TriAXIS · Unified Cyber Risk Monitoring Console
TriAXIS
Admin Portal
SOC Analyst
{{ r.icon }}
{{ r.label }}
TriAXIS
{{ n.label }}

Unified Risk Dashboard

Global Risk
78
High
Last Correlated: 06:03 · Last 24 Hours
Monitored Assets
142 Int · 38 Ext
Active IOCs
3.805
Critical Priorities
14
Auto-Triage
99,4%
Monitored Assets
142 Int · 38 Ext
Active IOCs
3.805
Critical Priorities
14
Auto-Triage
99,4%

Priority Risk Queue

6 Findings
RPS
Axis
Findings
Signal
Severity
{{ f.rps }}
RPS
{{ f.title }}
{{ f.asset }}
{{ b.t }}
{{ f.severity }}

Risk trend · 30 days

78 High
100500
30 Days agoNow

Severity distribution

{{ s.label }}
{{ s.count }}
Internal Vulnerability
218
Open Vulnerabilities
9
Critical
External Attack Surface
38
External Assets
5
Shadow
Cyber Threat Intelligence
379.700
Indicators
47
Matching AHU assets

Internal Vulnerability Management

Scheduled scanning & Auto-Triage of internal ICT asset vulnerabilities.

{{ k.label }}
{{ k.value }}
Scan Coverage
93%
Scanned
SIEM Sources
{{ s.n }}
Next scan at 22:00
Findings
Severity
Title
Host
Verdict
KEV
Status
{{ r.sev }}
{{ r.title }}
{{ r.host }}
{{ r.v }}{{ r.conf }}
KEV
{{ r.status }}
Internal Assets · 142
Host
Type
Zone
Vulnerabilities
Last scan
Risk
{{ r.host }}
{{ r.kind }}
{{ r.zone }}
{{ r.vuln }}
{{ r.scan }}
{{ r.risk }}
Scan History & ScheduleDaily 22:00 · credentialed weekly
Scan
Time
Scope
Findings
Status
{{ r.name }}
{{ r.when }}
{{ r.scope }}
{{ r.found }}
{{ r.status }}
Remediation & Tickets
Item
Host / target
Owner
SLA
Status
{{ r.item }}
{{ r.host }}
{{ r.owner }}
{{ r.sla }}
{{ r.s }}

External Attack Surface

Assess AHU's internet-facing assets from an attacker's perspective, plus Digital Risk Protection.

{{ k.label }}
{{ k.value }}
{{ k.note }}

Exposure Score

71
High
Largest contributors
11 findings critical
3 expired certificates
5 assets unmanaged

Severity Distribution

total 214
{{ s.label }}
{{ s.n }} {{ s.pct }}

Findings by Category

{{ c.label }}
{{ c.n }}

Discovery Sources

305 subdomains · 9 sources
{{ c.label }}
{{ c.n }}

Attack surface map

ahu.go.id · 38 assets
Critical High Low Shadow

Ports & certificates

Open ports
{{ p.p }} {{ p.n }}
TLS certificates
{{ c.label }} {{ c.n }}
TLS issues
{{ c.label }} {{ c.n }}

OWASP Top 10 Coverage

{{ c.label }}
{{ c.n }}

Detected Services

{{ c.label }}
{{ c.n }}

Top Vulnerable Assets

{{ c.a }}
{{ c.score }} {{ c.r }}

Top Risks

{{ c.sev }} {{ c.label }} {{ c.n }}
Latest Findings
Severity
Finding
Asset
Type
When
{{ r.sev }}
{{ r.f }} KEV
{{ r.a }}
{{ r.ty }}
{{ r.w }}
Domain / IP
IP Address
Score
Status
Last scan
Axis
Actions
{{ r.a }} {{ r.kind }}
{{ r.ip }}
{{ r.score }}
{{ r.st }}
{{ r.last }}
214 findings
{{ s.label }}
{{ s.n }}

