๐Ÿ—บ๏ธ The Full Map ๐Ÿฏ

Every endpoint. Every platform. Every page. ๐Ÿ’€ We're a startup โ€” code changes quick, ships fast, and this map is the proof. ๐Ÿš€๐Ÿ”ฅ

โšก startup mode โ€” shipping daily since jan 2025 ๐Ÿฅท
16 ๐Ÿฏ Platforms
13 ๐ŸŒ Domains
1M+ ๐Ÿง  Graph Nodes
95+ โš™๏ธ Ingesters
68 ๐Ÿ“ก Intel Sources
1 ๐Ÿฅท Engineer
๐Ÿฏ ninja.ing โ€” The Intelligence Mesh // niko: one person built all of this. yes, really. ๐Ÿคฏ โ”‚ โ”œโ”€โ”€ ๐Ÿ“ก ninjasignal.ninja โ€” Cyber Threat Intelligence ๐Ÿ”ฅ LIVE // niko: the mothership. 83 windows. the UI has a UI. โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Threat globe + dashboard โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” SSO identity provider (IDAM authority) SSO โ”‚ โ”œโ”€โ”€ ๐Ÿ“ /signup โ€” Registration (admin approval required) โ”‚ โ”œโ”€โ”€ ๐Ÿ”‘ /reset โ€” Password reset โ”‚ โ”œโ”€โ”€ โš™๏ธ /admin โ€” Users, Health, Password, Security, Audit, IDAM ADMIN โ”‚ โ”œโ”€โ”€ ๐ŸŽญ /theatre โ€” Threat Theatre: 3D Three.js galaxy (WASD fly-into, bloom, risk cloud) ๐ŸŒŒ PUBLIC // niko: it's like Google Earth but for hackers โ”‚ โ”œโ”€โ”€ ๐Ÿ“Š /signalhld โ€” High-level design document โ”‚ โ”œโ”€โ”€ ๐Ÿ” /spektr โ€” Ninja Spektr TI search engine ๐Ÿ”Ž PUBLIC // niko: Google for hackers. but cooler. โ”‚ โ”œโ”€โ”€ ๐Ÿ”— /auth/sso โ€” SSO entry point for cross-app auth โ”‚ โ”œโ”€โ”€ ๐Ÿค– /api/ml/* โ€” Risk, communities, centrality, GCN/GAT, forecast โ”‚ โ”œโ”€โ”€ ๐Ÿงฌ /api/twins/* โ€” Adversary digital twins + war gaming โ”‚ โ”œโ”€โ”€ ๐Ÿ“ก /api/graph/* โ€” Graph queries, search, stats โ”‚ โ”œโ”€โ”€ ๐Ÿ” /api/kql/* โ€” KQL detection rule generator โ”‚ โ”œโ”€โ”€ ๐Ÿง  /api/search/* โ€” Semantic search (LanceDB + TF-IDF hybrid) โ”‚ โ”œโ”€โ”€ ๐Ÿ—บ๏ธ /api/heatmap/* โ€” H3 hexagonal geo heatmaps + APT overlay โ”‚ โ”œโ”€โ”€ โš—๏ธ /api/causal/* โ€” DoWhy causal inference (4 CTI scenarios) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ /api/extraction/* โ€” LLM CTI entity extraction + graph commit โ”‚ โ”œโ”€โ”€ ๐Ÿงฌ /api/adversary/dna โ€” Adversary Behavioral DNA (18-dim fingerprinting) ๐Ÿ’€ NEW // niko: we fingerprint YOUR fingerprints โ”‚ โ”œโ”€โ”€ ๐Ÿงฌ /api/adversary/dna/{ip} โ€” Single IP behavioral profile + narrative โ”‚ โ”œโ”€โ”€ ๐Ÿ”— /api/adversary/clusters โ€” Behavioral clustering (same operator detection) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ /api/adversary/narratives โ€” Auto-generated threat narratives โ”‚ โ”œโ”€โ”€ โš–๏ธ /api/adversary/compare โ€” Compare two IPs (cosine similarity