Ninja Fusion RTFM
Signal manual
Read the manual

Ninja Fusion — the complete user manual

Where cyber meets geopolitical. Fusion is a cross-domain threat-fusion centre: it pulls 80+ sources across intelligence tiers into one knowledge graph, then gives you a tiling console of live modules — a 3D globe, situation reports, attribution, forecasting, and more. This manual walks the whole console, module by module.

How Fusion works

Signed-out, you get a public landing page and a free live SITREP. Signed-in, / becomes the Fusion console — and unlike most web apps, it's an i3-style tiling window manager: modules open as tiled panes (not floating windows), arranged across four workspaces, and your whole layout is remembered between sessions.

Tiling, not floating. Opening a module splits the focused pane rather than stacking a window on top. You navigate and rearrange panes mostly with the keyboard (all shortcuts use Alt — see Windows & tiling).

Get around three ways: the Sidebar (click a module to open it), the workspace tabs in the status bar (Alt+1…4), and the Alt-key focus/move shortcuts. New here? Start with signing in.

Sign in Public

/login · /login?fallback=1

Fusion is SSO-first: opening /login while signed out sends you to Ninja Signal to authenticate, then returns you here — one login covers the whole ecosystem.

  1. Go to /login — you're redirected to Signal SSO. Sign in there once. (Need the local Fusion form instead? use /login?fallback=1.)
  2. On the local form, enter your USERNAME (not your email) and PASSWORD, click AUTHENTICATE.
  3. If MFA is set, enter your 6–8 digit VERIFICATION CODE (authenticator or email) and click VERIFY — email method offers RESEND CODE.
  4. You land on the console at /.

Request access & reset Public

/signup · /reset

Sign up (/signup): enter Display Name, Email, and a Password (min 8) twice, click Request Access. Accounts are admin-approved — you're active once an administrator approves you.

Reset a password (/reset): enter your email → SEND RESET LINK; open the emailed link and set a new password (min 8) → RESET PASSWORD.

Two-factor: a "SECURE YOUR ACCOUNT" prompt lets you enrol an authenticator app (scan QR → verify) or email codes, ending with one-time backup codes — save them.

Workspaces & status bar Login

The i3-style status bar across the top shows four workspace tabs1 INTEL, 2 OPS, 3 SIGINT, 4 RECON — click one or press Alt+1…4 to switch. Each workspace holds its own set of tiled modules (defaults: INTEL = Intel + Graph Explorer + ML; OPS = Briefing + Digital Twins; SIGINT = Signal Wire + Social Monitor; RECON = empty). The centre shows the focused window's title; the right shows a live clock and system status.

Signal Wire ticker Login

Under the status bar, a scrolling WIRE ticker streams the last hour's signals (severity dot + time + headline + entity tags). Hover to pause; click any item to open the full Signal Wire module. It refreshes every 2 minutes.

Windows, tiling & shortcuts Login

Each pane has a title bar with an Info (ℹ) button on analytical modules (opens a "System Documentation" panel explaining the algorithms) and a Close (×). Drag the gutter between panes to resize; opening a module splits the focused pane. Your layout (workspaces + splits) is restored on return.

Keyboard shortcuts (all use Alt)

Alt+1 … 9Switch to workspace N
Alt+H / L / J / KMove focus left / right / down / up
Alt+Shift+H/L/J/KSwap the focused pane in that direction
Alt+QClose the focused pane
Alt+FToggle fullscreen for the focused pane

Niko AI, entity badges & dossiers Login

Niko AI (仁) is a context-aware analyst in the sidebar, scoped to the focused pane (a separate conversation per module) with full graph context. Expand it, type into "質問… Ask Niko", press Enter or 送信. It also surfaces live emergent signals with a red pulse.

Entity badges — the universal drill-down

Small coloured chips (label + value) for graph entities appear across almost every module:

Single-click
Searches that value in the Intel module.
Double-click
Opens a detail modal — an Actor Dossier for a threat actor (risk score, aliases, techniques, software, exploited CVEs, campaigns, related actors, recent social posts), or an Entity Detail modal (properties + incoming/outgoing connections) for anything else.

Welcome landing Public

/welcome

The public product page: hero ("Intelligence fusion for a world at war."), CTAs into the fusion centre and the free SITREP, a features grid (geopolitical conflict tracking, multi-tier source fusion, cyber × kinetic in one graph, early warning), and chips for the source coverage (80+ sources, 8 tiers, GDELT · SIPRI · OSINT).

Live SITREP — free Public

/sitrep

A free, real-time Situation Report — a 24-hour multi-domain fusion briefing, no account needed. It's served from a 24-hour cache, so it's instant and makes no live backend calls.

  1. Open /sitrep — it auto-loads (10–30s first time).
  2. Read the pulsing Priority Alert, then the Risk Matrix (per-domain critical/high/medium/low), then the six domain sections (Geopolitical, Sanctions, Cyber, Humanitarian, Supply Chain, Social).
  3. Follow the numbered Recommended Actions; the Raw Intelligence Stats (10 cards) render even if the AI writer is offline.

