Ninja Signal β the complete user manual
Every screen, every control, and exactly how to use it. Signal is a real-time threat-intelligence platform: it ingests dozens of feeds, maps them into a knowledge graph, and gives you live visualisations, briefings, detections, and AI analysis. This manual walks the whole interface, top to bottom.
How Signal works
Signal has two faces. Signed-out, you get a set of fast public pages and free tools (a daily brief, an IOC lookup, a 3D threat galaxy, semantic search). Signed-in, the app becomes a full-screen windowed "analyst desktop": a left navigation rail, a live 3D globe wallpaper, and draggable, resizable floating windows.
/. So typing /intel or /graph in the URL just shows the desktop; you reach those features by opening their window.The fastest ways to get around
- Sidebar (left rail) β every feature, grouped into collapsible sections (Core, Intelligence, Analysis, Detection, β¦). Click a name to open its window.
- Command Palette β press βK / Ctrl+K anywhere, type to fuzzy-find a window, CVE, or IOC, then Enter.
- Constellation Launcher β press ` (backtick) for a full-screen star-map of every window grouped by section; click a star to open it.
New here? Start with creating an account (2-factor is required), then read The console desktop.
Create an account Public
Founding-member registration ("You're one of the original 100" β one free year, access to every ninja app). A progress bar shows how many spots remain; when the cohort is full it shows a sign-in link instead.
How to register
- Go to
/signupand fill all four fields: name/handle, email, password (minimum 12 characters), and confirm password. - Click Claim my founding spot.
- You're logged in immediately but the account is inactive until you set up two-factor β you're sent straight to MFA enrolment.
Set up two-factor (required) Public
Two-factor authentication is mandatory for every new account β you can't use the platform until it's enrolled.
- The page prepares an authenticator secret automatically.
- Scan the QR code with Google Authenticator, 1Password, or any TOTP app. Can't scan? Expand "Enter the key by hand" to copy the secret.
- Type the 6-digit code from your app and click Verify & finish.
- Save your backup codes β they're shown once. Click "I've saved them β enter the ecosystem" to land on the desktop.
Sign in Public
Password sign-in, plus the 2-factor step when your account requires it. Live node/edge counts show at the bottom.
- Enter your username or email and password, click LOG IN.
- If MFA is set, the verification screen appears β type the 6β8 digit code from your authenticator app or email and click VERIFY. Email method offers Resend code; you can also use a backup code.
- On success you land on the console (or are returned to the ninja app that sent you β see SSO).
Links on this page: Request access (β signup), Forgot username?, Forgot password?, plus no-signup escape hatches to Spektr and Threat Check.
Reset password & recover username Public
- At
/reset, keep Password mode, enter your email, click SEND RESET LINK (or switch to Username mode for a username reminder). - Open the email and click the link β it lands on
/reset?token=β¦. - Enter and confirm a new password (minimum 8), click RESET PASSWORD, then BACK TO LOGIN.
Single sign-on across ninja apps
There's no SSO page β it's built into login. Sign in to Signal once; when you click into another trusted ninja app (Fusion, Raz0r, Nexus, Kin0bi, 1D, V0id, Social, War Room), you're returned automatically without re-entering credentials. Signal validates the return address against an allow-list of ecosystem hosts before redirecting, so the hand-off can't be hijacked to an untrusted site.
The console desktop Login
After sign-in, / renders the console: a left Sidebar, a 3D globe wallpaper with live threat arcs, a falling-hex "data river", and floating windows. Ambient signals surround your work:
- Entropy baseline
- The whole UI subtly "breathes" faster when global threat entropy is high; a peripheral edge-glow appears on high entropy.
- Tickers
- A scrolling News Ticker and Intel Ticker run along the bottom; a SITREP alert banner and risk traffic-lights flag current conditions.
- Window links & minimap
- Bezier lines connect related open windows; a minimap (bottom-right) shows all window positions.
