search
mTLS gRPC

Mission Control

Real-time security posture - AI-enriched intelligence

KEV
Loading CISA Known Exploited Vulnerabilities...
Risk Score
--
/100
Critical
--
findings
High
--
findings
Medium
--
findings
KEV Matches
--
exploited
Total Scans
--
completed
Assets
--
0 exposed
Open
--
0 resolved
CVEs
--
0 exploited
Weaknesses
--
unique CWEs
Ports Open
--
0 high-risk
Technologies
--
detected
pie_chartSeverity Breakdown
historyRecent Scans
radar
No scans yet - click Launch Scan to begin
warningActive KEV Matches
No KEV matches found
smart_toyAI Threat Insights

- Ask the AI Concierge for threat analysis

- Launch a scan to generate AI-powered findings

- KEV + EPSS data auto-enriches all CVEs

monitor_heartLive Monitor Feed -- events/min
Connecting to monitor stream...
bug_reportExploit Intelligence Hub
Loading...
my_locationTop Risk Targets
Loading...
categoryCWE Weakness Map
Loading...
priority_highRemediation Priority Queue
Loading...
monitor_heartScan Health Monitor
Loading...
verifiedCompliance Posture
Loading...
fact_checkValidation Integrity
Loading...
assignmentRecommended Actions
Loading...
monitoringVulnerability Lifecycle
Loading...
hubIntel Source Coverage
Loading...
psychologyAI Model Analysis
Loading...
rss_feedIntel Security Feeds
Loading...
dataset_linkedScan Data Provenance
Loading...
travel_exploreAttack Surface Exposure
Loading...
timerSLA Pressure
Loading...
schemaEvidence Pipeline
Loading...
Governed API Test Catalog
Intent-level coverage, safety class, and required evidence
Loading governed tests…

Scan Launcher

Execute security scans on Kali Linux VM → AI-powered analysis

Kali VM
Checking...
NIST References
--
With CI
--
Security Policies
--
Avg Posture
--
IP, CIDR, URL, domain, container:tag, or path
Tools In Profile
Select scan type →
Execution Terminal
IDLE 00:00
Phase
idle
Steps
0/0
Lines
0
Findings
0
Mode
ready
[VulnSentinel OS v4.3.0] Ready. Configure target and scan type, then launch.
$ _|
terminalLive Kali Terminal
Terminal is disconnected. Click Connect to open a bounded Kali PTY.
offline
historyComplete Scan History
--
Total
0
Running
0
Done
0
Failed
0
Cancelled
0
Findings
0
No scans yet
Page 1
scheduleScheduled Scans
No schedules configured

Findings Forge

AI-enriched vulnerability management — CVSS · EPSS · KEV

Severity Title / CVE CWE Target Type CVSS EPSS AI Tool Fix Status Age
search_off No findings. Launch a scan to get started.

Vulnerability Registry

Deep CVE-grouped view — CVSS · EPSS · KEV · CIRCL · OWASP · MITRE · Compliance mapped

Vulnerability Risk Index info
-- /100
Exploitable Threats (KEV / Exp) info
-- active threat vectors
-- CISA KEV entries
Urgent Priorities (Crit / High) info
-- vulnerabilities
-- Critical, -- High
Highest Risk Asset Scope info
--
Target exhibits highest threat surface
Severity CVE ID CWE ID Vulnerability Title / Weakness Affected Service/App CVSS EPSS Risk Score Assets Threat Intel Tool Fix Version Tags Exploit Age Status
security No vulnerabilities yet. Launch a scan to discover CVEs.

Asset Intelligence

Complete attack surface inventory — all tiers

search
-- assets

Investigation Graph

Case workspace linking targets, assets, findings, CVEs, evidence, and OSINT pivots

No case selected
0 nodes | 0 edges | 0 evidence
100%
CriticalHighAsset
Node Types
Risk Distribution
Relationship Summary
High-Value Nodes
0
Evidence Ledger
OSINT Source Coverage