verdict) โ”‚ โ”œโ”€โ”€ ๐ŸŽฏ /api/attribution/* โ€” ORIGAMI Attribution Engine (Diamond Model, temporal, infrastructure) ๐Ÿ—บ๏ธ NEW // niko: name and shame, but with math โ”‚ โ”œโ”€โ”€ ๐ŸŒŒ /api/galaxy/data โ€” 3D galaxy visualization data (nodes, edges, labels) NEW โ”‚ โ”œโ”€โ”€ ๐ŸŒŒ /api/galaxy/node/{name} โ€” Galaxy node drill-down detail โ”‚ โ”œโ”€โ”€ ๐Ÿ“‰ /api/diff/summary โ€” Threat Diff changelog (1d/7d/30d/90d windows) NEW โ”‚ โ”œโ”€โ”€ ๐Ÿ“‰ /api/diff/detail/{category} โ€” Detailed diff by category โ”‚ โ”œโ”€โ”€ ๐Ÿ“‹ /api/briefing/generate โ€” CISO Briefing (executive threat report JSON) NEW โ”‚ โ”œโ”€โ”€ ๐Ÿ“‹ /api/briefing/html โ€” CISO Briefing (print-ready HTML) โ”‚ โ”œโ”€โ”€ ๐Ÿฆ /api/tweets/* โ€” Auto-tweet bot (queue, post, history) NEW โ”‚ โ”œโ”€โ”€ ๐Ÿ“Š /api/access/intel โ€” Access intelligence + threat level assessment โ”‚ โ”œโ”€โ”€ ๐Ÿ“ˆ /api/traffic/* โ€” Live traffic analytics (all domains) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ค /api/upload โ€” STIX/MISP bundle upload โ”‚ โ”œโ”€โ”€ ๐Ÿ“„ /intel/cve/{id} โ€” SEO honeypot: per-CVE public pages (3,869 pages) ๐Ÿ•ท๏ธ PUBLIC // niko: 4,070 pages Google can't resist indexing โ”‚ โ”œโ”€โ”€ ๐Ÿ‘ค /intel/actor/{name} โ€” SEO honeypot: per-actor public pages (195 pages) PUBLIC โ”‚ โ”œโ”€โ”€ ๐ŸŒ /ws/threats โ€” Real-time threat WebSocket โšก โ”‚ โ””โ”€โ”€ ๐ŸŒ /ws/telemetry โ€” SIEM telemetry WebSocket โšก โ”‚ โ”œโ”€โ”€ ๐ŸŒ ninjafusion.ninja โ€” Geopolitical Intelligence Fusion ๐ŸŒ LIVE // niko: 80+ ingesters. it eats the entire internet for breakfast. โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Dashboard + 68 source fusion view โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ฐ /sitrep โ€” Free public situation report (SEO) ๐Ÿ“ก PUBLIC // niko: free intel. you're welcome. ๐ŸŽ โ”‚ โ”œโ”€โ”€ ๐Ÿค– /api/ml/* โ€” Risk propagation, communities, forecast โ”‚ โ”œโ”€โ”€ ๐Ÿงฌ /api/twins/* โ€” Adversary digital twins โ”‚ โ”œโ”€โ”€ ๐ŸŽญ /theatre โ€” Threat Theatre (interactive Canvas2D actor map) NEW โ”‚ โ”œโ”€โ”€ ๐Ÿ“Š /api/social/* โ€” Social media intelligence feeds โ”‚ โ””โ”€โ”€ ๐ŸŒ /ws/threats โ€” Real-time intel WebSocket โ”‚ โ”œโ”€โ”€ ๐Ÿ”ช ninjaraz0r.ninja โ€” Graph-Native SIEM + EDR ๐Ÿฆ€ LIVE // niko: a SIEM written in Rust. because why not. โ”‚ โ”œโ”€โ”€ ๐Ÿ“Š / โ€” SIEM dashboard (via Signal UI) โ”‚ โ”œโ”€โ”€ ๐Ÿฆ€ /agents/* โ€” Rust EDR agent management โ”‚ โ”œโ”€โ”€ ๐ŸŽฏ /rules/* โ€” Auto-generated detection rules (33 built-in) โ”‚ โ”œโ”€โ”€ ๐Ÿ”— /cross-node/* โ€” Cross-node