PROACTIP PROACTIVE · PRECISE · PROTECTED
{{ loginError }}
OR CONTINUE WITH
New to PROACTIP?

Existing customers sign in via SSO · prospects can self-provision a trial above.

DEMO ACCOUNTS · CLICK TO FILL CREDENTIALS
PROACTIPCreate your workspace — live in minutes
1 · CHOOSE A PLAN
2 · YOUR DETAILS

Paid plans are provisioned after a quick provider review · the Starter trial activates instantly.

Workspace created {{ signupStatusMsg }}
Resolving workspace access… checking tenant grants for a.khan@atomecore.io
✓ identity verified · SSO → resolving cross-tenant grants… · loading workspace
ACTIVE TENANT
{{ tenantInitials }}
{{ tenantName }} {{ tenantTier }}
{{ scoreDisplay }} / 100
PROACTIP RISK INDEX {{ bandLabel }} {{ trendArrow }} {{ trendValue }} 24h
ACTIVE INCIDENTS
{{ activeIncidents }} +{{ incidentsToday }} today
{{ critCount }} CRIT {{ highCount }} HIGH
FEED INGESTION
{{ f.name }} {{ f.countText }} {{ f.status }}
LAST UPDATED {{ clock }} {{ dateStr }} UTC LIVE · auto-refresh 30s
{{ moduleTitle }} {{ moduleSub }}
{{ tenantName }} {{ tenantTier }}
{{ clock }} UTC
{{ s.label }}
{{ s.count }} {{ s.delta }} vs prev 24h
THREAT ACTIVITY — EVENTS / HOUR (24H) peak {{ activityPeak }}/h
00:0006:0012:0018:00now
TOP ATTACK ORIGINS
{{ c.rank }} {{ c.name }} {{ c.count }}
LATEST HIGH-CONFIDENCE INDICATORS
{{ r.indicator }} {{ r.type }} {{ r.confidence }}% {{ r.source }}
{{ iocCountText }}
{{ selCount }} SELECTED
TYPE TLP ACTIONS
{{ row.indicator }} {{ row.type }} {{ row.confidence }} {{ row.source }} {{ row.tlp }} {{ row.firstSeen }} {{ row.lastSeen }}
No indicators match the current filter.
{{ pageRangeText }}
{{ pageInfo }}
GLOBAL ATTACK ORIGIN — ABSTRACT PROJECTION
live · {{ markerActiveText }} active sources · click a marker
TOP 5 ATTACKING COUNTRIES
ATTACK VECTORS
{{ v.name }} {{ v.pct }}%
{{ e.label }} {{ e.total }} monitored assets
{{ e.riskPct }}
{{ e.crit }}CRIT {{ e.high }}HIGH {{ e.med }}MED
EXPOSED ASSETS — PRIORITIZED
ASSETTYPESEVERITYFINDINGEXPOSURE
{{ a.name }} {{ a.type }} {{ a.severity }} {{ a.finding }} {{ a.exposure }}
MITRE ATT&CK — ENTERPRISE COVERAGE
uncovered detected active technique
{{ col.name }}
{{ col.detected }}/{{ col.total }}
{{ cell.tech }}
EXECUTIVE SUMMARY Threat Posture Report PROACTIP · AtomECore SOC-HYD-01 · week ending {{ dateStr }}
{{ k.label }} {{ k.value }} {{ k.sub }}
RISK INDEX — 7-DAY TREND
{{ d.val }}
{{ d.day }}
PROGRAM POSTURE
{{ p.label }} {{ p.pct }}%
KEY FINDINGS & ANALYST NOTES
{{ f.sev }} {{ f.text }}
{{ s.count }}
{{ s.label }} {{ s.delta }} / 24h
THREAT ACTIVITY · 24H
GLOBAL ATTACK ORIGIN
TOP ATTACK ORIGINS
{{ c.rank }} {{ c.name }} {{ c.count }}
ATTACK SURFACE EXPOSURE
{{ e.riskPct }}
{{ e.label }} {{ e.total }} assets
MITRE COVERAGE
{{ t.name }} {{ t.pct }}%
LIVE ALERTS
{{ al.severity }} {{ al.title }} {{ al.slaText }}
Provision a new tenantCreate a customer workspace and invite their first administrator.
SUBSCRIPTION PLAN
DATA REGION
Rename tenant
{{ manageT.initials }}
{{ manageT.name }}{{ manageT.admin }} · {{ manageT.adminEmail }}
STATUS{{ manageT.statusLabel }}
SEATS{{ manageT.seatsLabel }}
BILLING{{ manageT.mrrLabel }}
SUBSCRIPTION PLAN · {{ manageT.planName }}
Origin: {{ manageT.origin }} · Region: {{ manageT.region }} · Created {{ manageT.created }}
Delete tenant?