Top CVEs

{{ c.cve }} KEV
{{ c.count }}

Top Vulnerability Findings

{{ c.label }} {{ c.n }}

KEV Exposure

Active dieksploitasi · CISA Catalog
{{ easm.kev.findings }} findings
{{ easm.kev.cves }} KEV
{{ c.cve }}{{ c.n }} findings
Domain
Severity
Findings
Risk
{{ r.a }}
{{ r.ip }}
{{ s.n }}
{{ r.count }}
{{ r.riskScore }}
Target
Status
Type
Started
Duration
Findings
{{ r.t }}
{{ r.st }}
{{ r.ty }}
{{ r.start }}
{{ r.dur }}
{{ r.n }}

Detect look-alike domains against AHU domains using 14 generation techniques.

Monitored domains
3
Scans completed
3
Total variants
1.184
Active threats
118
resolve to a live IP
{{ d.d }} Completed
{{ d.date }}
Risk Distribution
{{ d.variants }} variants
{{ d.activeN }}
ACTIVE
{{ d.critN }}
CRITICAL
{{ d.highN }}
HIGH
{{ d.medN }}
MEDIUM
{{ d.lowN }}
LOW

Monitor Certificate Transparency logs and newly registered domains for brand abuse.

Total events
148
Active threats
12
CT Log Events
96
NRD Events
34
Phishing Events
18

Monitored keywords (7)

{{ k }}

Status Feed

{{ f.n }}
{{ f.s }}
Threat Events
No threat events detected
No monitored keywords matched. Add a brand name or domain in the Monitored keywords panel, then sync the NRD and Phishing feeds to start monitoring.
Domain
Source
Keyword matched
Registered / seen
Risk
Status
{{ r.d }}
{{ r.src }}
{{ r.kw }}
{{ r.w }}
{{ r.r }}
{{ r.st }}

Aggregate, search, and triage forum and leak posts with keyword-based alerting.

Total Posts
18.412
512 in 24 hours · 3.506 in 7 days
AHU mentions
37
4 peringatan terbuka
Source
186/233
Critical + High
3.080
505 critical · 2.575 high

Ingestion trend · 14 days

14 days agokini

Severity Mix

18.412
{{ s.label }}
{{ s.n }}

Top targeted countries · 30 days

{{ c.label }}
{{ c.n }}

Top Sources by Post Volume

{{ c.label }}
{{ c.n }}

Threat Actors

{{ a.n }}
{{ a.t }} · {{ a.p }}
{{ a.r }}

Monitored sources (233)

{{ s.n }}
{{ s.k }} · {{ s.p }} posting
{{ s.st }}

Search Engines

No dark web search engines configured. Add an Ahmia or OnionSearch endpoint in Integrations to enable cross-index search.
{{ p.r }} {{ p.score }} {{ p.cat }} {{ p.src }} baru
{{ p.title }}
{{ p.snippet }}
{{ p.who }} · {{ p.when }}
Showing 1–25 of 18.412 Page 1 / 737

Analyse infostealer logs with multi-device ingestion, 20+ family detection, and watchlist correlation.

Credentials
9.573.937
71.234 new in 7 days
AHU credentials
214
+18 in 7 days
Compromised devices
4
Unique domains
49.121
Import batches
162
2 failed

Most Targeted Domains

{{ c.label }} AHU
{{ c.n }}

Top Stealer Families

{{ c.label }}
{{ c.n }}
Top Reused Passwords
••••••••••412×
••••••••288×
•••••••••••196×
Passwords are always masked and never shown in aggregate panels.

Device ingest trend · 30 days

30 days agodaily average (dashed) · now

Top Victim Geography

{{ c.label }}
{{ c.n }}
No geographic data yet. Import a stealer-log batch containing device metadata to map victim countries.
Combo Lists
File
Size
Lines
AHU matches
Added
{{ r.name }}
{{ r.size }}
{{ r.lines }}
{{ r.hits }}
{{ r.when }}
Import Batches
Batch ID
Source
Item
Status
Started
{{ r.id }}
{{ r.src }}
{{ r.items }}
{{ r.st }}
{{ r.when }}

Telegram Sources

The global Telegram account is managed in Integrations — this page only lists monitored channels and their polling status.

