Cover image for project: NEXUS LeakIX IN PROGRESS

Technical summary

NEXUS plugin that scans leaks and exposed services on LeakIX from IPs and domains detected in tasks and comments. The Intelligence Hub enricher queries the official API with a 24h local cache, computes a risk score and returns structured signals to the Intel panel; the tab offers Lucene-like search, host lookup with force refresh and replayable history.

Executed scope

  • Registration: plugin.json v1.0.0, icon_bg #DC2626, lucide droplets icon and custom icon.svg (no is_core — additional plugin); registerTab('leakix-scan','LeakIX','droplets',tab.php,'Threat Intel'), registerDoc and registerModal('leakix-scan',modals.php) (no dedicated modals — the whole UI lives in the tab).
  • Tables via leakix_ensure_tables(): leakix_searches (query VARCHAR(512), scope default leak, results_json LONGTEXT, result_count, created_at, indexes on date and query) and leakix_hosts (ip VARCHAR(45) PK, hostname, services_json/leaks_json LONGTEXT, service_count, leak_count, risk_score TINYINT UNSIGNED, raw_response, last_checked, index on last_checked) — InnoDB, utf8mb4.
  • LeakIX API via cURL (https://leakix.net): api-key: <KEY> header, Accept: application/json, NEXUS-LeakIX/1.0 User-Agent, 10s connect / 30s response timeouts; endpoints GET /search?q=&scope=leak|service&page= and GET /host/:ip; 401/403 mapped to "invalid or unauthorized API key".
  • Target extraction from text: IPv4 and IPv6 (regex + FILTER_VALIDATE_IP excluding private/reserved ranges) and domains (filters code TLDs — php, json, md, html, etc. — and known hosts).
  • Standardized risk score: min(100, leaks × 25 + min(40, services × 5)) — 0–100 per host.
  • Resilient local cache with configurable TTL (default 86400s / 24h): leakix_lookup_host() answers from cache (cached: true) before any remote call; force bypasses the cache; searches and hosts are persisted in both tables.
  • API with 10 actions: leakix_status (stats + masked key + docs link), leakix_dashboard (10 recent searches + top 10 risky hosts), leakix_search, leakix_host, leakix_services, leakix_history (limit 1–50), leakix_enrich_task (on-demand task enrichment), leakix_settings_get (with a 4-step how-to), leakix_settings_save and leakix_test_connection.
  • Intelligence Hub enricher: nx_intel_register_enricher('leakix-scan', ['ip','domain'], 'leakix_intel_enrich', 42) — signals with ok/error/skipped/needs_key status, severity = risk score, respects the max_live_lookups budget and uses the cache for IPs beyond the budget; domains become up to 5 lightweight signals without lookup.
  • Fast Responses: fastr.json manifest with /leakix (required q argument, fixed scope=leak), action leakix_search.
  • On demand: cronjob.json with jobs: [] (no periodic routine needed); no CLI.
  • UI: Alpine.js tab (tab.php, 428 lines) with "API Key OK / No API Key" badge (no key redirects to the Config tab), stats cards (Searches, Cached Hosts, Default scope, TTL), Lucene-like search (e.g. +protocol:http +country:BR) with a results table, Host tab with lookup, force refresh, risk badge and raw services/leaks JSON, replayable history and a settings panel with connection test.
  • Without an API Key the plugin does not fail: it detects IPs/domains in text, flags needs_key in Intel and in the tab, and suggests complementing with Shodan/Censys/CrowdSec (soft note).
  • Legacy: leakix_filter_task_read/leakix_filter_comment_read @deprecated (no-op) — automatic enrichment moved to the Intelligence Hub (core/intel.php).

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (leakix_searches and leakix_hosts tables)
  • LeakIX API via cURL (leakix.net/search + /host/:ip, api-key header auth)
  • Alpine.js + Tailwind CSS (panel tab) + internal Plugin API (tabs/actions + fastr.json + Intel Hub)

Tags

LeakIX, Leaks, Exposed Services, Threat Intelligence, Intelligence Hub, NEXUS Plugin

Operational result

  • Integrated scanning: IPs and domains mentioned in tasks and comments become Intelligence Hub signals with real LeakIX data.
  • Works without an API Key: detects targets and flags needs_key in the tab and Intel instead of failing — just configure the key afterwards.
  • Standardized risk score: 0–100 computed from leaks and exposed services, with color-coded badge in the tab and severity in signals.
  • Configurable 24h cache: hits respond instantly with no traffic to leakix.net; force refresh in the tab.
  • Complementary by design: soft notes guide correlation with Shodan, Censys and CrowdSec.
  • On demand: no cron or CLI.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that scans leaks and exposed services on LeakIX from IPs and domains detected in tasks and comments. The Intelligence Hub enricher queries the official API with a 24h local cache, computes a risk score and returns structured signals to the Intel panel; the tab offers Lucene-like search, host lookup with force refresh and replayable history.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.