This permanently removes {{ delTenantName }}, revokes all member access, and stops billing. This cannot be undone.

Update compliance · {{ ceName }}Changes are timestamped and written to the audit log.
STATUS
{{ k.label }} {{ k.value }} {{ k.sub }}
Compliance postureCertifications, frameworks and standards PROACTIP holds or is pursuing — with targets, progress and the regions each applies to.
VIEW AS
{{ k.label }} {{ k.value }} {{ k.sub }}
Read-only · your service provider maintains the compliance posture. Owner assignments, review schedules and editing are restricted to the provider.
{{ L.title }}{{ L.subtitle }}
{{ f.name }}{{ f.body }}
{{ f.statusLabel }}
{{ f.percent }}
{{ f.milestone }}{{ f.target }}
{{ f.scope }}
{{ rg.label }}
Owner · {{ f.owner }}{{ f.reviewLabel }}
MAPS TO PROACTIP
{{ m.label }}
Next: {{ f.next }}
ORGANISATIONPLANSTATUSSEATSMRRORIGINACTIONS
{{ t.initials }} {{ t.name }}{{ t.admin }} · {{ t.region }} {{ t.planName }} {{ t.statusLabel }} {{ t.seatsLabel }} {{ t.mrrLabel }} {{ t.originLabel }}
Provider-createdYou provision a tenant directly, pick the plan and seat count, and invite their first admin. Live immediately.
Self-service signupProspects register at app.proactip.io/signup, pick a plan, and land here as a trial or pending approval.
Every customer is itself a tenant — they don't see this console. White-label / reseller partners on the MSSP plan can request multiple tenants and manage them here. Pricing and feature bundles can be set per tenant (custom price on provisioning), and clients may request a quote on any plan.
{{ p.name }} {{ p.tagline }}
{{ p.priceLabel }}{{ p.period }}
{{ p.seatsLabel }}
{{ m.label }}
{{ p.count }}
PENDING SELF-SERVICE SIGNUPS{{ provPendingCount }}
{{ p.initials }}
{{ p.name }}{{ p.admin }} · {{ p.email }}
{{ p.planName }} {{ p.created }}
USEREMAILTENANTSTATUSACTIONS
{{ u.initials }}{{ u.name }}{{ u.role }} {{ u.email }} {{ u.tenant }} {{ u.statusLabel }}
Detects base64-in-URL, percent-encoding & obfuscation automatically
{{ decOpActive }}/{{ decOpTotal }} ops active
OPERATIONS
{{ grp.cat }}
RECIPE runs top → bottom
Click operations on the left to build a decoding chain, or hit Magic auto-decode.
{{ r.idx }} {{ r.name }}
{{ r.argLabel }}
INPUT
{{ decInputBytes }}
OUTPUT{{ decOutputBytes }}
{{ decOutput }}
RANGE
TYPE
LIVE · {{ anRangeLabel }}
{{ k.label }}
{{ k.value }} {{ k.deltaArrow }} {{ k.delta }}
THREAT VOLUME OVER TIME
Total detections Critical peak {{ avPeakLabel }}
{{ a.label }}
IOC TYPE BREAKDOWN
{{ dtCenter }} {{ dtCenterLabel }}
SEVERITY DISTRIBUTION
{{ s.label }} {{ s.value }} {{ s.pct }}
DETECTION COVERAGE BY SOURCEVOLUME · HIT-RATE
{{ c.name }}
{{ c.count }}
{{ c.hit }}
CONTRIBUTION & SHARING
{{ contribStats.submissions }}SUBMITTED
{{ contribStats.shares }}SHARED OUT
{{ contribStats.accepted }}ACCEPTED
TLP DISTRIBUTION
{{ t.label }} {{ t.pct }}
DETECTION ACTIVITY · DAY × HOUR
LOW
HIGH
{{ row.day }}
{{ h }}
SOC OPERATIONS
{{ s.label }} {{ s.value }} {{ s.sub }}
TRIAGE TIME TREND
ANALYST THROUGHPUT · CASES CLOSED
{{ a.init }} {{ a.name }}
{{ a.closed }}
TOP CAMPAIGNS & THREAT ACTORS
CAMPAIGN INDICATORS SEVERITY Δ VOLUME
{{ c.name }}{{ c.actor }} · {{ c.last }}
{{ c.indicators }} {{ c.sevLabel }} {{ c.delta }}
TENANT / WORKSPACE ROLL-UP · MSSP cross-tenant · granted workspaces only
WORKSPACE TIER DETECTIONS CRITICAL HIT-RATE Δ VOL
{{ t.initials }}{{ t.name }} {{ t.tier }} {{ t.detections }} {{ t.critical }} {{ t.hit }} {{ t.delta }}
{{ iocQueryType }}
{{ repScore }}REPUTATION
{{ repLabel }}TLP:{{ iocResTlp }}
{{ iocResIndicator }}
{{ m.label }}{{ m.value }}
RELATED INDICATORS · PIVOT GRAPH
{{ iocResIndicator }}
{{ n.label }}
SEARCH HISTORY
Drop a file to detonate, or browseMax 256 MB · PE / Office / PDF / archives · sandboxed in isolated VM
invoice_2026_Q2.xlsmSHA-256 a3f5c9e1b27d4f88e0a16c4291de7b91c8042f… · 248 KB · Office Open XML (macro-enabled)
{{ fileDetectStat }} FLAGGED
{{ v.icon }}{{ v.name }}
{{ v.d }}
MALICIOUS · HIGH CONFIDENCEAtomECore Verdict — macro-laden dropper consistent with the TA505 delivery chain.
92
RISK / 100
BEHAVIORAL SUMMARY

