OrionEye — mappa mondiale di intelligence cyber in tempo reale
CYBER THREAT INTELLIGENCE

See who is attacking your infrastructure.

AI-powered cyber threat intelligence and active defence. Detect the attack, correlate the campaign, block it — from the map.

  1. 01Detect
  2. 02Investigate
  3. 03Correlate
  4. 04Respond
Scroll to explore
⌄

See OrionEye in action

Your server is under attack. This is what happens next.

  1. dalla piattaforma
    01

    Detect

    Repeated SSH authentication failures arrive on your server. OrionEye plots each source the moment it appears, instead of leaving it in a log nobody reads.

  2. OSINT di prossimità
    02

    Investigate

    One hostile address, opened: geolocation, autonomous system, network owner and reputation, side by side on the map. Ask in plain language and the AI runs the tools for you.

  3. rilevamento campagne
    03

    Correlate

    Scattered addresses stop being scattered. The AI groups them into one coordinated campaign with a confidence score, so you answer a campaign and not two hundred separate lines.

  4. difesa attiva
    04

    Respond

    Block the whole campaign through fail2ban on your own servers, report it to AbuseIPDB, share the finding. Through OmniAgent the action lands on your real infrastructure.

Free, Pro, Enterprise: explore, investigate, defend

The four steps above do not all open at once. Each plan is a verb — what you are able to do, not what you have bought.

Free·EXPLORE

The public world, on the map.

  • The 3D globe with OpenStreetMap buildings extruded at their real heights, satellite imagery and terrain relief.
  • NASA EONET disasters, ESA launches, live ISS tracking, weather layers, traffic cameras and news.
  • The shared threat feed: what other analysts are seeing, as they see it.

Pro·INVESTIGATE

Your own infrastructure, from the USB stick.

  • Uncover Engine: one query to Shodan, Censys, FOFA, ZoomEye, IPinfo and AbuseIPDB at once, on your own API keys, merged into one record per address on the map and the globe.
  • OmniAgent OS runs on your machine, even from the stick: your servers, a remote terminal, Wi-Fi surveys, and an encrypted Vault that never reaches the cloud.
  • Network topology, SSH attackers plotted, one-click fail2ban blocking and AbuseIPDB cross-checks.
  • Orion IA audits your own accesses and devices, and the AI orchestrates eight cloud models.

Enterprise·DEFEND

Nothing leaves the company.

  • Uncover Engine without limits: company-managed keys instead of personal ones, and recursive reconnaissance over a whole ASN or CIDR block rather than one host at a time.
  • SentraLink: local network telemetry and security alerts, read from inside the perimeter.
  • Models run locally, in a container on your own hardware — the analysis never reaches anyone’s cloud, air-gapped included.
  • File system deep-dive and an ECDSA-signed licence bound to your infrastructure.

Connect Grok & MCP-Compatible LLMs to Active Defence

Ask natural-language questions about SSH threats, campaign confidence, AbuseIPDB context and the shared Intel Feed through a standalone MCP gateway.

Grok/xAI directory availability subject to vendor support and approval
01 · PROVISIONAn administrator provisions a workspace URL and bearer token with the gateway CLI. In-app token provisioning is planned, not available yet.
02 · CONNECTAdd the HTTPS endpoint to a client that supports custom remote MCP servers, such as Claude Code.
03 · INVESTIGATEQuery threat intel and submit moderated feed items. Campaign blocking remains an operator-reviewed proposal in this release.

MCP is in private preview. Grok/xAI custom connector availability has not been verified; no official directory partnership or listing is claimed. MCP does not execute Fail2Ban actions.

What is OrionEye?

OrionEye is a unified intelligence platform combining cyber analysis, geospatial visualization, space tracking, job intelligence and AI orchestration. It provides real‑time tools for IP analysis, routing, satellite data, weather layers, job search, and space events — all powered by an interactive map and Gemini AI.

Created by Samuel La Manna, OrionEye integrates OSINT capabilities, RIPE Atlas network probes, NASA EONET natural disaster monitoring, ESA orbital launch data, real‑time ISS tracking, traffic surveillance cameras, and Google Analytics — all orchestrated through Gemini AI natural language commands on an interactive Google Maps interface.

OmniAgent Link

Pair OrionEye with OmniAgent OS on your own machine and bring your servers onto the map — SSH access, diagnostics and live telemetry no public API can give.