Working with windows Login
Every feature opens as a floating window you can drag by its title bar and resize from its edges. Windows remember their size and position per browser and open in a staggered cascade.
Title-bar controls
- Minimize
- Drops the window to the taskbar.
- Maximize / Restore
- Fills the desktop, or returns to the previous size.
- Pop out
- Opens the window's content in its own browser tab (
/popout/<id>) with a minimal title bar β handy for a second monitor. - Close
- Closes the window.
The Window Taskbar along the bottom shows one button per open window (with a status dot) β click to focus, or click a minimized one to restore it. A live 24-hour clock sits at the right.
Command Palette Login
- Press βK (Mac) or Ctrl+K anywhere in the console.
- Type into the box ("Search windows, CVEs, IOCsβ¦") to fuzzy-match windows by title, id, or kanji.
- Use β/β to move, Enter to open, Esc to close.
Constellation Launcher Login
An alternative visual launcher. Press ` (backtick) for a full-screen star-map where every window is a star, grouped into constellations by section. Hover a star to see its name; open windows glow. Click a star to open it; Esc or ` to close.
Niko AI β the built-in analyst Login
A context-aware AI analyst docked at the bottom of the sidebar. Collapsed, it's a NIKO AI button that shows a red dot when new emergent signals stream in. Expanded, it's a chat pane titled with the window you're currently focused on β ask Niko about what you're looking at.
- Click NIKO AI to expand it.
- Type in the "θ³ͺεβ¦ Ask Niko" box and press ιδΏ‘ (send) or Enter. Answers stream in.
- Conversation context is kept per window β each window has its own thread, so Niko's answers track what you're doing.
COMMS β team chat Login
A real-time human team chat (distinct from Niko), bottom-right, shown when signed in. Collapsed it's a COMMS pill with an unread badge; expanded it shows a live message list and a "Messageβ¦" box (500-char max, Enter to send). Your identity and role come from your verified session β you can't post as someone else; admins appear in red.
Threat Intelligence Login
Search the threat graph for any entity β CVE, technique, actor, malware, campaign β and generate an AI-written intelligence report about it, with a live "graph context" of connected nodes and a follow-up chat.
- Type an entity into "Search CVE, technique, threat actorβ¦" (e.g.
APT29,CVE-2024-3400,T1059,Cobalt Strike) and click Search. - Click a result row β a full AI report generates on the right (a 30β60s analysis).
- Expand GRAPH CONTEXT to see connected entities grouped by relationship, each with label, CVSS, description and confidence.
- Ask follow-ups in "Ask a follow-up questionβ¦", or click a suggested question chip, to interrogate the report.
Graph Explorer Login
Run read-only Cypher queries directly against the Neo4j threat graph and view results as a table with clickable entity names.
- Click a Quick Query (All Threat Actors, Actor β Technique, KEV Vulnerabilities, Top Connected Nodes, Campaigns, Software β Technique) to run an example instantly β or type your own Cypher.
- Set the Limit (1β1000, default 100) and click Run Query (or Ctrl+Enter).
- In the results table, double-click any entity name to open its neighbourhood in the Explorer + Spektr, or Ctrl+double-click to send it to Intel.
Queries are validated server-side and are strictly read-only.
Graph Database (raw Neo4j) Login
Connection details for opening the raw Neo4j Browser, with copyable credentials for two roles (Admin β full access; Viewer β read only).
- Pick the Admin or Viewer card and click Open Neo4j Browser (new tab).
- Paste the Bolt URI, then the Username and Password (use Show to reveal, Copy to copy).
- Run a query such as
MATCH (n:ThreatActor) RETURN n.name LIMIT 10.
ML Insights Login
Machine-learning analysis over the graph across 20 tabs. Each tab opens with a plain-language explainer; a footer shows whether the result was cached or freshly computed; almost every entity name is click-to-drill.
Global controls
Run Full Analysis recomputes the models; Clear Cache forces a fresh compute of the current tab.
