↑↓ navigate↵ openesc close
Daily brief
Command & Control Infrastructure
locating…
C2 and scanner points are IP-level geolocation of infrastructure — approximate, and not
attack paths. Ransomware markers are country aggregates plotted at country centroids,
not host locations. No attack arcs are drawn because the feeds do not contain
attacker→target pairs. Night shading is the real solar terminator, computed
from the sun’s current position — the gradient is civil, nautical and
astronomical twilight. The wavefront sweeps only when map data is genuinely
re-fetched, and markers light as it passes them; it is a refresh indicator,
not a scan.
Top Countries
C2 hosts—
Threat Wire
—Tuning feeds…
Latest Exploited Vulnerabilities
—Establishing feed…
Actively Exploited Vulnerabilities
Establishing feed…
Ransomware Activity
Recently Disclosed Victims
from leak-site monitoringLoading…
Most Active Groups
—
Targeted Sectors
—
Live Malware Delivery
Checking feed…
Active Phishing Infrastructure
Suspicious Domains
defangedLoading…
Most Impersonated
—
Internet Attack Surface
Most-Targeted Ports
honeypot telemetryLoading…
Top Attacking Sources
defangedLoading…
Public Safety & OT
Sector watch
ransomware victims by sectorSectors most relevant to emergency services and critical infrastructure.
Counts are recently disclosed victims from leak-site monitoring, not incidents in your organisation.
ICS / OT Advisories
CISALoading advisories…
Protocol exposure
attacked ports in your worldLoading…
Defang / Refang
Make indicators safe to paste — or restore them
Converts between live and neutralised forms so an indicator can go into a
ticket, an email, or a chat channel without becoming a clickable link.
Handles dots, scheme (
http → hxxp), @
in addresses, and ://. Nothing is sent anywhere — this runs
in your browser and no request leaves the page.
Subnet / CIDR
Break down an address, or test membership
Enter an IPv4 address or CIDR block for a full breakdown — network and
broadcast addresses, usable range, mask, and RFC classification (private,
CGNAT, loopback, link-local, multicast, public). Enter two values
separated by a space or comma (
10.4.2.9 10.0.0.0/8) to test
whether the address falls inside the block.
Indicator Lookup
Check an IP, domain or file hash
Paste an IP address, domain, or file hash (MD5 / SHA256) and Sentinel checks it
against every indicator currently loaded — botnet C2 hosts, malware-delivery
URLs, phishing domains, top attacking sources, and malware payload hashes.
Currently checking against — loaded indicators.
This is not a full reputation service: a clean result means
“not in these feeds,” not “proven safe.”
Encoding & Hashing
Decode obfuscated strings, or hash a payload
Phishing URLs and malware delivery chains routinely hide their real target in
Base64 or percent-encoding. Paste the string and unwrap it.
On hashing: browsers expose SHA-1/256/384/512 through WebCrypto but
not MD5 — it was left out deliberately as broken. Sentinel will
recognise an MD5 you paste in (for lookups and pivots) but only
generates SHA-256. Everything here is computed locally.
Patch Triage
Prioritised remediation list
Every actively-exploited vulnerability, ranked for your organisation:
items touching your stack first, then by CVSS severity, then by how close the
CISA remediation deadline is. Each row carries the required action so the list
can be handed straight to whoever does the work.
Building list…
Bulk Indicator Check
Paste indicators
One indicator per line — IP, domain, or file hash (MD5 / SHA256).
Commas and spaces also work. Each is checked against
— loaded indicators: C2 hosts, malware URLs, phishing domains,
top attacking sources and malware payload hashes.
A clean result means “not in these feeds,” not “proven safe.”
Asset Check
Check your own domain
Enter a domain you control. Sentinel performs passive, non-intrusive checks — a normal
HTTPS request plus a DNS lookup — then reports reachability, TLS, security-header grade,
and cross-references your resolved IPs and hostname against every threat feed loaded here.
No port scanning or probing is performed, so this is safe to run against your own infrastructure.
Blocklist Export
Format live indicators for your controls
Reformats indicators already loaded on this page into the shapes
firewalls and DNS filters expect. This is transcription, not detection
logic — no rule is invented. Review before deploying: these
feeds are third-party and unvetted by you, blocking is disruptive when
wrong, and Sentinel makes no availability guarantee. Respect each feed's
terms when redistributing.
Keyboard Shortcuts
/
Focus the filter bar
1–7
Jump to a tab
R
Refresh all feeds
Esc
Clear filter / close detail