$ ls ~/mycave

mycave.rocks

Art Le Bel’s projects, all in one place. Security tools, news, music and games — and a toybox to tinker with.

Art Le Bel

Every card opens the real thing in a new tab. Not sure what is behind a door? Open “What’s inside” underneath it for the tour.

  • artlebel.com Executive cybersecurity leadership and strategic advisory. artlebel.com
    What’s inside

    The cave’s front door: a red pulse and a straight answer.

    Art’s professional home page is a single dark card with a looping heartbeat-line video across the top. You can read his pitch (twenty-plus years across the Pentagon, Fortune 500 firms and managed security services), then a menu of three virtual CISO packages with their monthly prices published right on the page, from light advisory up to full program leadership, plus hourly rates for incident response, technical advisory and leadership reporting. A Products section introduces his tools and links out to each one, and a Services list and contact details close the page.

    • Three vCISO packages with published prices and hour counts
    • Compliance frameworks named, from HIPAA and CMMC 2.0 to FedRAMP, PCI DSS and NIST Zero Trust
    • Product index: UltimateIP, Threat Signal Forge, AI Auditor Assistant, Pentesting-Team
    • Services: security architecture, penetration testing, risk and compliance, cloud security on AWS, Azure and GCP
    • Scroll all the way down. There is something small and red past the copyright line.

    One page, no login, nothing to sign up for.

  • GitHub Code and open projects, published as artofscripting. github.com/artofscripting
    What’s inside

    Thirty-odd open tunnels of code, lit by one red heartbeat.

    This is Art’s public GitHub profile, where he posts as artofscripting from Houston, Texas. You land on the overview: pinned repositories, the green contribution calendar and an activity timeline you can step through year by year. The Repositories tab lists about thirty public projects you can search and filter by language. Networking and security tools in Python make up most of it, next to games, Minecraft mods and desktop utilities. Every README is readable and every repo can be cloned without an account.

    • Network-Vector: a Python port scanner that draws interactive D3.js network graphs
    • Web-Vectors: a website security scanner with a Flask web interface
    • Games and fun: Terminal-Farming, ArtHack, two Minecraft NeoForge mods, a Three.js solar system with a live demo
    • Utilities: CLI-dash (clock, weather and news in a terminal), ZipAndDate, Chrome-Cast-Remote
    • A secrets-manager family in Python, Rust, C++ and TypeScript, plus cloud IP-range libraries

    Browsing is open. You only need a GitHub account to star, follow or open issues.

  • Résumé Stephen “Art” Le Bel’s résumé, kept on GitHub in three flavours. github.com/artofscripting/Resume
    What’s inside

    The résumé wall, with a stats-dashboard tunnel behind it.

    The link opens a GitHub repository whose README is the résumé itself, rendered right on the page. You can read the summary (cyber security, twenty-plus years in IT, former Pentagon cyber work), then a career timeline that runs from the US Army and Apache helicopter combat networks through Lockheed Martin, Disney and Shell to Accenture Federal Services. Tables list certifications (CISSP, Security+), education, military awards and a technical-skills matrix. The README also links to a bonus page: a dark dashboard of charts covering all of his repositories.

    • README.md: the concise résumé
    • RESUME.md: a longer narrative version with key contributions per role
    • DEVELOPER.md: a software-developer cut with a key projects list
    • The GitHub Stats Dashboard: a repository-to-language Sankey diagram, language and license charts, a creation timeline and a searchable, sortable grid of repos

    No account needed. The dashboard is a snapshot from when it was last generated, so its numbers do not update live.

Security & threat intel

  • SOCtoys Free in-browser tools for security analysts and developers: command-line triage, a six-platform hunt query builder, IOC extraction, decoders and more. soctoys.com
    What’s inside

    The security, developer, notepad and to-do toys from this cave, now with their own home.

    Seventy-odd tools that used to live in the toybox here: a command-line analyzer that decodes encoded PowerShell and maps findings to ATT&CK, a log query builder that writes Splunk, KQL, XSIAM XQL, Elastic and Sigma, IOC and secrets extractors, certificate, header, cookie and JWT checkers, DNS and WHOIS lookups, formatters and encoders — plus the notepad and to-do list.

    Had notes, to-dos or saved hunts here? Move your saved data to SOCtoys in one click.

