Skip to main content

Open-Source Release: CyberCodex v3.2 - Autonomous 22-source zero-cost CTI aggregator (CISA KEV, FIRST EPSS, ThreatFox, Feodo C2, Hudson Rock, HIBP) + APT & Operation Encyclopedia

0
Medium
Published: 09/27/2026 (09/27/2026, 11:41:45 UTC)
Source: Reddit ThreatIntel

Description

CyberCodex v3.2 is an open-source Python CLI tool designed to aggregate cyber threat intelligence (CTI) from 22 public sources without requiring API keys. It provides live enrichment of indicators of compromise (IOCs) and hashes, vulnerability prioritization using MITRE CVE data combined with exploitation probability scores, and telemetry on infostealers and breaches. The tool also includes offline encyclopedic data on advanced persistent threat (APT) operations and actor profiles, supporting multiple languages and exporting data in Markdown or JSON formats.

Reddit Discussion

r/threatintel·posted by u/Traditional_Bear5492
00

Hey r/ThreatIntel,

I built CyberCodex (v3.2), a lightweight, zero-dependency Python CLI tool designed for CTI analysts who want fast terminal enrichment across 22 public intelligence feeds without managing API keys.

Key CTI Features:

- Live IOC & Hash Enrichment: Queries abuse.ch ThreatFox, Feodo Tracker Botnet C2 blocklists, Tor Project Exit Node lists, and Shodan InternetDB in parallel.

- Vulnerability Prioritization: Combines MITRE CVE v5 data with FIRST.org EPSS 30-day exploitation probability scores, CISA KEV ransomware campaign status, and live GitHub PoC repositories.

- Infostealer & Breach Telemetry: Aggregates domain-level exposure from HIBP v3 and Hudson Rock Cavalier (RedLine, Raccoon, Vidar, Lumma logs, compromised portal URLs, and employee password complexity).

- Offline APT & Incident Codex: Includes structured kill-chain breakdowns of 10 major operations (SolarWinds, NotPetya, Stuxnet, XZ Backdoor, Volt Typhoon, Scattered Spider) and 6 APT actor profiles, with automatic correlation between live IOCs/CVEs and historical campaigns.

- Multi-Language Support: Supports 11 languages out of the box and exports dossiers to Markdown or JSON.

GitHub Repository:

https://github.com/prox0959/CyberCodex

100% Python standard library (no pip packages required). Would love to hear what other free CTI feeds you'd like to see integrated!

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 11:18:28 UTC

Technical Analysis

CyberCodex v3.2 is a lightweight, zero-dependency CTI aggregator that queries multiple public threat intelligence feeds such as CISA KEV, FIRST EPSS, ThreatFox, Feodo C2, Hudson Rock, and Have I Been Pwned (HIBP). It enriches live IOCs and hashes, prioritizes vulnerabilities based on exploitation probabilities and ransomware campaign statuses, and aggregates breach telemetry. Additionally, it provides structured kill-chain breakdowns of major APT operations and profiles of threat actors, facilitating correlation between live threat data and historical campaigns. The tool is implemented entirely in Python standard library and is intended for CTI analysts seeking fast terminal-based enrichment without managing API keys.

Potential Impact

This tool enhances the efficiency and breadth of threat intelligence analysis by consolidating multiple public CTI sources into a single, easy-to-use CLI interface. It does not represent a vulnerability or threat itself but serves as a resource for security professionals to better understand and prioritize threats. There is no indication of exploitation or malicious activity associated with this tool.

Defensive Guidance

Not applicable. This is an open-source CTI aggregation tool, not a vulnerability or exploit. No remediation or patching is required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":41,"reasons":["external_link","newsworthy_keywords:rce,apt","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce","apt"]}
Has External Source
false
Trusted Domain
false

Threat ID: 6aba4cfaf7a7c54106950eec

Added to database: 09/28/2026, 11:18:18 UTC

Last enriched: 09/28/2026, 11:18:28 UTC

Last updated: 09/29/2026, 03:47:52 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses