Ninja Labz · R&D for ninja.ing

See the attacker before it has a name.

Local sensors fingerprint hostile traffic where your logs live. Our attribution engine names the botnet behind it, with a confidence score and the evidence to check it. CHATTER reads eleven live threat feeds so your team doesn't have to.

B-2 · low observable · high certainty
41,794edge requests fingerprinted in one day
0.54 sfor a local sensor to read all of them
0.91confidence: a Mirai botnet node, named from our own logs
11live threat feeds in one deep read
01 · The films

Real traffic. Real feeds. Nothing staged.

Both recorded end to end in 4K on the live platform on 24 September 2026. What you see is what the lab saw.

Adversary DNA: we named the botnet

From one suspicious request to a named Mirai botnet at 0.91 confidence, with the evidence chain and an incident Claude triages on its own.

Direct attributionLocal sensor93 s

CHATTER: eleven feeds, one deep read

Leak sites, dark-web mirrors, KEV, IOCs, Telegram and news, correlated to the graph and read into calibrated, falsifiable forecasts.

Deep forecastNovelty scoring78 s
02 · Direct attribution

Not “this IP is bad”. What it is, why, and how sure.

A reputation lookup gives you a verdict. Our attribution engine gives you a name, a confidence score and the evidence behind it. Independent evidence is combined, and nothing is asserted without it. If the graph can't prove an actor, it names none.

  • E1 · IOCOur threat intel had the IP serving Mirai builds for every IoT CPU, matched through the payload URL, not just a bare IP.
  • E2 · /242,344 known-bad indicators in its neighbourhood, 1,274 of them Mirai.
  • E3–E6Cited botnet tradecraft, actor bridges, shared behavioural DNA, coordinated campaigns.
0.91HIGH1 − (1−0.85)(1−0.40)
Evidence chain: 94.154.43.164 attributed to Mirai at 0.91 confidence
03 · Capabilities

What's on the bench.

An isolated, off-production stack with its own graph. It reads the estate. It never writes to it.

01

Local detection sensors

Analysis runs on the host that owns the logs. Only findings ship; raw logs never leave the box.

Live
02

Adversary DNA

A behavioural fingerprint per hostile source. The same DNA from new IPs exposes operators rotating addresses.

Live
03

Direct attribution

Botnet, campaign and actor, each with a confidence score, a band and a checkable evidence chain.

New
04

CHATTER

Eleven live feeds embedded on the box, linked to the nearest known threat, scored for novelty, read into a forecast.

Live
05

GraphRAG copilot

Ask the threat graph in plain language. Answers are cited to graph nodes, and refused when the graph has nothing.

Experimental
06

PRISM foresight

Link prediction over research graphs: where two fields are about to collide, with the backtest published.

Experimental
How CHATTER builds the deep report: eleven feeds, embed and correlate on the box, deep forecast

How we work.

Your logs stay home

Sensors fingerprint locally. Only findings, and the IPs you choose to check, leave the host.

Evidence or it didn't happen

Every attribution carries its chain. Every confidence has a formula you can recompute.

Receipts, including misses

Forecasts carry a window and get graded in public. Last edition: one hit, one miss, one unverified.

Off-production by design

Its own network and graph. Experiments can break here without touching anything live.

04 · Access

Put Adversary DNA on your own edge.

We're opening the lab to a small group of design partners: security teams with a web edge, a SOC and a preference for evidence. You keep your logs. We bring the sensor, the threat intel and the attribution engine.

Request access Sign in to the console
Accounts are reviewed by a person, usually within a day. Questions: [email protected]