  • ThreatSignalForge Search vulnerabilities, IPs, domains, malware, exploits and their correlations from one surface. threatsignalforge.com
    What’s inside

    One search, every signal in the cave.

    ThreatSignalForge is a threat-intelligence platform that runs as a single app in your browser. You search across vulnerabilities, IP addresses, domains, malware and exploits, then pivot from one to the next through the correlations between them: from a CVE to the exploits released for it, to the malware tagged with it, and back. Vulnerability records carry severities and a threat score, and you can narrow a list to known-exploited entries only or to CVEs that already have an exploit available.

    • Vulnerability records with severity breakdowns and threat scores
    • A “KEV only” filter and lists of exploitable CVEs
    • Exploits & News, with a heatmap of exploit releases
    • Malware samples, including the ones with command-and-control servers
    • A correlation matrix and correlation history, plus a daily report

    A JavaScript app, so it needs a modern browser. API keys for the UltimateIP tools come from UltimateIP Control, next door.

  • Nginx Signal Forge A live dashboard of real attacks hitting a web server: maps, timelines, clusters and reports. threat.ultimateip.info
    What’s inside

    Watch the bats that actually try the door.

    Nginx Signal Forge turns a web server’s access log into a dashboard of attacker activity. You can switch between Historical and LIVE, pick panels from a side menu, and click almost anything to filter the whole dashboard by it. A world map shows where attacks come from and can replay them over time; around it sit an hourly attack timeline, an hour-of-day by day-of-week heatmap, the mix of attack types and the top attacking IPs. Deeper panels group attackers by behaviour, and two report panels write up the day and the week.

    • Live: world map with play and record, attack timeline, attack heatmap
    • Breakdowns: attack types, top attacking IPs, country origins, a country-by-type chord graph
    • Events and agents: recent events with CSV export, user agents, top targeted paths, user-agent deception, search engines
    • Intelligence: IP behavioural similarity, coordinated cluster graph, cluster drift, attacker lifecycle
    • Visualisations: attack flow, radial hierarchy, Sankey, sunburst and a 3D attack flow
    • Daily Brief and Weekly Report, plus ready-made deny rules for the worst offenders

    No login. It is a big page with a lot of data, so give it a moment to load. Add ?report=<panel-id> to the address to open one panel directly.

  • UltimateIP Control Account console for the UltimateIP tools: users, API keys and monthly usage. users.ultimateip.info
    What’s inside

    One key. Four products. One analyst workflow.

    UltimateIP Control is the account console behind the UltimateIP family. Once you sign in you can manage user access, issue up to twenty API keys per account, check month-to-date usage and disable a key immediately. The landing page doubles as a map of the family: four cards explain what each product does and open it for you, so it is a good place to start if you are not sure which tool you need.

    • Domain Info: domain reports with WHOIS, DNS, TLS, headers and footprint data
    • IP Info: queued IP and email-domain lookups, as JSON or analyst-facing HTML
    • Threat Intel Event Console: current attacker activity and exportable blocklists
    • ThreatSignalForge: vulnerabilities, IPs, domains, malware and exploits in one search

    The landing page is public. The console itself needs an account.

  • Pentesting-Team.com Penetration testing for networks, web apps, mobile apps and people. Test everything, trust nothing. pentesting-team.com
    What’s inside

    Find your weaknesses before attackers do.

    Pentesting-Team.com is the services site for hands-on offensive security work. One long page walks you through what gets tested and how: each service has its own card with the approach and what is in scope, followed by the engagement process step by step, the reasons to hire the team, a set of common questions and a contact section where you can request a quote. You can pick a single discipline or combine several into a full assessment.

    • Internal network testing: lateral movement, privilege escalation, data exfiltration paths
    • External attack surface: websites, servers, cloud infrastructure and edge devices
    • Web application testing aligned to the OWASP Top 10
    • iOS and Android app testing
    • User pentesting and phishing simulations
    • Black, white or grey box engagements, with reports written for the engineers who fix things

    A brochure site: no login, nothing to install. Quotes go through the contact section.

  • AI Auditor Assistant AI-powered NIST compliance assessments and automatic System Security Plans. aiauditorassistant.com
    What’s inside

    Stop spending weeks on NIST compliance.

    AI Auditor Assistant is a workspace for cybersecurity compliance. You run an AI-driven assessment that goes through your security controls one by one and cites the evidence it relied on, then it writes the System Security Plan from the results, with an implementation status for every control family and documents ready to export for an audit. The landing page explains the three pieces, lists the supported frameworks and has a video showing the product at work before you sign up.