{{ c.n }}
{{ c.s }}
{{ c.last }}
Show passwords
Passwords are masked by default. Every reveal action is recorded in the audit log in line with the Personal Data Protection Act.
URL
Email / Username
Password
Victim
Captured
{{ r.url }}
{{ r.em }}
{{ r.pw }}
{{ r.fam }}
{{ r.w }}

Rogue Mobile Apps

No rogue mobile apps detected. Add the official AHU app names to start monitoring third-party app stores.

Cyber Threat Intelligence

Feed and IOC aggregation, exploit intelligence, actor profiling, and ATT&CK coverage.

{{ k.label }}
{{ k.value }}
{{ k.sub }}

AHU relevance

47 indicators match monitored AHU assets — these are the indicators that move the Risk Priority Score.

EASM + CTI
{{ r.label }}
{{ r.value }}

{{ cti.ingestion.title }}

{{ cti.ingestion.sub }}

{{ r.label }}
{{ r.value }} {{ r.note }}

{{ cti.sevMix.title }}

Across all active indicators

{{ cti.sevMix.total }} {{ cti.sevMix.totalLabel }}
{{ s.label }} {{ s.value }} {{ s.pct }}

{{ cti.indTypes.title }}

{{ cti.indTypes.sub }}

{{ r.label }}
{{ r.value }} {{ r.note }}

Latest intelligence

Newest reports and campaigns

{{ l.t }}
{{ l.k }} {{ l.s }} {{ l.w }}

Feed health

Feed
Type
Last sync
Records
Status
{{ r.f }}
{{ r.t }}
{{ r.s }}
{{ r.r }}
{{ r.st }}

Indicators

Manage and track threat indicators across the AHU environment.

379.700 indicators
Value
Type
Severity
Confidence
TLP
Source
First / Last seen
Actions
{{ r.v }}
{{ t.t }} {{ r.overflow }}
{{ r.ty }}
{{ r.sev }}
{{ r.confTxt }}
{{ r.tlp }}
{{ r.src }}
{{ r.seen }}

Observables

STIX Cyber Observable Objects (SCOs) — network, host, and artifact observations.

{{ k.label }}
{{ k.value }}
{{ k.sub }}
Observables are raw observations. Indicators are observables with a detection pattern and a verdict.
348.337 observables
Type
Value
Source
TLP
Sightings
First seen
Actions
{{ r.ty }}
{{ r.v }}
{{ r.src }}
{{ r.tlp }}
{{ r.si }}
{{ r.first }}

Intrusion sets

Track and profile intrusion sets and APT groups.

{{ a.n }} {{ a.geo }}
{{ a.d }}
{{ c.t }}
Targets government
First seen {{ a.f }}Last seen {{ a.l }}

Malware

Track malware families, variants, and capabilities.

{{ m.n }}
{{ m.d }}
{{ c.t }}
{{ m.note }}

Campaigns

Track threat campaigns and attack operations.

Name
Targets
Source
Status
First seen
Actions
{{ c.n }}
Relevant to AHU
{{ t.t }} {{ t.t }}
{{ c.src }}
{{ c.st }}
{{ c.f }}

Locations

Geo-distribution of threat origins, targets, and intrusion sets.

160 countries
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Country
Origin
Targeted
Sets
{{ r.c }} AHU home country
{{ r.o }}
{{ r.t }}
{{ r.s }}

ATT&CK coverage

Visual heatmap of MITRE ATT&CK Enterprise technique coverage based on observed threat intelligence.

