Ninja Signal RTFM
融 Fusion manual β†’
Read the manual

Ninja Signal β€” the complete user manual

Every screen, every control, and exactly how to use it. Signal is a real-time threat-intelligence platform: it ingests dozens of feeds, maps them into a knowledge graph, and gives you live visualisations, briefings, detections, and AI analysis. This manual walks the whole interface, top to bottom.

How Signal works

Signal has two faces. Signed-out, you get a set of fast public pages and free tools (a daily brief, an IOC lookup, a 3D threat galaxy, semantic search). Signed-in, the app becomes a full-screen windowed "analyst desktop": a left navigation rail, a live 3D globe wallpaper, and draggable, resizable floating windows.

The one thing to understand first: inside the console, navigation is window-based, not URL-based. Clicking a sidebar item opens a floating window on the desktop β€” the address bar stays at /. So typing /intel or /graph in the URL just shows the desktop; you reach those features by opening their window.

The fastest ways to get around

  • Sidebar (left rail) β€” every feature, grouped into collapsible sections (Core, Intelligence, Analysis, Detection, …). Click a name to open its window.
  • Command Palette β€” press ⌘K / Ctrl+K anywhere, type to fuzzy-find a window, CVE, or IOC, then Enter.
  • Constellation Launcher β€” press ` (backtick) for a full-screen star-map of every window grouped by section; click a star to open it.

New here? Start with creating an account (2-factor is required), then read The console desktop.

Create an account Public

/signup

Founding-member registration ("You're one of the original 100" β€” one free year, access to every ninja app). A progress bar shows how many spots remain; when the cohort is full it shows a sign-in link instead.

How to register

  1. Go to /signup and fill all four fields: name/handle, email, password (minimum 12 characters), and confirm password.
  2. Click Claim my founding spot.
  3. You're logged in immediately but the account is inactive until you set up two-factor β€” you're sent straight to MFA enrolment.

Set up two-factor (required) Public

/setup-mfa

Two-factor authentication is mandatory for every new account β€” you can't use the platform until it's enrolled.

  1. The page prepares an authenticator secret automatically.
  2. Scan the QR code with Google Authenticator, 1Password, or any TOTP app. Can't scan? Expand "Enter the key by hand" to copy the secret.
  3. Type the 6-digit code from your app and click Verify & finish.
  4. Save your backup codes β€” they're shown once. Click "I've saved them β€” enter the ecosystem" to land on the desktop.
Already have an account without MFA? A "Secure Your Account" prompt appears over the desktop offering Authenticator App or Email Codes β€” same flow, ending in backup codes.

Sign in Public

/login

Password sign-in, plus the 2-factor step when your account requires it. Live node/edge counts show at the bottom.

  1. Enter your username or email and password, click LOG IN.
  2. If MFA is set, the verification screen appears β€” type the 6–8 digit code from your authenticator app or email and click VERIFY. Email method offers Resend code; you can also use a backup code.
  3. On success you land on the console (or are returned to the ninja app that sent you β€” see SSO).

Links on this page: Request access (β†’ signup), Forgot username?, Forgot password?, plus no-signup escape hatches to Spektr and Threat Check.

Reset password & recover username Public

/reset
  1. At /reset, keep Password mode, enter your email, click SEND RESET LINK (or switch to Username mode for a username reminder).
  2. Open the email and click the link β€” it lands on /reset?token=….
  3. Enter and confirm a new password (minimum 8), click RESET PASSWORD, then BACK TO LOGIN.

Single sign-on across ninja apps

There's no SSO page β€” it's built into login. Sign in to Signal once; when you click into another trusted ninja app (Fusion, Raz0r, Nexus, Kin0bi, 1D, V0id, Social, War Room), you're returned automatically without re-entering credentials. Signal validates the return address against an allow-list of ecosystem hosts before redirecting, so the hand-off can't be hijacked to an untrusted site.

The console desktop Login

After sign-in, / renders the console: a left Sidebar, a 3D globe wallpaper with live threat arcs, a falling-hex "data river", and floating windows. Ambient signals surround your work:

Entropy baseline
The whole UI subtly "breathes" faster when global threat entropy is high; a peripheral edge-glow appears on high entropy.
Tickers
A scrolling News Ticker and Intel Ticker run along the bottom; a SITREP alert banner and risk traffic-lights flag current conditions.
Window links & minimap
Bezier lines connect related open windows; a minimap (bottom-right) shows all window positions.

