S
SENTINEL
Threat Intelligence Console
0 kev 0 ransom 0 c2
mikeshelby.com
Threat Posture
Derived indicator, not an official threat level. Computed from: new KEV entries (7d), ransomware victims (7d), online C2 nodes, and live malware URLs — each scored against a rolling baseline.
CONNECTING
--:--:-- UTC
Intercept acquiring…
Exploited CVE Ransomware C2 Malware URL Phishing Wire

Daily brief

My stack
Saved in this browser only — not synced across devices.

Command & Control Infrastructure

locating…
C2 and scanner points are IP-level geolocation of infrastructure — approximate, and not attack paths. Ransomware markers are country aggregates plotted at country centroids, not host locations. No attack arcs are drawn because the feeds do not contain attacker→target pairs. Night shading is the real solar terminator, computed from the sun’s current position — the gradient is civil, nautical and astronomical twilight. The wavefront sweeps only when map data is genuinely re-fetched, and markers light as it passes them; it is a refresh indicator, not a scan.

Top Countries

C2 hosts

Threat Wire

Tuning feeds…

Latest Exploited Vulnerabilities

Establishing feed…

Actively Exploited Vulnerabilities

Establishing feed…

Ransomware Activity

Recently Disclosed Victims

from leak-site monitoring
Loading…

Most Active Groups

Targeted Sectors

Live Malware Delivery

Checking feed…

Active Phishing Infrastructure

Suspicious Domains

defanged
Loading…

Most Impersonated

Internet Attack Surface

Most-Targeted Ports

honeypot telemetry
Loading…

Top Attacking Sources

defanged
Loading…

Public Safety & OT

Sector watch

ransomware victims by sector
Sectors most relevant to emergency services and critical infrastructure. Counts are recently disclosed victims from leak-site monitoring, not incidents in your organisation.

ICS / OT Advisories

CISA
Loading advisories…

Protocol exposure

attacked ports in your world
Loading…

Defang / Refang

runs entirely in your browser

Make indicators safe to paste — or restore them

Converts between live and neutralised forms so an indicator can go into a ticket, an email, or a chat channel without becoming a clickable link. Handles dots, scheme (httphxxp), @ in addresses, and ://. Nothing is sent anywhere — this runs in your browser and no request leaves the page.

Subnet / CIDR

local calculation

Break down an address, or test membership

Enter an IPv4 address or CIDR block for a full breakdown — network and broadcast addresses, usable range, mask, and RFC classification (private, CGNAT, loopback, link-local, multicast, public). Enter two values separated by a space or comma (10.4.2.9 10.0.0.0/8) to test whether the address falls inside the block.

Indicator Lookup

checked against loaded feeds

Check an IP, domain or file hash

Paste an IP address, domain, or file hash (MD5 / SHA256) and Sentinel checks it against every indicator currently loaded — botnet C2 hosts, malware-delivery URLs, phishing domains, top attacking sources, and malware payload hashes. Currently checking against loaded indicators. This is not a full reputation service: a clean result means “not in these feeds,” not “proven safe.”

Encoding & Hashing

WebCrypto · local only

Decode obfuscated strings, or hash a payload

Phishing URLs and malware delivery chains routinely hide their real target in Base64 or percent-encoding. Paste the string and unwrap it. On hashing: browsers expose SHA-1/256/384/512 through WebCrypto but not MD5 — it was left out deliberately as broken. Sentinel will recognise an MD5 you paste in (for lookups and pivots) but only generates SHA-256. Everything here is computed locally.

Patch Triage

Prioritised remediation list

Every actively-exploited vulnerability, ranked for your organisation: items touching your stack first, then by CVSS severity, then by how close the CISA remediation deadline is. Each row carries the required action so the list can be handed straight to whoever does the work.
Building list…

Bulk Indicator Check

up to 100 at once

Paste indicators

One indicator per line — IP, domain, or file hash (MD5 / SHA256). Commas and spaces also work. Each is checked against loaded indicators: C2 hosts, malware URLs, phishing domains, top attacking sources and malware payload hashes. A clean result means “not in these feeds,” not “proven safe.”

Asset Check

monitor a domain you own

Check your own domain

Enter a domain you control. Sentinel performs passive, non-intrusive checks — a normal HTTPS request plus a DNS lookup — then reports reachability, TLS, security-header grade, and cross-references your resolved IPs and hostname against every threat feed loaded here. No port scanning or probing is performed, so this is safe to run against your own infrastructure.

Blocklist Export

from loaded feeds

Format live indicators for your controls

Reformats indicators already loaded on this page into the shapes firewalls and DNS filters expect. This is transcription, not detection logic — no rule is invented. Review before deploying: these feeds are third-party and unvetted by you, blocking is disruptive when wrong, and Sentinel makes no availability guarantee. Respect each feed's terms when redistributing.

Keyboard Shortcuts

/
Focus the filter bar
1–7
Jump to a tab
R
Refresh all feeds
Esc
Clear filter / close detail