Threat Intelligence Command

CISA KEV / EPSS / NVD / MITRE / CVEFeed / CVEDetails / Exploit Intelligence

CVE Lookup
hubIntel API Sources
⚡ KEV CISA Known Exploited Vulnerabilities -- entries
CVE ID Vulnerability Vendor Due Date
hub CIRCL Vulnerability-Lookup — Live Feed 71 DBs · 2.27M records
Click "Load 30" to fetch the latest from all 71 databases
analytics CVEDetails Live Intelligence news / OSV / emerging / exploits / advisories / code
Choose a CVEDetails category and click Load
manage_searchBrowse Vendor Products
storageDatabase Registry
Security News Feeds
Click "Load Feeds" to fetch latest security news

External Attack Surface

Subdomain discovery · Web fingerprints · Certificates · Cloud assets · Attack surface graph

Assets
--
Subdomains
--
Web Apps
--
Certificates
--
Cloud Assets
--
Risk Score
--
hubAttack Surface Graph
No EASM data — run a scan or enrich a domain
Deep Enrichment
Enter a domain and click Enrich for deep fingerprinting (TLS cert, HTTP headers, DNS, cloud detection)
Quick Assets

Red Team Operations

MITRE ATT&CK · Campaign Builder · Adversary Simulation

Campaign Setup
MITRE ATT&CK Chain
Recon
amass · subfinder
Init Access
nuclei · nikto
Execution
metasploit
Priv Esc
linpeas · pspy
Lateral
crackmapexec
Exfil
dnscat2 · curl
[Red Team] Configure campaign and launch →

Bug Bounty Recon

Automated bug bounty reconnaissance — subdomain · exposure · XSS · SQLi

Tools: amass, httpx, nuclei, gau, waybackurls, xsstrike
[Bug Bounty] Enter target domain and start recon →

Skills Browser

1,099 Security Skills · MITRE ATT&CK · NIST CSF · OWASP · Remediation Workflows

-
Total Skills
-
Domains
-
MITRE Techniques
-
NIST Controls
-
Unique Tags
Loading skills...

Autonomous Threat Hunter

Proactive Pattern Detection · Attack Path Discovery · Cross-Scan Correlation

-
Total Hunts
-
Hypotheses Triggered
-
Findings Correlated
-
Attack Paths
-
Memory Patterns
Hunt Configuration
Hunt Results
Click "Run Hunt" to start proactive threat hunting...
Attack Paths
No attack paths discovered yet.
Vector Memory — Cross-Scan Patterns
Loading memory stats...

Compliance & Governance

NIST CSF · CIS Benchmarks · ISO 27001 · PCI DSS · OWASP

Framework Posture
Calculating
Priority Governance Actions
Loading actions...
Control Evidence Trail
Loading mapped evidence...
Top Control Gaps
Loading gaps...
NIST CSF Coverage
Govern (CSF 2.0)0%
Identify0%
Protect0%
Detect0%
Respond0%
Recover0%
Hardening Scan
Tools: lynis, rkhunter, chkrootkit, openvas
SSL/TLS Audit
Tools: testssl.sh, sslyze, sslscan
[Compliance] Select audit type and target →
OWASP Top 10 : 2025 — Finding Presence
Loading OWASP mapping...
CWE Top 25 (2024) — Vulnerability Heatmap
Loading...
smart_toySigma Rule Generator (Cloud AI)

Reports & Analytics

AI-generated executive reports · Export · Trend analysis

Loading stats...
Executive Report
AI-generated CISO-ready summary of all findings, risk posture, and recommendations.
Technical Report
Full technical findings with CVEs, EPSS, KEV status, and remediation steps.
Findings Export
Export all findings to JSON or CSV for SIEM/ticketing integration.

Exploit Intelligence

ExploitDB · Sploitus · AttackerKB · Searchsploit · PoC Monitoring

Exploit Search
Quick CVE Lookup
securityExploitDB Results
Search for exploits above
boltSploitus Results
Search for exploits above

Zero-Day Response Center

Rapid response playbooks · AI triage · Emergency scanning · KEV alerts

⚡ LIVE MONITORING
Latest KEV Alerts
AI Response Console
[Zero-Day Response] Monitoring CISA KEV feed...
[AI] Ready to analyze and respond to zero-day threats
$ vulnsentinel --watch-kev --auto-triage --notify
play_circleActive Response Playbooks
CRITICAL
Log4Shell Response
CVE-2021-44228 — Patch + block JNDI lookups
HIGH
SSH Backdoor (XZ)
CVE-2024-3094 — Detect + remove xz-utils 5.6.x
HIGH
HTTP/2 Rapid Reset
CVE-2023-44487 — Rate limit + upgrade servers
+ Generate New
Playbook with AI