{{ k.label }}
{{ k.value }}
{{ k.sub }}
0
13.440 indicators
{{ t.t }}
{{ t.n }}
{{ c.id }}
{{ c.name }}
{{ c.count }}

{{ cti.covBars.title }}

{{ cti.covBars.sub }}

{{ r.label }}
{{ r.value }} {{ r.note }}

CVEs & KEV

Track CVEs, exploits, PoCs, and vulnerability intelligence from multiple sources.

{{ k.label }}
{{ k.value }}
{{ k.sub }}
{{ k.sub }}

Vulnerability trend

Last 30 days · by publish date
Total Critical High

{{ cti.cveSev.title }}

Across all tracked CVEs

{{ cti.cveSev.total }} {{ cti.cveSev.totalLabel }}
{{ s.label }} {{ s.value }} {{ s.pct }}

{{ cti.vendors.title }}

{{ cti.vendors.sub }}

{{ r.label }}
{{ r.value }} {{ r.note }}

CISA KEV additions

Cumulative, last 12 months
Aug 2025Jul 2026

Latest CISA KEV

Known exploited vulnerabilities with remediation due dates

{{ r.cve }} {{ r.sev }} {{ r.vp }}
{{ r.d }}
Added {{ r.a }}Due {{ r.due }}

{{ cti.cveSources.title }}

{{ cti.cveSources.sub }}

{{ r.label }}
{{ r.value }} {{ r.note }}

Trending CVE timeline

Ranked by exploitation signal and EPSS movement

#
CVE
Severity
CVSS
EPSS
Vendor / product
Signals
Trend
{{ r.rank }}
{{ r.cve }}
{{ r.sev }}
{{ r.cvss }}
{{ r.epss }}
{{ r.vp }}
{{ r.rel }}
{{ b.t }}

Exploits & proof of concept

Weaponised code and templates mapped to tracked CVEs

CVE
Source
Type
Reference
Verified
{{ r.cve }}
{{ r.src }}
{{ r.ty }}
{{ r.ref }}
{{ r.v }}

Data sources

Feeds that populate the vulnerability corpus

Source
Type
Last sync
Records
Status
{{ r.n }}
{{ r.ty }}
{{ r.sync }}
{{ r.rec }}
{{ r.st }}

Malicious packages

Supply-chain extension of exploit intelligence — malicious open-source packages across npm, PyPI, RubyGems, NuGet, Go, Rust, Maven, and VS Code registries.

{{ k.label }}
{{ k.value }}
{{ k.sub }}

{{ cti.pkgEco.title }}

Detections per registry

{{ cti.pkgEco.total }} {{ cti.pkgEco.totalLabel }}
{{ s.label }} {{ s.value }} {{ s.pct }}

{{ cti.pkgVer.title }}

Declared version sanity

{{ cti.pkgVer.total }} {{ cti.pkgVer.totalLabel }}
{{ s.label }} {{ s.value }} {{ s.pct }}

{{ cti.pkgVer.caption }}

Detection timeline

Daily detections, last 30 days

Monthly trend

Detections per month

JanJul
34.970 results
Package
Ecosystem
MAL ID
Published
Severity
{{ r.n }} {{ r.ver }}
Embedded malicious code detected
{{ r.eco }}
{{ r.mal }}
{{ r.p }}
{{ r.sev }}
Showing 1–6 of 34.970 · Page 1 / 5.829

Package campaign network IOCs

Auto-updated daily

1.049 IOCs
Type
Value
Affected package campaign
Severity
Confidence
First seen
{{ r.ty }}
{{ r.v }}
{{ r.c }}
{{ r.sev }}
{{ r.conf }}
{{ r.f }}

Threat landscape

Comprehensive threat landscape analysis.

{{ r.title }}
{{ b.t }}
{{ r.period }}{{ r.gen }}

{{ r.sum }}

{{ m.v }} {{ m.d }}
{{ m.l }}

STIX reports

Manage and track STIX Report SDOs.

