Intelligence overview
Operational picture
What needs attention now
Loading current workspace…
Threat outlook
What reporting trends suggest may come next
Trend-based analyst support — not a prediction or guarantee.
Threat stream
Recent intelligence
Auto-refreshing every 5 minutes
Data sources
Integration health
Case queue
Current investigations
Built daily at 06:00 Eastern
Daily hunt
Ranked hunts from today's Threat Outlook and threat stream: fresh IOC sweeps (ThreatFox, URLhaus, Feodo, OTX, published reporting, your confirmed IOCs), behavior hunts matched to the forecast, and new known-exploited CVEs. Every query is generated from templates for Splunk, Sentinel/Defender and Elastic.
Free sources · counted, not guessed
Global threat signals
Topics gaining attention across independent sources: government CERTs (English, French, German, Ukrainian, Dutch and more), vendor research, security news, CISA KEV, GitHub advisories and exploit repos, nuclei templates, OTX, ThreatFox, Mastodon and Bluesky researchers. Trends are calculated from counts. The strongest ones feed the Threat Outlook and the Daily hunt.
Multi-model analyst agent
Ask the AI analyst
Choose a single analyst or a multi-model Council. Auto Council starts with three low-cost models and brings in OpenAI and Claude only when they disagree or find something malicious. Every mode is read-only; operational actions stay with you.
Prompts and investigation context submitted to the AI Analyst may be processed by configured third-party AI providers, including OpenAI, Anthropic, Google, or Cloudflare-hosted models. Do not submit PHI/HIPAA-regulated data, classified or CUI data, credentials, secrets, or confidential company/customer information unless your organization has approved the provider and applicable agreements and controls.
What should we look into?
Try one of these, or ask your own question.
Multi-source enrichment
Indicator lookup
IPs, domains, URLs, file hashes, email addresses and CVEs. Defanged input is fine. Every applicable source runs server-side; API keys never reach the browser.
Ready for analysis
Configured enrichment sources will appear here, followed by an optional evidence-based AI assessment.
Paste anything
Bulk triage
Paste an email, alert JSON, log lines or a threat report. SSNS pulls out every IP, domain, URL, hash, email and CVE (defanged or not), skips private and internal values, enriches the rest, and ranks them by risk.
Ctrl/⌘ + Enter runs triage. Private IPs, reserved TLDs and your INTERNAL_DOMAINS are never sent to external sources.
Case management
Investigations
Indicator repository
IOC tracker
Analyst deliverables
Reports
Priority queue