Threat Briefing Login

A dashboard summarising threat activity over a window you choose. Pick a range (1H / 6H / 24H / 7D) and Refresh. Six headline cards (CVEs mentioned, active actors, social posts, KEV entries, breaches, supply-chain), then panels: Trending Vulnerabilities (CVSS + KEV + exploiting actors), Active Threat Actors (double-click a card or VIEW DOSSIER for the actor dossier), Supply Chain Alerts, Recent Breaches, Social Intelligence, ML Predictions, and Changepoints.

Signal Wire Login

A live, auto-refreshing (2 min) intelligence feed with anomaly dashboards. Choose a range (1H/6H/24H); click an anomaly card (Volume Spikes, Bursts, Novel Entities, Convergences) to filter; filter by type (Social/Geopolitical/KEV/Anomalies). Each row shows the source, time, headline (external link), entity badges, an urgency meter, and mention-velocity vs baseline. Panels for Trending Entities and Platform Breakdown.

SITREP (console) Login

The richer console version of the Situation Report. Choose a window (6H/24H/7D/30D) and a Focus (Auto/Geopolitical/Cyber/Sanctions/Supply Chain), then REFRESH to regenerate (a CACHED badge and elapsed time show when it's served from cache; auto-refreshes every 15 min). Same shape as the public SITREP — Priority Alert, Risk Matrix, six domain boxes, Recommended Actions, and 10 raw-stat cards.

Inferences Login

The "Fusion Intelligence Engine" — it runs 12 cross-domain correlation queries and synthesises them into ranked inferences, a forward prediction, and intelligence blind spots. Nine stat cards (Sanctions-Cyber Nexus, high-risk CVEs, shared TTPs, breach+sanction, 4+ domain risk, social cross-ref, KEV attributed, geo-cyber, unmitigated). Raw Cross-Domain Findings expand into 11 detailed tables (one at a time), every entity clickable. REFRESH to recompute; auto-refresh 15 min.

Intel Login

Universal knowledge-graph search. Type into "Search threats, actors, vulnerabilities, packages…"SEARCH → result cards (type badge, name, key properties). Click a card to pivot the search to that entity. This is where entity-badge single-clicks and the globe's "SEARCH INTEL" land.

Social Monitor Login

A live (30s auto-refresh) feed of cyber chatter with CVE/actor/IOC extraction. Filter by platform (RSS / Mastodon / Reddit / Telegram / Twitter), time range (1h–7d), and a local text filter. Post cards show platform, author, relevance, content, clickable entity tags (→ Intel), and a link to the original.

Threat Globe Login

A 3D (or 2D) globe rendering every data category as glowing point clouds over a risk-coloured Earth, plus threat-relationship arcs.

  1. Drag to rotate (it auto-rotates), scroll to zoom; toggle 3D / 2D top-right.
  2. Point-cloud layers: Fires, Flights, Radiation, Maritime, Conflicts, Disasters, Cyber, Social (colour = type, size = intensity). Arcs (3D only) are coloured by type (cyber, social, supply-chain, sanction).
  3. Hover a point for a tooltip; click for a detail card with lat/lng/intensity and two buttons — SEARCH INTEL (opens Intel) and DRILL IN (Actor Dossier or Entity Detail).

The country-risk legend (bottom-left) grades HIGH/MED/LOW.

Fusion Galaxy Login

A 3D "intelligence galaxy" plotting the whole graph as a navigable star-field. Drag to orbit, scroll to zoom, or fly with WASD (Q/Space up, E/Shift down). Hover a star for its label/name/degree. Click a Person / Org / Wallet / Sanction / Breach to light up its full connection trail; click any node to drill down (neighbours fan into a ring, up to 3 levels) with a breadcrumb bar (Back / Reset).

Graph Explorer Login

A filter-driven visual browser. Pick a preset (Cyber Threat / Geopolitical / Sanctions / Supply Chain / Social OSINT), tick the node types to include (25 types, with ALL/NONE), set a LIMIT (50–1000), and LOAD GRAPH. Toggle GRAPH (force-directed; size = risk) or TABLE.

Explorer — visual Cypher Login

A Cypher-driven visual explorer. Write Cypher (or pick a Preset), run with Run or Ctrl/Cmd+Enter, and toggle Table/Graph. In graph view, click a node for its properties and right-click to expand its neighbours. Copy Cypher, Export JSON (downloads the result), and a History of your last 10 queries.

Graph DB — tabular Cypher Login

A spreadsheet-style Cypher console. Use a QUICK preset (Node Counts / Top Risk / Cross-Domain Paths / Recent Ingests) or type your own (Ctrl+Enter to run), and read results in a result grid.

Three Cypher surfaces exist: Explorer (visual), Graph DB (tabular), and admin Data Lab (full CRUD).