Working with windows Login

Every feature opens as a floating window you can drag by its title bar and resize from its edges. Windows remember their size and position per browser and open in a staggered cascade.

Title-bar controls

Minimize
Drops the window to the taskbar.
Maximize / Restore
Fills the desktop, or returns to the previous size.
Pop out
Opens the window's content in its own browser tab (/popout/<id>) with a minimal title bar β€” handy for a second monitor.
Close
Closes the window.

The Window Taskbar along the bottom shows one button per open window (with a status dot) β€” click to focus, or click a minimized one to restore it. A live 24-hour clock sits at the right.

Command Palette Login

  1. Press ⌘K (Mac) or Ctrl+K anywhere in the console.
  2. Type into the box ("Search windows, CVEs, IOCs…") to fuzzy-match windows by title, id, or kanji.
  3. Use ↑/↓ to move, Enter to open, Esc to close.
If your text looks like an IOC (a CVE-…, an IP, or a long hash), a top action offers to search it in Spektr β€” one keystroke from "I have an indicator" to a full result.

Constellation Launcher Login

An alternative visual launcher. Press ` (backtick) for a full-screen star-map where every window is a star, grouped into constellations by section. Hover a star to see its name; open windows glow. Click a star to open it; Esc or ` to close.

Niko AI β€” the built-in analyst Login

A context-aware AI analyst docked at the bottom of the sidebar. Collapsed, it's a NIKO AI button that shows a red dot when new emergent signals stream in. Expanded, it's a chat pane titled with the window you're currently focused on β€” ask Niko about what you're looking at.

  1. Click NIKO AI to expand it.
  2. Type in the "θ³ͺ問… Ask Niko" box and press 送俑 (send) or Enter. Answers stream in.
  3. Conversation context is kept per window β€” each window has its own thread, so Niko's answers track what you're doing.

COMMS β€” team chat Login

A real-time human team chat (distinct from Niko), bottom-right, shown when signed in. Collapsed it's a COMMS pill with an unread badge; expanded it shows a live message list and a "Message…" box (500-char max, Enter to send). Your identity and role come from your verified session β€” you can't post as someone else; admins appear in red.

Threat Intelligence Login

Sidebar β†’ Intel (window)

Search the threat graph for any entity β€” CVE, technique, actor, malware, campaign β€” and generate an AI-written intelligence report about it, with a live "graph context" of connected nodes and a follow-up chat.

  1. Type an entity into "Search CVE, technique, threat actor…" (e.g. APT29, CVE-2024-3400, T1059, Cobalt Strike) and click Search.
  2. Click a result row β€” a full AI report generates on the right (a 30–60s analysis).
  3. Expand GRAPH CONTEXT to see connected entities grouped by relationship, each with label, CVSS, description and confidence.
  4. Ask follow-ups in "Ask a follow-up question…", or click a suggested question chip, to interrogate the report.
Arriving from a click on the globe's arcs auto-runs the search (a "Drill-in from Globe" banner appears).

Graph Explorer Login

Sidebar β†’ Graph Explorer (window)

Run read-only Cypher queries directly against the Neo4j threat graph and view results as a table with clickable entity names.

  1. Click a Quick Query (All Threat Actors, Actor β†’ Technique, KEV Vulnerabilities, Top Connected Nodes, Campaigns, Software ↔ Technique) to run an example instantly β€” or type your own Cypher.
  2. Set the Limit (1–1000, default 100) and click Run Query (or Ctrl+Enter).
  3. In the results table, double-click any entity name to open its neighbourhood in the Explorer + Spektr, or Ctrl+double-click to send it to Intel.

Queries are validated server-side and are strictly read-only.

Graph Database (raw Neo4j) Login

Sidebar β†’ Graph DB (window)

Connection details for opening the raw Neo4j Browser, with copyable credentials for two roles (Admin β€” full access; Viewer β€” read only).

  1. Pick the Admin or Viewer card and click Open Neo4j Browser (new tab).
  2. Paste the Bolt URI, then the Username and Password (use Show to reveal, Copy to copy).
  3. Run a query such as MATCH (n:ThreatActor) RETURN n.name LIMIT 10.
Neo4j Community Edition doesn't enforce role separation, so for guaranteed read-only access prefer the server-validated Graph Explorer.