On open, the workbook executes an obfuscated VBA macro that spawns powershell.exe with a hidden window, pulls a second-stage payload from a hardcoded C2, and establishes persistence via a Run key. Process injection into explorer.exe was observed, followed by periodic beaconing.

ATT&CK TECHNIQUES OBSERVED
{{ t }}
EXTRACTED IOCs
{{ io.type }}{{ io.value }}
ANALYST NOTES
STATIC ANALYSIS
{{ s.label }}{{ s.value }}
DYNAMIC ANALYSIS · SANDBOX
[ sandbox screen capture ]
PROCESS TREE
{{ pr.branch }} {{ pr.name }}
NETWORK CALLS
{{ nc.dir }}{{ nc.addr }}{{ nc.port }}
PHISHING · BRAND IMPERSONATIONCredential-harvesting page impersonating Microsoft OneDrive · newly registered domain.
88
RISK / 100
https://{{ urlPermalink }}SCAN {{ urlScanId }} · captured {{ urlCapturedStamp }}
RETENTION · {{ urlTenantPlan }}{{ urlRetentionDays }} days · expires {{ urlExpiresDay }}
PAGE CAPTURE
{{ urlInput }}
Sign into continue to OneDrive
Email, phone, or Skype
Next
⚠ CREDENTIAL FORM {{ urlCapRes }}
{{ m.label }}{{ m.value }}
REDIRECT CHAIN
{{ r.code }}{{ r.url }}{{ r.note }}
SSL / TLS
{{ s.label }}{{ s.value }}
FLAGS
{{ f.label }}{{ f.tag }}
{{ v.icon }}{{ v.name }}
{{ v.d }}
ATOMECORE VERDICT

Domain registered 2 days ago via a bulletproof registrar resolves to a host serving a pixel-perfect clone of the Microsoft OneDrive sign-in page. The form posts credentials to an attacker-controlled endpoint over the redirect chain above. Recommend immediate block at the secure web gateway and a tenant-wide phishing advisory.

