Intelligence overview
Live data from your VAJRAINTEL instance
—
—
Top trending IOCs
Highest-risk indicators in range
| Indicator | Type | Malware | Risk |
|---|
Latest threat news
Most recent ingested RSS/report items
Exploitation intelligence
Local NVD + CISA KEV dataset
Threat actors by country
Actor origin/state-sponsorship attribution - not the countries they target
Ransomware & extortion intelligence
Disclosed leak-site victims — click a metric to open the filtered library
Recent victims
IOC Lookup
Search and analyse Indicators of Compromise — source/vendor identity intentionally not shown
| IOC | Type | Category ⓘ | Country | First seen | Last seen | Confidence | Risk score | Reputation | Sources |
|---|
Threat Actors
Track and analyze the intrusion sets, malware and ATT&CK techniques in your intelligence catalog
Know Your Enemy
Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques, campaigns and indicators.
Threat Actors
IOC Indicators
ATT&CK Techniques
SEARCH THREAT ACTORS
Threat Actors
Malware Families & Tools
Malware family and tool intelligence — platforms, associated threat actors, targeting, and indicators for every tracked family in your catalog
Families & Tools
Active (90d)
Ransomware
Malware Families & Tools
Ransomware & Extortion
Tracked ransomware groups and disclosed victims — click a metric, chart segment, or row
Regional impact (top 5)
Threat group distribution (top 5)
Industry distribution (top 5)
| Victim | Threat group | Country | Industry | First seen | Last updated |
|---|
| Group | Victims (tracked) | First seen | Last active |
|---|
Vulnerability intelligence
Local NVD dataset cross-referenced with CISA KEV and FIRST.org EPSS — click a card or a row below
| CVE | Severity | CVSS | EPSS | Known exploited | Published | Modified |
|---|
Detection rules
Sigma, Yara, Suricata and Snort content ingested from configured feeds — click a rule to view its content
Threat Reports
Uploaded intelligence reports — click one to read it inside FLAG
Loading…
RSS feed items
Ingested threat news — external articles, not stored FLAG reports
Threat graph
AI intelligence analyst
Evidence-constrained — never fabricates attribution; relationships are shown as "mentions" unless confirmed
Checking AI status…
Access APIs
Browse full API documentation and manage your API keys
Your API keys
Long-lived keys for server-to-server integration — sent as X-API-Key
| Name | Prefix | Scopes | Created | Last used |
|---|
Investigation Cases
Track an investigation and the real intelligence linked to it
| Title | Status | Severity | Owner | Linked intel | Created | Updated |
|---|
Administration
Sources & feeds
Provenance is hidden from the intelligence views above by design; visible here for diagnostics
| Name | Type | Enabled | Interval | Last success | Last error |
|---|
Users
Role-based access control
| Username | Role | Active | Last login |
|---|
Alert webhooks
HMAC-signed JSON notifications on critical events
| Name | Min severity | Status |
|---|
STIX export & import
STIX 2.1 bundle of current IOCs, actors, and malware
Download STIX bundle (.json)
TAXII 2.1 server
Connect external TAXII clients (MISP, OpenCTI, etc.) to this instance
Threat report PDF
Text-extracted and auto-tagged against known entities
Provider collectors
Native public-source collectors
Malware & Threat Actor catalog
Backfill catalog entries from malware/actor names already attached to existing IOCs
Country data
Normalizes IOC country values to ISO-2 (fixes mixed "United States"/"US"-style data) and enriches Threat Actor origin/state-sponsorship attribution from MITRE's own descriptions - safe to re-run, never overwrites an existing value
Threat Actor executive summaries
Generates a clean, customer-facing summary for every Threat Actor from MITRE's own description (markdown/citations stripped, sentences de-duplicated and lightly restructured) - never regenerated on page load, safe to re-run, never overwrites an existing summary or invents facts
Malware & Tools executive summaries
Same cleanup as Threat Actor summaries, for Malware/Software descriptions - fixes the raw MITRE markdown/citations that otherwise show up both on the Malware page itself and nested in the Threat Actor detail page's Malware & Tools tab
System diagnostics
If job history shows "success" but counts stay at 0, check this first — it usually means two server processes are pointed at two different database files
Audit log
Every administrative action, who performed it, and when
| Time | Actor | Action | Entity | Detail |
|---|
Organizations
SUPER_ADMIN creates every organization and its first ORG_ADMIN together in one step — there is no public self-registration anywhere in this app
| Organization | Plan | License | Users | Status |
|---|
Technical Managers
VAJRAINTEL staff assigned to handle one or more organizations' support queries — not a member of any customer organization
| Name | Assigned orgs | Open queries | Active |
|---|
Support queries (all organizations)
Every organization's support tickets, across every technical manager
| Organization | Subject | Category | Priority | Status | Technical manager | Updated |
|---|
My Organization
—
—
Licensed features
What your organization's current plan and license status grant access to
Organization users
Invite-only — there is no public sign-up. Onboarding: temporary password → forced password change → mandatory email OTP → dashboard
| Name | Role | Status | Email verified |
|---|
Support
Reach VAJRAINTEL's support team for this organization
| Subject | Category | Priority | Status | Updated |
|---|
Support Console
Your queue
Assigned organizations
You only ever see support queries for organizations explicitly assigned to you by SUPER_ADMIN
| Organization | Status |
|---|
Support queue
| Organization | Subject | Category | Priority | Status | Technical manager | Updated |
|---|