Canonical Workflow
The ecosystem
GNAT
GNAT's Not A TIP
Ingest, normalize, enrich, and investigate threat intelligence across 159 connectors. STIX 2.1 keeps your data model and workflows portable between tools.
Learn moreRedGNAT
Continuous automated readiness testing (CART) with explicit safety boundaries, plugged into the GNAT workflow engine.
Learn moreSandGNAT
Automated malware sandbox analysis that feeds detonation results directly into GNAT investigations and reports.
Learn moreSenseGNAT
Network profiling and behavior analysis that surfaces anomalies and enriches GNAT investigations with traffic-layer context.
Learn moreGNAT-gui
Desktop GUI for GNAT analyst workflows. Structured investigations, hypothesis tracking, evidence graphs, rules authoring, and automated reporting — no CLI required.
Learn morePresentations
GNAT-o-sphere Overview
A deep-dive into the full ecosystem — architecture, canonical workflow, per-product capabilities, and adoption path. Aimed at a mixed audience of analysts, investigators, and engineers.
GNAT-gui
The desktop GUI for GNAT analyst workflows — investigations, hypothesis testing, evidence graphs, detection rule authoring, and automated reporting.
GNAT Core
Ingestion, normalization, STIX 2.1 conversion, and the workflow engine. For analysts and engineers evaluating the platform.
SenseGNAT
Network behavioral profiling and anomaly detection integrated with the GNAT workflow engine.
SandGNAT
Automated malware sandbox detonation and artifact enrichment feeding directly into GNAT investigations.
RedGNAT
Continuous automated readiness testing with explicit safety boundaries and GNAT workflow integration.