Cover image for project: NEXUS BeVigil IN PROGRESS

Technical summary

NEXUS integration with the BeVigil OSINT API for asset discovery in Android applications: lookup by package_id (com.example.app) or domain, exposing hosts, S3 buckets, REST paths, IPs, emails, indexed apps and subdomains — with a 0–100 exposure score, 7-day local cache, surface comparator, paginated history and JSON export.

Executed scope

  • plugin.json: v1.0.0, "Intelligence" category, website bevigil.com.
  • backend.php backend (742 lines) — integration with the BeVigil OSINT API (https://osint.bevigil.com, X-Access-Token header, Accept: application/json; 5s connect timeout, 25s total timeout, SSL_VERIFYPEER => true — certificate verification enabled, unlike other plugins in the series).
  • bevigil_scans table (created by bevigil_install(), 7-day cache): query_hash varchar(32) UNIQUE (md5('package:…') or md5('domain:…')), query_type, query_value, hosts_count, s3_count, apps_count, urls_count, assets_summary JSON, report_json JSON, score, raw_json JSON, task_id, cached, scanned_at; indexes idx_query_type, idx_scanned_at, idx_score.
  • bevigil_detect_query_type — regex to tell package (com.foo.bar) from domain; bevigil_lookup routes accordingly (or errors with instructions).
  • bevigil_lookup_package — 4 calls (/api/{pkg}/hosts, /S3-buckets, /all-assets, /report); extracts IPs (IP Address disclosure), AWS URLs, rest_api and emails from the all-assets block; assets_summary slices (hosts 80, s3 40, rest 40, ips 40, aws 40, emails 20).
  • bevigil_lookup_domain — normalizes (strips http(s)://, path and trailing dot), calls /api/{domain}/apps, /subdomains and /urls; summary with packages 50, subdomains 60, urls 40.
  • Score 0–100 (lower = more exposure): prefers explicit report fields (score, risk_score, riskScore, security_score, app_score; nested in summary/meta/app); falls back to heuristics — package: max(5, 100 − min(90, hosts*0.4 + s3*8 + ips*2 + aws*6)); domain: max(5, 100 − min(90, apps*3 + urls*0.2 + subs*0.3)).
  • Cache — reuses records by query_hash when scanned_at > NOW() − 7 days; force=1 bypasses; inserts/updates with ON DUPLICATE KEY UPDATE and cached flag ("cache" badge in the UI).
  • bevigil_stats — total, packages, domains, today's lookups, average score, critical (score < 40), api_configured, api_online, auto_enrich.
  • bevigil_history — paginated (page, limit ≤ 50), ORDER BY scanned_at DESC; returns items/page/pages/total.
  • bevigil_compare — two lookups (a, b) with B−A delta of score, hosts, s3, apps and urls.
  • bevigil_test_connection — smoke against /api/com.whatsapp/hosts: 401/402 = error, 200/404 = connection OK (404 still proves auth).
  • bevigil_export — lookup payload as JSON with format: 'json' and filename: 'bevigil-{query}.json'.
  • Mapped errors: 401 invalid key, 402 insufficient credits, 404 not found, connection timeout/error.
  • Intelligence Hub: SIGNAL enricher (with severity) bevigil_intel_enrich (priority 41, types domain, url, _text) — domain/url → domain surface; _text → package extraction with false-positive filter (java., javax., kotlin., android., androidx., org.w3c., org.xml., com.google.android., com.android.); up to 4 packages + 4 domains; lookup budget (NX_INTEL_MAX_LIVE_LOOKUPS, default 12); severity = 100 − score (30 when no score); status ok/error/needs_key (no API key)/skipped (budget); cached flag; honors auto_enrich.
  • Settings (bevigil_settings / bevigil_settings_save) — api_key (with keep_key so it is not overwritten) + auto_enrich via DB::setConfig('bevigil_settings'); bevigil_public_config only exposes api_configured/auto_enrich (never the key).
  • Alpine.js UI (tab.php, 374 lines) — emerald theme, smartphone icon, Security tab; 4 sub-tabs (Lookup, History, Compare, Settings); 5 KPI cards (Lookups, Packages, Domains, Avg score, Critical); API Key OK / Configure key badge with shortcut; scoreClass (rose < 40, amber < 70, emerald ≥ 70); result header changes color with score (rose/emerald) + "cache" badge; host chips, S3 in red, REST paths in <pre>, apps with names; client-side JSON export (Blob + download); clickable history (re-queries); delta comparator (A / Delta B−A / B); settings with "How to get the API Key" guide + Test connection button.
  • Fastr: /bevigil <package_id|domain> → bevigil_lookup (required argument).
  • No cron (on-demand — lookups only run when triggered; the cache avoids burning credits repeatedly).
  • API note: public docs use osint.bevigil.com (lookup by package/domain); APK upload is not supported by the public API — it stays on the web/Enterprise product; for static APK scans in CI use MobSF/QARK with BeVigil as a complementary OSINT layer.

Stack and tools

  • PHP 8 (no framework)
  • MySQL 8 (bevigil_scans — 7-day cache)
  • Alpine.js + Tailwind CSS (premium light, emerald)
  • BeVigil OSINT API (osint.bevigil.com, X-Access-Token)
  • cURL with SSL verify ON (5s connect / 25s timeout)
  • NEXUS plugin system (PluginManager + Intel Hub enricher)

Operational tags

  • BeVigil
  • OSINT
  • Mobile Security
  • Android
  • Asset Discovery
  • Intelligence Hub
  • Plugin NEXUS

Operational result

  • Android package or domain lookup with 0–100 exposure score (lower = more exposure) and a highlighted color in the UI (red < 40).
  • Consolidated asset surface: hosts, S3 buckets, REST paths, IPs, AWS URLs, emails, indexed apps and subdomains.
  • 7-day local cache per query — avoids wasting BeVigil credits on repeated lookups.
  • Comparator of two surfaces (e.g., app versions) with B−A delta.
  • Auto-enrich in the Intelligence Hub: domain/URL/text mentions with packages → severity signals.
  • No cron: on-demand, no hidden cost.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Mobile-focused threat intelligence (OSINT) module powered by the BeVigil API. Analyzes Android packages (APKs) and domains to discover exposed internal endpoints, leaked API keys, hardcoded credentials, and unsecured AWS S3 buckets, scoring real-time attack exposure.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.