Forensic Deep Dive

Asset forensics · Process analysis · Log investigation · IOC extraction

Forensic Terminal
[Forensics] Configure target and analysis type →
$ ssh kali@${KALI} 'ps aux | netstat -tulnp | last -20'

Strategic Risk Projection

AI-generated executive risk narrative · Trend analysis · Board-ready insights

trending_flat
AI Risk Assessment
ANALYZING...
Click "Refresh AI Analysis" to generate risk projection...
priority_high
Recommended Action
Risk Metrics
7-Day Trend
Findings by Category

AI Remediation Playbooks

AI-generated fix scripts · Verification commands · MITRE ATT&CK coverage

CRITICAL CVE-2021-44228
Patch Log4Shell
Java JNDI injection via Log4j — Full remediation
★ Success Rate: 99.2%
HIGH CWE-89
Fix SQL Injection
Parameterized queries + WAF rules
★ Success Rate: 97.8%
MEDIUM CIS SSH
Harden SSH Config
Disable root, key-only auth, port change
★ Success Rate: 99.9%
CRITICAL CVE-2022-22965
Patch Spring4Shell
Spring Framework RCE via data binding
★ Success Rate: 98.5%
HIGH CWE-522
Rotate Leaked Creds
AWS IAM + K8s Secrets + Vault rotation
★ Success Rate: 99.4%
add_circle
Generate Custom Playbook
Powered by Cloud AI

IAST / RASP / MAST

Interactive AST · Runtime Application Self-Protection · Mobile App Security

code
IAST Scanner
Instrument running apps for real-time vulnerability detection. Requires agent injection.
Tools: nuclei + nikto + custom IAST probes
shield
RASP Analysis
Analyze application runtime behavior for self-protection gaps and bypass techniques.
Tools: trivy + kubescape + docker inspect
smartphone
MAST Scanner
Static analysis of Android APKs. Upload to Kali via SCP then scan.
Tools: apktool + jadx + mobsfscan
[IAST/RASP/MAST] Configure target and launch →

AI CyberSecurity Assistant

Deep reasoning agent-intelligence and exploit path synthesis

ACTIVE MODELS: --
chat_bubble Active Swarm Reasoning
VulnSentinel Deep Reasoning
Welcome to the Deep-Reasoning AI Assistant. I have full read-access to the current findings database, OWASP security cheat sheets, and local threat models. Ask me anything about exploit chaining, source-code analysis, or real-time remediation playbooks.
timeline Exploit Chain Synthesizer
Synthesize and model theoretical attack vectors using discovered assets and live findings.
network_ping Model Diagnostics
Loading models...

