Unified Risk Dashboard
Risk trend · 30 days
78 HighSeverity distribution
Internal Vulnerability Management
Scheduled scanning & Auto-Triage of internal ICT asset vulnerabilities.
External Attack Surface
Assess AHU's internet-facing assets from an attacker's perspective, plus Digital Risk Protection.
Exposure Score
Severity Distribution
total 214Findings by Category
Discovery Sources
305 subdomains · 9 sourcesAttack surface map
ahu.go.id · 38 assetsPorts & certificates
OWASP Top 10 Coverage
Detected Services
Top Vulnerable Assets
Top Risks
Top CVEs
Top Vulnerability Findings
KEV Exposure
Detect look-alike domains against AHU domains using 14 generation techniques.
Monitor Certificate Transparency logs and newly registered domains for brand abuse.
Monitored keywords (7)
Status Feed
Aggregate, search, and triage forum and leak posts with keyword-based alerting.
Ingestion trend · 14 days
Severity Mix
18.412Top targeted countries · 30 days
Top Sources by Post Volume
Threat Actors
Monitored sources (233)
Search Engines
Analyse infostealer logs with multi-device ingestion, 20+ family detection, and watchlist correlation.
Most Targeted Domains
Top Stealer Families
Device ingest trend · 30 days
Top Victim Geography
Telegram Sources
The global Telegram account is managed in Integrations — this page only lists monitored channels and their polling status.
Rogue Mobile Apps
No rogue mobile apps detected. Add the official AHU app names to start monitoring third-party app stores.
Cyber Threat Intelligence
Feed and IOC aggregation, exploit intelligence, actor profiling, and ATT&CK coverage.
AHU relevance
47 indicators match monitored AHU assets — these are the indicators that move the Risk Priority Score.
{{ cti.ingestion.title }}
{{ cti.ingestion.sub }}
{{ cti.sevMix.title }}
Across all active indicators
{{ cti.indTypes.title }}
{{ cti.indTypes.sub }}
Latest intelligence
Newest reports and campaigns
Indicators
Manage and track threat indicators across the AHU environment.
Observables
STIX Cyber Observable Objects (SCOs) — network, host, and artifact observations.
Intrusion sets
Track and profile intrusion sets and APT groups.
Malware
Track malware families, variants, and capabilities.
Campaigns
Track threat campaigns and attack operations.
Locations
Geo-distribution of threat origins, targets, and intrusion sets.
ATT&CK coverage
Visual heatmap of MITRE ATT&CK Enterprise technique coverage based on observed threat intelligence.
{{ cti.covBars.title }}
{{ cti.covBars.sub }}
CVEs & KEV
Track CVEs, exploits, PoCs, and vulnerability intelligence from multiple sources.
Vulnerability trend
Last 30 days · by publish date{{ cti.cveSev.title }}
Across all tracked CVEs
{{ cti.vendors.title }}
{{ cti.vendors.sub }}
CISA KEV additions
Cumulative, last 12 months{{ cti.cveSources.title }}
{{ cti.cveSources.sub }}
Malicious packages
Supply-chain extension of exploit intelligence — malicious open-source packages across npm, PyPI, RubyGems, NuGet, Go, Rust, Maven, and VS Code registries.
{{ cti.pkgEco.title }}
Detections per registry
{{ cti.pkgVer.title }}
Declared version sanity
{{ cti.pkgVer.caption }}
Detection timeline
Daily detections, last 30 days
Monthly trend
Detections per month
Threat landscape
Comprehensive threat landscape analysis.
{{ r.sum }}
STIX reports
Manage and track STIX Report SDOs.
Distribution
Push intelligence to AHU security controls.
Export format
Select the output format for your indicators
Filters
Narrow the exported indicator set
Actions
Generate the file or check the output first
Programmatic access
SIEM/SOAR integration via API key or basic auth
https://triaxis.ahu.go.id/api/export/snort
curl -H "Authorization: Bearer <YOUR_API_TOKEN>" \ "https://triaxis.ahu.go.id/api/export/snort?severity=critical,high&min_confidence=70&limit=10000"
Correlation Queue
All findings are correlated, sorted by the highest RPS.
Agent Org Chart
Reporting lines, roles, and permissions across {{ ag.count }} active agents
Integrations
Connect SIEMs, security tools, and threat intelligence providers. All credentials are encrypted at rest.
{{ intg.catTitle }}
{{ intg.catSub }}
Telegram MTProto Account
Required for downloading large archives via MTProto. The Telegram account is shared platform-wide and managed in one place — connect it once in Settings and it works here and in Dark Web Monitor.
Monitored Channels
Channels are polled every N minutes (configurable). Each new ZIP/7z attachment is queued for download and extraction.
Ingestion Queue
Live view of download and extract jobs. Updates every 3s.
{{ emptyTitle }}
{{ emptyMsg }}