Skip to main content

CyberCodex v3.2: Zero-dependency CLI engine unifying 22 free Threat Intel, Infostealer, and OSINT feeds (EPSS, CISA KEV, HIBP, Hudson Rock, Shodan InternetDB, RIPE BGP) with an offline APT & Incident Codex

0
Medium
Published: 09/27/2026 (09/27/2026, 11:41:06 UTC)
Source: Reddit BlueTeam

Description

CyberCodex v3.2 is an open-source, zero-dependency command-line interface (CLI) tool that aggregates 22 free threat intelligence, infostealer telemetry, and OSINT feeds. It enables security teams to perform domain and credential exposure checks, infrastructure and DNS telemetry, and offline cyber warfare correlation with detection rule generation. The tool integrates data from sources such as HaveIBeenPwned, Hudson Rock, Shodan InternetDB, RIPE BGP, EPSS, and CISA KEV, providing a unified interface without requiring API keys or external dependencies.

Reddit Discussion

r/blueteamsec·posted by u/Traditional_Bear5492
00

Hi r/blueteamsec,

During SOC triage and domain exposure checks, I got tired of opening 20 browser tabs across Shodan, HaveIBeenPwned, Hudson Rock, crt.sh, RIPE BGP, FIRST EPSS, and CISA KEV, or hitting paywalls requiring expensive API keys.

So I built CyberCodex (v3.2), an open-source, terminal-first Threat Intelligence and OSINT CLI engine built purely with the Python standard library (zero external dependencies, 0 API keys, $0 cost).

What it pulls in parallel with a single command:

  1. Domain & Credential Exposure (leak command):

- HaveIBeenPwned (HIBP v3): Extracts the most recent breach date, largest historical breach volume (PwnCount), compromised DataClasses, and chronological timeline for any domain.

- Hudson Rock Cavalier Infostealer Telemetry: Separates server-side database breaches from client-side RedLine, Raccoon, Vidar, and Lumma stealer infections, showing compromised employee vs user counts, exact login URLs where credentials were stolen, password strength metrics, and bypassed Antiviruses.

- ProxyNova COMB & HIBP K-Anonymity: Checks password exposure across 850M+ records by sending only the first 5 SHA-1 hex characters.

  1. Infrastructure, DNS & Crypto Telemetry (intel / cve / ioc commands):

- Shodan InternetDB & RIPE BGP: Open ports, CPEs, hostnames, exposed CVEs, BGP CIDR prefixes, Origin ASNs, and Tor Exit Node verification.

- Cloudflare DoH (RFC 8484) & DMARC Auditor: Queries MX, NS, SPF, and _dmarc records to output an automated Email Spoofing Risk Verdict (LOW / MODERATE / HIGH).

- Live TLS/SSL X.509 Socket Inspector: Extracts cipher suites and SHA-256 certificate thumbprints, and flags self-signed or default Cobalt Strike C2 certificates.

- FIRST.org EPSS + CISA KEV + GitHub PoC Hunter: Combines CVSS scores with 30-day exploitation probability (%) and live public exploit repositories.

  1. Offline Cyber Warfare Codex & SIEM Rule Generator:

- Auto-correlates live findings against 10 major historical operations (Stuxnet, SolarWinds SUNBURST, NotPetya, Log4Shell, XZ Utils Backdoor, Volt Typhoon, Lazarus) and generates Wazuh XML, Sigma, Sentinel KQL, and Splunk SPL detection rules.

GitHub Repository (MIT Licensed):

https://github.com/prox0959/CyberCodex

Feedback and suggestions from blue teamers are very welcome!

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/27/2026, 19:48:20 UTC

Technical Analysis

CyberCodex v3.2 is a Python standard library-based CLI engine that consolidates multiple free threat intelligence and OSINT feeds into a single tool. It supports domain and credential exposure analysis by querying HaveIBeenPwned, Hudson Rock infostealer telemetry, and password exposure databases. Infrastructure telemetry includes Shodan InternetDB, RIPE BGP, DNS records, TLS/SSL inspection, and email spoofing risk assessment. It also correlates live findings with historical cyber operations and generates detection rules for various SIEM platforms. The tool is open-source and designed to streamline SOC triage and threat intelligence workflows without cost or API key limitations.

Potential Impact

CyberCodex itself is not a vulnerability or exploit but a security tool that aids defenders by aggregating threat intelligence and telemetry data. It facilitates faster and more comprehensive incident triage and detection rule creation, potentially improving security operations efficiency. There is no indication that CyberCodex introduces security risks or is exploited in the wild.

Defensive Guidance

No remediation or patching is applicable as CyberCodex is a defensive tool. Users should review and validate the tool's outputs and integrate it into their security workflows as appropriate. Since it is open-source, users should ensure they obtain it from the official GitHub repository to avoid tampered versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":44,"reasons":["external_link","newsworthy_keywords:infostealer,apt,incident","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["infostealer","apt","incident"]}
Has External Source
false
Trusted Domain
false

Threat ID: 6ab97300f7a7c54106691fe5

Added to database: 09/27/2026, 19:48:16 UTC

Last enriched: 09/27/2026, 19:48:20 UTC

Last updated: 09/28/2026, 03:47:42 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses