Cover image for project: NEXUS AlienVault OTX IN PROGRESS

Technical summary

NEXUS plugin for free Threat Intelligence via AlienVault OTX: IOC lookups (IP, domain, hash, URL and CVE) with automatic type classification, subscribed pulse syncing that turns into NEXUS tasks with pulse_id dedup, task enrichment in the Intelligence Hub, configurable TTL cache and a poll cron with a 15-minute throttle — 100% free of license cost.

Executed scope

  • backend.php backend (688 lines): OTX_API_BASE = https://otx.alienvault.com/api/v1; X-OTX-API-KEY header authentication (free account).
  • Configuration (otx_get_config / otx_settings_save): api_key, enrich_tasks, auto_tasks, default_project (default "Geral"), min_severity (low/medium/high), filter_types and cache_ttl (clamped 60s–30 days); otx_public_config() never exposes the key (only api_configured).
  • Tables (created by otx_install()): otx_cache (kind, query_key, data, error, status, http_code, task_id; UNIQUE uk_kind_key), otx_history (provider, query_type, query_val, status, task_id; idx_provider) and otx_pulses (pulse_id with UNIQUE uk_pulse, name, description, severity, author, adversary, ioc_count, task_id, raw).
  • Cache: configurable TTL (cache_ttl), upsert per kind+key (lowercase key); otx_cache_put writes cache and history together; the force parameter bypasses cache.
  • HTTP (otx_http_get): 5s connect / 20s timeout; handles 401/403 (invalid key), 404 as not_found: true (indicator with no pulses), 429 (rate limit) and errors with the JSON detail.
  • otx_classify — automatic detection: IPv4, IPv6, MD5 (32 hex), SHA1 (40), SHA256 (64), URL (http(s)://), CVE (CVE-\d{4}-\d{4,}) and domain (regex); unrecognized input returns a descriptive error.
  • otx_search / otx_indicator_get — GET /indicators/{type}/{indicator}/general; returns first_seen, last_seen and associated pulse_info.pulses.
  • otx_status — GET /users/me; validates the key and returns the profile (username/login).
  • otx_sync_pulses — GET /pulses/subscribed?limit=100; pulse_id dedup (already-processed pulses are skipped); min_severity filter; creates a NEXUS task via task_create with [OTX] {pulse} — {adversary} title, markdown description (author, adversary, TLP, IOC list) and mapped priority (critical 4, high/blocking 3, medium 2, low 1); adds a system comment with the IOC count; stores in otx_pulses.
  • otx_pulse_get — GET /pulses/{id} (pulse cache kind).
  • otx_stats — processed pulses, today's lookups, pulses with task, api_configured and cache entries.
  • otx_pulses_list — limit ≤ 200, ordered by created_at DESC; otx_history — page and limit ≤ 100.
  • Cron (cronjob.json): otx_poll_pulses job — subscribed pulse polling with 15-minute throttle (otx_cron_check(900) records last_cron in config; otx_cron_run → otx_sync_pulses).
  • Intelligence Hub: alienvault-otx enricher (priority 40, types ip, ipv4, ipv6, domain, hostname, url, hash, md5, sha1, sha256, cve) — enabled by enrich_tasks + configured key; type:value dedup; IOC present in pulses → signal with severity: 'high', status: 'malicious', summary OTX: IOC present in N pulse(s) · {first pulse name}.
  • API: 11 actions via PluginManager::registerApiAction (otx_settings, otx_settings_save, otx_status, otx_search, otx_indicator_get, otx_pulse_get, otx_sync_pulses, otx_pulses, otx_stats, otx_history, otx_enrich_task).
  • Alpine.js UI (tab.php, 440 lines): amber theme; status indicator (green "API Online" with pulse / red "Invalid key" / amber "Not configured") with a Configure link; 4 stat cards (Pulses, Today's lookups, With task, Cache); Lookup IOC tab ("Force" checkbox, Cache/Live badge, first_seen/last_seen, associated pulses with ATTRIBUTION badge when attack_ids exist), Pulses tab ("Sync now" button, severity, linked task), History (type/value/status/date) and Settings (API Key, auto-task and enrichment toggles, minimum severity, default project, IOC types).
  • Fastr: 1 command — /otx <IOC> (query, arg_required=true).
  • First plugin in the series with a cronjob.json — periodic pulse polling (15 min), on top of the 7-day cache.

Stack and tools

  • PHP 8 (no framework)
  • MySQL 8 (otx_cache + otx_history + otx_pulses)
  • Alpine.js + Tailwind CSS (premium light, amber ring)
  • NEXUS plugin system (PluginManager + cronjob.json)
  • cURL → AlienVault OTX API v1 (otx.alienvault.com)

Operational tags

  • Threat Intelligence
  • OTX
  • AlienVault
  • IOC
  • Threat Pulses
  • OSINT
  • Plugin NEXUS

Operational outcome

  • Free IOC lookup with automatic type classification (IP, domain, hash, URL, CVE) and associated pulses readable right in the tab.
  • Subscribed pulses become automatic NEXUS tasks with pulse_id dedup — continuous intelligence at no cost and no duplication.
  • Automatic enrichment: IOCs mentioned in tasks/comments become high-severity signals when present in OTX pulses.
  • Built-in monitoring: pulse stats, today's lookups, created tasks and cache entries.
  • 15-minute cron keeps pulses fresh without relying on manual action.
  • Configurable TTL cache and an auditable history of lookups and syncs.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin for free Threat Intelligence via AlienVault OTX: IOC lookups (IP, domain, hash, URL and CVE) with automatic type classification, subscribed pulse syncing that turns into NEXUS tasks with pulse_id dedup, task enrichment in the Intelligence Hub, configurable TTL cache and a poll cron with 15-minute throttle.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.