Lab
Practical security tools for defenders and engineers working with AI systems and cloud infrastructure.
Each one does something specific and hands back a file you can take with you: a query, a layer, a rule, a debrief, a table.
CVE Watch
Last 30 days11,531 scored·25 in CISA KEV·203 added in the last run
- CVE-2026-672796.5mikrotik
- CVE-2026-879028.1unattributed
- CVE-2026-851029.8checkpoint
Local Model Verifier
Generates proof that a local AI model cannot reach the network, and that it still works. Answer three questions and get the settings that block it, a script that checks both directions, and the risks isolation cannot fix, mapped to MITRE ATLAS. Every file explains itself and says how to undo it.
ReactNext.jsTypeScriptsystemdnftablesMITRE ATLASIncident Triage Drill
AI-generated on-call scenarios for AI and cloud security incidents. Work through realistic triage decisions and get a full debrief showing what thorough coverage looks like.
ReactNext.jsTypeScriptAnthropicPacket to Prompt
One request traced end to end, from a laptop’s network card to a model’s response: the header values before and after every hop, the literal log record each sensor emits, what that sensor cannot see, and the ATT&CK and ATLAS techniques that abuse each step. Read it, or walk it and export the debrief.
ReactNext.jsTypeScriptMITRE ATT&CKMITRE ATLASMITRE ATT&CK 3D Explorer
The ATT&CK matrix has 700+ techniques. This makes the relationships visible: which threat groups use which techniques, how techniques cluster by tactic, and how malware connects to specific attack patterns.
ReactThree.jsR3FTypeScriptATLAS Threat Hunt Generator
AI systems face attacks your existing SIEM rules were not written to catch. Pick an attack technique from the MITRE ATLAS catalog, describe your system, and get a structured hunt hypothesis and detection query you can run today.
ReactNext.jsTypeScriptAnthropicSTRIDE Threat Model Generator
Describe your system architecture and get a prioritized list of what could go wrong: spoofing, tampering, data leakage, denial of service, privilege escalation. Each threat is scored so you know where to start. Exports as a markdown file you can commit to the repo.
ReactNext.jsTypeScriptAnthropicATLAS Sigma Rule Library
Pre-built detection rules for attacks specific to AI systems, ready to convert to Splunk SPL, Sentinel KQL, or Elastic EQL. Each rule includes a plain-English explanation of what it detects, what logs you need to enable, and a tool to adapt it to your specific setup.
ReactNext.jsTypeScriptSigmaAnthropicATLAS to ATT&CK Parent Mapper
Every MITRE ATLAS technique mapped to its ATT&CK equivalent: formal cross-references, conceptual analogues, and AI-unique techniques with no ATT&CK parent. Bidirectional view with cloud-relevance filtering.
ReactNext.jsTypeScriptAnthropicCVE Landscape
The last 30 days of scored CVEs as a treemap, with a lens that toggles between CVSS severity and what is actually being exploited in the wild, powered by CISA KEV and FIRST EPSS.
ReactNext.jsTypeScriptD3NIST CSF 2.0 Crosswalk
NIST publishes official mappings from the Cybersecurity Framework to the frameworks you already run, then buries them in a spreadsheet. This surfaces them, including the mappings to the OWASP Top 10 for LLM Applications, so you can see which CSF Subcategories govern each AI risk and where your current framework leaves blind spots.
ReactNext.jsTypeScriptNIST CSF