    • Control-by-control AI analysis with cited evidence
    • Automated System Security Plan (SSP) generation
    • Full assessment workflows for NIST SP 800-171A and NIST SP 800-53 Rev. 5
    • AI chat coverage for CMMC, SOC 2, HIPAA and ISO 27001

    You need to sign up and log in to run an assessment. The landing page and video are open.

News & ideas

  • NewsReader A live news dashboard: headlines, topics, sentiment and leaning, with map and globe views. news.artlebel.com/home
    What’s inside

    The whole surface world, read from underground.

    NewsReader collects articles from news sources around the clock, tags each one with where it is about and how it reads, and lays the result out as a dashboard. On the home view you can scan top headlines and top topics, follow story clusters, search, filter by date range and save the views you return to. Charts show how many articles arrive per time slice, how sentiment and political leaning are distributed, and which keywords are being mentioned. From there you can jump to a map, a globe and a set of visualisations of the same feed.

    • Top headlines, top topics and story clusters
    • Topic feeds you can edit, with filters, date ranges and saved views
    • Sentiment, political leaning, source leaning and source funding for what you are reading
    • Keyword mentions and a velocity sparkline for how fast a story is moving
    • Side panels: world clock, weather, exchange rates, a stock ticker, a live stream and traffic cameras

    No login. The page loads its data after it opens, so the panels fill in over a few seconds.

  • Research Workspace Search, filter and compare news coverage across topics, sources and countries. news.artlebel.com/workspace
    What’s inside

    Bring a question. Leave with a table.

    The Research Workspace is the analyst’s side of NewsReader. Instead of a front page you get a query bench: choose the main feed or the topic feeds, set a time range from the last 24 hours to all time (or a custom one), type a search and run it. A timeline shows how many articles land in each time bucket, and you can split it by tone, political leaning or topic. Below it, tabs turn the same results into different cuts, and you can pin articles and save a query to run again later.

    • Time ranges: 24 hours, 3, 7, 30 and 90 days, all time, or custom
    • A timeline you can split by tone, leaning or topic
    • Tabs: Table, Articles, Countries, Sources & hosting, Breakdown, Compare and Pins
    • Saved queries and pinned articles
    • Shortcuts to the Home, Map, Globe and Viz views

    Search is a plain substring match on headlines (“drone” also finds “drones”). Article bodies are not searched.

  • Free the People Learn the systems that shaped the world, think with evidence, and build a freer future. freethepeople.us
    What’s inside

    Maps of who and what connects, and when.

    Free the People is an independent research project presented as a collection of interactive reports. The front page opens with a short essay on why connected history matters, then summarises each report and links to it. Most of them are network graphs, family trees and timelines that you explore by clicking through nodes and their source cards. The site says how to read them: treat every report as a model of relationships rather than final proof, and check contested claims against primary sources.

    • Religion: Abrahamic Religions: History and Relationships, and World Religions: Theory, Lore, and Historical Record
    • Family and network histories: Rockefeller, Rothschild and Saudi family trees, and the Epstein Connections Map
    • Frameworks: Human Control Systems Map and Human Evolution Map
    • The 13 Families in “Bloodlines of the Illuminati”: the claims organised with caution notes and a timeline
    • An overall synthesis tying the reports together

    No login. Some reports are marked on the site itself as controversial or needing verification. Read them that way.

Music & audio

  • Artust Studios A music and video library you play in the browser, with playlists, filters and an equalizer. music.artuststudios.com
    What’s inside

    The cave has surprisingly good acoustics.

    Artust Studios is a web player for Art’s music and video library. Pick a folder or a playlist on the left and the tracks appear in a table with their genres, instruments and running time; switch between Audio and Video at the top. You can search, filter by genre or instrument, sort, play everything or shuffle, queue tracks up, mark favourites and build your own playlists. A panel of playback tools sits behind the player bar at the bottom.

    • Folders, recently played, favourites and playlists (create your own or import an XSPF file)
    • Search plus genre and instrument filters, with seven ways to sort
    • Equalizer presets: Flat, Rock, Pop, Vocal Boost and Loudness, and you can save your own
    • Crossfade, loudness normalisation and a sleep timer from 15 to 90 minutes
    • A play queue, casting to another device, library stats, and a light or dark theme

    No account. Favourites, playlists and history live only in your browser, and the site can back them up to a file and restore them.