1.581 reports
Name
Type
Published
Refs
STIX ID
Actions
{{ r.n }}
{{ r.ty }}
{{ r.p }}
{{ r.refs }}
{{ r.id }}

Distribution

Push intelligence to AHU security controls.

Export format

Select the output format for your indicators

{{ g.g }}
{{ i.label }} {{ i.ext }}

Filters

Narrow the exported indicator set

Actions

Generate the file or check the output first

Every export is written to the distribution log below with the analyst or automation that triggered it.

Programmatic access

SIEM/SOAR integration via API key or basic auth

GET https://triaxis.ahu.go.id/api/export/snort
curl -H "Authorization: Bearer <YOUR_API_TOKEN>" \
  "https://triaxis.ahu.go.id/api/export/snort?severity=critical,high&min_confidence=70&limit=10000"
Recommended for Splunk, QRadar, Microsoft Sentinel, XSOAR, and TheHive.

Distribution log

Every push is recorded for audit

Timestamp
Destination
Format
Indicators pushed
Triggered by
Result
{{ r.ts }}
{{ r.dest }}
{{ r.f }}
{{ r.n }}
{{ r.by }}
{{ r.st }}

Correlation Queue

All findings are correlated, sorted by the highest RPS.

RPS
Axis
Findings
Signal
Severity
{{ f.rps }}
RPS
{{ f.title }}
{{ f.asset }}
{{ b.t }}
{{ f.severity }}
No findings light up this axis in the selected range.

Agent Org Chart

Reporting lines, roles, and permissions across {{ ag.count }} active agents

{{ k.count }}/ {{ k.total }}
{{ k.label }}
Legend
{{ l.label }}
Click a node to open its spec, tools.md, and skills.md. Its reporting chain stays lit.

Integrations

Connect SIEMs, security tools, and threat intelligence providers. All credentials are encrypted at rest.

{{ k.label }}
{{ k.value }}
{{ k.note }}

{{ intg.catTitle }}

{{ intg.catSub }}

{{ c.mono }}
{{ c.pillText }}
{{ c.name }}
{{ c.desc }}
{{ ch.t }}

Telegram MTProto Account

Required for downloading large archives via MTProto. The Telegram account is shared platform-wide and managed in one place — connect it once in Settings and it works here and in Dark Web Monitor.

Connected as dark code
Shared global Telegram account (used by Stealer Intelligence & Dark Web Monitor)
Connected

Monitored Channels

Channels are polled every N minutes (configurable). Each new ZIP/7z attachment is queued for download and extraction.

No channels yet. Click "Add channel" with a @username, t.me link, or numeric id.

Ingestion Queue

Live view of download and extract jobs. Updates every 3s.

No jobs in queue.
Stealer Log BatchesParsed credentials feed the CTI axis automatically
Batch
Lines
Credentials
New
Ingested
Status
{{ r.batch }}
{{ r.lines }}
{{ r.creds }}
{{ r.new }}
{{ r.when }}
{{ r.status }}
Combo Lists
File
Size
Lines
AHU hits
Added
{{ r.name }}
{{ r.size }}
{{ r.lines }}
{{ r.hits }}
{{ r.when }}
Import Batches
Batch ID
Source
Items
State
Started
{{ r.id }}
{{ r.src }}
{{ r.items }}
{{ r.state }}
{{ r.when }}

{{ emptyTitle }}

{{ emptyMsg }}

{{ cti.rep.title }}

{{ b.t }} High confidence
{{ cti.rep.period }}{{ cti.rep.gen }}
{{ k.l }}
{{ k.v }} {{ k.d }}

{{ p.title }}

{{ p.sub }}

{{ r.label }}
{{ r.value }}
{{ s.num }}

{{ s.title }}

{{ p.p }}

{{ c.c }}
{{ c.c }}
{{ g.g }}
{{ c.c }}
{{ b.h }}
{{ t.t }}
{{ t.n }} {{ t.t }}
{{ t.t }}
Methodology: TriAXIS Cyber Threat Landscape Analysis
{{ t.msg }}