Cover image for project: NEXUS Hybrid Analysis IN PROGRESS

Technical summary

NEXUS Hybrid Analysis integrates the CrowdStrike Falcon dynamic sandbox: it submits files (up to 32MB) and URLs for analysis, keeps a local history with summary/network/process reports and polls pending analyses via cron and CLI. It searches hashes without spending quota and contributes hash and URL signals through the Intelligence Hub, with a soft URLhaus integration and direct VirusTotal links.

Executed scope

  • Plugin registration (registerTab('hybrid-analysis','Hybrid Analysis','shield-alert',tab.php,'Segurança') + registerDoc + registerModal) and ha_install() preparing the plugin_hybrid_analyses table (job_id, sha256, submit_type, source_name/url, environment_id, status, verdict, threat_score, task_id, report_json/network_json/process_json, timestamps) via install.sql.
  • 11 API actions: ha_stats (counters + API status), ha_settings_get/ha_settings_save (key, environment_id, toggles, share_community), ha_test_connection (EICAR lookup), ha_submit_file (multipart file or file_base64, 32MB), ha_submit_url, ha_report (summary + network + process), ha_search_hash, ha_history (paginated), ha_poll_pending and ha_quota.
  • Hybrid Analysis API v2 integration (https://hybrid-analysis.com/api/v2): api-key + User-Agent: Falcon Sandbox headers; endpoints submit/file, submit/url, search/hash (GET, new format with reports/sha256s + overview/{sha256} fallback), report/{id}/summary|network|process and key/current; 60–90s timeouts, SSL verify and safe POST redirects (CURLOPT_POSTREDIR).
  • File submission: local SHA-256 hashing before upload; if the hash is already known on HA, answers cached with a lookup that consumes no submission quota; multipart with allow_community_access/no_share_third_party per config.
  • URL submission: soft URLhaus integration (uh_verify) annotates _urlhaus in the report if the URL is malicious; FILTER_VALIDATE_URL http/https validation.
  • Pending polling: ha_poll_pending() refreshes pending/queued/in_progress analyses (usleep 250ms between calls to stay under 5 req/min); ha_cron_check() with 5-min throttle via cronjob.json (job ha_poll, tick: true) and allowlisted CLI cli.php (ha_poll_pending(10)).
  • Hash search: ha_search_hash() accepts MD5/SHA1/SHA256; when the report lacks a verdict it fetches overview/{sha256} (with last_analysis.verdict fallback); ha_lookup_hash_summary() returns public HA + VT links even without an API key (link_only).
  • Enrichment (Intelligence Hub): nx_intel_register_enricher('hybrid-analysis', ['hash','url'], 'ha_intel_enrich', 50) consults the local cache / search/hash (never auto-submits on the hub); severity 80 when verdict is malicious/suspicious or score ≥50, otherwise 12; max_live_lookups budget (up to 4 hashes + 3 URLs per run), the rest skipped.
  • Security: API key stays server-side (DB::setConfig), the UI never re-displays it; ha_quota() returns a masked key (api_key_masked); uploads capped at 32MB.
  • UI (tab.php, 575 lines, Alpine haApp()): Submit/Reports/Config tabs, drag-and-drop file upload, URL submission, hash search, Poll pending button, auto-poll every 45s (when auto_poll and there are pending items), history table with detailed inline report (verdict, score, network, process, MITRE) and modal.

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (plugin_hybrid_analyses)
  • Hybrid Analysis API v2 (CrowdStrike Falcon Sandbox) — submit file/url, search hash, report, quota
  • URLhaus (soft integration) + VirusTotal (direct per-hash links)
  • Alpine.js + Tailwind CSS (tab.php)
  • Internal Plugin API (PluginManager tabs/actions/modals + cronjob.json + CLI + enricher)

Operational tags

  • Hybrid Analysis
  • CrowdStrike
  • Sandbox
  • Malware
  • Dynamic analysis
  • Hash
  • URL
  • NEXUS Plugin

Operational result

  • Dynamic analysis: files (up to 32MB) and URLs are executed in the CrowdStrike Falcon sandbox with network, process and MITRE reports.
  • Quota savings: a known hash answers via lookup (cached) with no submission consumed; hash search uses search/hash/overview.
  • Early detection: the soft URLhaus integration flags submitted URLs that are already malicious before analysis.
  • Polling automation: cron + CLI refresh pending analyses automatically (5-min throttle, ~4 req/min).
  • Hub enrichment: hashes and URLs mentioned in tasks/comments gain threat signals with calibrated severity.
  • Investigation links: every hash has direct Hybrid Analysis and VirusTotal links, even without an API key.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

CrowdStrike Falcon dynamic sandbox: submits files (up to 32MB) and URLs for analysis, keeps a local history with summary/network/process reports, polls pending analyses (cron + CLI), searches hashes without spending quota and contributes hash and URL signals via the Intelligence Hub — with a soft URLhaus integration and direct VirusTotal links.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.