Intelligence overview

N
Authorized userAnalyst

Operational picture

What needs attention now

Loading current workspace…

Open investigations—Active cases
Tracked indicators—— high risk
Active alerts—Awaiting review
Integrations online—Enrichment sources

Threat outlook

What reporting trends suggest may come next

Trend-based analyst support — not a prediction or guarantee.

Building a near-term outlook from recent cyber reporting…

Threat stream

Recent intelligence

Auto-refreshing every 5 minutes

Loading threat activity…

Data sources

Integration health

Checking integrations…

Case queue

Current investigations

Loading investigations…

Built daily at 06:00 Eastern

Daily hunt

Ranked hunts from today's Threat Outlook and threat stream: fresh IOC sweeps (ThreatFox, URLhaus, Feodo, OTX, published reporting, your confirmed IOCs), behavior hunts matched to the forecast, and new known-exploited CVEs. Every query is generated from templates for Splunk, Sentinel/Defender and Elastic.

Loading today's hunt package…

Free sources · counted, not guessed

Global threat signals

Topics gaining attention across independent sources: government CERTs (English, French, German, Ukrainian, Dutch and more), vendor research, security news, CISA KEV, GitHub advisories and exploit repos, nuclei templates, OTX, ThreatFox, Mastodon and Bluesky researchers. Trends are calculated from counts. The strongest ones feed the Threat Outlook and the Daily hunt.

Loading signals…

Multi-model analyst agent

Ask the AI analyst

Choose a single analyst or a multi-model Council. Auto Council starts with three low-cost models and brings in OpenAI and Claude only when they disagree or find something malicious. Every mode is read-only; operational actions stay with you.

External AI processing

Prompts and investigation context submitted to the AI Analyst may be processed by configured third-party AI providers, including OpenAI, Anthropic, Google, or Cloudflare-hosted models. Do not submit PHI/HIPAA-regulated data, classified or CUI data, credentials, secrets, or confidential company/customer information unless your organization has approved the provider and applicable agreements and controls.

Cheapest to most thorough: Economy → Auto → Standard → Full → Adversarial (Full + a Qwen dissent pass). Identical Council questions are served from the AI Gateway cache for 15 minutes.

What should we look into?

Try one of these, or ask your own question.

Enter to send · Shift+Enter for a new line

Multi-source enrichment

Indicator lookup

IPs, domains, URLs, file hashes, email addresses and CVEs. Defanged input is fine. Every applicable source runs server-side; API keys never reach the browser.

Ready for analysis

Configured enrichment sources will appear here, followed by an optional evidence-based AI assessment.

Paste anything

Bulk triage

Paste an email, alert JSON, log lines or a threat report. SSNS pulls out every IP, domain, URL, hash, email and CVE (defanged or not), skips private and internal values, enriches the rest, and ranks them by risk.

Ctrl/⌘ + Enter runs triage. Private IPs, reserved TLDs and your INTERNAL_DOMAINS are never sent to external sources.

Case management

Investigations

Loading investigations…

Indicator repository

IOC tracker

Loading indicators…

Analyst deliverables

Reports

Loading reports…

Priority queue

Alerts

Loading alerts…

New case

Create investigation

Track indicator

Add IOC

New deliverable

Create report

Act on indicators

Hunt & export

Behavior hunt

Behavior hunt

Hits found

Hunt

Last 30 days

Hunt log

Reviewed templates · Splunk, Sentinel/Defender, Elastic

Behavior hunt library

Signal evidence

Signal

Collection health

Signal sources

Firewall integration

Blocklist feeds

Loading feed configuration…

Add to case

Choose a case

↑↓ moveEnter openEsc closeCtrl+K or / from anywhere

External AI processing

Before you continue

This AI request may send your prompt and relevant SSNS investigation context to one or more configured external AI providers.

Do not submit PHI/HIPAA-regulated data, classified or CUI data, credentials, secrets, or confidential company/customer information unless your organization has approved the provider and applicable agreements and controls.

This notice is shown once per browser session after you choose to continue.