The 20 tabs
- Overview β headline stats, emergent top-10, active countries, targeted sectors, predicted links, clusters.
- Risk Scores β nodes ranked by propagated risk with contributing factors.
- Communities β Louvain groups; double-click a card for a drill-down modal.
- Centrality β top nodes by Degree / Betweenness / PageRank.
- Link Predictions β Adamic-Adar or Katz (multi-hop) predicted relationships with scores and paths.
- Similarity β search a node to find cosine-similar entities.
- Anomalies β degree / bridge / temporal structural anomalies.
- Attack Paths β pick From/To node types + max hops β ranked paths with per-hop risk.
- Trends β activity velocity, trending techniques, emerging actors.
- Changepoints β surges, drops, inflection points over time.
- Simulator β select mitigations/techniques/software to "remove" β modelled risk reduction.
- CVE Priority β a ranked patch queue with reasons.
- KEV Predictor β exploitation-probability model with accuracy vs baseline and feature importances.
- Verified Predictions β save predictions, verify later, track hit-rate over time.
- Actor Clusters β attribution clusters by shared TTPs/software.
- MetaPath β relation-aware similarity search.
- Hierarchical β multi-resolution communities; drill sub-communities.
- Activity Forecast β Hawkes-process "predicted next / overdue" per entity.
- Graph Neural Net β GCN/GAT node classification, predicted vs actual.
- Emergent Signals β scan for strategic shifts; expandable signal cards with impact and recommended actions.
The Community Drill-Down modal (from Communities/Hierarchical) offers sub-tabs: Graph (with Export PNG), Members, Mitigations, Cypher (copyable reproducible query), and Report (generate an AI community report and ask follow-ups).
Administration & Settings Admin + all
The window is titled Administration for admins and Settings for everyone else. Non-admins see only the Security tab; all admin tabs are enforced admin-only on the server. Tabs: Users, IDAM, Health Check, Password, Security, Audit Log.
Common tasks
- Approve a signup (Users)
- Click APPROVE (or REJECT) in "Pending Approvals". Add operators directly with username/password/role, or delete users with an inline confirm.
- Grant app access (IDAM)
- A per-user grid with a checkbox per app (Signal, Fusion, Nexus, Kin0bi, 1D, V0id, V01d, Raz0r, ANTOS) and document (Exec, M&A, Diary). Tick to grant (saves immediately), or use per-row ALL / NONE. Filter by ALL / PENDING / APPROVED.
- Check platform health (Health Check)
- REFRESH (auto every 60s) shows every API endpoint with a status dot, latency, HTTP code, and errors; summary OK/SLOW/ERROR counts.
- Reset a password (Password)
- Pick a user, enter a new password twice (min 8), CHANGE PASSWORD.
- Manage your 2FA (Security β all users)
- Enable an authenticator (scan QR β verify β save backup codes) or email codes; disable MFA by confirming a current code. Backup-codes-remaining turns amber at β€2.
- Investigate logins (Audit Log)
- Stat cards (total, last 24h, failed logins 24h, unique users 24h) plus a filterable event table (by event type and username), auto-refreshing every 30s, with LOAD MORE paging.
LLM burn rate Login
An internal spend dashboard for the estate's AI usage β forward run-rate, projections, and breakdowns by app, feature, and model.
- Pick a window (7d / 30d / 90d); read the Run rate ($/day) and Projected monthly tiles first, then the breakdown tables.
- Watch Cache hit ratio and any amber caching warning.
- To pull fresh threat intel, click Collect only (free) or, as an admin, Run with Claude (paid), then refresh.
DEFCON β daily threat brief Public
A free, public, one-page brief naming the single most important threat today (ranked from CISA KEV, EPSS, CVSS and ubiquity), published 07:15 UK daily. No signup.
- Open
/defconto jump to today's edition (a dated permalink). - Read TODAY (the headline), then THE THREE for prioritized actions, and TRAVERSAL + NUMBERS for context.
