FissionOps
by NullVector Security
Incident Response Platform

Respond faster.
See further.
Miss nothing.

FissionOps is a self-hosted incident response platform built for cyber operations teams. Kill chain visualisation, full MITRE ATT&CK coverage, real-time collaboration, and intelligence enrichment — in a single deployable package.

FissionOps — Active Incidents
IR-2024-047 Suspected lateral movement, domain controller Lateral Movement Critical
IR-2024-046 Ransomware precursor, endpoint cluster C2 Established Critical
IR-2024-045 Phishing campaign, finance team Initial Access High
IR-2024-044 OT network anomaly, SCADA zone Discovery Medium
ATT&CK TTPs assigned to IR-2024-047
T1021.002 T1075 T1550.002 T1135 T1078.002
3
Supported kill chain frameworks
1,400+
MITRE ATT&CK techniques covered
3
Threat intel enrichment sources
1
Command to deploy
Kill chain visualisation

See the full attack story — across every framework

Map attacker activity across Lockheed Martin Cyber Kill Chain, MITRE ATT&CK Enterprise, and MITRE ATT&CK ICS simultaneously. Every incident stage is tracked, visualised, and linked to specific TTPs.

Lockheed Martin Cyber Kill Chain
7-phase adversary lifecycle
Active
01Recon
02Weaponise
03Deliver
04Exploit
05Install
06C2
07Act
MITRE ATT&CK Enterprise
14 tactics, 1,400+ techniques
Active
TA0043Recon
TA0042Resource
TA0001Initial
TA0002Execute
TA0003Persist
TA0004Priv Esc
TA0010Exfil
MITRE ATT&CK ICS
Industrial control systems
ICS / OT
TA0108Initial
TA0102Execute
TA0100Persist
TA0110Evasion
TA0101Discovery
TA0109Lateral
TA0104Impact
Network boundary traversal
IT and OT zone mapping
IT / OT
IT ZONE
Corporate LAN
DMZ
Cloud workloads
OT ZONE
SCADA systems
HMI networks
Field devices
Platform features

Everything your team needs during an incident

Designed for responders, not managers. Every feature is there because analysts asked for it.

🕸
Entity relationship mapping

Visualise the relationships between hosts, users, processes, and network connections. Build a live graph of the attacker's footprint as the investigation progresses.

🎯
Full MITRE ATT&CK TTP assignment

Assign ATT&CK techniques to every observed behaviour. Supports Enterprise and ICS matrices. Search, filter, and export TTP mappings for reporting or sharing with CISA.

Enterprise ICS Navigator export
🔍
Threat intelligence enrichment

Automatically enrich IOCs against VirusTotal, AbuseIPDB, and Shodan. See reputation scores, geolocation, open ports, and historical context without leaving the incident.

VirusTotal AbuseIPDB Shodan
🚩
IOC flagging and management

Flag IPs, domains, hashes, and email addresses as indicators of compromise. Track IOC status, add analyst notes, and export in STIX/TAXII or plain CSV for blocking.

👥
Real-time collaboration

Multiple analysts work the same incident simultaneously. Live updates, activity feeds, task assignment, and inline comments — no more emailing spreadsheets between shifts.

📄
Executive summary and PDF export

Generate board-ready executive summaries from the incident timeline automatically. Technical appendices, TTP mappings, IOC lists, and remediation recommendations included. Export to PDF in one click.

Deployment

Self-hosted, yours to control

FissionOps is designed to run inside your perimeter. Your incident data never leaves your environment. Deploy in minutes with Docker Compose — no cloud dependency required.

docker-compose.yml
# Deploy FissionOps in one command

git clone https://github.com/nullvector/fissionops
cd fissionops
cp .env.example .env
# Edit .env with your config
docker compose up -d

# FissionOps running on https://localhost:8443
 Platform ready in <60 seconds
🐳

Docker Compose deployment

Single command deployment. All services containerised and pre-configured. Runs on any Linux host with Docker installed — on-premise, air-gapped, or private cloud.

🔑

SSO via Azure AD and Okta

Native SAML 2.0 and OIDC support. Connect FissionOps to your existing identity provider and enforce MFA through your current policies.

Azure AD Okta SAML 2.0 OIDC
🛡

Air-gapped compatible

Fully operational without internet access. Intelligence enrichment falls back gracefully when external APIs are unavailable. Designed for sensitive and classified environments.

📦

Role-based access control

Granular RBAC with predefined roles for Analyst, Senior Analyst, Team Lead, and read-only Executive. Custom roles configurable via the admin panel.

Ready to see FissionOps in action?

Request a demo or get in touch to discuss licensing and deployment options for your organisation.