ML Insights Login

Sidebar β†’ ML Insights (window) Β· also /ml

Machine-learning analysis over the graph across 20 tabs. Each tab opens with a plain-language explainer; a footer shows whether the result was cached or freshly computed; almost every entity name is click-to-drill.

Global controls

Run Full Analysis recomputes the models; Clear Cache forces a fresh compute of the current tab.

The 20 tabs

  • Overview β€” headline stats, emergent top-10, active countries, targeted sectors, predicted links, clusters.
  • Risk Scores β€” nodes ranked by propagated risk with contributing factors.
  • Communities β€” Louvain groups; double-click a card for a drill-down modal.
  • Centrality β€” top nodes by Degree / Betweenness / PageRank.
  • Link Predictions β€” Adamic-Adar or Katz (multi-hop) predicted relationships with scores and paths.
  • Similarity β€” search a node to find cosine-similar entities.
  • Anomalies β€” degree / bridge / temporal structural anomalies.
  • Attack Paths β€” pick From/To node types + max hops β†’ ranked paths with per-hop risk.
  • Trends β€” activity velocity, trending techniques, emerging actors.
  • Changepoints β€” surges, drops, inflection points over time.
  • Simulator β€” select mitigations/techniques/software to "remove" β†’ modelled risk reduction.
  • CVE Priority β€” a ranked patch queue with reasons.
  • KEV Predictor β€” exploitation-probability model with accuracy vs baseline and feature importances.
  • Verified Predictions β€” save predictions, verify later, track hit-rate over time.
  • Actor Clusters β€” attribution clusters by shared TTPs/software.
  • MetaPath β€” relation-aware similarity search.
  • Hierarchical β€” multi-resolution communities; drill sub-communities.
  • Activity Forecast β€” Hawkes-process "predicted next / overdue" per entity.
  • Graph Neural Net β€” GCN/GAT node classification, predicted vs actual.
  • Emergent Signals β€” scan for strategic shifts; expandable signal cards with impact and recommended actions.

The Community Drill-Down modal (from Communities/Hierarchical) offers sub-tabs: Graph (with Export PNG), Members, Mitigations, Cypher (copyable reproducible query), and Report (generate an AI community report and ask follow-ups).

Administration & Settings Admin + all

Sidebar β†’ Admin (window)

The window is titled Administration for admins and Settings for everyone else. Non-admins see only the Security tab; all admin tabs are enforced admin-only on the server. Tabs: Users, IDAM, Health Check, Password, Security, Audit Log.

Common tasks

Approve a signup (Users)
Click APPROVE (or REJECT) in "Pending Approvals". Add operators directly with username/password/role, or delete users with an inline confirm.
Grant app access (IDAM)
A per-user grid with a checkbox per app (Signal, Fusion, Nexus, Kin0bi, 1D, V0id, V01d, Raz0r, ANTOS) and document (Exec, M&A, Diary). Tick to grant (saves immediately), or use per-row ALL / NONE. Filter by ALL / PENDING / APPROVED.
Check platform health (Health Check)
REFRESH (auto every 60s) shows every API endpoint with a status dot, latency, HTTP code, and errors; summary OK/SLOW/ERROR counts.
Reset a password (Password)
Pick a user, enter a new password twice (min 8), CHANGE PASSWORD.
Manage your 2FA (Security β€” all users)
Enable an authenticator (scan QR β†’ verify β†’ save backup codes) or email codes; disable MFA by confirming a current code. Backup-codes-remaining turns amber at ≀2.
Investigate logins (Audit Log)
Stat cards (total, last 24h, failed logins 24h, unique users 24h) plus a filterable event table (by event type and username), auto-refreshing every 30s, with LOAD MORE paging.

LLM burn rate Login

/burn

An internal spend dashboard for the estate's AI usage β€” forward run-rate, projections, and breakdowns by app, feature, and model.

  1. Pick a window (7d / 30d / 90d); read the Run rate ($/day) and Projected monthly tiles first, then the breakdown tables.
  2. Watch Cache hit ratio and any amber caching warning.
  3. To pull fresh threat intel, click Collect only (free) or, as an admin, Run with Claude (paid), then refresh.

