Ninja V01d RTFM
Signal
Read the manual — 虚空予知

Ninja V01d — the complete ecosystem manual

Predictive sentiment intelligence — the mesh's front brain. V01d forecasts global conflict, cyber warfare, and economic disruption from the world's sentiment, with an early-warning Oracle firing every few minutes. This manual covers the whole ninjav0id.io ecosystem: the V01d workspace and Oracle, the Brain situation room, the Void galaxy, plus V0id Agents and the Los Alamos range.

How the V01d ecosystem works

Everything lives under ninjav0id.io. Signed-out, you get two free public surfaces — the ninjaTONE Oracle briefing and the landing page. Signed-in, the root becomes a windowed Desktop: a left sidebar, floating draggable windows, and a bottom taskbar. Three sister apps round out the ecosystem:

V01d Login
The predictive-sentiment workspace — the Desktop, the Oracle, the Void galaxy, the Brain situation room, plus adversary and interaction views.
V0id Agents Maintenance
An autonomous defensive-AI SOC at /v (currently showing a maintenance page — documented in V0id Agents).
Los Alamos Login
An agentic Red-vs-Blue live-fire cyber range at /losalamos — see Los Alamos.
Two things to know. V01d has no MFA (a valid session is the gate). And your personal layers — watch-list, notebook, alert rules, pinboard — are stored in your browser, so they don't sync across devices.

Sign in & register Public

/login · /login?fallback=1 · /signup

V01d is SSO-first: opening a gated page or /login while signed out bounces you to Ninja Signal to authenticate, then returns you here.

  1. Go to any V01d page — you're redirected to Signal SSO. Sign in there once. (Need the local form? use /login?fallback=1.)
  2. On the local form, enter USERNAME and PASSWORD, click AUTHENTICATE. There is no MFA step.
  3. To request an account, use REQUEST ACCESS/signup (username + password → CREATE ACCOUNT).

The V01d Desktop Login

Once signed in, the root (/) renders the workspace: a fixed left Sidebar (虚 emblem, a pipeline status chip showing LIVE/STANDBY + live feed/event counts, four big destination tiles — THE VOID / ADVERSARY / THE BRAIN / INTERACTIONS — and a list of window launchers), floating windows, and a bottom Taskbar.

Working with windows

Each window is draggable by its title bar and resizable (min 400×300), with Minimize / Maximize / Close controls; the V01d Dashboard opens automatically on first visit, and your layout is remembered between sessions. Click a taskbar button to focus or minimize a window.

The twelve windows

  • V01d Dashboard — at-a-glance posture, global status, top entities.
  • Sentiment Theatre — cinematic global sentiment with a DEFCON-style threat condition, radar, critical watch, and live feed.
  • Sentiment Globe — a world map of regional sentiment (toggle STORIES; click a region).
  • Timeline — bucketed sentiment over 6h–168h, filterable by entity.
  • Entities — a ranked, searchable entity table (sort by Events or Tone; click to drill).
  • Topics — TF-IDF topic clusters, tone-coloured and volume-sized.
  • V01d Oracle — the flagship early-warning score (see below).
  • Cyber Barometer — a 0–100 cyber-domain gauge with a component breakdown + 24h timeline.
  • Economic — FRED macro indicators (VIX, EPU, yield curve, CPI…) and a sentiment↔market Correlate tool.
  • Explorer — the raw event feed/table with source filters, sorting, and paging.
  • ML Lab — a 13-tab ML workbench (Consensus, Reliability, Anomalies, Forecast, Cascades, Calibration, Embeddings, Contagion, Communities, Narratives, Diffusion, Lead/Lag, Thresholds) — enter an entity and hit Go.
  • Admin — an ops console (pipeline status + users).

The V01d Oracle Login

The flagship "Predictive Sentiment Intelligence Engine" — a probabilistic threat/sentiment score that auto-refreshes every two minutes.

  1. Open Oracle from the sidebar.
  2. Read the big score + level (stable → critical, colour-coded).
  3. Scan the five weighted component bars to see why: Mood/Tone (30%), Velocity (25%), Anomaly — Isolation Forest (20%), Topic Heat (15%), Economic — VIX/EPU/yield (10%).
  4. Click any tile in Entity Readings to drill into that entity, region, or topic.

The Void — federated galaxy Login

/void

A 3D WebGL galaxy federating entities across three domains — V01d (sentiment), Signal (threat graph), Fusion (cross-domain) — into one point cloud, with cross-domain link discovery.

