Ninja V01d — the complete ecosystem manual
Predictive sentiment intelligence — the mesh's front brain. V01d forecasts global conflict, cyber warfare, and economic disruption from the world's sentiment, with an early-warning Oracle firing every few minutes. This manual covers the whole ninjav0id.io ecosystem: the V01d workspace and Oracle, the Brain situation room, the Void galaxy, plus V0id Agents and the Los Alamos range.
How the V01d ecosystem works
Everything lives under ninjav0id.io. Signed-out, you get two free public surfaces — the ninjaTONE Oracle briefing and the landing page. Signed-in, the root becomes a windowed Desktop: a left sidebar, floating draggable windows, and a bottom taskbar. Three sister apps round out the ecosystem:
- V01d Login
- The predictive-sentiment workspace — the Desktop, the Oracle, the Void galaxy, the Brain situation room, plus adversary and interaction views.
- V0id Agents Maintenance
- An autonomous defensive-AI SOC at
/v(currently showing a maintenance page — documented in V0id Agents). - Los Alamos Login
- An agentic Red-vs-Blue live-fire cyber range at
/losalamos— see Los Alamos.
Sign in & register Public
V01d is SSO-first: opening a gated page or /login while signed out bounces you to Ninja Signal to authenticate, then returns you here.
- Go to any V01d page — you're redirected to Signal SSO. Sign in there once. (Need the local form? use
/login?fallback=1.) - On the local form, enter USERNAME and PASSWORD, click AUTHENTICATE. There is no MFA step.
- To request an account, use REQUEST ACCESS →
/signup(username + password → CREATE ACCOUNT).
The V01d Desktop Login
Once signed in, the root (/) renders the workspace: a fixed left Sidebar (虚 emblem, a pipeline status chip showing LIVE/STANDBY + live feed/event counts, four big destination tiles — THE VOID / ADVERSARY / THE BRAIN / INTERACTIONS — and a list of window launchers), floating windows, and a bottom Taskbar.
Working with windows
Each window is draggable by its title bar and resizable (min 400×300), with Minimize / Maximize / Close controls; the V01d Dashboard opens automatically on first visit, and your layout is remembered between sessions. Click a taskbar button to focus or minimize a window.
The twelve windows
- V01d Dashboard — at-a-glance posture, global status, top entities.
- Sentiment Theatre — cinematic global sentiment with a DEFCON-style threat condition, radar, critical watch, and live feed.
- Sentiment Globe — a world map of regional sentiment (toggle STORIES; click a region).
- Timeline — bucketed sentiment over 6h–168h, filterable by entity.
- Entities — a ranked, searchable entity table (sort by Events or Tone; click to drill).
- Topics — TF-IDF topic clusters, tone-coloured and volume-sized.
- V01d Oracle — the flagship early-warning score (see below).
- Cyber Barometer — a 0–100 cyber-domain gauge with a component breakdown + 24h timeline.
- Economic — FRED macro indicators (VIX, EPU, yield curve, CPI…) and a sentiment↔market Correlate tool.
- Explorer — the raw event feed/table with source filters, sorting, and paging.
- ML Lab — a 13-tab ML workbench (Consensus, Reliability, Anomalies, Forecast, Cascades, Calibration, Embeddings, Contagion, Communities, Narratives, Diffusion, Lead/Lag, Thresholds) — enter an entity and hit Go.
- Admin — an ops console (pipeline status + users).
The V01d Oracle Login
The flagship "Predictive Sentiment Intelligence Engine" — a probabilistic threat/sentiment score that auto-refreshes every two minutes.
- Open Oracle from the sidebar.
- Read the big score + level (stable → critical, colour-coded).
- Scan the five weighted component bars to see why: Mood/Tone (30%), Velocity (25%), Anomaly — Isolation Forest (20%), Topic Heat (15%), Economic — VIX/EPU/yield (10%).
- Click any tile in Entity Readings to drill into that entity, region, or topic.
The Void — federated galaxy Login
A 3D WebGL galaxy federating entities across three domains — V01d (sentiment), Signal (threat graph), Fusion (cross-domain) — into one point cloud, with cross-domain link discovery.
- Open THE VOID from the sidebar. Navigate with drag (orbit), wheel (zoom), WASD (fly), Q/E (up/down), and press G to toggle edges.
- Read the stats overlay (V01d / Signal / Fusion counts, edges, sentiment-linked, stories).
