IN PROGRESS
Technical summary
NEXUS plugin for free Threat Intelligence via AlienVault OTX: IOC lookups (IP, domain, hash, URL and CVE) with automatic type classification, subscribed pulse syncing that turns into NEXUS tasks with pulse_id dedup, task enrichment in the Intelligence Hub, configurable TTL cache and a poll cron with a 15-minute throttle — 100% free of license cost.
Executed scope
backend.phpbackend (688 lines):OTX_API_BASE = https://otx.alienvault.com/api/v1;X-OTX-API-KEYheader authentication (free account).- Configuration (
otx_get_config/otx_settings_save):api_key,enrich_tasks,auto_tasks,default_project(default "Geral"),min_severity(low/medium/high),filter_typesandcache_ttl(clamped 60s–30 days);otx_public_config()never exposes the key (onlyapi_configured). - Tables (created by
otx_install()):otx_cache(kind, query_key, data, error, status, http_code, task_id;UNIQUE uk_kind_key),otx_history(provider, query_type, query_val, status, task_id;idx_provider) andotx_pulses(pulse_id withUNIQUE uk_pulse, name, description, severity, author, adversary, ioc_count, task_id, raw). - Cache: configurable TTL (
cache_ttl), upsert per kind+key (lowercase key);otx_cache_putwrites cache and history together; theforceparameter bypasses cache. - HTTP (
otx_http_get): 5s connect / 20s timeout; handles 401/403 (invalid key), 404 asnot_found: true(indicator with no pulses), 429 (rate limit) and errors with the JSONdetail. otx_classify— automatic detection: IPv4, IPv6, MD5 (32 hex), SHA1 (40), SHA256 (64), URL (http(s)://), CVE (CVE-\d{4}-\d{4,}) and domain (regex); unrecognized input returns a descriptive error.otx_search/otx_indicator_get— GET/indicators/{type}/{indicator}/general; returnsfirst_seen,last_seenand associatedpulse_info.pulses.otx_status— GET/users/me; validates the key and returns the profile (username/login).otx_sync_pulses— GET/pulses/subscribed?limit=100;pulse_iddedup (already-processed pulses are skipped);min_severityfilter; creates a NEXUS task viatask_createwith[OTX] {pulse} — {adversary}title, markdown description (author, adversary, TLP, IOC list) and mapped priority (critical 4, high/blocking 3, medium 2, low 1); adds asystemcomment with the IOC count; stores inotx_pulses.otx_pulse_get— GET/pulses/{id}(pulsecache kind).otx_stats— processed pulses, today's lookups, pulses with task,api_configuredand cache entries.otx_pulses_list— limit ≤ 200, ordered bycreated_at DESC;otx_history— page and limit ≤ 100.- Cron (
cronjob.json):otx_poll_pulsesjob — subscribed pulse polling with 15-minute throttle (otx_cron_check(900)recordslast_cronin config;otx_cron_run→otx_sync_pulses). - Intelligence Hub:
alienvault-otxenricher (priority 40, typesip,ipv4,ipv6,domain,hostname,url,hash,md5,sha1,sha256,cve) — enabled byenrich_tasks+ configured key;type:valuededup; IOC present in pulses → signal withseverity: 'high',status: 'malicious', summaryOTX: IOC present in N pulse(s) · {first pulse name}. - API: 11 actions via
PluginManager::registerApiAction(otx_settings, otx_settings_save, otx_status, otx_search, otx_indicator_get, otx_pulse_get, otx_sync_pulses, otx_pulses, otx_stats, otx_history, otx_enrich_task). - Alpine.js UI (
tab.php, 440 lines): amber theme; status indicator (green "API Online" with pulse / red "Invalid key" / amber "Not configured") with a Configure link; 4 stat cards (Pulses, Today's lookups, With task, Cache); Lookup IOC tab ("Force" checkbox, Cache/Live badge, first_seen/last_seen, associated pulses with ATTRIBUTION badge when attack_ids exist), Pulses tab ("Sync now" button, severity, linked task), History (type/value/status/date) and Settings (API Key, auto-task and enrichment toggles, minimum severity, default project, IOC types). - Fastr: 1 command —
/otx <IOC>(query,arg_required=true). - First plugin in the series with a
cronjob.json— periodic pulse polling (15 min), on top of the 7-day cache.
Stack and tools
- PHP 8 (no framework)
- MySQL 8 (otx_cache + otx_history + otx_pulses)
- Alpine.js + Tailwind CSS (premium light, amber ring)
- NEXUS plugin system (PluginManager + cronjob.json)
- cURL → AlienVault OTX API v1 (otx.alienvault.com)
Operational tags
- Threat Intelligence
- OTX
- AlienVault
- IOC
- Threat Pulses
- OSINT
- Plugin NEXUS
Operational outcome
- Free IOC lookup with automatic type classification (IP, domain, hash, URL, CVE) and associated pulses readable right in the tab.
- Subscribed pulses become automatic NEXUS tasks with
pulse_iddedup — continuous intelligence at no cost and no duplication. - Automatic enrichment: IOCs mentioned in tasks/comments become high-severity signals when present in OTX pulses.
- Built-in monitoring: pulse stats, today's lookups, created tasks and cache entries.
- 15-minute cron keeps pulses fresh without relying on manual action.
- Configurable TTL cache and an auditable history of lookups and syncs.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin for free Threat Intelligence via AlienVault OTX: IOC lookups (IP, domain, hash, URL and CVE) with automatic type classification, subscribed pulse syncing that turns into NEXUS tasks with pulse_id dedup, task enrichment in the Intelligence Hub, configurable TTL cache and a poll cron with 15-minute throttle.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.