ransomware correlation โ”‚ โ”œโ”€โ”€ ๐Ÿ—บ๏ธ /assets/* โ€” AssetMapper + BFS blast radius โ”‚ โ””โ”€โ”€ โš ๏ธ /alerts/* โ€” 5-phase kill chain alerts โ”‚ โ”œโ”€โ”€ ๐Ÿ•ต๏ธ ninjanexus.ninja โ€” OSINT Investigative Intelligence ๐Ÿ”Ž LIVE // niko: follow the money. always follow the money. ๐Ÿ’ธ โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Investigation board + entity graph โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐Ÿ” /api/investigate/* โ€” Case management + entity pinning โ”‚ โ”œโ”€โ”€ ๐Ÿฆ /api/financial/* โ€” Money flow tracing + UBO resolution โ”‚ โ”œโ”€โ”€ ๐Ÿšข /api/sanctions/* โ€” Sanctions screening (OpenSanctions + OFAC) โ”‚ โ”œโ”€โ”€ ๐Ÿ๏ธ /api/offshore/* โ€” ICIJ Offshore Leaks integration โ”‚ โ””โ”€โ”€ ๐Ÿค– /api/ml/* โ€” Suspicion propagation + network detection โ”‚ โ”œโ”€โ”€ ๐Ÿ’ฐ ninjaken0bi.ninja โ€” Financial Intelligence ๐Ÿ“ˆ LIVE // niko: crypto, stocks, forex โ€” and it tells you when things smell weird โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Dashboard + ticker bar + globe โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ˆ /api/market/* โ€” Real-time crypto/stocks/forex โ”‚ โ”œโ”€โ”€ ๐Ÿง  /api/ml/* โ€” Price prediction + anomaly detection โ”‚ โ”œโ”€โ”€ ๐Ÿ’ฌ /api/sentiment/* โ€” ApeWisdom + RSS VADER analysis โ”‚ โ””โ”€โ”€ ๐Ÿ“Š /api/portfolio/* โ€” Portfolio risk + correlation matrix โ”‚ โ”œโ”€โ”€ ๐Ÿชช 1d.ninja.ing โ€” Identity Intelligence ๐Ÿ‘ค LIVE // niko: finds your shadow admins before the red team does โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Identity dashboard + AD graph โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ โš”๏ธ /api/paths/* โ€” BFS attack path analysis โ”‚ โ”œโ”€โ”€ ๐ŸŽซ /api/kerberos/* โ€” Kerberoasting + AS-REP roasting โ”‚ โ”œโ”€โ”€ ๐Ÿ‘ค /api/identities/* โ€” Identity risk scores + shadow admins โ”‚ โ””โ”€โ”€ ๐Ÿ“ฅ /api/import/* โ€” BloodHound ZIP, LDAP, Azure AD, CSV ingest โ”‚ โ”œโ”€โ”€ ๐Ÿค– ninjav0id.io โ€” V: Autonomous Defensive Cyber Agents ๐Ÿ›ก๏ธ LIVE // niko: three AIs that argue about whether to quarantine your laptop โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Agent control panel + mission board โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐ŸŸข /api/agents/sentinel โ€” Alert triage + confidence scoring โ”‚ โ”œโ”€โ”€ ๐ŸŸก /api/agents/warden โ€” Automated containment + isolation โ”‚ โ”œโ”€โ”€ ๐ŸŸฃ /api/agents/spectre โ€” Threat hunting + forensic collection โ”‚ โ”œโ”€โ”€ ๐Ÿ“‹ /api/playbooks/* โ€” 8 IR playbooks (SOAR-style) โ”‚ โ””โ”€โ”€ ๐Ÿ”— /api/connectors/* โ€” Raz0r + Signal + Azure AD โ”‚ โ”œโ”€โ”€ ๐Ÿ”ฎ ninjav0id.io โ€” V0id: Predictive Sentiment Intelligence (landing page + ecosystem hub) ๐Ÿงฟ LIVE // niko: it predicted that tariff announcement 3 days early. just saying. โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Landing page (public) / Oracle dashboard (authenticated) โ”‚ โ”œโ”€โ”€ ๐Ÿ—บ๏ธ /ninjatone โ€” ninjaTONE daily intelligence briefing (public, free) ๐Ÿ“ฐ // niko: the world's vibes, distilled into one number ๐Ÿงฟ โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐Ÿงฟ /api/oracle โ€” Composite 0-100 geopolitical score โ”‚ โ”œโ”€โ”€ ๐Ÿ“ฐ /api/sentiment/* โ€” GDELT + RSS + Reddit feeds โ”‚ โ”œโ”€โ”€ ๐Ÿ“ˆ /api/economic/* โ€” FRED indicators + correlation โ”‚ โ”œโ”€โ”€ ๐Ÿค– /api/ml/* โ€” Anomaly detection + topic clustering โ”‚ โ”œโ”€โ”€ ๐Ÿ›ก๏ธ /v โ€” V0id Agents: Sentinel, Warden, Spectre (autonomous defense) โ”‚ โ””โ”€โ”€ ๐ŸŒŒ /ninjatone#galaxy โ€” 3D Galaxy: Three.js point cloud of 1M+ threat entities ๐ŸŒ  NEW // niko: it's basically Elite Dangerous for threat data โ”‚ โ”œโ”€โ”€ โš™๏ธ antos.ninja.ing โ€” AI-Orchestrated DevSecOps ๐Ÿœ LIVE // niko: 17 tools, 1 pipeline, 0 human approvals needed โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” 8-stage pipeline dashboard (17 tools, Claude AI triage) โ”‚ โ””โ”€โ”€ ๐Ÿ“Š /traffic โ€” Cloudflare traffic analytics (all 7 zones) โ”‚ โ”œโ”€โ”€ ๐Ÿ›ก๏ธ gitair.ninja โ€” Git Security Scanning ๐Ÿ” LIVE // niko: it finds your .env files before the bad guys do โ”‚ โ””โ”€โ”€ ๐Ÿ  / โ€” Git repository security scanner + secret detection โ”‚ โ”œโ”€โ”€ ๐Ÿ” ninjav0id.io/knox โ€” Secrets, Privacy & Crypto โ€” ้‡‘ๅบซ ๐Ÿ”‘ SOON // niko: AES-GCM + ChaCha20 + SHA3 + KEM. knox doesn't play. โ”‚ โ”œโ”€โ”€ ๐Ÿ”‘ /knox/vault โ€” Encrypted secrets vault (Fernet, machine-bound) โ”‚ โ”œโ”€โ”€ ๐Ÿ›ก๏ธ /knox/crypto โ€” Crypto toolkit (AES-GCM, ChaCha20, SHA3, Ed25519, KEM) โ”‚ โ”œโ”€โ”€ ๐Ÿ‘๏ธ /knox/privacy โ€” PII detection + anonymisation (13 types) โ”‚ โ”œโ”€โ”€ โœณ๏ธ /knox/passwords โ€” Password + passphrase generator with strength meter โ”‚ โ”œโ”€โ”€ โฑ๏ธ /knox/authenticator โ€” TOTP authenticator (RFC 6238) โ”‚ โ””โ”€โ”€ ๐Ÿ“œ /knox/audit โ€” Chain-hashed tamper-evident audit log โ”‚ โ”œโ”€โ”€ ๐Ÿ’ฌ ninjasocial.ninja โ€” Threat Intel Collaboration ๐Ÿฆ LIVE NEW // niko: Twitter for threat analysts. minus the doomscrolling. ok maybe some doomscrolling. โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Channel feed + DMs + NATS