Threat Mapping

Every SSH attacker geolocated, cross‑checked against public reputation lists, and read by AI — who is hitting you, from where, and who already got in.

Active Defence

AI clusters attackers into coordinated bot campaigns with a confidence score — then you block an entire campaign in one click via fail2ban, with live progress. From detection to defence, on the map.

Intel Feed

A shared, moderated board where your team posts indicators, incidents and findings — collaborative threat intelligence in real time, tagged by type and severity.

Cyber Intel

IP geolocation, DNS, traceroute, ping, RIPE Atlas, malware C2 tracking — full network visibility.

Geo Intelligence

Interactive map with routing, live cameras, weather, Street View, area inspection and satellite tiles.

Space Tracking

ISS tracker, ESA launches, astronauts, launch pads, space stations — real-time orbital data.

3D Globe

Switch the whole map to a rotating globe with OpenStreetMap buildings extruded at their real heights. Every layer and every tool keeps working on it — nothing is a separate view.

Area Briefing

Draw an area or drop the reticle: every active layer inside it is counted and listed, each element ringed on the map, with a written read-out of the territory beside the circle.

Event Video

Click a hurricane, a wildfire or a conflict marker and OrionEye searches the web for related footage, then plays it in its own player — no tab switching.

Multi-LLM AI

Agentic orchestration over every module. Gemini by default, or any provider on your own key — it runs the tools, draws the diagrams, explains the analysis.

Platform Capabilities

3D Globe · SSH markers, country cards and campaign vectors carry across

Network Forensics & OSINT

Perform deep IP geolocation, DNS resolution, multi‑hop traceroute visualization, and RIPE Atlas probe analysis. Identify network paths, autonomous systems, and routing anomalies in real time on an interactive map.

Network Forensics & OSINT · live demo

Space & Orbital Intelligence

Track the International Space Station in real time, monitor ESA rocket launches, explore global launch pads, and overlay NASA EONET natural disaster events — wildfires, storms, volcanic eruptions — directly on the map.

AI‑Powered Orchestration

Drive all 20+ modules through natural language. Gemini by default, or bring any provider on your own key — the AI runs the tools, draws the diagrams and explains the analysis, and through OmniAgent OS it reads your own servers: SSH logs, diagnostics and live telemetry no public API can offer.

Active Defence & Response

Move from detection to defence: AI correlates SSH attackers into coordinated bot campaigns with a confidence score, then you block a whole campaign — or every unblocked offender — in one click via fail2ban, cross‑check and report to AbuseIPDB, and share findings on a collaborative, moderated intel feed.

Uncover Engine — Multi‑Engine OSINT Aggregator

Instead of running the same query by hand on five platforms and stitching the answers together in a spreadsheet, ask once. OrionEye sends one reconnaissance query to Shodan, Censys, FOFA, ZoomEye, IPinfo and AbuseIPDB at the same time and returns one record per address — open ports with product and version, hostnames, ASN, reputation, CVEs the engine itself declares — plotted on the 2D map and the 3D globe together, each marker clickable for the full card. The record carries its provenance: you see which engines confirmed a finding and which never answered, because three engines agreeing is not the same fact as one engine guessing. Nothing is inferred: a vulnerability is shown only where an engine declares it.

OrionAI Universal Topology Engine & Proximity OSINT

Beyond threat intel: map the infrastructure itself. Every tool in the platform — bot campaigns, OSINT cameras, satellites, natural events — renders as an interactive 2D/3D relational graph. Single brute‑force attempts are told apart from coordinated campaigns and linked to their ASN group and Master C2 node. Click any attacker and a proximity agent sweeps the ground around it: local news on outages and blackouts, public webcams in range, notable places nearby — because an address knocking from a city that has been dark for six hours is a different story from one knocking from a quiet datacentre. Network topology and server file systems require an OmniAgent USB key.

Multi‑LLM Agentic Engine & Source Topology

Human‑in‑the‑loop investigation: the agent proposes what to examine on the node you clicked, and nothing runs until you approve it. Connect Gemini, Claude, OpenAI and local models in Docker on OmniAgent OS through your USB Vault, and every question goes to all of them at once. You get measured latency and output rate side by side, an OrionAI synthesis of where they agree and where they contradict each other, and a topology map of the sources they cited — with YouTube videos playable in place. Accuracy is deliberately not scored: nobody here knows which answer is right, so what is shown is agreement between models, which is an observable fact.

Active Defence & Response · live demo