IN PROGRESS
Technical summary
NEXUS plugin that scans leaks and exposed services on LeakIX from IPs and domains detected in tasks and comments. The Intelligence Hub enricher queries the official API with a 24h local cache, computes a risk score and returns structured signals to the Intel panel; the tab offers Lucene-like search, host lookup with force refresh and replayable history.
Executed scope
- Registration:
plugin.jsonv1.0.0,icon_bg #DC2626, lucidedropletsicon and customicon.svg(nois_core— additional plugin);registerTab('leakix-scan','LeakIX','droplets',tab.php,'Threat Intel'),registerDocandregisterModal('leakix-scan',modals.php)(no dedicated modals — the whole UI lives in the tab). - Tables via
leakix_ensure_tables():leakix_searches(query VARCHAR(512),scopedefaultleak,results_json LONGTEXT,result_count,created_at, indexes on date and query) andleakix_hosts(ip VARCHAR(45)PK,hostname,services_json/leaks_json LONGTEXT,service_count,leak_count,risk_score TINYINT UNSIGNED,raw_response,last_checked, index onlast_checked) — InnoDB, utf8mb4. - LeakIX API via cURL (
https://leakix.net):api-key: <KEY>header,Accept: application/json,NEXUS-LeakIX/1.0User-Agent, 10s connect / 30s response timeouts; endpointsGET /search?q=&scope=leak|service&page=andGET /host/:ip; 401/403 mapped to "invalid or unauthorized API key". - Target extraction from text: IPv4 and IPv6 (regex +
FILTER_VALIDATE_IPexcluding private/reserved ranges) and domains (filters code TLDs —php,json,md,html, etc. — and known hosts). - Standardized risk score:
min(100, leaks × 25 + min(40, services × 5))— 0–100 per host. - Resilient local cache with configurable TTL (default 86400s / 24h):
leakix_lookup_host()answers from cache (cached: true) before any remote call;forcebypasses the cache; searches and hosts are persisted in both tables. - API with 10 actions:
leakix_status(stats + masked key + docs link),leakix_dashboard(10 recent searches + top 10 risky hosts),leakix_search,leakix_host,leakix_services,leakix_history(limit 1–50),leakix_enrich_task(on-demand task enrichment),leakix_settings_get(with a 4-step how-to),leakix_settings_saveandleakix_test_connection. - Intelligence Hub enricher:
nx_intel_register_enricher('leakix-scan', ['ip','domain'], 'leakix_intel_enrich', 42)— signals withok/error/skipped/needs_keystatus,severity= risk score, respects themax_live_lookupsbudget and uses the cache for IPs beyond the budget; domains become up to 5 lightweight signals without lookup. - Fast Responses:
fastr.jsonmanifest with/leakix(requiredqargument, fixedscope=leak), actionleakix_search. - On demand:
cronjob.jsonwithjobs: [](no periodic routine needed); no CLI. - UI: Alpine.js tab (
tab.php, 428 lines) with "API Key OK / No API Key" badge (no key redirects to the Config tab), stats cards (Searches, Cached Hosts, Default scope, TTL), Lucene-like search (e.g.+protocol:http +country:BR) with a results table, Host tab with lookup, force refresh, risk badge and raw services/leaks JSON, replayable history and a settings panel with connection test. - Without an API Key the plugin does not fail: it detects IPs/domains in text, flags
needs_keyin Intel and in the tab, and suggests complementing with Shodan/Censys/CrowdSec (soft note). - Legacy:
leakix_filter_task_read/leakix_filter_comment_read@deprecated(no-op) — automatic enrichment moved to the Intelligence Hub (core/intel.php).
Stack and tools
- PHP 8 backend (no framework) + MySQL 8 (
leakix_searchesandleakix_hoststables) - LeakIX API via cURL (
leakix.net/search+/host/:ip,api-keyheader auth) - Alpine.js + Tailwind CSS (panel tab) + internal Plugin API (tabs/actions +
fastr.json+ Intel Hub)
Tags
LeakIX, Leaks, Exposed Services, Threat Intelligence, Intelligence Hub, NEXUS Plugin
Operational result
- Integrated scanning: IPs and domains mentioned in tasks and comments become Intelligence Hub signals with real LeakIX data.
- Works without an API Key: detects targets and flags
needs_keyin the tab and Intel instead of failing — just configure the key afterwards. - Standardized risk score: 0–100 computed from leaks and exposed services, with color-coded badge in the tab and severity in signals.
- Configurable 24h cache: hits respond instantly with no traffic to leakix.net; force refresh in the tab.
- Complementary by design: soft notes guide correlation with Shodan, Censys and CrowdSec.
- On demand: no cron or CLI.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that scans leaks and exposed services on LeakIX from IPs and domains detected in tasks and comments. The Intelligence Hub enricher queries the official API with a 24h local cache, computes a risk score and returns structured signals to the Intel panel; the tab offers Lucene-like search, host lookup with force refresh and replayable history.
Architecture and organization
- PHP 8
- MySQL 8
- cURL
- LeakIX API
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.