- Share via LinkedIn / X / Copy post text, or subscribe with your email (Get DEFCON). Browse past briefs via Archive or subscribe to RSS.
Threat Check β free IOC lookup Public
Paste an IP, domain, hash, CVE, or actor name and get a threat assessment β no account needed.
- Type or paste an indicator (or click an example / recent chip) and press CHECK.
- Read the verdict: a Found result shows a 0β100 threat-score gauge, timeline, description, CVSS (for CVEs), properties, related actors/campaigns/techniques, and graph connections. Not Found is framed as good news with a deep-search offer; rate-limit/errors are shown plainly.
- Click any related entity or connection to pivot β the URL updates to
/threat-check/<ioc>, so results are shareable. Use SHARE (Copy Link / Markdown / X / cURL) or open the result in Spektr / Galaxy.
Spektr β semantic search Public
A Google-style search over the whole threat graph (hundreds of thousands of entities).
- Type into "Search threat actors, CVEs, malware, techniquesβ¦" β or click a starter chip (Russian APT groups, ransomware double extortion, β¦).
- Choose a MODE β KEYWORD, SEMANTIC, or HYBRID (default) β which re-runs instantly. Narrow with the entity-type chips (ThreatActor, Vulnerability, Software, Technique, Indicator, Campaign, Infrastructure, Mitigation), then re-submit to apply.
- Click a result for a detail panel: description, AI RESEARCH (open the query in Claude or Gemini), properties, and relationships you can click to traverse the graph. View in Signal β opens the full console.
Threat Theatre β 3D galaxy Public
An immersive real-time 3D "galaxy" of the threat graph, built for a SOC wall. Nodes are coloured by recency (red 0β6h β grey >7d).
Fly & camera
WASD fly Β· Q/Space up Β· E/Shift down Β· scroll zoom Β· left-drag rotate Β· right-drag pan. It auto-rotates when idle.
- Use the Find box (or press /) to fly to a node by name β it pulses and, if outside the sample, searches the full graph.
- Hover a node for a tooltip; click for a detail panel with EXPLORE (isolate its neighbour tree) and INVESTIGATE (opens Spektr).
- Cycle the Edges toggle (off β proximity β all); scrub the Timeline (play/pause, or click a 6-hour bucket) to recolour the galaxy for that window; LIVE resets.
SUBTEXT// β discourse analyser Public
Paste online text and get an AI "forensic" read of its hidden agenda and manipulation signals.
- Paste content into the evidence box (or load a sample: Concerned Parent / Industry Defender / Wellness Influencer); optionally add platform, author handle, and timestamp. Minimum 20 characters.
- Click β‘ Initiate Forensic Scan.
- Read the Dashboard (verdict, Subtext Score /100, six-dimension grid, inferred author profile, red flags), then drill into the Forensic Report per dimension (with a charitable counter-reading). EXPORT downloads a .txt report.
Marketing & information pages Public
- /welcome β landing
- The signed-out home. Live graph counts, an inline Threat-Check box, today's DEFCON card, trending IOCs, a features grid, and links into the platform.
- /overview β the 30-second view
- A single scrolling page for execs/investors with an embedded live Threat Theatre and a sample attacker fingerprint.
- /pricing β pricing
- Three tiers: DEFCON (free), Signal Team (Β£1,200/mo β API, 10 seats + SSO, custom feeds, SLA), Enterprise (self-hosted, contact us).
- /trust β trust & data handling
- A procurement reference: region (Hetzner Finland, EEA-only), key custody, retention, incident contact, sub-processors, GDPR compliance.
- /demo β book a demo
- Request a 30-minute Google Meet walkthrough β enter work email, company, and a preferred time.
- /access β the vault gate
- Where signed-out users land when they hit a gated page: create an account, sign in, or request enterprise/researcher access, plus links to the free tools.
