Your server is under attack. This is what happens next.
dalla piattaforma01
Detect
Repeated SSH authentication failures arrive on your server. OrionEye plots each source the moment it appears, instead of leaving it in a log nobody reads.
OSINT di prossimità02
Investigate
One hostile address, opened: geolocation, autonomous system, network owner and reputation, side by side on the map. Ask in plain language and the AI runs the tools for you.
rilevamento campagne03
Correlate
Scattered addresses stop being scattered. The AI groups them into one coordinated campaign with a confidence score, so you answer a campaign and not two hundred separate lines.
difesa attiva04
Respond
Block the whole campaign through fail2ban on your own servers, report it to AbuseIPDB, share the finding. Through OmniAgent the action lands on your real infrastructure.
The four steps above do not all open at once. Each plan is a verb — what you are able to do, not what you have bought.
Free·EXPLORE
The public world, on the map.
The 3D globe with OpenStreetMap buildings extruded at their real heights, satellite imagery and terrain relief.
NASA EONET disasters, ESA launches, live ISS tracking, weather layers, traffic cameras and news.
The shared threat feed: what other analysts are seeing, as they see it.
Pro·INVESTIGATE
Your own infrastructure, from the USB stick.
Uncover Engine: one query to Shodan, Censys, FOFA, ZoomEye, IPinfo and AbuseIPDB at once, on your own API keys, merged into one record per address on the map and the globe.
OmniAgent OS runs on your machine, even from the stick: your servers, a remote terminal, Wi-Fi surveys, and an encrypted Vault that never reaches the cloud.
Orion IA audits your own accesses and devices, and the AI orchestrates eight cloud models.
Enterprise·DEFEND
Nothing leaves the company.
Uncover Engine without limits: company-managed keys instead of personal ones, and recursive reconnaissance over a whole ASN or CIDR block rather than one host at a time.
SentraLink: local network telemetry and security alerts, read from inside the perimeter.
Models run locally, in a container on your own hardware — the analysis never reaches anyone’s cloud, air-gapped included.
File system deep-dive and an ECDSA-signed licence bound to your infrastructure.
Connect Grok & MCP-Compatible LLMs to Active Defence
Ask natural-language questions about SSH threats, campaign confidence, AbuseIPDB context and the shared Intel Feed through a standalone MCP gateway.
Grok/xAI directory availability subject to vendor support and approval
01 · PROVISIONAn administrator provisions a workspace URL and bearer token with the gateway CLI. In-app token provisioning is planned, not available yet.
02 · CONNECTAdd the HTTPS endpoint to a client that supports custom remote MCP servers, such as Claude Code.
03 · INVESTIGATEQuery threat intel and submit moderated feed items. Campaign blocking remains an operator-reviewed proposal in this release.
MCP is in private preview. Grok/xAI custom connector availability has not been verified; no official directory partnership or listing is claimed. MCP does not execute Fail2Ban actions.
OrionEye is a unified intelligence platform combining cyber analysis, geospatial visualization,
space tracking, job intelligence and AI orchestration. It provides real‑time tools for IP analysis,
routing, satellite data, weather layers, job search, and space events — all powered by an interactive
map and Gemini AI.
Created by Samuel La Manna, OrionEye integrates OSINT capabilities, RIPE Atlas network probes,
NASA EONET natural disaster monitoring, ESA orbital launch data, real‑time ISS tracking,
traffic surveillance cameras, and Google Analytics — all orchestrated through Gemini AI
natural language commands on an interactive Google Maps interface.
OmniAgent Link
Pair OrionEye with OmniAgent OS on your own machine and bring your servers onto the map — SSH access, diagnostics and live telemetry no public API can give.
Threat Mapping
Every SSH attacker geolocated, cross‑checked against public reputation lists, and read by AI — who is hitting you, from where, and who already got in.
Active Defence
AI clusters attackers into coordinated bot campaigns with a confidence score — then you block an entire campaign in one click via fail2ban, with live progress. From detection to defence, on the map.
Intel Feed
A shared, moderated board where your team posts indicators, incidents and findings — collaborative threat intelligence in real time, tagged by type and severity.
Cyber Intel
IP geolocation, DNS, traceroute, ping, RIPE Atlas, malware C2 tracking — full network visibility.
Geo Intelligence
Interactive map with routing, live cameras, weather, Street View, area inspection and satellite tiles.
Space Tracking
ISS tracker, ESA launches, astronauts, launch pads, space stations — real-time orbital data.
3D Globe
Switch the whole map to a rotating globe with OpenStreetMap buildings extruded at their real heights. Every layer and every tool keeps working on it — nothing is a separate view.
Area Briefing
Draw an area or drop the reticle: every active layer inside it is counted and listed, each element ringed on the map, with a written read-out of the territory beside the circle.
Event Video
Click a hurricane, a wildfire or a conflict marker and OrionEye searches the web for related footage, then plays it in its own player — no tab switching.
Multi-LLM AI
Agentic orchestration over every module. Gemini by default, or any provider on your own key — it runs the tools, draws the diagrams, explains the analysis.
Platform Capabilities
3D Globe · SSH markers, country cards and campaign vectors carry acrossMalware C2 · QakBot, Emotet and distribution nodes located and ringed inside the area
Network Forensics & OSINT
Perform deep IP geolocation, DNS resolution, multi‑hop traceroute visualization, and RIPE Atlas probe analysis. Identify network paths, autonomous systems, and routing anomalies in real time on an interactive map.
Network Forensics & OSINT · live demo
Space & Orbital Intelligence
Track the International Space Station in real time, monitor ESA rocket launches, explore global launch pads, and overlay NASA EONET natural disaster events — wildfires, storms, volcanic eruptions — directly on the map.
AI‑Powered Orchestration
Drive all 20+ modules through natural language. Gemini by default, or bring any provider on your own key — the AI runs the tools, draws the diagrams and explains the analysis, and through OmniAgent OS it reads your own servers: SSH logs, diagnostics and live telemetry no public API can offer.
Active Defence & Response
Move from detection to defence: AI correlates SSH attackers into coordinated bot campaigns with a confidence score, then you block a whole campaign — or every unblocked offender — in one click via fail2ban, cross‑check and report to AbuseIPDB, and share findings on a collaborative, moderated intel feed.
Uncover Engine — Multi‑Engine OSINT Aggregator
Instead of running the same query by hand on five platforms and stitching the answers together in a spreadsheet, ask once. OrionEye sends one reconnaissance query to Shodan, Censys, FOFA, ZoomEye, IPinfo and AbuseIPDB at the same time and returns one record per address — open ports with product and version, hostnames, ASN, reputation, CVEs the engine itself declares — plotted on the 2D map and the 3D globe together, each marker clickable for the full card. The record carries its provenance: you see which engines confirmed a finding and which never answered, because three engines agreeing is not the same fact as one engine guessing. Nothing is inferred: a vulnerability is shown only where an engine declares it.
Beyond threat intel: map the infrastructure itself. Every tool in the platform — bot campaigns, OSINT cameras, satellites, natural events — renders as an interactive 2D/3D relational graph. Single brute‑force attempts are told apart from coordinated campaigns and linked to their ASN group and Master C2 node. Click any attacker and a proximity agent sweeps the ground around it: local news on outages and blackouts, public webcams in range, notable places nearby — because an address knocking from a city that has been dark for six hours is a different story from one knocking from a quiet datacentre. Network topology and server file systems require an OmniAgent USB key.
Multi‑LLM Agentic Engine & Source Topology
Human‑in‑the‑loop investigation: the agent proposes what to examine on the node you clicked, and nothing runs until you approve it. Connect Gemini, Claude, OpenAI and local models in Docker on OmniAgent OS through your USB Vault, and every question goes to all of them at once. You get measured latency and output rate side by side, an OrionAI synthesis of where they agree and where they contradict each other, and a topology map of the sources they cited — with YouTube videos playable in place. Accuracy is deliberately not scored: nobody here knows which answer is right, so what is shown is agreement between models, which is an observable fact.