Cover image for project: NEXUS Intigriti Researcher IN PROGRESS

Technical summary

Separate plugin from Intigriti Company (plugins/intigriti/): Intigriti Researcher (plugins/intigriti-researcher/) uses the Researcher API with a Personal Access Token (PAT) — no webhooks — to query programs, scopes/domains, RoE and activities and create NEXUS tasks (up to 20/sync, 6h throttle). It follows the principle that Intigriti is the source of truth.

Executed scope

  • backend.php backend (1011 lines): intigriti_researcher_get_config()/intigriti_researcher_save_config() in DB::getConfig('plugin.intigriti-researcher') with pat, auth_mode (bearer/basic PAT:PAT), following_only, sync_activities, create_tasks_on_change, default_project, last_activity_since, last_sync_at.
  • API client (intigriti_researcher_api, cURL): Bearer <PAT> or Basic base64(PAT:PAT), base api.intigriti.com/external/researcher/v1, 45s timeout; 401/403 → "check PAT/auth_mode".
  • Programs sync (intigriti_researcher_sync_programs): pages GET /programs?limit=100 (cap 500) → cache intigriti_researcher_programs (handle/name/following/status/type/industry/bounty range/domains_json+version/RoE version/detail_url/raw_json); does not fetch detail in bulk (domains/RoE on modal via enrich).
  • Activities sync (intigriti_researcher_sync_activities): GET /programs/activities (incremental via createdSince) → dedup by activity_key (sha1 of payload) → prioritizes following → creates tasks (max 20/sync, maxTasksPerSync=20) via intigriti_researcher_task_from_activity() + intigriti_researcher_build_task_content() (severity→priority critical=4/high=3/medium=2/low=1; title [Intigriti] {program} — {type} ({date}); description with severity/score/bounty/domains/RoE + "How to test" block).
  • Throttle: intigriti_researcher_cron_check() (soft-cron, 6h) stores plugin.intigriti-researcher.last_cron ({ts, at, ok}); full sync via tick.
  • Live enrich (intigriti_researcher_enrich_program): GET /programs/{id} → detailed domains + RoE → updates cache (used in modal).
  • API: 11 actions via PluginManager::registerApiAction — intigriti_researcher_settings/_save, _stats, _programs, _program (+enrich), _activities, _test, _sync (mode full|programs|activities), _refresh_briefing — session + CSRF.
  • Alpine.js UI (tab.php, 339 lines, teal ring): PAT status badge, stat cards (Programs/Following/Activities/PAT/Last sync), Programs tab (table + following/status filters + enrich modal) + Config (PAT, auth_mode, toggles, default_project picker, Test/Connect/Sync/Save).
  • Tables: intigriti_researcher_programs + intigriti_researcher_activities (dedup cache). No version-controlled install.sql (loaded via file_get_contents in intigriti_researcher_install()).
  • cronjob.json: job intigriti_researcher_sync (tick, 6h throttle, functions check=intigriti_researcher_cron_check/run=intigriti_researcher_full_sync) + cli_options → cli.php (full sync off-line).

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (config in admin_configs; intigriti_researcher_programs + intigriti_researcher_activities)
  • Alpine.js + Tailwind CSS (premium light, teal ring)
  • NEXUS plugin system (PluginManager)
  • cURL → Intigriti Researcher API (PAT Bearer/Basic)

Operational tags

  • Intigriti
  • Bug Bounty
  • Researcher API
  • PAT
  • Plugin NEXUS
  • OSINT

Operational outcome

  • On-demand pipeline: set PAT → Test connection → Sync (full) → new activities become tasks in the default project with correct priority (critical=4 … low=1); tasks prioritize followed programs.
  • Incremental without loss: last_activity_since (epoch) filters activities on re-sync — only new ones come through; dedup by activity_key (sha1 of payload) prevents duplicate tasks.
  • Resilient sync: 500-program cap in the loop + 20 tasks/sync avoids overload; 6h cron throttle + CLI for headless runners.
  • Contextual enrichment: linked tasks show severity + score + accumulated bounty + Intigriti submission status in the Intelligence Hub.
  • PAT safety: never exposed in public UI (only pat_set flag); configurable auth (Bearer or Basic); 401/403 returns a targeted message.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Separate Intigriti Researcher plugin — Researcher API (PAT) to query programs/activities and create NEXUS tasks (up to 20/sync, 6h throttle).

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.