T1566 PhishingT1598 Credential Harvest
Every scan is stored for {{ urlRetentionDays }} days on the {{ urlTenantPlan }} plan and addressable by its permalink — analysts can cite the link in tickets and reopen the exact result any time before expiry.
URLVERDICTRISKCAPTUREDEXPIRESLINK
{{ h.url }}{{ h.verdict }}{{ h.risk }}{{ h.captured }}{{ h.expires }}
RAW MESSAGE HEADER
{{ emailVerdictLabel }}
From{{ emailFrom }} Return-Path{{ emailReturn }} Reply-To{{ emailReply }} Subject{{ emailSubject }}
{{ a.name }}{{ a.result }}{{ a.detail }}
SPOOFING RISK{{ emailSpoofLevel }}{{ emailSpoofDetail }}
SENDER REPUTATION{{ emailRepScore }} / 100{{ emailRepDetail }}
ORIGINATING IP{{ emailOriginIp }}
GEOLOCATION{{ emailGeo }}
DELIVERY FORENSICS
{{ f.label }}{{ f.value }}{{ f.detail }}
HOP-BY-HOP ROUTING
{{ h.server }}{{ h.ip }} · +{{ h.delay }}
SUBMIT INTELLIGENCE
TLP LEVEL
CONFIDENCE{{ cConfidence }}%
MY CONTRIBUTIONS
INDICATORTYPETLPSUBMITTEDSTATUS
{{ c.indicator }}{{ c.type }}{{ c.tlp }}{{ c.submitted }}{{ c.status }}
{{ i.initials }}
{{ i.name }}
{{ i.dirLabel }}{{ i.cat }} · {{ i.proto }}
{{ i.countLabel }}
{{ c.env }}{{ c.name }}
TAXII 2.1 COLLECTIONSSTIX 2.1
DISCOVERYhttps://{{ taxiiUrl }}
{{ c.name }}{{ c.desc }}
{{ c.count }}{{ c.tlp }}
WEBHOOK SUBSCRIBERS
{{ w.url }}{{ w.events }}
{{ w.statusLabel }}
API KEYS · INBOUND / OUTBOUND
DIRLABELKEYSCOPECREATED
{{ k.dir }}{{ k.label }}{{ k.value }}{{ k.scope }}{{ k.created }}
API ACTIVITY LOG · TENANT-SCOPED
{{ s.label }}{{ s.value }}
TIME · UTCKEYDIRMETHODENDPOINTSTATUSSOURCE IP
{{ e.time }}{{ e.label }}{{ e.dir }}{{ e.method }}{{ e.endpoint }}{{ e.status }}{{ e.ip }}
Access Control — {{ tenantName }}tenant-scoped · click any cell to change access level
{{ lg.label }}MAX TLP CLEARANCE · click to cycle
USER / ROLE{{ m }}MAX TLP
{{ r.initials }}
{{ r.name }}{{ r.statusLabel }}{{ r.subtitle }}
Click any cell to cycle access · the menu resets passwords, suspends or removes a user. Every change is written to the audit log.
Immutable activity trail for {{ tenantName }} · newest first · access changes, auth events, account actions and operations.
DATE · TIME · UTCACTORACTIONTARGETCATEGORY
{{ e.date }}{{ e.time }}{{ e.actor }}{{ e.action }}{{ e.target }}{{ e.cat }}
{{ drawer.badge }} {{ drawer.kicker }}
{{ drawer.title }}
{{ drawer.subtitle }}
{{ mi.label }} {{ mi.value }}
{{ sec.title }}
{{ it.primary }} {{ it.secondary }}
CYBER KILL CHAIN
{{ k.phase }} {{ k.activeLabel }}
MITRE ATT&CK MAPPING
{{ ch.label }}
Invite usertenant: {{ tenantName }}
Create roletenant: {{ tenantName }}
You can fine-tune per-module access from the matrix after the role is created.
{{ configInitials }}
{{ configTitle }}{{ configCat }} · {{ configProto }} · {{ tenantName }}
Generate API keytenant: {{ tenantName }}
The full secret is shown once on generation — it's masked everywhere afterwards.
API key created{{ revealLabel }} · {{ revealDir }} · {{ revealScope }}
Copy this secret now and store it securely. For your protection it's shown only once — PROACTIP keeps a hash, never the plaintext, so it can't be retrieved again.
{{ revealKey }}
Deliver via your secrets manager (Vault, AWS Secrets Manager, 1Password) or paste into the receiving connector's credential field — never email or chat the plaintext.
{{ manage.initials }}
{{ manage.name }}{{ manage.statusLabel }}
{{ manage.email }}
Role{{ manage.role }} Scope{{ manage.scope }}
CREDENTIALS
NEW TEMP PASSWORD{{ manageReset }}share securely · expires on first login
ACCOUNT STATE
You are signed in as this account — removal is disabled.
{{ toast }}