Credential Vault

Encrypted storage for scan credentials

No credentials stored yet

System Settings

Kali VM · Cloud AI · API Keys · Connection Test

terminalKali Linux VM
vpn_lockTailscale Setup
▸ On Kali: curl -fsSL https://tailscale.com/install.sh | sh
▸ On Kali: sudo tailscale up
▸ Copy Tailscale IP (100.x.x.x) → paste in Host field above
▸ Enable SSH: sudo systemctl enable ssh && sudo systemctl start ssh
⚠ Both Kali and Render must have Tailscale configured
codeGitHub Repository API
▸ Enables private repository cloning for SAST/SCA scans
▸ Use a fine-grained token with repository Contents: Read
securityWPScan API
▸ Adds WordPress core, plugin, and theme vulnerability data
▸ Token: wpscan.com/profile
keyVulnCheck API
▸ Extends KEV with VulnCheck data
▸ Sign up: vulncheck.com
▸ Provides exploit availability + KEV enrichment
local_fire_departmentNVD API Key
▸ Without key: 5 req / 30 sec (slow)
▸ With key: 50 req / 30 sec (10× faster)
▸ Free at nvd.nist.gov/developers/request-an-api-key
psychologyAttackerKB API
▸ Community CVE assessments from pentesters
▸ Free tier available at attackerkb.com
▸ Enriches CVE lookup with exploitability ratings
keyCIRCL VulnLookup API
▸ Enables authenticated queries on vulnerability.circl.lu
▸ Aggregates NVD, GHSA, CSAF, OSV, CISA KEV, EPSS
▸ Unlocks extended telemetry & bundle status
keyCVEFeed API
â–¸ Adds CVEFeed vulnerability, news, product, vendor, and CVEQL lookups
â–¸ PRO endpoints such as CWE, CAPEC, EPSS, and exploit intel require subscription access
â–¸ Used automatically during CVE enrichment when configured
keyCVEDetails API
â–¸ Adds CVEDetails CVE, CVSS, EPSS history, mentions, timeline, remediation, and product intelligence
â–¸ Supports OSV, threat-intel, inventory, tech-stack, SBOM, and alert endpoint forwarding
â–¸ Used automatically during CVE enrichment when configured
keyOpenRouter API
▸ Connects to ranked free frontier models: Qwen3 Coder, GPT-OSS 120B, Hermes 405B, Nemotron, Gemma, Laguna, Llama
▸ High-performance reasoning on cloud weights
▸ Get your key free at openrouter.ai
boltOpenCode Zen API
▸ Curated models: big-pickle, deepseek-v4-flash-free, mimo-v2.5-free
▸ Optimized for coding & security analysis
▸ Get your key at opencode.ai/auth
codeGitHub Models
▸ Enables GitHub-hosted AI models for analysis and remediation
▸ Create a token with GitHub Models access at github.com/settings/tokens
hubHugging Face
â–¸ Uses Hugging Face Inference Providers via router.huggingface.co/v1
â–¸ Works with supported chat-completion models in your free/provider quota
â–¸ Token needs Inference Providers permission
searchShodan API
▸ Queries Shodan to map external exposure & ports
▸ Saved key will initialize shodan CLI on Kali
shieldVirusTotal API
▸ Enriches target file and domain hashes in scans
▸ Queries malicious reputation telemetry
travel_exploreURLScan API
Enriches URLs/domains with crawl, screenshot, and page intelligence
Useful after web, phishing, OSINT, EASM, and malware URL scans
bug_reportJira Ticketing
assignmentServiceNow Incident Management
shareMISP Threat Intel Sharing
gpp_badAbuseIPDB API
▸ Checks IPs against community-reported abuse database
▸ Free at abuseipdb.com/account/api
radarSecurityTrails API
▸ Domain intelligence, DNS history, WHOIS, subdomains
▸ Free at securitytrails.com/app/account
phone_iphoneBeVigil API
Mobile app, domain, package, and exposed asset intelligence
Useful for EASM, appsec, OSINT, and brand exposure checks
publicNetlas API
Internet asset search, DNS, certs, and service fingerprints
Useful during external recon and attack surface expansion
visibilityZoomEye API
Cyberspace search for hosts, web apps, ports, and services
Useful for EASM, internet exposure, and technology discovery
hubProjectDiscovery API
Cloud-backed ProjectDiscovery workflows for nuclei/subfinder
Exported to Kali as PROJECTDISCOVERY_API_KEY and PDCP_API_KEY
scatter_plotProjectDiscovery Chaos
Subdomain and attack surface dataset from ProjectDiscovery
Useful when EASM subdomain enum says Chaos key missing
data_objectLeakIX API
Exposed services, leaks, misconfigurations, and internet risk
Useful after EASM, cloud, and external service discovery
manage_searchCensys API
Host, certificate, service, and exposure intelligence
Supports legacy ID/secret or Platform PAT + organization ID
orbitAlienVault OTX
▸ Open Threat Exchange — crowd-sourced threat intel
▸ Free API, no key required for basic lookups
bug_reportHybrid Analysis (Falcon Sandbox)
▸ Malware analysis sandbox — file/URL detonation
▸ Free tier at hybrid-analysis.com
▸ Search hashes, submit URLs, get verdicts + reports
cloudAWS Security Audit
▸ Uses IAM user with SecurityAudit + ReadOnlyAccess policies
cloudAzure Security Audit
▸ Register app in Azure AD with Security Reader role
cloudGCP Security Audit
▸ Create service account with Security Reviewer role
lockAPI Key Security
All API routes require X-Api-Key header. Include in every request.
▸ Set VULNSENTINEL_API_KEY env var to override
▸ Regenerating invalidates all existing sessions
▸ Store securely — this key controls all vulnerability data
Platform Status
Loading...

