TONK

Threat Observation & Network Kill-chain

train
DETECT
detect

Suricata and Zeek detection rule reference. Signature management, rule tuning, and detection engineering mapped to the network threat landscape.

▸ open detect ↗
operational tools
NET
net-hunt-ref

Network-based detection reference. Kibana, Arkime, and Suricata queries mapped across the ATT&CK matrix, with APT correlation, OSINT notes, and air-gapped vs connected tripwire framing.

▸ open reference
HOST
host-hunt-ref

Host analyst threat hunting: indicators, detection syntax, and APT correlation, OSINT notes across the attack lifecycle .

▸ open reference
ATTRIB
attribution

Evidence-driven adversary attribution. Reads the indicators you've starred in HUNT and ranks likely threat actors cross-nation by the attribution baked into each one. Save and restore hunt state for continuity across sessions and machines.

▸ open attribution