  • Foundry, live A full digital audio workstation you can try right in the browser. foundrydaw.com/live
    What’s inside

    Make the whole song without leaving the tab.

    Foundry is a digital audio workstation for Windows, macOS and Linux, and this link opens the free demo of it in your browser. You get the real arrangement window: add audio, MIDI and drum tracks, record, edit notes in the piano roll, program beats on the drum machine, add effects and mix, with a transport bar, tempo and metronome across the top. You can import audio and MIDI files, start from a template, and export what you make.

    • Audio, MIDI and drum tracks with select, edit, split, erase and paint tools and snap-to-grid
    • Piano roll, drum machine and sampler
    • Track effects with sidechain, MIDI effects and track presets
    • Tempo map, time stretch, beat detection, markers, loop and punch recording
    • Tuner, visualizer, undo history, templates and remote control
    • VST3 plugin chains per track in the desktop version

    It is a large app, so the first load takes a while. Recording needs you to allow the microphone, and plugin hosting is for the desktop build.

  • Foundry forum The Foundry community forum. Freqs sharing freqs. foundry.artuststudios.com/forum
    What’s inside

    Where the freqs trade freqs.

    This is the community corner of the Foundry website. The Foundry Reel Forum is a place to share .reel projects, the songs people make in Foundry, and to talk about them. It is brand new: at the moment there is one board, Reels, with a demo track called Night Market to get things started, so you would be one of the first to post. The menu around the forum leads to the rest of the Foundry site.

    • Reels: music made in Foundry, shared as .reel files
    • Forum and Activity views, with unread and new-post tracking
    • From the menu: the Foundry shop, the manual, downloads, the licence agreement and the live demo

    Anyone can read. You need to register and log in to create topics and posts.

Games

  • ArtHack: Dungeon Escape A browser roguelike where guards carry poleaxes and the doors run SSH. artofscripting.github.io/ArtHackWeb
    What’s inside

    Sneak, hack, loot and fight your way to daylight.

    ArtHack is a turn-based dungeon crawler in which a medieval keep and a corporate intrusion job are the same contract. You pick an operative and a difficulty, read the briefing, and start climbing out of the Black Keep through procedurally generated floors: oubliettes, barracks, throne antechambers. Every step, swing, search or hack takes a turn, and the guards move after you. You explore through fog of war, open doors, loot rooms and break into castle terminals with your portable rig. Reach the surface gate and you are out.

    • Stealth, melee and ranged combat against tougher foes the higher you climb
    • Hacking: search and breach terminals instead of fighting through
    • Loot, inventory, crafting, tools and skills to build your character
    • A map, journal, secrets and a travel log to keep track of the run
    • Saves, so you can come back to a run

    Nothing to install. Move with the arrow keys, WASD or hjkl and press ? for help. On a phone, turn on Touch Mode in the corner to get swipe movement and an action bar.

  • Terminal Harvest A farming game played in a terminal-style screen, with a whole town beyond the fence. artofscripting.github.io/Terminal-Farming
    What’s inside

    Till, plant, water, harvest. Repeat until rich.

    Terminal Harvest is a farming game drawn entirely in text characters. From the title screen you start a new game, load a save or set up a custom one, choosing your starting gold, number of plots and season. A welcome letter left around the farmhouse explains the loop: till the soil, plant, water and harvest, then spend what you earn. Beyond the home plot there is a town, a ranch, a kitchen, workshops, a tractor and hired labour to grow into, with quests, seed unlocks and achievements along the way.

    • New game, saved games, or a custom start from 100 to 50,000 gold and one to five plots
    • Auto-farm the field, auto-harvest, or let auto-play run the farm for you
    • Town, ranch, kitchen, workshops, tractor and labour systems
    • Quests, seed unlocks and achievements that pop up as you earn them
    • Built-in help with ? and a command console with /

    Played from the keyboard. The browser version adds on-screen arrow buttons and text-size controls, so it works on a phone too.

Toybox

Small things to play with while you’re here, sorted into tools, fun and games. The security, developer, notepad and to-do tools have moved to SOCtoys.com (bring your saved data). Open a few at once, drag them around, minimize them to the dock — timers and alarms keep ticking while they’re tucked away.