Air Force Logo
Thundercats Logo

Lab

Practical security tools for defenders and engineers working with AI systems and cloud infrastructure.

Each tool does something specific and produces output you can act on.

Incident Triage Drill

AI-generated on-call scenarios for AI and cloud security incidents. Work through realistic triage decisions and get a full debrief showing what thorough coverage looks like.

ReactNext.jsTypeScriptAnthropic

MITRE ATT&CK 3D Explorer

The ATT&CK matrix has 700+ techniques. This makes the relationships visible: which threat groups use which techniques, how techniques cluster by tactic, and how malware connects to specific attack patterns.

ReactThree.jsR3FTypeScript

ATLAS Threat Hunt Generator

AI systems face attacks your existing SIEM rules were not written to catch. Pick an attack technique from the MITRE ATLAS catalog, describe your system, and get a structured hunt hypothesis and detection query you can run today.

ReactNext.jsTypeScriptAnthropic

STRIDE Threat Model Generator

Describe your system architecture and get a prioritized list of what could go wrong: spoofing, tampering, data leakage, denial of service, privilege escalation. Each threat is scored so you know where to start. Exports as a markdown file you can commit to the repo.

ReactNext.jsTypeScriptAnthropic

ATLAS Sigma Rule Library

Pre-built detection rules for attacks specific to AI systems, ready to convert to Splunk SPL, Sentinel KQL, or Elastic EQL. Each rule includes a plain-English explanation of what it detects, what logs you need to enable, and a tool to adapt it to your specific setup.

ReactNext.jsTypeScriptSigmaAnthropic

ATLAS to ATT&CK Parent Mapper

Every MITRE ATLAS technique mapped to its ATT&CK equivalent: formal cross-references, conceptual analogues, and AI-unique techniques with no ATT&CK parent. Bidirectional view with cloud-relevance filtering.

ReactNext.jsTypeScriptAnthropic

CVE Landscape

The last 30 days of scored CVEs as a treemap, with a lens that toggles between CVSS severity and what is actually being exploited in the wild, powered by CISA KEV and FIRST EPSS.

ReactNext.jsTypeScriptD3