About Threat Sentinel
Public OSINT dashboard for IT administrators, SOC analysts, incident responders and security consultants. Aggregates ransomware activity, known exploited vulnerabilities, critical CVEs, security news and practical incident response resources — updated daily from public sources.
Coverage
Ransomware
Active campaigns, recent victim disclosures and threat actor activity aggregated from public sources.
CISA KEV
Vulnerabilities confirmed to be actively exploited — the most direct remediation priority signal available.
Critical CVEs
Critical and high severity CVEs from NIST NVD, enriched with EPSS exploitation probability and CISA KEV status — severity, likelihood and confirmed exploitation in one view.
Security News
Selected from eight public security feeds — breach reports, advisories and relevant analysis.
Threat Research
Long-form intrusion analyses and threat actor research from The DFIR Report, Unit 42, Talos, Red Canary, Huntress and Microsoft.
Indicator Lookup
Paste an IP, domain, URL, hash or CVE and jump straight to VirusTotal, urlscan, Shodan, crt.sh and a dozen more — defanged input understood.
Resources
Curated tools, references and frameworks for threat analysis, detection and incident response.
IR Playbooks
Structured response guides for ransomware, phishing, data breach and identity compromise — in English and German.
Data & scope
All data is aggregated from publicly available sources: ransomware.live, the CISA Known Exploited Vulnerabilities Catalog, the NIST National Vulnerability Database, the FIRST EPSS exploit prediction model and selected public security news feeds. Threat Sentinel provides a consolidated daily view — not proprietary threat intelligence.
Data sources
18 in totalEverything Threat Sentinel displays comes from the sources below. All of them are public; none of them are paid, licensed or private. This list is generated from the same definitions the loaders use, so it cannot fall behind the site.
Vulnerability and incident data
4 sourcesQueried as JSON APIs. Every request is made server side by the proxy, never by your browser — see the privacy notice.
| Source | Provides |
|---|---|
| ransomware.live | Ransomware victim disclosures and threat actor group profiles |
| CISA Known Exploited Vulnerabilities Catalog | Vulnerabilities confirmed to be exploited in the wild, with due dates |
| NIST National Vulnerability Database | CVE records, CVSS base scores and CPE configuration data |
| FIRST EPSS | Daily probability that a given CVE will be exploited in the next 30 days |
Security news feeds
8 sourcesPublic RSS and Atom feeds. Headlines link to the original publisher; no article text is reproduced.
| Source | Provides |
|---|---|
| Krebs on Security | RSS / Atom feed |
| The Hacker News | RSS / Atom feed |
| Bleeping Computer | RSS / Atom feed |
| BSI / CERT-Bund | RSS / Atom feed |
| CISA | RSS / Atom feed |
| SANS ISC | RSS / Atom feed |
| Heise Security | RSS / Atom feed |
| Sophos News | RSS / Atom feed |
Threat research feeds
6 sourcesLong-form intrusion analysis and threat actor research. Same handling as the news feeds.
| Source | Provides |
|---|---|
| The DFIR Report | RSS / Atom feed |
| Unit 42 | RSS / Atom feed |
| Cisco Talos | RSS / Atom feed |
| Red Canary | RSS / Atom feed |
| Huntress | RSS / Atom feed |
| Microsoft Security | RSS / Atom feed |
For situational awareness, operational triage and incident readiness. Not a replacement for internal risk assessment, vulnerability management, legal review, forensic investigation or organization-specific incident response planning.