DEFCON β€” daily threat brief Public

/defcon Β· /defcon/<date> Β· /defcon/archive

A free, public, one-page brief naming the single most important threat today (ranked from CISA KEV, EPSS, CVSS and ubiquity), published 07:15 UK daily. No signup.

  1. Open /defcon to jump to today's edition (a dated permalink).
  2. Read TODAY (the headline), then THE THREE for prioritized actions, and TRAVERSAL + NUMBERS for context.
  3. Share via LinkedIn / X / Copy post text, or subscribe with your email (Get DEFCON). Browse past briefs via Archive or subscribe to RSS.

Threat Check β€” free IOC lookup Public

/threat-check Β· /threat-check/<ioc>

Paste an IP, domain, hash, CVE, or actor name and get a threat assessment β€” no account needed.

  1. Type or paste an indicator (or click an example / recent chip) and press CHECK.
  2. Read the verdict: a Found result shows a 0–100 threat-score gauge, timeline, description, CVSS (for CVEs), properties, related actors/campaigns/techniques, and graph connections. Not Found is framed as good news with a deep-search offer; rate-limit/errors are shown plainly.
  3. Click any related entity or connection to pivot β€” the URL updates to /threat-check/<ioc>, so results are shareable. Use SHARE (Copy Link / Markdown / X / cURL) or open the result in Spektr / Galaxy.

Spektr β€” semantic search Public

/spektr Β· /spektr?q=… (also a console window)

A Google-style search over the whole threat graph (hundreds of thousands of entities).

  1. Type into "Search threat actors, CVEs, malware, techniques…" β€” or click a starter chip (Russian APT groups, ransomware double extortion, …).
  2. Choose a MODE β€” KEYWORD, SEMANTIC, or HYBRID (default) β€” which re-runs instantly. Narrow with the entity-type chips (ThreatActor, Vulnerability, Software, Technique, Indicator, Campaign, Infrastructure, Mitigation), then re-submit to apply.
  3. Click a result for a detail panel: description, AI RESEARCH (open the query in Claude or Gemini), properties, and relationships you can click to traverse the graph. View in Signal β†— opens the full console.

Threat Theatre β€” 3D galaxy Public

/theatre

An immersive real-time 3D "galaxy" of the threat graph, built for a SOC wall. Nodes are coloured by recency (red 0–6h β†’ grey >7d).

Fly & camera

WASD fly Β· Q/Space up Β· E/Shift down Β· scroll zoom Β· left-drag rotate Β· right-drag pan. It auto-rotates when idle.

  1. Use the Find box (or press /) to fly to a node by name β€” it pulses and, if outside the sample, searches the full graph.
  2. Hover a node for a tooltip; click for a detail panel with EXPLORE (isolate its neighbour tree) and INVESTIGATE (opens Spektr).
  3. Cycle the Edges toggle (off β†’ proximity β†’ all); scrub the Timeline (play/pause, or click a 6-hour bucket) to recolour the galaxy for that window; LIVE resets.

SUBTEXT// β€” discourse analyser Public

/subtext

Paste online text and get an AI "forensic" read of its hidden agenda and manipulation signals.

  1. Paste content into the evidence box (or load a sample: Concerned Parent / Industry Defender / Wellness Influencer); optionally add platform, author handle, and timestamp. Minimum 20 characters.
  2. Click ⚑ Initiate Forensic Scan.
  3. Read the Dashboard (verdict, Subtext Score /100, six-dimension grid, inferred author profile, red flags), then drill into the Forensic Report per dimension (with a charitable counter-reading). EXPORT downloads a .txt report.

Marketing & information pages Public

/welcome β€” landing
The signed-out home. Live graph counts, an inline Threat-Check box, today's DEFCON card, trending IOCs, a features grid, and links into the platform.
/overview β€” the 30-second view
A single scrolling page for execs/investors with an embedded live Threat Theatre and a sample attacker fingerprint.
/pricing β€” pricing
Three tiers: DEFCON (free), Signal Team (Β£1,200/mo β€” API, 10 seats + SSO, custom feeds, SLA), Enterprise (self-hosted, contact us).
/trust β€” trust & data handling
A procurement reference: region (Hetzner Finland, EEA-only), key custody, retention, incident contact, sub-processors, GDPR compliance.
/demo β€” book a demo
Request a 30-minute Google Meet walkthrough β€” enter work email, company, and a preferred time.
/access β€” the vault gate
Where signed-out users land when they hit a gated page: create an account, sign in, or request enterprise/researcher access, plus links to the free tools.
/signalhld β€” Signal design doc
The long-form Signal High-Level Design (architecture, data model, feeds, graph schema, ML engine, security) with Mermaid diagrams.
/hld β€” ANTOS design doc
The ANTOS DevSecOps-pipeline design document (a sibling system), read-only with rendered diagrams.

