H3AD-SEC · AI-ASSISTED ANALYSIS HUB

Seven AI Tools Built for
SOC Workflows.

VERDIKT-AI, INSIGHT-AI, QUERYCRAFT-AI, FPLENS-AI, ATTMAP-AI, CHRONO-AI, MALBRIEF-AI, and PROMPTVAULT, each purpose-built for a distinct analyst workflow. L3 analyst persona throughout. Client-side execution, no data stored, no account required.

ZERO DATA RETENTION BROWSER-NATIVE MULTI-SELECT MODES PARALLEL EXECUTION NO ACCOUNT REQUIRED
7AI TOOLS
4AI PROVIDERS
ZERODATA RETENTION
4SIEM FORMATS

An analyst shouldn't spend forty minutes writing the same runbook for the same alert type for the hundredth time. Pick the tool. Paste the alert. Get L3-grade output in seconds.
No backend. No retention. Your API key, your LLM, your output.

TOOLS
AI Tools 7 Tools Live
Use Cases SOC Workflows
Persona L3 Analyst
Privacy No Data Stored
INSIGHT-AI
LIVE
AI Runbook Generator · L3 Analyst Persona
AI runbook generator with an L3 analyst persona. Produces a structured 10-section investigation playbook from a single alert input.
FULL RUNBOOK
10-section parallel generation, summary through containment
TRIAGE
Severity badge + ordered L3 investigation chain
PLAYBOOK
L1 / L2 / L3 / IR tiered response steps
FP LENS
TP / FP / Benign breakdown with verdict guide
QUERIES
DETECT and HUNT queries in your SIEM format
ATT&CK
Sub-technique mapping with actor attribution
ARTIFACTS
Structured IOC extraction with confidence scoring
TIMELINE
Chronological event reconstruction from raw logs
L3 SOC analyst persona, APT hunting depth, precise MITRE sub-techniques (T1059.001 not T1059), DETECT and HUNT query prefixes, forensic artifact specificity with exact event IDs and registry paths
Strict data discipline, no hallucinated IPs, hashes, or filenames; severity is never inflated; every output element is grounded in your input or omitted entirely
Multi-select execution, combine any modes; parallel API calls with per-mode skeleton slots and independent per-mode retry on rate limit or failure
Auto-groups fire when context is present, timeline reconstruction, cross-source correlation, and artifact extraction run automatically alongside the standard sections
Export in four formats, Markdown, JSON, YAML, plain text, or copy the full runbook to clipboard in one click
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
8 MODES · 4 PROVIDERS · KQL · SPL · SIGMA · XQL · EXPORT MD / JSON / YAML / TXT
LAUNCH INSIGHT-AI →
QUERYCRAFT-AI
LIVE
AI Detection Query Builder · KQL · Sigma · XQL
Describe what you want to detect in plain language, get a structured KQL, Sigma, or XQL query with MITRE tagging.
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
4 SIEM FORMATS · DETECT + HUNT TRACKS · MITRE COVERAGE · KQL · SPL · SIGMA · XQL
LAUNCH QUERYCRAFT-AI →
FPLENS-AI
LIVE
"Tune smarter. Detect cleaner."
Analyse a detection alert for false positive likelihood. Outputs suppression suggestions and whitelist logic.
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
RULE LANGUAGE AUTO-DETECTED · FP / TP ANALYSIS · EXCLUSION GENERATION · TUNING GUIDANCE
LAUNCH FPLENS-AI →
ATTMAP-AI
LIVE
"Behavior to ATT&CK. Mapped."
Map an alert or log snippet to MITRE ATT&CK techniques and sub-techniques with confidence scores.
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
ATT&CK ENTERPRISE · TECHNIQUE + SUB-TECHNIQUE · CONFIDENCE SCORING · KILL CHAIN MAPPING
LAUNCH ATTMAP-AI →
CHRONO-AI
LIVE
"From logs to kill chain. Chronologically."
Reconstruct a kill chain timeline from log events, ordered by MITRE phase, with lateral movement and persistence flagged.
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
MIXED LOG FORMATS · KILL CHAIN STAGES · MITRE TECHNIQUE MAPPING · GAP ANALYSIS
LAUNCH CHRONO-AI →
MALBRIEF-AI
LIVE
Malware Classification · MITRE Mapping · Detection Signatures
Submit behavioral indicators to an AI analyst and get malware classification, MITRE ATT&CK technique mapping, detection signatures, and hunting pivot recommendations.
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
MALWARE CLASSIFICATION · MITRE TECHNIQUES · DETECTION SIGNATURES · HUNTING PIVOTS
LAUNCH MALBRIEF-AI →
PROMPTVAULT
LIVE
AI Prompt Arsenal · Community Vault · SOC Analyst Toolkit
Community-driven library of AI prompts for SOC analysts, detection engineers, and threat hunters. Browse, filter, and copy prompts by role, task, and platform.
SOC ANALYST · DETECTION ENGINEERING · THREAT HUNTING · AI PROMPTS
LAUNCH PROMPTVAULT →
VERDIKT-AI
LIVE
IOC Enrichment + AI Analysis · Narrative · MITRE · Detection Queries
Deep IOC enrichment across 9 sources (VT, AbuseIPDB, OTX, ThreatFox, URLScan, URLhaus, MalwareBazaar, HybridAnalysis) with BYOK AI analysis — analyst narrative, MITRE ATT&CK mapping, and KQL/SPL/Sigma query generation per IOC.
CLAUDE (ANTHROPIC) GPT-4O (OPENAI) GEMINI FLASH (GOOGLE) LLAMA 3.3 (GROQ)
IP · DOMAIN · URL · HASH · BYOK · MITRE MAPPING · KQL · SPL · SIGMA · 9 SOURCES
LAUNCH VERDIKT-AI →
BUILT FOR SECURITY TEAMS
01
ZERO DATA FOOTPRINT
Your alert travels directly from browser to the LLM provider you choose. No H3AD-SEC backend, no logging, no retention. API keys live in localStorage and never leave your machine. Safe for sensitive alert context.
02
L3 ANALYST GRADE OUTPUT
The underlying persona is a senior threat hunter, APT campaign experience, malware analysis depth, production SIEM rule authorship, IR for critical infrastructure. The analyst gets L3-quality guidance executable without hand-holding.
03
YOUR STACK, YOUR PROVIDER
KQL, SPL, Sigma, or XQL. Claude, GPT-4o, Gemini Flash, or Groq. Your API key, your model, your budget. Switch provider per session with no re-configuration. Bring your own contract.
TRUST & ARCHITECTURE
BROWSER-ONLY
NO SERVER COMPONENT
ZERO RETENTION
NO H3AD-SEC LOGGING
localStorage
API KEYS NEVER TRANSMITTED
BYOK
BRING YOUR OWN KEY
STATIC DEPLOY
GITHUB PAGES / NO RUNTIME
← BACK TO H3AD-SEC
VISITORS