- /signalhld β Signal design doc
- The long-form Signal High-Level Design (architecture, data model, feeds, graph schema, ML engine, security) with Mermaid diagrams.
- /hld β ANTOS design doc
- The ANTOS DevSecOps-pipeline design document (a sibling system), read-only with rendered diagrams.
Full window catalog Login
Every window available from the sidebar, by section. Open any of them from the Sidebar, the Command Palette (βK), or the Constellation Launcher (`).
Autonomous
- SHOGUN β autonomous threat commander that orchestrates all windows.
Core
- Dashboard β system overview: node counts, risk scores, feed status.
- AIP / AIP Logic β natural-language graph queries and multi-step reasoning chains.
- Threat Theatre β the 3D temporal visualizer (see above).
- SITREP β situation-report generator (IIR / INTREP / Executive).
- CISO Briefing β auto-generated executive threat briefing.
- Ops Center β health, latency, queue depth.
- PIM / PAM β privileged access & identity monitor.
- KIZUNA β cross-ecosystem relationship intelligence.
- Help β in-app user guide.
Intelligence
- Intel, Spektr β see the sections above.
- Intel Mesh β cross-app intelligence over the NATS event bus.
- APT Sightings β sighting heatmap by actor and region.
- Threat Drops β live feed from every ingester.
- CTI Extract β paste raw CTI text β auto-extract entities into the graph.
- Investigations β case management.
- MONOGATARI β narrative intelligence storytelling.
Analysis
- Adversary DNA β 18-dimension behavioural fingerprinting.
- ORIGAMI β multi-source actor attribution.
- Causal Analysis β DoWhy causal inference / what-if modelling.
- Strategic Forecast, TTP Trends, Phylogeny, Contagion β landscape forecasting, TTP adoption, actor lineage, malware spread simulation.
- Threat Diff / Time Machine β compare or rewind graph snapshots over time.
- Hex Heatmap β H3 geospatial heatmap of threat origins.
- Explainable Risk, Graph Anomalies, Attack Probability, Entity Resolution, Quiver, YOGEN β score explanations, structural anomalies, path likelihood, duplicate merging, signal correlation, predictive forecasting.
Detection
- KQL Rules β generate Microsoft Sentinel detection rules from the graph.
- Threat Hunting, Emulation, raZ0r (SIEM), D3FEND Gaps β hunting workbench, ATT&CK replay, EDR correlation, coverage-gap analysis.
- Ransomware, Supply Chain, Gator, KENJUTSU, HIBANA β ransomware tracker, dependency risk, alert triage, surgical response, early-warning signals.
Response
- SOAR Engine (automated playbooks), Attack Surface (external discovery), Behavioral Auth (biometric analytics).
Data
- Graph Explorer, Graph DB β see the sections above.
- Explorer, Data Lab, Workbench, Code Workbook β browse nodes by label, SQL/Cypher notebooks, an analyst scratch-pad with evidence pinning.
- Digital Twins, Merkle Graph, Connector, Pipelines β actor simulation, integrity proofs, data-source config, a visual pipeline builder.
Foundry
- Workshop (analysis environment), Contour (statistical charting).
Feeds
- Hot C2Β² / Hot Phish Tank β live C2 and phishing trackers.
- Traffic (Caddy log analytics), AML Intel, Darknet, Patent Intel, Pharma Intel, Geopolitical β sector and OSINT feeds.
- Ingestion Monitor β status/counts/errors for every ingester run.
Advanced & Experimental
- ML Insights (see above), Federated TI, Org Twin, Causal RL, Cascade, Dashboards (drag-and-drop builder).
- Neuromorphic, LLM Agents, Temporal GAT, Encrypted IOC, Explainable/Streaming GNN β research-grade models.
- INFO THEORY, TDA, NEURO-SYM, CROSS-MODAL, DIFFUSION β entropy/surprise scoring, topological gap analysis, symbolic validation, unified cross-modal search, generative scenario synthesis.