IN PROGRESS
Technical summary
NEXUS plugin that enriches IOCs — MD5/SHA1/SHA256 hashes, IPs, domains and URLs — with the Kaspersky OpenTIP verdict. The Intelligence Hub enricher queries the official API with a 7-day local cache, maps campaigns and MITRE ATT&CK and returns severity signals; the tab offers type auto-detection search, paginated history and malicious IOC alerts.
Executed scope
- Registration:
plugin.jsonv1.0.0,icon_bg #00A88E, lucidebrainicon and customicon.png(nois_core— additional plugin);registerTab('kaspersky-tip','Kaspersky OpenTIP','brain',tab.php,'Threat Intel')andregisterDoc('kaspersky-tip','Kaspersky OpenTIP','brain',doc.md); no dedicated modals and no cronjob (no periodic routine). tip_cachetable viatip_install():ioc_hash VARCHAR(32)PK (md5 oftype:value),ioc_type VARCHAR(20),ioc_value TEXT,verdict VARCHAR(50),detection VARCHAR(255),category VARCHAR(100),campaigns/mitre/related_iocs/raw_responseJSON andenriched_at DATETIME— with indexes on type, verdict and date (InnoDB, utf8mb4).- Kaspersky OpenTIP API via cURL (
https://opentip.kaspersky.com/api/v1/search/{ip|domain|url|hash}?request=):X-Api-Keyheader,Accept: application/json, URL-encoded request, 3s connect / 5s response timeouts,SSL_VERIFYPEERenabled; HTTP 429 mapped to "daily quota exceeded (100 requests/day)". - IOC type auto-detection: MD5 (32 hex), SHA1 (40), SHA256 (64), IP via
FILTER_VALIDATE_IP, URL (^https?://) and domain by regex —tip_enrichidentifies the type without an explicit parameter. - Response mapping:
Zone→ verdict (Grey by default); hash viaFileGeneralInfo(FileStatus/Type + up to 3DetectionNames), IP viaIpGeneralInfo(Status + Categories), domain viaDomainGeneralInfo(Status/DomainStatus) and URL viaUrlGeneralInfo(Status/UrlStatus); campaigns, MITRE ATT&CK (tactics/techniques) and related IOCs. - 7-day local cache:
tip_enrich()answers from cache (cached: true) before the remote call, with upsert (ON DUPLICATE KEY UPDATE) on miss — instant hits and the free plan's 100 requests/day go further. - API with 6 actions:
tip_enrich(value+ optionaltype),tip_stats(totals +api_configured+api_onlinepulse with 2 test URLs),tip_history(paginated,limit1–200),tip_alerts(malware/malicious/suspicious/dangerousverdicts),tip_settings(is a key configured?) andtip_settings_save(api_keyviaDB::setConfig('kaspersky_tip_settings')). - Intelligence Hub enricher:
nx_intel_register_enricher('kaspersky-tip', ['ip','domain','url','hash'], 'tip_intel_enrich', 48)— signals withok/error/needs_key/skippedstatus,severity85 (malicious verdicts) or 10 (clean), summary with the detection or verdict, respects themax_live_lookupsbudget (slice ≤ min(8, budget × 2)) and flagscached. - Fast Responses:
fastr.jsonmanifest with/tip(required IOC argument — hash, IP, domain or URL), actiontip_enrich. - On demand: no
cronjob.json(no periodic routine needed); no CLI. - UI: Alpine.js tab (
tab.php, 475 lines) with "API Online/Offline" badge (3 states: green pulse, red, amber), stats cards (Total IOCs, Malicious, Clean, Today with proportion bars), type auto-detection search with a rich result (rose/emerald color-coded verdict, type/category/verdict/consulted, campaigns with targeted countries, MITRE ATT&CK chips, related IOCs), paginated history with expandable rows, malicious alerts and a settings panel with a 4-step how-to. - Legacy:
tip_filter_task_read/tip_filter_comment_readdisabled (commented out inplugin.php) — they appended a "Kaspersky Threat Intel — IOCs Detectados" markdown block; automatic enrichment moved to the Intelligence Hub (core/intel.php).
Stack and tools
- PHP 8 backend (no framework) + MySQL 8 (
tip_cachetable) - Kaspersky OpenTIP API via cURL (
opentip.kaspersky.com/api/v1/search) - Alpine.js + Tailwind CSS (panel tab) + internal Plugin API (tabs/actions +
fastr.json+ Intel Hub)
Tags
Kaspersky, OpenTIP, IOC, Threat Intelligence, Intelligence Hub, NEXUS Plugin
Operational result
- 4 IOC types: MD5/SHA1/SHA256 hashes, IPs, domains and URLs with the official Kaspersky verdict.
- Type auto-detection: paste the IOC and the plugin identifies it by itself — no dropdown or format errors.
- Attack context: campaigns (with targeted countries), MITRE ATT&CK and related IOCs in the search result.
- 7-day cache: instant hits; the free plan's 100 requests/day quota is preserved.
- Severity in signals: 85 for malicious verdicts, 10 for clean — easy correlation in the Intel panel.
- No routines: purely on-demand plugin — no cron or CLI.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that enriches IOCs — MD5/SHA1/SHA256 hashes, IPs, domains and URLs — with the Kaspersky OpenTIP verdict. The Intelligence Hub enricher queries the official API with a 7-day local cache, maps campaigns and MITRE ATT&CK and returns severity signals; the tab offers type auto-detection search, paginated history and malicious IOC alerts.
Architecture and organization
- PHP 8
- MySQL 8
- cURL
- Kaspersky OpenTIP API
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.