Cover image for project: Nexus Intelligence Lists IN PROGRESS

Technical summary

Native NEXUS plugin that controls which artifacts the Intelligence Hub ignores or approves. Core logic persists mutually exclusive lists, matches exact values or domains, and invalidates cache by revision; the interface and task sidebar classify IPs, domains, URLs, emails, hashes and other types without a dedicated table.

Executed scope

  • plugin.json — v1.0.1, is_core: true, NEXUS category, lucide list icon with icon_bg #eef2ff.
  • Registrations: registerTab("nexus-intel-lists", "Intel Lists", "list", tab.php, "NEXUS") and registerDoc("nexus-intel-lists", "Intelligence Lists", "list", doc.md).
  • 5 API actions (plugin.php, via PluginManager::registerApiAction) — intel_lists_get, intel_ignore (ignore with note), intel_approve, intel_list_add (generic list), intel_list_remove — all delegating to the core.
  • ACL in api.php (lines 308-309): the 5 actions require the nexus-intel-lists plugin permission (action → plugin map).
  • Core core/intel.php — nx_intel_lists_get (request-scoped $GLOBALS memo with refresh), nx_intel_lists_rev, nx_intel_lists_set (persistence + rev++), nx_intel_host_from_value, nx_intel_list_entry_matches (exact or domain → subdomain/URL/email), nx_intel_is_ignored/nx_intel_is_approved, nx_intel_filter_ignored_artifacts, nx_intel_list_normalize_entry, nx_intel_list_add (validation, dedupe, list switching), nx_intel_list_remove.
  • Hub integration: nx_intel_for_text() filters ignored artifacts on extraction; nx_intel_build_payload() flags approved per artifact; nx_intel_attach_to_task()/nx_intel_attach_to_comment() use a cache key with rev (TTL 600s) → changing the list reprocesses on the next get; api.php calls nx_intel_attach_to_comment on comment endpoints (lines 830, 913, 939).
  • Task sidebar (partials/modals/view-task.php, lines 267-290): x-show per activeTask?.intel?.artifacts with intelIgnoreArtifact/intelApproveArtifact buttons.
  • Alpine.js UI (tab.php, ~9.9 KB, no backend): 3 cards (Ignored/Approved/Revision), Ignored/Approved/Add tabs, client-side search (value/type/note), list with type badge + code + note + removal (trash-2), manual add form (list, domain/url/ip/email/hash/cve/cnpj type, value, note) with toasts via Alpine.store('tasks').

Stack and tools

  • PHP 8 (no framework)
  • DB config (nx_intel_lists) — no dedicated MySQL table
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager::registerTab/registerDoc/registerApiAction)
  • NEXUS Intelligence Hub (core/intel.php)

Operational tags

  • Intelligence
  • Ignored
  • Approved
  • Threat Intel
  • Artifacts
  • NEXUS Plugin
  • Filters

Operational result

  • Fine-grained Intelligence Hub control: detected domains, URLs, IPs, emails, hashes, CVEs and CNPJs can be ignored (hidden from display and enrichment) or approved (kept visible and flagged, without action buttons).
  • A single domain entry covers subdomains, URLs and emails of that host — no need to list every variation.
  • rev in the Hub cache key means list changes reflect on the next task/comment view, with no manual cache clearing.
  • Request-scoped memo prevents the ignore from "leaking" across requests/workers and re-attaching freshly ignored intel.
  • Without the plugin, every detected artifact shows and gets enriched with no way to filter it.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Centralized allowlist and denylist system for the NEXUS Intelligence Hub. Enables global rules to automatically ignore or approve artifacts such as IPs, domains, emails, URLs, hashes, and CVEs across tasks and comments, eliminating alert fatigue and streamlining security triage.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.