live TI stream โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ข /channels/* โ€” 6 default channels (general, threat-intel, IR, detection-eng, sitrep, alerts) โ”‚ โ”œโ”€โ”€ ๐Ÿ’Œ /dm/* โ€” Encrypted direct messages โ”‚ โ”œโ”€โ”€ ๐Ÿ” /api/ioc/* โ€” Auto-IOC detection in messages โ”‚ โ””โ”€โ”€ ๐ŸŒ /ws/messages โ€” Real-time WebSocket messaging โ”‚ โ”œโ”€โ”€ ๐ŸŽ–๏ธ warroom.ninja โ€” Incident War Room ๐Ÿ”ด LIVE NEW // niko: LiveKit video + shared timelines. it's like Zoom but everyone's stressed. โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Room dashboard + breach containment tracker (8 phases) โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐ŸŽฅ /room/* โ€” LiveKit video conferencing rooms โ”‚ โ”œโ”€โ”€ ๐Ÿ“‹ /playbooks/* โ€” 4 IR playbooks (ransomware, data breach, DDoS, insider threat) โ”‚ โ”œโ”€โ”€ ๐ŸŽฏ /ioc/* โ€” IOC panel + Signal enrichment โ”‚ โ””โ”€โ”€ ๐Ÿ“ก /ws/alerts โ€” NATS alert feed WebSocket โ”‚ โ”œโ”€โ”€ โš–๏ธ ninja.ing/ninjasabaki โ€” ่ฃใ Vulnerability Triage & Remediation โš”๏ธ LIVE NEW // niko: finally a vuln tool that doesn't make you want to cry. mostly. โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” Triage dashboard + priority scoring (8-factor) โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login โ€” Auth (SSO โ†’ Signal) โ”‚ โ”œโ”€โ”€ ๐Ÿ“ฅ /api/import/* โ€” Multi-scanner ingest (Nessus/Qualys/Tenable/Inspector) โ”‚ โ”œโ”€โ”€ ๐ŸŽฏ /api/triage/* โ€” Auto-FP detection (4 rules) + coverage gap analysis โ”‚ โ”œโ”€โ”€ ๐Ÿ”Ÿ /api/top10 โ€” Top 10 generator (prioritised remediation list) โ”‚ โ””โ”€โ”€ ๐ŸŽซ /api/servicenow/* โ€” ServiceNow integration (auto-ticket + resolver routing + email) โ”‚ โ”œโ”€โ”€ ๐Ÿฏ Los Alamos Range โ€” ๅฐ„ๅ ด Agentic Live Fire Cyber Range ๐ŸŽฒ SOON // niko: LLM agents play war games. the ELO system is brutal. ๐Ÿ’€ โ”‚ โ”œโ”€โ”€ โš”๏ธ /arena โ€” Red vs Blue wargaming arena + tick engine โ”‚ โ”œโ”€โ”€ ๐Ÿ‘น /kage, /oni, /yurei โ€” Red Trinity: LLM-driven adversary agents โ”‚ โ”œโ”€โ”€ ๐Ÿ›ก๏ธ /blue โ€” Blue team: V0id agents (Sentinel/Warden/Spectre) โ”‚ โ”œโ”€โ”€ ๐Ÿ† /scoreboard โ€” ELO scoring + kill chain heatmap โ”‚ โ”œโ”€โ”€ ๐ŸŒ /environment โ€” 5 enterprise templates (corp/cloud/ICS/finance/gov) โ”‚ โ””โ”€โ”€ ๐ŸŽฒ /workbench โ€” Chimera randomizer + chaos mutations โ”‚ โ”œโ”€โ”€ ๐Ÿฆž NinjaClaw โ€” Hardened CLI Security Agent ๐Ÿ–ฅ๏ธ PyPI // niko: pip install ninjaclaw. that's it. that's the pitch. โ”‚ โ””โ”€โ”€ ๐Ÿ”ง CLI โ€” 10 scanners, CIS rules, Claude AI assess, Signal intel, zero