Full window catalog Login

Every window available from the sidebar, by section. Open any of them from the Sidebar, the Command Palette (⌘K), or the Constellation Launcher (`).

Autonomous

  • SHOGUN β€” autonomous threat commander that orchestrates all windows.

Core

  • Dashboard β€” system overview: node counts, risk scores, feed status.
  • AIP / AIP Logic β€” natural-language graph queries and multi-step reasoning chains.
  • Threat Theatre β€” the 3D temporal visualizer (see above).
  • SITREP β€” situation-report generator (IIR / INTREP / Executive).
  • CISO Briefing β€” auto-generated executive threat briefing.
  • Ops Center β€” health, latency, queue depth.
  • PIM / PAM β€” privileged access & identity monitor.
  • KIZUNA β€” cross-ecosystem relationship intelligence.
  • Help β€” in-app user guide.

Intelligence

  • Intel, Spektr β€” see the sections above.
  • Intel Mesh β€” cross-app intelligence over the NATS event bus.
  • APT Sightings β€” sighting heatmap by actor and region.
  • Threat Drops β€” live feed from every ingester.
  • CTI Extract β€” paste raw CTI text β†’ auto-extract entities into the graph.
  • Investigations β€” case management.
  • MONOGATARI β€” narrative intelligence storytelling.

Analysis

  • Adversary DNA β€” 18-dimension behavioural fingerprinting.
  • ORIGAMI β€” multi-source actor attribution.
  • Causal Analysis β€” DoWhy causal inference / what-if modelling.
  • Strategic Forecast, TTP Trends, Phylogeny, Contagion β€” landscape forecasting, TTP adoption, actor lineage, malware spread simulation.
  • Threat Diff / Time Machine β€” compare or rewind graph snapshots over time.
  • Hex Heatmap β€” H3 geospatial heatmap of threat origins.
  • Explainable Risk, Graph Anomalies, Attack Probability, Entity Resolution, Quiver, YOGEN β€” score explanations, structural anomalies, path likelihood, duplicate merging, signal correlation, predictive forecasting.

Detection

  • KQL Rules β€” generate Microsoft Sentinel detection rules from the graph.
  • Threat Hunting, Emulation, raZ0r (SIEM), D3FEND Gaps β€” hunting workbench, ATT&CK replay, EDR correlation, coverage-gap analysis.
  • Ransomware, Supply Chain, Gator, KENJUTSU, HIBANA β€” ransomware tracker, dependency risk, alert triage, surgical response, early-warning signals.

Response

  • SOAR Engine (automated playbooks), Attack Surface (external discovery), Behavioral Auth (biometric analytics).

Data

  • Graph Explorer, Graph DB β€” see the sections above.
  • Explorer, Data Lab, Workbench, Code Workbook β€” browse nodes by label, SQL/Cypher notebooks, an analyst scratch-pad with evidence pinning.
  • Digital Twins, Merkle Graph, Connector, Pipelines β€” actor simulation, integrity proofs, data-source config, a visual pipeline builder.

Foundry

  • Workshop (analysis environment), Contour (statistical charting).

Feeds

  • Hot C2Β² / Hot Phish Tank β€” live C2 and phishing trackers.
  • Traffic (Caddy log analytics), AML Intel, Darknet, Patent Intel, Pharma Intel, Geopolitical β€” sector and OSINT feeds.
  • Ingestion Monitor β€” status/counts/errors for every ingester run.

Advanced & Experimental

  • ML Insights (see above), Federated TI, Org Twin, Causal RL, Cascade, Dashboards (drag-and-drop builder).
  • Neuromorphic, LLM Agents, Temporal GAT, Encrypted IOC, Explainable/Streaming GNN β€” research-grade models.
  • INFO THEORY, TDA, NEURO-SYM, CROSS-MODAL, DIFFUSION β€” entropy/surprise scoring, topological gap analysis, symbolic validation, unified cross-modal search, generative scenario synthesis.