AI Copilot

🤖 Analyst Copilot

AGENTS 🧪 Triage📡 Collection🧠 Analyst🎓 Trainer
8.8.8.8 evil.com Russia sources for GEOINT free apis for crypto assess ransomware threat what is ACH

Four agents, all local-first: Triage (IoC/country lookup), Collection (find the best free sources from 1,033), Analyst (assessment frames), Trainer (tradecraft). No data leaves the platform.

📡 Collection Agent — 14 sources

Tracks botnet C2 servers (Emotet, Dridex, QakBot, TrickBot); downloadable IP/port blocklists.
Blacklist of SSL certificate SHA1 fingerprints and JA3 hashes tied to malware/botnet C2.
Family-labelled IoC exchange.
Entity attribution & flow analysis.
BGP routing & network intelligence.
Carnegie Mellon insider-threat research corpus.
Univ. of Minnesota center's authoritative daily infectious-disease and biosecurity news with RSS feeds.
US-CERT indicator sharing / advisories.
Federal insider-threat guidance & indicators.
Daily dark-web and cybercrime threat-intel feed covering leaks, breaches and ransomware claims.
Public dashboard indexing ransomware leak-site victims and threat-actor activity (paid API tier).
Free OSINT IoC feeds (domains, IPs, URLs, hashes) in MISP, STIX and CSV.
ECDC NONE
European Centre for Disease Prevention and Control; downloadable EU/EEA surveillance datasets and threat repor
Global financial intelligence unit network.

Full filters in the Source Catalog.

Tip: add an apikey_openai or apikey_anthropic in settings (or an OPENAI_API_KEY/ANTHROPIC_API_KEY constant in config.php) to get an AI narrative on top of the local facts below.

Threat Actor Intelligence — OTHER ioc

Local statusNot currently in the indicator store
ACTIONS
Enrich nowAdd to case
PIVOTS
Full profile →OSINT pivot →Link analysis →Export STIX/MISP →
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php