About Threat Sentinel
Public OSINT dashboard for IT administrators, SOC analysts, incident responders and security consultants. Aggregates ransomware activity, known exploited vulnerabilities, critical CVEs, security news and practical incident response resources — updated daily from public sources.
Coverage
Situation Report
The last 24 hours across every source on this site, written out in German and English each morning — and machine-checked against those sources before it is published.
Ransomware
Active campaigns, recent victim disclosures and threat actor activity aggregated from public sources.
CISA KEV
Vulnerabilities confirmed to be actively exploited — the most direct remediation priority signal available.
Critical CVEs
Critical and high severity CVEs from NIST NVD, enriched with EPSS exploitation probability and CISA KEV status — severity, likelihood and confirmed exploitation in one view, and per entry the affected products with the version that fixes them.
Security News
Selected from eight public security feeds — breach reports, advisories and relevant analysis.
Threat Research
Long-form intrusion analyses and threat actor research from The DFIR Report, Unit 42, Talos, Red Canary, Huntress and Microsoft.
Indicator Lookup
Paste an IP, domain, URL, hash or CVE and jump straight to VirusTotal, urlscan, Shodan, crt.sh and a dozen more — defanged input understood.
Resources
Curated tools, references and frameworks for threat analysis, detection and incident response.
IR Playbooks
Structured response guides for ransomware, phishing, data breach and identity compromise — in English and German.
Data & scope
All data is aggregated from publicly available sources: ransomware.live, the CISA Known Exploited Vulnerabilities Catalog, the NIST National Vulnerability Database, the FIRST EPSS exploit prediction model and selected public security news feeds. Threat Sentinel provides a consolidated daily view — not proprietary threat intelligence.
One page is written rather than aggregated. The daily situation report is produced each morning by a language model, from a snapshot of exactly the sources above and nothing else — no web access, no memory of yesterday, no training-data recall. The result is then checked mechanically against that snapshot: every CVE identifier, every figure and every link in the text must appear in the collected data, and a CVSS or EPSS value must belong to the vulnerability it is quoted beside. If any claim fails, the model is given the failures and rewrites; after three attempts the run is abandoned and the previous day's report stays up. A day without a report is a smaller problem than a report with an invented CVE number in it.
Data sources
18 in totalEverything Threat Sentinel displays comes from the sources below. All of them are public; none of them are paid, licensed or private. This list is generated from the same definitions the loaders use, so it cannot fall behind the site.
Vulnerability and incident data
4 sourcesQueried as JSON APIs. Every request is made server side by the proxy, never by your browser — see the privacy notice.
| Source | Provides |
|---|---|
| ransomware.live | Ransomware victim disclosures and threat actor group profiles |
| CISA Known Exploited Vulnerabilities Catalog | Vulnerabilities confirmed to be exploited in the wild, with due dates |
| NIST National Vulnerability Database | CVE records, CVSS base scores and CPE configuration data |
| FIRST EPSS | Daily probability that a given CVE will be exploited in the next 30 days |
Security news feeds
8 sourcesPublic RSS and Atom feeds. Headlines link to the original publisher; no article text is reproduced.
| Source | Provides |
|---|---|
| Krebs on Security | RSS / Atom feed |
| The Hacker News | RSS / Atom feed |
| Bleeping Computer | RSS / Atom feed |
| BSI / CERT-Bund | RSS / Atom feed |
| CISA | RSS / Atom feed |
| SANS ISC | RSS / Atom feed |
| Heise Security | RSS / Atom feed |
| Sophos News | RSS / Atom feed |
Threat research feeds
6 sourcesLong-form intrusion analysis and threat actor research. Same handling as the news feeds.
| Source | Provides |
|---|---|
| The DFIR Report | RSS / Atom feed |
| Unit 42 | RSS / Atom feed |
| Cisco Talos | RSS / Atom feed |
| Red Canary | RSS / Atom feed |
| Huntress | RSS / Atom feed |
| Microsoft Security | RSS / Atom feed |
For situational awareness, operational triage and incident readiness. Not a replacement for internal risk assessment, vulnerability management, legal review, forensic investigation or organization-specific incident response planning.