:/ vector for every finding — verifiable against CISA's own SSVC calculator. Observable factors (Exploitation, Technical Impact) are derived from vulnerability data; the two judgment factors (Automatable, Mission & Well-being) are human-in-the-middle, operator-set per finding and never auto-fabricated. Every decision carries its full 5 W provenance (what/why/who/when/where) and reads as a plain-English sentence. Complements Tool 06, which scores what's in KEV. CSV catalog export with vectors.
10 tools · IDS · IR Playbooks · Log Analysis · PCAP · Phishing
31LIVE
🚨
Real-Time Intrusion Detection
32 MITRE ATT&CK-mapped detection rules firing in real time. Paste logs, upload files, or run live simulation. Covers SSH/RDP brute force, credential dumping, ransomware, C2 beacons, web shells, lateral movement, defense evasion, and exfiltration. CSV export.
29AI
📋
IR Playbook Builder
AI-generates complete IR playbooks from attack descriptions in 30 seconds. 12 preset scenarios. NIST SP 800-61r2, SANS PICERL, or MITRE ATT&CK aligned. Phase-by-phase steps, MITRE mapping, IOC hunt list, and stakeholder comms templates.
24Free
📜
Log Analyzer + PCAP
Browser-side log analysis with 18 MITRE ATT&CK-mapped detection rules. Supports syslog, Windows Event Log, SSH, Apache, nginx, and auditd. PCAP upload and network capture parsing — 100% local, nothing transmitted.
19AI
🎣
Phishing Email Validator
Full phishing analysis: SPF/DKIM/DMARC validation, sender spoofing detection, URL inspection, AI verdict with confidence score, IOC extraction, and attachment static analysis sandbox — 100% local, no files uploaded.
18Free
📡
KEV Detection Signatures
Production-ready Sigma (SIEM), Snort/Suricata (IDS), and YARA (malware) rules for every CISA KEV entry. Deploy compensating detection rules while patches are being staged. One-click copy to clipboard.
22Free
🦠
Botnet IOC Scanner
Checks IPs, domains, and hashes against JDY botnet IOC feed plus STIX/TAXII-imported threat feeds. Bulk target scanning. STIX 2.0 and TAXII 2.1 import for custom threat intelligence feeds.
20Free
🔐
DNSSEC Validator
Full DNSSEC chain-of-trust validation. Bulk CSV domain scanning. CISA BOD 18-01 compliance dashboard for .gov domains. Checks SPF, DKIM, DMARC, CAA, and MTA-STS. Exportable compliance reports.
08Free
💾
Hardware Identifier
MAC address, USB device, and PCI hardware identification using the IEEE OUI database. Rogue device detection — identify unknown hardware on your network by manufacturer. Bulk MAC lookup supported.
04Free
ATG Exposure Map
Maps US internet-exposed automated tank gauge infrastructure. Critical for energy, fuel storage, and water sector operators. Identifies ICS/SCADA systems accessible from the internet — a top CyberAv3ngers target vector.
16AI
🔬
Nessus Integration Dashboard
Connects to live Nessus API or accepts .nessus file upload. Cross-references all findings against CISA KEV. AI-powered triage and remediation prioritization. Generates executive summary and patch priority recommendations.
6 tools · Maritime · Aircraft · Satellite · Telecom · Radio · Global Ops Radar
07Free
🚢
Global Ship Traffic Monitor
Live maritime AIS vessel tracking with shadow fleet detection, 12 strategic chokepoint monitoring, and submarine cable corridor proximity alerts. OpenSeaMap overlay. Shadow fleet vessels highlighted. Vessel detail cards with flags and cargo type.
27Free
✈️
Aircraft Tracker
Live ADS-B aircraft tracking via OpenSky Network. Military, medical, and cargo classification. Emergency squawk code alerts: 7700 (emergency), 7600 (radio failure), 7500 (hijack). Flight path history and position data.
26Free
🛰️
Satellite Comms Monitor
Status of 9 satellite constellations: Starlink, Iridium, Inmarsat, OneWeb, O3b/SES, ViaSat-3, Globalstar, Kuiper, and Thuraya. Animated orbital diagram. Communications continuity priority order and backup planning guidance.
25Free
📡
Telecom Grid Monitor
Live connectivity checks across 12 major carriers (AT&T, Verizon, T-Mobile, Comcast, BT, Deutsche Telekom). BGP/ASN health via RIPE NCC. DNS resolver status. Active incident feed. Comms continuity readiness checklist.
28Free
📻
Radio Frequency Monitor + SDR
111 frequencies across VHF, UHF, HF, AM, FM, SSB, SW, CB, and satellite L-band. TUNE button on every row opens a live WebSDR receiver. Emergency frequencies highlighted. NOAA WX, aviation guard, maritime Ch 16, national interop channels.
56FREE
🌍
Global Ops Weather Radar
Global ops-domain weather picture with optional local-briefing layer. Three status pills for Communications / Aviation / Maritime (NOMINAL / ADVISORY / ELEVATED / IMPACT) computed arithmetically from all active signals. Sources: NOAA SWPC (space weather + solar flares), AviationWeather.gov (international + CONUS SIGMETs, moderate-hazard AIRMETs, live PIREPs), NHC Atlantic + E-Pacific storms, JTWC Western Pacific + Indian Ocean + South Pacific typhoons via RSS, USGS M4.5+ earthquakes with tsunami flags, embedded live GFA Progressive Chart. Optional US location adds a local-briefing panel with NWS current conditions + active alerts. Seven data sources on a rotating radar-sweep loading overlay. Auto-refresh 15-min. Print-clean.
2 tools · Phishing Simulations · Red Flag Analysis · Awareness Quiz
30AI
🎣
Phishing Simulation Builder
AI-generated phishing simulations for authorized security awareness training. 10 preset templates (credential harvest, BEC, IT alert, SharePoint, payroll, invoice, MFA bypass, smishing, HR benefits, vendor fraud). 4 difficulty levels. Red flag analysis, training content, and interactive quiz.
1 tool · 10 live feeds · CVE detection · KEV cross-reference · AI synthesis
37LIVE
📰
Vulnerability News Aggregator
3-column live intelligence dashboard. Left: security news from Bleeping Computer, The Hacker News, Dark Reading, Krebs on Security, SANS ISC, SecurityWeek — CVEs auto-detected and highlighted. Center: CVE & advisory feed from CISA, NVD, GitHub Security, Exploit-DB — sorted by severity with KEV badges and CVSS scores. Right: trending CVEs, vendor mentions, active exploitation alerts, AI synthesis. Keyword filter, CSV export, auto-refreshes every 15 minutes. Click any CVE to open in KEV Scanner.
7 items · Snapshot + Word docs
🗺️ Capability Snapshot — Live web view of all 54 tools 📄 Capability Snapshot — Word document 🧩 Browser Extension — Chrome & Edge 🏭 Sector CVE Intelligence Guide — Tool 38 ⚠️ Limitations & Constraints Document 📋 Capability Brief v2.0 — All 36 Tools 📘 User Guide v5.0 — All 33 Tools 📗 KEV Patch Ranker Guide 📙 Nessus Dashboard Guide 📕 CI Threat Map Guide v3