CAI & Reference Archive

Cybersecurity AI framework · 1,099 skills · 13 reference repositories · Intelligence source registry

Skills
--
Domains
--
Reference Repos
--
OSINT Sources
--
MITRE Mapped
--
CAI Models
300+
categorySkill Domains
Loading...
inventory_2Reference Repositories
Loading...
view_listSample Skills
Loading...
databaseIntelligence Source Registry
Loading...

OSINT Hub

Open-source intelligence — DNS · WHOIS · Shodan · AbuseIPDB · Subdomains · OSINTko Suite: Username · Email · Phone · Social · Image · sn0int

OSINT Output
[OSINT Hub] Enter a target and select modules to begin reconnaissance.
🔍 OSINTko SUITE — Running on Kali via SSH
manage_accounts Username Intelligence

Find accounts across 600+ platforms · Tools: Blackbird + UserFinder

[Blackbird / UserFinder] Ready — enter a username above.
alternate_email Email Intelligence

Breach & exposure lookup · Tools: Zehef + NoInfoga

[Zehef / NoInfoga] Ready — enter an email address above.
phone_iphone Phone Intelligence

Carrier · geolocation · social links · Tools: Phunter + Inspector + Findigo

[Phunter / Inspector / Findigo] Ready — enter a phone number above.
group Social Media Intelligence

Profile & footprint mapping · Tools: AliensEye + Masto + Osgint (GitHub)

[AliensEye / Masto / Osgint] Ready — enter a username above.
image_search Image Intelligence

Reverse image search + face recon · Tool: Eyes

[Eyes] Ready — enter an image path or URL above.
domain sn0int — Passive Domain Recon

CT logs · passive DNS · subdomain & email harvesting · Tool: sn0int

[sn0int] Ready — enter a domain above.

OSINT Mapping Tool

Interactive node-graph and map visualization for OSINT intelligence — entities, relationships, locations

Drag nodes to reposition. Click two nodes to connect them. 0 nodes 0 edges

Network Discovery

Map network hosts — ping sweep, ARP scan, TCP SYN discovery

Discovery Output
[Network Discovery] Enter a subnet and start discovery.
Discovered Hosts
IP Hostname MAC Vendor Status
No hosts discovered yet

Vulnerability Scanner

Nmap, Nikto, Nuclei, Masscan — scan targets for known vulnerabilities

Scan Output
IDLE
[Vuln Scanner] Configure target and scanner, then launch.

Web App Security

HTTP headers, SSL/TLS, CORS, cookies, directory listing audit

Audit Results
Enter a URL and click Run Audit

API Security

Fuzzing, SQLi, XSS testing for REST/GraphQL API endpoints

Test Results
[API Security] Configure endpoint and launch tests.

Social Engineering

Phishing simulation, pretexting, physical security testing

Generated Template
Select a scenario and click Generate Campaign

Password & Crypto

Hash identification, password strength, HIBP breach check, SSL testing

Results
Select a mode and enter a value to analyze.

Container Security

Trivy image scanning, Docker daemon audit, vulnerability assessment

Scan Results
Enter an image name and click Scan Image

Cloud Security

AWS, Azure, GCP misconfiguration audit — S3, IAM, security groups

Findings
Enter credentials and click Audit

Incident Response

IR case management, timeline analysis, AI-powered investigation

Active IR Cases
No active cases
Playbook Templates
Loading playbooks...
Case Timeline
No case selected
AI Analysis
Click AI Analyze to generate insights
Evidence Log
No evidence logged

Live Security Monitor

Real-time events from all 15 cybersecurity modules

DISCONNECTED
Event Stats
0
Total
0
Critical
0
Warnings
0
Info
Filter by Category
Severity
Module Activity
OSINT
Scanning
Web App
Network
Container
Cloud
Intel
IR
Live Event Feed
0 events/min
monitor Connect to the monitor stream to see live events...
CRITICAL

CVSS v3
--
CVSS v4
--
EPSS
--
EPSS %ile
--
AI Risk
--
Description
terminalDetection Logic & Evidence
Executable Command:
Detection Logic:
Evidence:
Affected Component
Target
Recommendation
smart_toy
AI Concierge
Cloud AI — deepseek-r1
AI Engine
VulnSentinel AI
Hello. I'm your AI security concierge powered by cloud AI. I can analyze findings, generate remediations, write reports, and control scans. What would you like to know?