ML Insights Login

The analytics workbench — 26 analyses across a grouped, colour-coded tab bar. Tabs lazy-load and cache ~15 min; tables sort; most carry a "How this works" panel.

  • Overview — Multi-Domain mega-risks, Dashboard.
  • Graph ML — Risk (propagation), Communities (Louvain; double-click a card to drill, with a Cypher sub-tab), Centrality (Degree/Betweenness/PageRank), Predictions (link prediction, Adamic-Adar / Katz), Similar (cosine).
  • Detection — Anomalies, Attack Paths (Source/Target type + max hops), Trends, Changepoints.
  • Intel — CVE Priority, KEV Predict (with AUC + feature importance), Clusters (DBSCAN), Simulator (node-removal what-if), Verified (save + track accuracy).
  • Advanced — MetaPath, Hierarchical, Fusion dashboard.
  • Cross-Domain — Country Nexus, Hidden Links, X-Domain entities, Correlations, Narratives.
  • Emergent — Signals (temporal graph-diff; Run Analysis for AI analysis, impact, and recommended actions).

Attribution Login

Attribute an intrusion to the most likely threat actor. Three modes: Campaign (pick from a dropdown), Evidence (enter ATT&CK techniques, software/malware, indicators, countries), or Search (free text). Results rank up to 10 candidate actors with similarity bars, shared-TTP/infra/indicator counts, and a "show shared evidence" expander, plus an evidence fingerprint and a highest-confidence callout.

Supply Chain Login

Third-party and open-source risk. Deep Scan: enter a vendor (e.g. SolarWinds) → SCAN → an AI dossier (risk pill, confidence gauge, products, known CVEs, personnel, domains, incidents, dependencies, customers, competitors). Blast Radius: enter a package (e.g. pkg:npm/lodash) → ANALYZE → a blast-radius gauge with affected repos/orgs/industries and the dependency chain.

Sanctions Login

Screen an entity against global sanctions lists and measure graph proximity. Choose a type (Person / Organization / Package), search, and ANALYZE → a degrees-of-separation figure with a risk band, a proximity score, a path visualisation to the nearest sanctioned entity, and that entity's details (list, country, type, reason).

Breaches Login

Trace a breach's cascade. Search a breach (e.g. LinkedIn) → TRACE → breach metadata plus three cascade layers: exposed people → the packages they maintain → downstream orgs affected, with an aggregate compromised-maintainer risk.

Enterprise Login

Profile your own attack surface, then generate a consolidated threat surface. Fill the profile form (organisation, industries, operating countries, software stack, packages, vendors, domains, IP ranges) → SAVE PROFILE & ANALYZE → a threat dashboard: a risk-score ring, a risk breakdown (CVE exposure, actor targeting, breach, sanctions, supply chain, geopolitical), and detailed tables of your critical vulnerabilities, targeting actors, breach and sanctions exposure, supply-chain risks, and social mentions.

Digital Twins Login

Behavioural adversary emulation. Select an actor, then use the tabs: Profile (kill-chain coverage, techniques, cadence, infrastructure), Simulate (Monte Carlo runs → a probabilistic kill chain + P10/median/P90 timeline), Playbook (generate a purple-team playbook with red-team steps + blue-team KQL detections), War Game (set EDR/NTA/SIEM sliders → run 500 sims → detection rate + per-phase heatmap + ROI), and Predictions (predicted technique adoption).

Strategic Forecast Login

A forward-looking threat forecast. FORECAST: pick a horizon (7d/30d/90d) and focus → an executive summary + threat-level, expandable predictions (confidence, timeframe, impact, indicators), sector impact, recommended posture, and wild cards. SCENARIO: describe a what-if → plausibility, cascade effects, actor responses, detection, mitigation. ACCURACY: verify past predictions and track hit-rate by category and confidence.

Admin panel Admin

Tabs: Users (approve/reject pending signups; manage active users — role dropdown, MFA, delete), Status (API, Neo4j, last ingestion, uptime), Ingest (RUN INGESTION + a per-feed status table polling every 10s), and Settings (placeholder).

Data Lab Admin

A full Neo4j workbench. Schema (node/rel stats, property coverage, data quality), Nodes (filtered CRUD table with create/edit/delete), Bulk (CSV/JSON import, filtered update, and delete — all with a Dry Run, delete requires typing "DELETE"), Export (query → CSV/JSON download, up to 10k rows), and Queries (a saved Cypher library).

Scanner & Integrations Admin

External attack-surface scanning (Nuclei / testssl / httpx). Config (add target domains, scope Quick/Standard/Deep, optional schedule, Save, Scan Now), Dashboard (live status + severity stat cards), Findings (filter by severity/tool/domain; rows expand to description/URL/evidence/remediation), and History.

Economics Admin

A read-only macro-economic risk dashboard. Choose a window (30D–365D) and read latest-value cards + sparklines for VIX, economic-policy uncertainty, supply-chain pressure, GDP, unemployment, CPI, Fed funds, yield spread, 10Y treasury, USD/EUR, and WTI crude.