CyberCodex v3.2: Zero-dependency CLI engine unifying 22 free Threat Intel, Infostealer, and OSINT feeds (EPSS, CISA KEV, HIBP, Hudson Rock, Shodan InternetDB, RIPE BGP) with an offline APT & Incident Codex
CyberCodex v3.2 is an open-source, zero-dependency command-line interface (CLI) tool that aggregates 22 free threat intelligence, infostealer telemetry, and OSINT feeds. It enables security teams to perform domain and credential exposure checks, infrastructure and DNS telemetry, and offline cyber warfare correlation with detection rule generation. The tool integrates data from sources such as HaveIBeenPwned, Hudson Rock, Shodan InternetDB, RIPE BGP, EPSS, and CISA KEV, providing a unified interface without requiring API keys or external dependencies.
AI Analysis
Technical Summary
CyberCodex v3.2 is a Python standard library-based CLI engine that consolidates multiple free threat intelligence and OSINT feeds into a single tool. It supports domain and credential exposure analysis by querying HaveIBeenPwned, Hudson Rock infostealer telemetry, and password exposure databases. Infrastructure telemetry includes Shodan InternetDB, RIPE BGP, DNS records, TLS/SSL inspection, and email spoofing risk assessment. It also correlates live findings with historical cyber operations and generates detection rules for various SIEM platforms. The tool is open-source and designed to streamline SOC triage and threat intelligence workflows without cost or API key limitations.
Potential Impact
CyberCodex itself is not a vulnerability or exploit but a security tool that aids defenders by aggregating threat intelligence and telemetry data. It facilitates faster and more comprehensive incident triage and detection rule creation, potentially improving security operations efficiency. There is no indication that CyberCodex introduces security risks or is exploited in the wild.
Mitigation Recommendations
No remediation or patching is applicable as CyberCodex is a defensive tool. Users should review and validate the tool's outputs and integrate it into their security workflows as appropriate. Since it is open-source, users should ensure they obtain it from the official GitHub repository to avoid tampered versions.
CyberCodex v3.2: Zero-dependency CLI engine unifying 22 free Threat Intel, Infostealer, and OSINT feeds (EPSS, CISA KEV, HIBP, Hudson Rock, Shodan InternetDB, RIPE BGP) with an offline APT & Incident Codex
Description
CyberCodex v3.2 is an open-source, zero-dependency command-line interface (CLI) tool that aggregates 22 free threat intelligence, infostealer telemetry, and OSINT feeds. It enables security teams to perform domain and credential exposure checks, infrastructure and DNS telemetry, and offline cyber warfare correlation with detection rule generation. The tool integrates data from sources such as HaveIBeenPwned, Hudson Rock, Shodan InternetDB, RIPE BGP, EPSS, and CISA KEV, providing a unified interface without requiring API keys or external dependencies.
Reddit Discussion
Hi r/blueteamsec,
During SOC triage and domain exposure checks, I got tired of opening 20 browser tabs across Shodan, HaveIBeenPwned, Hudson Rock, crt.sh, RIPE BGP, FIRST EPSS, and CISA KEV, or hitting paywalls requiring expensive API keys.
So I built CyberCodex (v3.2), an open-source, terminal-first Threat Intelligence and OSINT CLI engine built purely with the Python standard library (zero external dependencies, 0 API keys, $0 cost).
What it pulls in parallel with a single command:
- Domain & Credential Exposure (leak command):
- HaveIBeenPwned (HIBP v3): Extracts the most recent breach date, largest historical breach volume (PwnCount), compromised DataClasses, and chronological timeline for any domain.
- Hudson Rock Cavalier Infostealer Telemetry: Separates server-side database breaches from client-side RedLine, Raccoon, Vidar, and Lumma stealer infections, showing compromised employee vs user counts, exact login URLs where credentials were stolen, password strength metrics, and bypassed Antiviruses.
- ProxyNova COMB & HIBP K-Anonymity: Checks password exposure across 850M+ records by sending only the first 5 SHA-1 hex characters.
- Infrastructure, DNS & Crypto Telemetry (intel / cve / ioc commands):
- Shodan InternetDB & RIPE BGP: Open ports, CPEs, hostnames, exposed CVEs, BGP CIDR prefixes, Origin ASNs, and Tor Exit Node verification.
- Cloudflare DoH (RFC 8484) & DMARC Auditor: Queries MX, NS, SPF, and _dmarc records to output an automated Email Spoofing Risk Verdict (LOW / MODERATE / HIGH).
- Live TLS/SSL X.509 Socket Inspector: Extracts cipher suites and SHA-256 certificate thumbprints, and flags self-signed or default Cobalt Strike C2 certificates.
- FIRST.org EPSS + CISA KEV + GitHub PoC Hunter: Combines CVSS scores with 30-day exploitation probability (%) and live public exploit repositories.
- Offline Cyber Warfare Codex & SIEM Rule Generator:
- Auto-correlates live findings against 10 major historical operations (Stuxnet, SolarWinds SUNBURST, NotPetya, Log4Shell, XZ Utils Backdoor, Volt Typhoon, Lazarus) and generates Wazuh XML, Sigma, Sentinel KQL, and Splunk SPL detection rules.
GitHub Repository (MIT Licensed):
https://github.com/prox0959/CyberCodex
Feedback and suggestions from blue teamers are very welcome!
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CyberCodex v3.2 is a Python standard library-based CLI engine that consolidates multiple free threat intelligence and OSINT feeds into a single tool. It supports domain and credential exposure analysis by querying HaveIBeenPwned, Hudson Rock infostealer telemetry, and password exposure databases. Infrastructure telemetry includes Shodan InternetDB, RIPE BGP, DNS records, TLS/SSL inspection, and email spoofing risk assessment. It also correlates live findings with historical cyber operations and generates detection rules for various SIEM platforms. The tool is open-source and designed to streamline SOC triage and threat intelligence workflows without cost or API key limitations.
Potential Impact
CyberCodex itself is not a vulnerability or exploit but a security tool that aids defenders by aggregating threat intelligence and telemetry data. It facilitates faster and more comprehensive incident triage and detection rule creation, potentially improving security operations efficiency. There is no indication that CyberCodex introduces security risks or is exploited in the wild.
Defensive Guidance
No remediation or patching is applicable as CyberCodex is a defensive tool. Users should review and validate the tool's outputs and integrate it into their security workflows as appropriate. Since it is open-source, users should ensure they obtain it from the official GitHub repository to avoid tampered versions.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":44,"reasons":["external_link","newsworthy_keywords:infostealer,apt,incident","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["infostealer","apt","incident"]}
- Has External Source
- false
- Trusted Domain
- false
Threat ID: 6ab97300f7a7c54106691fe5
Added to database: 09/27/2026, 19:48:16 UTC
Last enriched: 09/27/2026, 19:48:20 UTC
Last updated: 09/28/2026, 03:47:42 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.