- Click a node for its detail panel — score/tone/risk, the entities it's sentiment-linked via, recent stories, and cross-domain matches (click one to traverse between linked nodes).
?path=name1,name2,… to the URL to glow a chain through the galaxy (a PATH ACTIVE banner appears). The Brain's path-finder links here directly.Adversary view Login
Flips the graph to a ransomware crew's perspective. Pick a group from the dropdown (each shows its victim count) and read its operational profile — sponsor, victims, velocity/day, KEV count, target sectors and countries, and recent victims — rendered as a radial diagram (actor core → sectors → countries → victims).
Interaction model Login
Models how V01d sentiment meets Signal/Fusion threat actors and their attributed countries. The PROFILES tab browses per-actor cards (attribution, stories, co-mentioned peers); the MATRIX tab is an actor × country interaction-intensity heatmap (hover a cell for the exact score).
ninjaTONE — the public Oracle Public
A free, no-login daily cross-graph intelligence briefing that fuses V01d + Signal + Fusion + global news into one threat picture — the public face of the Oracle. It refreshes daily.
- Open
ninjav0id.io/ninjatone(no login). - Read the THREAT ASSESSMENT gauge (level + score /100), then jump around with the NAVIGATE chips.
- Explore the sections — a 3D threat galaxy, executive summary, the Fusion SITREP, Signal's threat theatre, the sentiment landscape, predictive intelligence, a live news wire, and the Threat Map Playground (hover/click actors and campaign arcs).
- Use the inline Claude buttons to copy a research prompt and open claude.ai for any entity.
The Brain — situation room Login
A multi-graph situation room: one scrolling dashboard that scores threat posture, narrates it in plain English, predicts intent, flags anomalies, and streams fresh events — auto-refreshing every 60 seconds, and never spending AI tokens unless you ask.
The header controls
- VIEW preset
- FULL / CISO / SOC / BOARD — tailors which sections render for your audience (saved locally).
- Time Scrubber & Replay
- A storm-intensity sparkline + slider to rewind the whole dashboard to a past hour; ▶ replays storm history; ⟲ snaps back to live.
- Exports
- ⬇ JSON (state snapshot), ⬇ MD (briefing), ⬇ STIX (STIX 2.1 bundle).
- − KEV
- A counterfactual toggle that recomputes the storm without CISA-KEV events.
Key interactive tools on the dashboard
- Posture Hero — a 0–100 gauge with a 24h trend and five weighted component bars.
- ASK — ask the brain a free-text question; see the answer + which tools it called, and ★ SAVE HUNT to keep it.
- Exec Briefing — a Claude-written briefing with text-to-speech (▶ PLAY, speed control) and ⟳ REGEN.
- Path-Finder — enter two entities (e.g. APT28 → Microsoft) and FIND the shortest path; open the chain in the Void galaxy.
- Alert Rules — build threshold rules (field/operator/value) that fire browser notifications; Notebook, Sigma Rules (copyable YAML), and Webhooks (Slack/Discord) panels.
Beyond the dashboard, the Brain opens onto a set of specialised views (below). A 📍 pin button on most cards captures findings into an investigation on the Pinboard, and a ☆ watch-list star pins entities to the dashboard.
/brain/welcome is a ~90-second guided tour, and /brain/docs is a live, filterable catalogue of the /void/* API.Brain visualizations Login
- Network — actor × sector × country
- A force-directed relationship graph over a 7–60d window; toggle node types, hover to isolate a node's neighbours, and open its dossier.
- Flow — kill-chain Sankey
- A four-stage Sankey (country → actor → sector → technique); ribbon width = claim volume; hover a node to isolate its chain.
- Galaxy — actor universe
- A 3D galaxy where each ransomware actor is a star sized by victims; click a star for its predicted next target and dossier.
- Heatglobe — risk weather
- A 3D globe with per-country risk bars; click a bar for its risk tiles and country dossier.
Brain analysis tools Login
- ATT&CK Matrix
- A heatmap of active threat groups × MITRE techniques, coloured by tactic; click a group to drill in.
- Hunts
- Save natural-language hunt questions and re-run them on demand (or ⟳ RUN ALL), keeping each latest answer.
- Detection Rules
- A review queue of auto-generated Sigma/Snort/YARA candidates — ⟳ SYNTHESIZE FROM CLAIMS, then inspect and ✓ APPROVE / ✗ REJECT.
- Cases
- A lightweight investigation tracker: create a case, advance it through states, attach refs/notes, and export a portable
.v01dcase file. - Compare
- Load two brain snapshots side by side and see exactly what changed (storm, sectors, actors, hypotheses, country risk).
- What If…
- Mute actors, sectors, or sources and recompute the picture without them, then read the delta from the real baseline.
- Hypotheses
- A reasoning ledger — each hypothesis has a claim, a confidence, a falsifier (what would refute it), evidence with deep-links, and the history of the same reasoning over time.
Dossiers & the pinboard Login
Deep-dive profiles you reach by clicking any entity across the Brain:
- Actor dossier
- Recent victims, an intent prediction (next sector/country), an activity timeline, an IR Playbook and an Adversary Playbook (operational cadence — hour-of-day/day-of-week heat strips), peer actors, and a local notebook.
- Country dossier
- Who's attacking, which sectors, recent victims, peer countries (by actor overlap), and news tone.
- Sector dossier
- Curated risk factors, top groups, intent predictions, geographic spread, recent victims, and related news.
- Pinboard — case files
- Organise the 📍 pins you capture across the Brain into named investigations, then ⤓ EXPORT any one as a portable case file. (All browser-local.)
V0id Agents — autonomous SOC Maintenance
/v is serving a maintenance page while it's being updated; the capabilities below describe the app when it's live.An autonomous, LLM-powered defensive SOC ("AGENTIC AI DEFENSE / POWERED BY CLAUDE"). Three AI agents perceive, reason, decide, and act on security alerts: Sentinel (triage), Warden (containment), and Spectre (threat hunting). It's a windowed desktop (drag/resize windows, bottom taskbar, layout persists); Command Center opens by default.
The windows
- Command Center — a live dashboard of all three agents, open incidents, and recent AI decisions.
- Sentinel — monitor triage and inject a test alert (edit the JSON, click INJECT ALERT, watch the decision + rationale).
- Warden — review containment actions; ROLLBACK reversible completed ones.
- Spectre — launch a manual threat hunt (describe what to hunt for → EXECUTE HUNT → read findings).
- IR Playbooks — browse SOAR playbooks and TRIGGER them; watch executions run through their phases.
- Incidents — filter and advance incident lifecycle (open → investigating → contained → resolved).
- Decisions — an audit trail of agent reasoning (with LLM latency) and the raw action log.
- Context — a Neo4j graph console with node counts and a Cypher query box.
- Coverage Map — MITRE ATT&CK detection-coverage overview and gaps.
- Rule Tuner & Correlations — auto-generated detection-threshold and multi-event correlation recommendations.
- Forensics — view collected evidence/packages and INITIATE COLLECTION (memory / disk / network) on a host.
- Claude AI — a conversational assistant for config, incident analysis, playbooks, and hunting.
- Admin — set the agents' autonomy level (Notify-only → Full-auto) and manage users.
Los Alamos — live-fire cyber range Login
An agentic live-fire cyber range: autonomous Red Team AI agents (Kage, Oni, Yurei) attack a simulated enterprise network while the V0id Blue Team defends — a full LLM-vs-LLM battle you configure, launch, and spectate. It's a windowed desktop (drag + minimize/close).
Run a full exercise
- Workbench — either click LAUNCH on a Quick-Launch scenario, or configure SETUP (environment template, difficulty, chaos level) → ADVERSARY (threat actor, optional Chimera/Randomize) → LAUNCH → 発射 INITIATE LIVE FIRE.
- Arena or Theatre — spectate the live battle tick-by-tick; Theatre adds a network-topology map, damage/containment panels, and a SPEED slider to pace the sim.
- Track detail with Kill Chain (phase heatmap), Topology (per-host drill-down), Casualties (blast radius), Timeline, and Commentary (play-by-play).
- When it ends, review Scoreboard (winner, history, ELO leaderboard) and step through Replay (VCR-style scrubbing).
Extra views
- Kage / Oni / Yurei — per-red-agent telemetry (recon/access, execution/lateral/persistence, evasion/C2/exfil).
- V0id Agents (Blue) — the defending agents' health and activity.
- Grudge Match — pit two fully-configured AI lineups (choose Claude / GPT / Gemini + model per side) on the same scenario and compare verdicts.
- Environment — preview a network template (Enterprise, Cloud Hybrid, ICS/SCADA, Healthcare, Financial, Small Business) or inspect the live match's network.