Open-source cyber intelligence

Make sense of every signal.

RedNoe turns scattered public data into connected, explainable intelligence for security researchers and operators — without hiding the evidence.

Open architecturePrivacy firstBuilt for analysts
signal_graph / simulation
Signals05 connected
Confidencehigh · 0.92
Activitygraph ready
DiscoverResolve entitiesCorrelate evidenceVerify sourcesMonitor changeExplain context
01Discover exposed assets
02Connect fragmented evidence
03Monitor meaningful change

01 / Toolkit

Three modules.
One evidence trail.

A focused toolset for moving from discovery to context and continuous awareness. Each module is being built in the open, with traceable sources at its core.

MODULE_01In development

RedNoe Recon

Map public-facing assets and surface the relationships that make an exposure worth investigating.

DomainsIPsServicesCertificates
MODULE_02In development

RedNoe Graph

Turn isolated observations into a navigable intelligence graph with evidence attached to every link.

EntitiesRelationsSourcesContext
MODULE_03In development

RedNoe Watch

Track the signals that matter and get alerted when the exposure surface changes — not when the noise does.

ChangesAlertsHistoryDiffs

02 / Method

From observation to decision.

RedNoe keeps the path from raw signal to conclusion visible, so analysts can verify what matters and ignore what does not.

01

Collect

Gather public, defensible signals from the surface.

02

Correlate

Resolve entities and reveal relationships across sources.

03

Explain

Return context with provenance, confidence, and next actions.

evidence_view.jsoncorrelating
$ rednoe investigate --entity example.tld
→ resolving connected public signals...
DNS
203.0.113.42A record · observed recently
0.99
TLS
Wildcard certificate3 related hostnames
0.94
ASN
Shared infrastructure2 linked entities
0.88
OBS
Exposure changedNew service detected
0.91
4 findings · 7 sourcesprovenance attached

03 / Principles

Trust is part of
the architecture.

Cyber intelligence is only useful when its origin, handling, and limits are clear. RedNoe is designed around that responsibility.

Open by design

Inspect the logic, not just the output.

The project is being built toward auditable workflows and transparent methods — no unexplained scores and no black-box conclusions.

Privacy first

Your investigation stays yours.

Privacy is treated as a system constraint, not a toggle added after the fact.

Evidence linked

Every relationship needs a reason.

Findings are designed to preserve provenance, confidence, and the context needed for verification.

Operator focused

Less noise. More defensible next steps.

The goal is not to collect everything. It is to help researchers prioritize the handful of signals that actually change a decision.

04 / Roadmap

Built carefully.
Shipped openly.

RedNoe is early. The focus now is a solid technical foundation, a useful first module, and transparent public releases.

PHASE 01

Core foundation

Shared data model, evidence structure, and privacy boundaries.

Active
PHASE 02

Recon preview

The first end-to-end workflow for asset discovery and context.

Next
PHASE 03

Open release

Source, documentation, contribution path, and public feedback loop.

Planned

Follow RedNoe from first signal to open release.

Interested in testing early builds, contributing, or talking about the problem space? Start a conversation.