  1. Open THE VOID from the sidebar. Navigate with drag (orbit), wheel (zoom), WASD (fly), Q/E (up/down), and press G to toggle edges.
  2. Read the stats overlay (V01d / Signal / Fusion counts, edges, sentiment-linked, stories).
  3. Click a node for its detail panel — score/tone/risk, the entities it's sentiment-linked via, recent stories, and cross-domain matches (click one to traverse between linked nodes).
Append ?path=name1,name2,… to the URL to glow a chain through the galaxy (a PATH ACTIVE banner appears). The Brain's path-finder links here directly.

Adversary view Login

/adversary

Flips the graph to a ransomware crew's perspective. Pick a group from the dropdown (each shows its victim count) and read its operational profile — sponsor, victims, velocity/day, KEV count, target sectors and countries, and recent victims — rendered as a radial diagram (actor core → sectors → countries → victims).

Interaction model Login

/interactions

Models how V01d sentiment meets Signal/Fusion threat actors and their attributed countries. The PROFILES tab browses per-actor cards (attribution, stories, co-mentioned peers); the MATRIX tab is an actor × country interaction-intensity heatmap (hover a cell for the exact score).

ninjaTONE — the public Oracle Public

/ninjatone

A free, no-login daily cross-graph intelligence briefing that fuses V01d + Signal + Fusion + global news into one threat picture — the public face of the Oracle. It refreshes daily.

  1. Open ninjav0id.io/ninjatone (no login).
  2. Read the THREAT ASSESSMENT gauge (level + score /100), then jump around with the NAVIGATE chips.
  3. Explore the sections — a 3D threat galaxy, executive summary, the Fusion SITREP, Signal's threat theatre, the sentiment landscape, predictive intelligence, a live news wire, and the Threat Map Playground (hover/click actors and campaign arcs).
  4. Use the inline Claude buttons to copy a research prompt and open claude.ai for any entity.

The Brain — situation room Login

/brain · 頭脳

A multi-graph situation room: one scrolling dashboard that scores threat posture, narrates it in plain English, predicts intent, flags anomalies, and streams fresh events — auto-refreshing every 60 seconds, and never spending AI tokens unless you ask.

The header controls

VIEW preset
FULL / CISO / SOC / BOARD — tailors which sections render for your audience (saved locally).
Time Scrubber & Replay
A storm-intensity sparkline + slider to rewind the whole dashboard to a past hour; replays storm history; snaps back to live.
Exports
⬇ JSON (state snapshot), ⬇ MD (briefing), ⬇ STIX (STIX 2.1 bundle).
− KEV
A counterfactual toggle that recomputes the storm without CISA-KEV events.

Key interactive tools on the dashboard

  • Posture Hero — a 0–100 gauge with a 24h trend and five weighted component bars.
  • ASK — ask the brain a free-text question; see the answer + which tools it called, and ★ SAVE HUNT to keep it.
  • Exec Briefing — a Claude-written briefing with text-to-speech (▶ PLAY, speed control) and ⟳ REGEN.
  • Path-Finder — enter two entities (e.g. APT28 → Microsoft) and FIND the shortest path; open the chain in the Void galaxy.
  • Alert Rules — build threshold rules (field/operator/value) that fire browser notifications; Notebook, Sigma Rules (copyable YAML), and Webhooks (Slack/Discord) panels.

Beyond the dashboard, the Brain opens onto a set of specialised views (below). A 📍 pin button on most cards captures findings into an investigation on the Pinboard, and a ☆ watch-list star pins entities to the dashboard.

New to the Brain? /brain/welcome is a ~90-second guided tour, and /brain/docs is a live, filterable catalogue of the /void/* API.

Brain visualizations Login

Network — actor × sector × country
A force-directed relationship graph over a 7–60d window; toggle node types, hover to isolate a node's neighbours, and open its dossier.
Flow — kill-chain Sankey
A four-stage Sankey (country → actor → sector → technique); ribbon width = claim volume; hover a node to isolate its chain.
Galaxy — actor universe
A 3D galaxy where each ransomware actor is a star sized by victims; click a star for its predicted next target and dossier.
Heatglobe — risk weather
A 3D globe with per-country risk bars; click a bar for its risk tiles and country dossier.

