ninjatone ✨ -> Free morning TIP access, and more -> with your morning coffee, and doomscroll
Most people build threat intelligence platforms because they identified a gap in the market.
I built one because I couldn't sleep.
Not in the romantic, tortured-genius way. In the "I just read about Volt Typhoon pre-positioning in US critical infrastructure and now I'm staring at my ceiling at 3am wondering if the water treatment plant down the road is running Fortinet" way.
So I did what any reasonable person would do. I opened a terminal at 3:47am, poured something Turkish (tea), and started writing Python.
That was the first line of code. There are now approximately 400,000 more.
The problem with cyber threat intelligence isn't that it doesn't exist.
It's that it exists in 47 different places, speaks 12 different taxonomies, costs more than my mortgage, and by the time you've normalised it into something actionable, Lazarus Group has already stolen another $1.5 billion in crypto and still can't afford decent OpSec.
The fundamental psychological trap of modern CTI is this: the more you know, the less you act. Information abundance creates decision paralysis. You're drowning in CVEs, swimming in IOCs, buried under MITRE techniques, and your board still asks "so... are we secure?" while you die a little inside.
I wanted to build something that answers that question. Not with a 200-page PDF. Not with a $250k/year platform license. With a single number. A vibe. A tone.
ninjaTONE.
Here's the philosophical bit. Bear with me.
Sun Tzu said "know your enemy and know yourself, and you will not be imperilled in a hundred battles." Beautiful advice. Absolutely useless in 2026 when your enemy is a mass-resourced nation-state APT hiding inside a Cisco router and "knowing yourself" means auditing 14,000 SaaS applications your marketing team signed up for with their personal Gmail.
The real insight isn't in Sun Tzu. It's in Kahneman.
System 1 and System 2 thinking. Your SOC runs on System 1 — fast, reactive, pattern-matching. Alert fires, analyst triages, ticket closes. Repeat 400 times a day until burnout. Your threat intel team should run on System 2 — slow, deliberate, strategic. But they can't, because they're also drowning in the same alert tsunami, writing the same reports nobody reads, and attending the same meetings where someone asks "what's our risk posture?" and everyone looks at each other.
ninjaTONE is what happens when you force System 2 thinking into a System 1 interface.
One page. Every morning. Everything that matters. Nothing that doesn't.
What's actually on it:
A daily cross-graph intelligence briefing that pulls from three separate knowledge graphs containing 160,000+ nodes of threat intelligence, runs ML models across all of them overnight, correlates global sentiment data from GDELT, RSS, Reddit, and FRED economic indicators, and compresses the entire state of thecyber threat landscape into something you can read while your coffee cools.
- Threat gauge — A single 0-100 score. The number your CISO actually wants. Derived from graph velocity, sentiment anomalies, active campaigns, and ML risk propagation. Not vibes. Math.
- Fusion Daily SITREP — Trending CVEs with CISA KEV badges, active threat actors with TTP counts, supply chain risks, and breach tracking. The brief your team writes manually, generated automatically.
- Animated threat intelligence network — A force-directed graph with 300 twinkling stars, nebula halos, radar sweep, and orbital rings around high-risk nodes. Because data visualisation should make you feel something. Yes, I gave it a space aesthetic. No, I will not apologise.
- Threat actor roasts — Rotating commentary on APT groups that is both technically accurate and emotionally satisfying. APT28: Fancy Bear? More like Sloppy Bear after that GRU leak. Scattered Spider: their OPSEC is posting screenshots on Discord. Bold strategy.
- Cyber Sentiment Barometer — Real-time sentiment analysis across 7 security-focused sources. When the internet starts talking about a vulnerability with negative sentiment velocity, you want to know before it trends.
- Predictive intelligence — ML link predictions on what connects next in the threat graph. Technique adoption forecasts. Activity projections. The future, probabilistically.
- Live global news wire — GDELT articles auto-categorised into cyber, geopolitical, vulnerability, crisis, and technology. The open-source intelligence firehose, filtered into a garden hose.
And here's the bit that makes procurement departments nervous:
It's free. No login. No paywall. No "book a demo" button that routes you to a 22-year-old SDR named Jake.
"But Scott, why would you give this away for free?"
Because the cybersecurity industry has a grotesque incentive problem.
The vendors who sell threat intelligence have a financial interest in you being afraid. Fear sells renewals. Complexity sells professional services. Opacity sells consulting hours. The entire industry is built on the implicit promise that security is too hard for you to do yourself, so please sign this enterprise agreement and we'll handle it.
I think that's philosophically bankrupt.
The threats are real. The fear-mongering is not. And the people who need threat intelligence most — the under-resourced SOC analyst at a hospital, the lone security engineer at a startup, the CISO of a mid-market company with a budget that wouldn't cover CrowdStrike's catering — those people get nothing.
ninjaTONE is for them.
The paid platforms behind it — Signal, Fusion, Nexus, Raz0r, Kin0bi, V01d, V0id — those are for the teams that want the full graph, the ML lab, the digital twins, the autonomous agents, the detection engineering pipeline. But the daily briefing? The situational awareness? The answer to "what happened overnight?"
That should be free. And now it is.
The technical bit, for the engineers still reading:
This is not a dashboard connected to someone else's API.
This is nine interconnected platforms, seven Neo4j knowledge graphs, 80+ data ingesters, ML pipelines running GCN/GAT graph neural networks, Hawkes process activity forecasting, Monte Carlo campaign simulation, Louvain community detection, isolation forest anomaly detection, and a sentiment engine processing GDELT's 15-minute global knowledge graph updates.
It's FastAPI and Next.js 16. It runs on one server. I built it alone.
Not because I'm special. Because I'm stubborn. There's a meaningful difference, and if you've read this far, you probably understand it.
The Nietzsche bit, because apparently we're doing this:
"He who has a why to live can bear almost any how."
My why is simple: I believe the asymmetry between attackers and defenders is not a technology problem. It's an information problem. Attackers share freely — tools, techniques, exploits, access — on forums, Telegram channels, and dark web marketplaces. Defenders hoard behind paywalls, NDAs, TLP:RED markings, and enterprise licenses.
We will never win this game by outspending the adversary. We win by out-sharing them.
ninjaTONE is a small bet on that thesis.
One engineer. Nine platforms. 400,000 lines of code. Zero VC funding. Free daily briefing.
Read it at ninjav0id.io/void/ninjatone
Or don't. Lazarus Group doesn't care either way. They're busy.
虚空予知
The void sees what others cannot.
Scott Gardner is a security engineer at ninja.ing who builds things at 3am and writes LinkedIn posts at unreasonable lengths. He has mass-deployed a stealth bomber aesthetic across nine production platforms and feels no remorse. If you're hiring, he's not available. If you're a threat actor, he's already graphed you.
#cybersecurity #threatintelligence #ninjatone #buildinpublic #infosec
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·