attack surface โ”‚ โ”œโ”€โ”€ ๐Ÿฏ ninja.ing โ€” Showcase & Documentation ๐Ÿ“š LIVE // niko: the gift shop is this way โ†’ โ”‚ โ”œโ”€โ”€ ๐Ÿ  / โ€” The Intelligence Mesh landing page ๐Ÿ•ธ๏ธ โ”‚ โ”œโ”€โ”€ ๐Ÿ—บ๏ธ /sitemap.html โ€” You are here ๐Ÿ“ // niko: inception. a map of the map. โ”‚ โ”œโ”€โ”€ ๐Ÿ” /login.html โ€” Showcase auth gate โ”‚ โ”œโ”€โ”€ ๐Ÿ“„ /exec-summary.html โ€” Executive summary (why this exists) AUTH โ”‚ โ”œโ”€โ”€ ๐Ÿ’ผ /ma-guide.html โ€” Insight³ technical deep dive AUTH โ”‚ โ”œโ”€โ”€ ๐Ÿ““ /diary.html โ€” Development diary (the whole journey) ๐Ÿ“– AUTH โ”‚ โ”œโ”€โ”€ ๐Ÿ’š /niko.html โ€” Niko's Corner (dispatches from the front) ๐Ÿฑ NEW // niko: my page! finally! about time. โ”‚ โ”œโ”€โ”€ โš”๏ธ /philosophy.html โ€” Ninja Philosophy manifesto (BSG Razor aesthetic) ๐Ÿ—ก๏ธ NEW โ”‚ โ””โ”€โ”€ ๐ŸŽธ /tonelab/ โ€” ninjaTONE Lab (14 tone labs) ๐ŸŽต // niko: guitar nerd alert. proceed with caution. ๐ŸŽถ โ”‚ โ”œโ”€โ”€ โš”๏ธ raz0r.io โ€” Philosophy & Contact ๐Ÿ—ก๏ธ LIVE NEW // niko: "first rule of ninja club is you DO talk about ninja club" โ”‚ โ””โ”€โ”€ ๐Ÿ“ฌ / โ€” Ninja Philosophy + contact form (FormSubmit โ†’ [email protected]) โ”‚ โ””โ”€โ”€ ๐Ÿ”ง Infrastructure โ€” The plumbing ๐Ÿช  // niko: the stuff nobody sees but everything breaks without โ”œโ”€โ”€ ๐Ÿ—„๏ธ Neo4j 5.x + GDS 2.22 โ€” Graph database (8 instances, shared prod server) โ”œโ”€โ”€ ๐Ÿ FastAPI + Python 3.14 โ€” 13 API backends โ”œโ”€โ”€ โš›๏ธ Next.js 16 + React 19 โ€” 14 UI frontends (Tailwind 4) โ”œโ”€โ”€ ๐Ÿ”’ Caddy 2 โ€” Reverse proxy + TLS (13 domains, one instance) โ”œโ”€โ”€ โ˜๏ธ Cloudflare โ€” DNS + proxy + origin certs (7 zones) โ”œโ”€โ”€ ๐Ÿณ Docker Compose โ€” 30+ containers, one network // niko: docker ps is a scroll fest ๐Ÿ“œ โ”œโ”€โ”€ ๐Ÿฆ€ Rust โ€” Raz0r EDR agent (ETW + AMSI + memory scanning) โ”œโ”€โ”€ ๐Ÿง  ML Stack โ€” GCN/GAT, Hawkes, GraphSAGE, Louvain, DoWhy, LanceDB โ”œโ”€โ”€ ๐Ÿ“ก NATS JetStream โ€” Event bus (9 subject hierarchies, cross-platform pub/sub) โ”œโ”€โ”€ ๐Ÿ”‘ SSO / IDAM โ€” Signal as identity provider, cross-domain auth โ”œโ”€โ”€ ๐Ÿ”ด Redis 7 โ€” Presence, sessions, pub/sub (Social + War Room) โ”œโ”€โ”€ ๐ŸŽฅ LiveKit โ€” WebRTC video conferencing (War Room) โ””โ”€โ”€ ๐Ÿ—๏ธ Hetzner Dedicated โ€” Two servers, WireGuard tunnel, zero cloud bills ๐Ÿ’ธ // niko: two servers to rule them all ๐Ÿ’
17 platforms, 13 domains, 13 APIs, 14 UIs, 10 graphs, 1 engineer, 0 excuses. ๐Ÿš€๐Ÿ”ฅ๐Ÿ’€ // niko: "is this a startup or a cry for help?" โ€” yes.
NEW CAPABILITY
ๆ•ต้บไผๅญ