Brain analysis tools Login

ATT&CK Matrix
A heatmap of active threat groups × MITRE techniques, coloured by tactic; click a group to drill in.
Hunts
Save natural-language hunt questions and re-run them on demand (or ⟳ RUN ALL), keeping each latest answer.
Detection Rules
A review queue of auto-generated Sigma/Snort/YARA candidates — ⟳ SYNTHESIZE FROM CLAIMS, then inspect and ✓ APPROVE / ✗ REJECT.
Cases
A lightweight investigation tracker: create a case, advance it through states, attach refs/notes, and export a portable .v01d case file.
Compare
Load two brain snapshots side by side and see exactly what changed (storm, sectors, actors, hypotheses, country risk).
What If…
Mute actors, sectors, or sources and recompute the picture without them, then read the delta from the real baseline.
Hypotheses
A reasoning ledger — each hypothesis has a claim, a confidence, a falsifier (what would refute it), evidence with deep-links, and the history of the same reasoning over time.

Dossiers & the pinboard Login

Deep-dive profiles you reach by clicking any entity across the Brain:

Actor dossier
Recent victims, an intent prediction (next sector/country), an activity timeline, an IR Playbook and an Adversary Playbook (operational cadence — hour-of-day/day-of-week heat strips), peer actors, and a local notebook.
Country dossier
Who's attacking, which sectors, recent victims, peer countries (by actor overlap), and news tone.
Sector dossier
Curated risk factors, top groups, intent predictions, geographic spread, recent victims, and related news.
Pinboard — case files
Organise the 📍 pins you capture across the Brain into named investigations, then ⤓ EXPORT any one as a portable case file. (All browser-local.)

V0id Agents — autonomous SOC Maintenance

/v · 虚空守護
Currently under maintenance. /v is serving a maintenance page while it's being updated; the capabilities below describe the app when it's live.

An autonomous, LLM-powered defensive SOC ("AGENTIC AI DEFENSE / POWERED BY CLAUDE"). Three AI agents perceive, reason, decide, and act on security alerts: Sentinel (triage), Warden (containment), and Spectre (threat hunting). It's a windowed desktop (drag/resize windows, bottom taskbar, layout persists); Command Center opens by default.

The windows

  • Command Center — a live dashboard of all three agents, open incidents, and recent AI decisions.
  • Sentinel — monitor triage and inject a test alert (edit the JSON, click INJECT ALERT, watch the decision + rationale).
  • Warden — review containment actions; ROLLBACK reversible completed ones.
  • Spectre — launch a manual threat hunt (describe what to hunt for → EXECUTE HUNT → read findings).
  • IR Playbooks — browse SOAR playbooks and TRIGGER them; watch executions run through their phases.
  • Incidents — filter and advance incident lifecycle (open → investigating → contained → resolved).
  • Decisions — an audit trail of agent reasoning (with LLM latency) and the raw action log.
  • Context — a Neo4j graph console with node counts and a Cypher query box.
  • Coverage Map — MITRE ATT&CK detection-coverage overview and gaps.
  • Rule Tuner & Correlations — auto-generated detection-threshold and multi-event correlation recommendations.
  • Forensics — view collected evidence/packages and INITIATE COLLECTION (memory / disk / network) on a host.
  • Claude AI — a conversational assistant for config, incident analysis, playbooks, and hunting.
  • Admin — set the agents' autonomy level (Notify-only → Full-auto) and manage users.

Los Alamos — live-fire cyber range Login

/losalamos · 射場

An agentic live-fire cyber range: autonomous Red Team AI agents (Kage, Oni, Yurei) attack a simulated enterprise network while the V0id Blue Team defends — a full LLM-vs-LLM battle you configure, launch, and spectate. It's a windowed desktop (drag + minimize/close).

Run a full exercise

  1. Workbench — either click LAUNCH on a Quick-Launch scenario, or configure SETUP (environment template, difficulty, chaos level) → ADVERSARY (threat actor, optional Chimera/Randomize) → LAUNCH発射 INITIATE LIVE FIRE.
  2. Arena or Theatre — spectate the live battle tick-by-tick; Theatre adds a network-topology map, damage/containment panels, and a SPEED slider to pace the sim.
  3. Track detail with Kill Chain (phase heatmap), Topology (per-host drill-down), Casualties (blast radius), Timeline, and Commentary (play-by-play).
  4. When it ends, review Scoreboard (winner, history, ELO leaderboard) and step through Replay (VCR-style scrubbing).

Extra views

  • Kage / Oni / Yurei — per-red-agent telemetry (recon/access, execution/lateral/persistence, evasion/C2/exfil).
  • V0id Agents (Blue) — the defending agents' health and activity.
  • Grudge Match — pit two fully-configured AI lineups (choose Claude / GPT / Gemini + model per side) on the same scenario and compare verdicts.
  • Environment — preview a network template (Enterprise, Cloud Hybrid, ICS/SCADA, Healthcare, Financial, Small Business) or inspect the live match's network.