Cover image for project: NEXUS Kaspersky OpenTIP IN PROGRESS

Technical summary

NEXUS plugin that enriches IOCs — MD5/SHA1/SHA256 hashes, IPs, domains and URLs — with the Kaspersky OpenTIP verdict. The Intelligence Hub enricher queries the official API with a 7-day local cache, maps campaigns and MITRE ATT&CK and returns severity signals; the tab offers type auto-detection search, paginated history and malicious IOC alerts.

Executed scope

  • Registration: plugin.json v1.0.0, icon_bg #00A88E, lucide brain icon and custom icon.png (no is_core — additional plugin); registerTab('kaspersky-tip','Kaspersky OpenTIP','brain',tab.php,'Threat Intel') and registerDoc('kaspersky-tip','Kaspersky OpenTIP','brain',doc.md); no dedicated modals and no cronjob (no periodic routine).
  • tip_cache table via tip_install(): ioc_hash VARCHAR(32) PK (md5 of type:value), ioc_type VARCHAR(20), ioc_value TEXT, verdict VARCHAR(50), detection VARCHAR(255), category VARCHAR(100), campaigns/mitre/related_iocs/raw_response JSON and enriched_at DATETIME — with indexes on type, verdict and date (InnoDB, utf8mb4).
  • Kaspersky OpenTIP API via cURL (https://opentip.kaspersky.com/api/v1/search/{ip|domain|url|hash}?request=): X-Api-Key header, Accept: application/json, URL-encoded request, 3s connect / 5s response timeouts, SSL_VERIFYPEER enabled; HTTP 429 mapped to "daily quota exceeded (100 requests/day)".
  • IOC type auto-detection: MD5 (32 hex), SHA1 (40), SHA256 (64), IP via FILTER_VALIDATE_IP, URL (^https?://) and domain by regex — tip_enrich identifies the type without an explicit parameter.
  • Response mapping: Zone → verdict (Grey by default); hash via FileGeneralInfo (FileStatus/Type + up to 3 DetectionNames), IP via IpGeneralInfo (Status + Categories), domain via DomainGeneralInfo (Status/DomainStatus) and URL via UrlGeneralInfo (Status/UrlStatus); campaigns, MITRE ATT&CK (tactics/techniques) and related IOCs.
  • 7-day local cache: tip_enrich() answers from cache (cached: true) before the remote call, with upsert (ON DUPLICATE KEY UPDATE) on miss — instant hits and the free plan's 100 requests/day go further.
  • API with 6 actions: tip_enrich (value + optional type), tip_stats (totals + api_configured + api_online pulse with 2 test URLs), tip_history (paginated, limit 1–200), tip_alerts (malware/malicious/suspicious/dangerous verdicts), tip_settings (is a key configured?) and tip_settings_save (api_key via DB::setConfig('kaspersky_tip_settings')).
  • Intelligence Hub enricher: nx_intel_register_enricher('kaspersky-tip', ['ip','domain','url','hash'], 'tip_intel_enrich', 48) — signals with ok/error/needs_key/skipped status, severity 85 (malicious verdicts) or 10 (clean), summary with the detection or verdict, respects the max_live_lookups budget (slice ≤ min(8, budget × 2)) and flags cached.
  • Fast Responses: fastr.json manifest with /tip (required IOC argument — hash, IP, domain or URL), action tip_enrich.
  • On demand: no cronjob.json (no periodic routine needed); no CLI.
  • UI: Alpine.js tab (tab.php, 475 lines) with "API Online/Offline" badge (3 states: green pulse, red, amber), stats cards (Total IOCs, Malicious, Clean, Today with proportion bars), type auto-detection search with a rich result (rose/emerald color-coded verdict, type/category/verdict/consulted, campaigns with targeted countries, MITRE ATT&CK chips, related IOCs), paginated history with expandable rows, malicious alerts and a settings panel with a 4-step how-to.
  • Legacy: tip_filter_task_read/tip_filter_comment_read disabled (commented out in plugin.php) — they appended a "Kaspersky Threat Intel — IOCs Detectados" markdown block; automatic enrichment moved to the Intelligence Hub (core/intel.php).

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (tip_cache table)
  • Kaspersky OpenTIP API via cURL (opentip.kaspersky.com/api/v1/search)
  • Alpine.js + Tailwind CSS (panel tab) + internal Plugin API (tabs/actions + fastr.json + Intel Hub)

Tags

Kaspersky, OpenTIP, IOC, Threat Intelligence, Intelligence Hub, NEXUS Plugin

Operational result

  • 4 IOC types: MD5/SHA1/SHA256 hashes, IPs, domains and URLs with the official Kaspersky verdict.
  • Type auto-detection: paste the IOC and the plugin identifies it by itself — no dropdown or format errors.
  • Attack context: campaigns (with targeted countries), MITRE ATT&CK and related IOCs in the search result.
  • 7-day cache: instant hits; the free plan's 100 requests/day quota is preserved.
  • Severity in signals: 85 for malicious verdicts, 10 for clean — easy correlation in the Intel panel.
  • No routines: purely on-demand plugin — no cron or CLI.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that enriches IOCs — MD5/SHA1/SHA256 hashes, IPs, domains and URLs — with the Kaspersky OpenTIP verdict. The Intelligence Hub enricher queries the official API with a 7-day local cache, maps campaigns and MITRE ATT&CK and returns severity signals; the tab offers type auto-detection search, paginated history and malicious IOC alerts.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.