Open-Source Release: CyberCodex v3.2 - Autonomous 22-source zero-cost CTI aggregator (CISA KEV, FIRST EPSS, ThreatFox, Feodo C2, Hudson Rock, HIBP) + APT & Operation Encyclopedia
CyberCodex v3.2 is an open-source Python CLI tool designed to aggregate cyber threat intelligence (CTI) from 22 public sources without requiring API keys. It provides live enrichment of indicators of compromise (IOCs) and hashes, vulnerability prioritization using MITRE CVE data combined with exploitation probability scores, and telemetry on infostealers and breaches. The tool also includes offline encyclopedic data on advanced persistent threat (APT) operations and actor profiles, supporting multiple languages and exporting data in Markdown or JSON formats.
AI Analysis
Technical Summary
CyberCodex v3.2 is a lightweight, zero-dependency CTI aggregator that queries multiple public threat intelligence feeds such as CISA KEV, FIRST EPSS, ThreatFox, Feodo C2, Hudson Rock, and Have I Been Pwned (HIBP). It enriches live IOCs and hashes, prioritizes vulnerabilities based on exploitation probabilities and ransomware campaign statuses, and aggregates breach telemetry. Additionally, it provides structured kill-chain breakdowns of major APT operations and profiles of threat actors, facilitating correlation between live threat data and historical campaigns. The tool is implemented entirely in Python standard library and is intended for CTI analysts seeking fast terminal-based enrichment without managing API keys.
Potential Impact
This tool enhances the efficiency and breadth of threat intelligence analysis by consolidating multiple public CTI sources into a single, easy-to-use CLI interface. It does not represent a vulnerability or threat itself but serves as a resource for security professionals to better understand and prioritize threats. There is no indication of exploitation or malicious activity associated with this tool.
Mitigation Recommendations
Not applicable. This is an open-source CTI aggregation tool, not a vulnerability or exploit. No remediation or patching is required.
Open-Source Release: CyberCodex v3.2 - Autonomous 22-source zero-cost CTI aggregator (CISA KEV, FIRST EPSS, ThreatFox, Feodo C2, Hudson Rock, HIBP) + APT & Operation Encyclopedia
Description
CyberCodex v3.2 is an open-source Python CLI tool designed to aggregate cyber threat intelligence (CTI) from 22 public sources without requiring API keys. It provides live enrichment of indicators of compromise (IOCs) and hashes, vulnerability prioritization using MITRE CVE data combined with exploitation probability scores, and telemetry on infostealers and breaches. The tool also includes offline encyclopedic data on advanced persistent threat (APT) operations and actor profiles, supporting multiple languages and exporting data in Markdown or JSON formats.
Reddit Discussion
Hey r/ThreatIntel,
I built CyberCodex (v3.2), a lightweight, zero-dependency Python CLI tool designed for CTI analysts who want fast terminal enrichment across 22 public intelligence feeds without managing API keys.
Key CTI Features:
- Live IOC & Hash Enrichment: Queries abuse.ch ThreatFox, Feodo Tracker Botnet C2 blocklists, Tor Project Exit Node lists, and Shodan InternetDB in parallel.
- Vulnerability Prioritization: Combines MITRE CVE v5 data with FIRST.org EPSS 30-day exploitation probability scores, CISA KEV ransomware campaign status, and live GitHub PoC repositories.
- Infostealer & Breach Telemetry: Aggregates domain-level exposure from HIBP v3 and Hudson Rock Cavalier (RedLine, Raccoon, Vidar, Lumma logs, compromised portal URLs, and employee password complexity).
- Offline APT & Incident Codex: Includes structured kill-chain breakdowns of 10 major operations (SolarWinds, NotPetya, Stuxnet, XZ Backdoor, Volt Typhoon, Scattered Spider) and 6 APT actor profiles, with automatic correlation between live IOCs/CVEs and historical campaigns.
- Multi-Language Support: Supports 11 languages out of the box and exports dossiers to Markdown or JSON.
GitHub Repository:
https://github.com/prox0959/CyberCodex
100% Python standard library (no pip packages required). Would love to hear what other free CTI feeds you'd like to see integrated!
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CyberCodex v3.2 is a lightweight, zero-dependency CTI aggregator that queries multiple public threat intelligence feeds such as CISA KEV, FIRST EPSS, ThreatFox, Feodo C2, Hudson Rock, and Have I Been Pwned (HIBP). It enriches live IOCs and hashes, prioritizes vulnerabilities based on exploitation probabilities and ransomware campaign statuses, and aggregates breach telemetry. Additionally, it provides structured kill-chain breakdowns of major APT operations and profiles of threat actors, facilitating correlation between live threat data and historical campaigns. The tool is implemented entirely in Python standard library and is intended for CTI analysts seeking fast terminal-based enrichment without managing API keys.
Potential Impact
This tool enhances the efficiency and breadth of threat intelligence analysis by consolidating multiple public CTI sources into a single, easy-to-use CLI interface. It does not represent a vulnerability or threat itself but serves as a resource for security professionals to better understand and prioritize threats. There is no indication of exploitation or malicious activity associated with this tool.
Defensive Guidance
Not applicable. This is an open-source CTI aggregation tool, not a vulnerability or exploit. No remediation or patching is required.
Technical Details
- Source Type
- Subreddit
- ThreatIntelligence+threatintel+websecurityresearch
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":41,"reasons":["external_link","newsworthy_keywords:rce,apt","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce","apt"]}
- Has External Source
- false
- Trusted Domain
- false
Threat ID: 6aba4cfaf7a7c54106950eec
Added to database: 09/28/2026, 11:18:18 UTC
Last enriched: 09/28/2026, 11:18:28 UTC
Last updated: 09/29/2026, 03:47:52 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.