IN PROGRESS
Technical summary
Native NEXUS plugin that controls which artifacts the Intelligence Hub ignores or approves. Core logic persists mutually exclusive lists, matches exact values or domains, and invalidates cache by revision; the interface and task sidebar classify IPs, domains, URLs, emails, hashes and other types without a dedicated table.
Executed scope
plugin.json— v1.0.1,is_core: true, NEXUS category, lucidelisticon withicon_bg #eef2ff.- Registrations:
registerTab("nexus-intel-lists", "Intel Lists", "list", tab.php, "NEXUS")andregisterDoc("nexus-intel-lists", "Intelligence Lists", "list", doc.md). - 5 API actions (
plugin.php, viaPluginManager::registerApiAction) —intel_lists_get,intel_ignore(ignore withnote),intel_approve,intel_list_add(generic list),intel_list_remove— all delegating to the core. - ACL in
api.php(lines 308-309): the 5 actions require thenexus-intel-listsplugin permission (action → plugin map). - Core
core/intel.php—nx_intel_lists_get(request-scoped$GLOBALSmemo withrefresh),nx_intel_lists_rev,nx_intel_lists_set(persistence +rev++),nx_intel_host_from_value,nx_intel_list_entry_matches(exact or domain → subdomain/URL/email),nx_intel_is_ignored/nx_intel_is_approved,nx_intel_filter_ignored_artifacts,nx_intel_list_normalize_entry,nx_intel_list_add(validation, dedupe, list switching),nx_intel_list_remove. - Hub integration:
nx_intel_for_text()filters ignored artifacts on extraction;nx_intel_build_payload()flagsapprovedper artifact;nx_intel_attach_to_task()/nx_intel_attach_to_comment()use a cache key withrev(TTL 600s) → changing the list reprocesses on the next get;api.phpcallsnx_intel_attach_to_commenton comment endpoints (lines 830, 913, 939). - Task sidebar (
partials/modals/view-task.php, lines 267-290):x-showperactiveTask?.intel?.artifactswithintelIgnoreArtifact/intelApproveArtifactbuttons. - Alpine.js UI (
tab.php, ~9.9 KB, no backend): 3 cards (Ignored/Approved/Revision), Ignored/Approved/Add tabs, client-side search (value/type/note), list with type badge +code+ note + removal (trash-2), manual add form (list, domain/url/ip/email/hash/cve/cnpj type, value, note) with toasts viaAlpine.store('tasks').
Stack and tools
- PHP 8 (no framework)
- DB config (
nx_intel_lists) — no dedicated MySQL table - Alpine.js + Tailwind CSS
- NEXUS plugin system (
PluginManager::registerTab/registerDoc/registerApiAction) - NEXUS Intelligence Hub (
core/intel.php)
Operational tags
- Intelligence
- Ignored
- Approved
- Threat Intel
- Artifacts
- NEXUS Plugin
- Filters
Operational result
- Fine-grained Intelligence Hub control: detected domains, URLs, IPs, emails, hashes, CVEs and CNPJs can be ignored (hidden from display and enrichment) or approved (kept visible and flagged, without action buttons).
- A single
domainentry covers subdomains, URLs and emails of that host — no need to list every variation. revin the Hub cache key means list changes reflect on the next task/comment view, with no manual cache clearing.- Request-scoped memo prevents the ignore from "leaking" across requests/workers and re-attaching freshly ignored intel.
- Without the plugin, every detected artifact shows and gets enriched with no way to filter it.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Centralized allowlist and denylist system for the NEXUS Intelligence Hub. Enables global rules to automatically ignore or approve artifacts such as IPs, domains, emails, URLs, hashes, and CVEs across tasks and comments, eliminating alert fatigue and streamlining security triage.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.