← All flagship demos
Interactive Demo · cyber

Cyber Mesh Demo

Persona: CISO

You are CISO of a 2,400-employee Canadian bank — Tuesday 09:14 ET. CISA publishes a new Known Exploited Vulnerability (CVE-2026-13947, Citrix NetScaler ADC, CVSS 9.8). Your SOC analyst asks: "Are we exposed, who's targeting it, and what's the blast radius if we get hit before patch window?"

Live mesh panels (synthetic data)
ThreatPulse — CVE intelligence
CVE-2026-13947CVSS 9.8RCE, pre-auth
CISA KEVAdded 09:01exploited in wild
Active campaigns3 knownransom + APT-Asia + commodity
Exploit availabilityPoC publicMetasploit module exists
Patch SLA<72hregulatory + insurance
EndpointPulse — your exposure
Citrix ADC instances12all production
Internet-facing4highest priority
Patch level6 unpatchedv13.1-49.15
Compensating controlsWAF + GeoIPpartial mitigation
Time-to-patch est.~36hneeds change board
AdversarialAI — attack-path simulation
Initial accessRCE on ADCno auth required
Lateral movementAD trustdomain admin in 4-6h
Crown jewels reachCore banking12 hops max
Data exfil capacity~80 GB/hvia legit DNS
Confidence82%ResiliencePulse drill data
Mesh query
Are we exposed to CVE-2026-13947, and what's the blast radius before patch?
Mesh composite answer

Exposed: 4 internet-facing ADCs unpatched. Blast radius: full domain compromise within 6h. Patch the 4 by EOD.

ThreatPulse confirms CVE-2026-13947 is a pre-auth RCE on Citrix NetScaler with active wild exploitation (3 campaigns, including APT-Asia which has previously hit Canadian banking). EndpointPulse shows you have 12 ADC instances; 6 are unpatched, of which 4 are internet-facing — those are the real risk. AdversarialAI ran the attack-path: an attacker landing on any of the 4 internet-facing ADCs reaches domain admin within 4-6h via existing AD trust paths, and crown-jewel banking systems within 12 hops. Your WAF + GeoIP provide partial mitigation but PoC bypasses are already public. ResiliencePulse playbook says patch within 24h or temporarily disable the 4 internet-facing ADCs; the other 8 (internal-only) can wait for next change window.
Provenance — which flagship contributed what
ThreatPulseCISA KEV ingest 09:01 → CVE + 3 campaigns + PoC
EndpointPulseasset graph → 12 ADCs, 6 unpatched, 4 exposed
AdversarialAIgraph-based attack-path → 4-6h to DA, 12 hops to core
ResiliencePulseplaybook PB-CITRIX-RCE-01 → patch SLA + isolation steps
Recommended actions
Cost compare
Equivalent stack
$32,000/mo (CrowdStrike + Mandiant + Recorded Future)
Manera Mesh Tier
$999/mo Mesh Tier
Savings
97% lower
This is a recorded demo. Numbers shown are synthetic and illustrative — designed to show how the mesh fuses signals across flagships. The free trial runs the same workflow on your own data with live FXWatch / SentimentDNA / CreditPulse / etc. feeds. No live Claude calls were made on this page.