Adversary Behavioral DNA

The first system to fingerprint attackers by behaviour, not IOCs.

Every attacker has unconscious habits — the order they probe paths, timing patterns, tool signatures, target preferences. Adversary DNA extracts an 18-dimensional behavioral vector from raw access logs, creating a unique fingerprint for every IP that touches our infrastructure.

No training data. No external ML libraries. Pure statistical inference from production traffic. ๐Ÿงช๐Ÿ”ฅ

๐Ÿงฌ
Behavioral Fingerprinting
18 dimensions: temporal entropy, velocity, acceleration, path vocabulary, method entropy, error rate, inter-request timing, domain spread, auth ratio, sensitive path ratio, UA consistency, response size variance
๐ŸŽญ
Archetype Classification
Weighted scoring classifies every IP as one of five archetypes: Scanner, Brute-Forcer, Researcher, Bot/Crawler, or Targeted Operator
๐Ÿ”—
Same-Operator Detection
Cosine similarity clustering with union-find to detect the same human behind different IPs and VPNs. Threshold: 0.85 similarity
๐ŸŽฏ
Kill Chain Mapping
Maps observed behaviour to Lockheed Martin kill chain stages: reconnaissance, weaponization, delivery, exploitation, installation, C2, exfiltration
๐Ÿ”ฎ
Markov Prediction
Learns transition probabilities between request categories. Given the attacker's last action, predicts their next likely move
๐Ÿ“
Threat Narratives
Auto-generates human-readable intelligence reports per adversary combining all signals: archetype, kill chain, features, and predictions
๐Ÿ”ด Live Production Results โ€” 48 hours, real attackers ๐Ÿ’€
198 IPs Observed
54 Profiled
18 DNA Dimensions
5 Archetypes
0.997 Scanner Match
Key finding: Two Microsoft Azure IPs (different subnets) running PHP webshell scanners returned 0.9975 cosine similarity — confirmed as the same operator using two VMs. Behavioral DNA identified what IP blocklists couldn't: the human behind the machines.
GET /adversary/dna · GET /adversary/dna/{ip} · GET /adversary/clusters · GET /adversary/narratives · GET /adversary/compare?ip_a=X&ip_b=Y
ๆƒ…ๅ ฑ็ถฒ

The Intelligence Mesh

17 platforms · 8 intelligence domains · 1 unified graph ๐Ÿง ๐Ÿ”ฅ

ๅฟ SIGNAL SSO HUB ่ž FUSION Geopolitical Intel ้‡‘ KIN0BI Financial Intel ็น‹ NEXUS OSINT ๅฃฑ 1D Identity ็ฉบ V01D Predictive ่™š V0ID Agents ๅฐ„ LOS ALAMOS Live Fire Range ๅบซ KNOX Secrets ่Ÿป ANTOS DevSecOps ็›พ GITAIR Git Sec ็ˆช CLAW CLI Agent ๅˆƒ RAZ0R SIEM + EDR
๐Ÿ“ก
Cyber Threat Intel
Signal · Raz0r · Spektr
Threat graph, SIEM, detection rules, KQL, semantic search, CTI extraction
๐ŸŒ
Geopolitical Intel
Fusion · V01d
68-source fusion, sentiment pipeline, GDELT/RSS/Reddit, Oracle score
๐Ÿ•ต๏ธ
Investigations
Nexus · 1D
OSINT, money flow, sanctions, UBO, identity graphs, attack paths
๐Ÿ’ฐ
Financial Intel
Kin0bi
Real-time crypto/stocks/forex, anomaly detection, portfolio risk
๐Ÿค–
Autonomous Ops
V0id · Los Alamos
3 AI agents, IR playbooks, red vs blue wargaming, LLM adversaries
๐Ÿ’ฌ
Collaboration & IR
Social · War Room
Real-time TI messaging, video conferencing, incident timelines, breach containment
โš–๏ธ
Vulnerability Mgmt
Sabaki
Multi-scanner triage, priority scoring, auto-FP, ServiceNow ticketing
๐Ÿ”ง
Security Tooling
Knox · ANTOS · GITAIR · Claw
Secrets vault, crypto toolkit, DevSecOps, git scanning, CLI agent
Intelligence Pipeline
68 Sources
95+ Ingesters
1M+ Graph Nodes
12 ML Models
18 DNA Dimensions
3 AI Agents
Python 3.14 FastAPI Neo4j 5 + GDS Next.js 16 React 19 Tailwind 4 Rust Docker Caddy NATS WebSocket GCN / GAT LanceDB DoWhy Cloudflare

๐Ÿ” Quick Access โ€” All Platform Logins ๐Ÿšชโœจ

๐Ÿ”ฅ Recent Deploys ๐Ÿš€๐Ÿ’€

← Back to the Mesh