Cover image for project: NEXUS SecurityTrails IN PROGRESS

Technical summary

NEXUS plugin that enriches domains detected in tasks and comments with WHOIS, DNS history (IP History), subdomains and current IPs via the SecurityTrails v1 API, feeding the Intelligence Hub with severity signals. Queries with local TTL cache, a dedicated tab with lookup, history and settings, and automatic domain detection in texts.

Executed scope

  • Registration: plugin.json v1.0.0, lucide globe icon, icon_bg #0ea5e9, custom icon.png; registerTab('securitytrails','SecurityTrails','globe',tab.php,'OSINT & Enrichment') + registerDoc('securitytrails','SecurityTrails','globe',doc.md); no cronjob.json (on-demand plugin).
  • Dedicated tab (Alpine.js): 3 tabs (Lookup / History / Settings); API Online/Offline badge on top (validated via GET /v1/ping); 4 cache stat cards (total, today, with history, with subdomains); lookup with a Force checkbox (bypasses the cache) and a result with registrar, org/registrant, created/expires, current IPs, subdomains (up to 24) and a DNS History table (first/last seen + IPs); clickable recent-cache history that re-queries with one click.
  • Configuration: API key in DB::setConfig('plugin.securitytrails'); enrich_tasks/enrich_comments/include_whois/include_subdomains/include_dns_history toggles; cache TTL 1–168h (default 24h); an empty key field keeps the saved key.
  • v1 API via cURL: base https://api.securitytrails.com/v1, APIKEY header, NEXUS-SecurityTrails/1.0 user agent, 8s connect and 30s total timeouts; endpoints GET /ping, /domain/{hostname}, /domain/{hostname}/whois, /domain/{hostname}/subdomains (children_only=false) and /history/{hostname}/dns/a (page=1); handles 401/403 (invalid key), 429 (rate limit), 404 (not in the database).
  • Automatic detection: st_extract_domains() extracts URLs and FQDNs from tasks/comments (skips localhost, example.*, IPs and file extensions), up to 3 domains per document; the enrichment injects a ### SecurityTrails — OSINT block with registrar, org, created/expires, NS, IPs, subdomains (up to 8 in the preview) and A-record history.
  • Local MySQL cache: securitytrails_cache table (unique domain with ON DUPLICATE KEY UPDATE) storing current_ips_json, subdomains_json, subdomains_count, whois_json, dns_history_json, summary_json, raw_response and checked_at; configurable TTL; force bypasses; table creation/write failures handled silently.
  • Intelligence Hub enricher: nx_intel_register_enricher('securitytrails', ['domain'], 'st_intel_enrich', 44) — ok/needs_key/error/skipped signals; without a key → needs_key ("API Key necessária"); budget slice ≤ min(5, max_live_lookups); severity 35 when more than 50 subdomains, otherwise 15; summary "N IP(s) · N subdomain(s) · N DNS hist. rec.".
  • Fast Responses: /securitytrails <domain> (required argument) → st_lookup.
  • API with 6 actions: st_lookup (cache-first + force), st_stats (cache totals + api_online), st_history (paginated recent cache, limit ≤ 100), st_settings (public config with masked key), st_settings_save and st_delete (clears the cache of one domain).
  • Normalization: st_normalize_domain (strips scheme, port, path and www., validates FQDN, rejects IPs); normalized WHOIS (registrar, registrant, up to 12 name servers, contact email); DNS history with ≤ 15 records and ≤ 20 IPs per record; summary with alexa_rank, apex_domain and current NS/MX (≤ 8).

Stack and tools

  • PHP 8 backend (no framework) + cURL (SecurityTrails API v1)
  • Alpine.js + Tailwind CSS (dedicated tab in NEXUS)
  • Internal Plugin API (actions + enricher + fastr.json + MySQL cache + system_settings)

Tags

SecurityTrails, OSINT, WHOIS, DNS, Subdomains, Intelligence Hub, NEXUS Plugin

Operational result

  • OSINT in one click: domains quoted in tasks/comments become WHOIS, DNS and subdomains without leaving NEXUS.
  • TTL cache: repeated lookups answer from the local cache without spending free-tier quota.
  • No key? No noise: the hub signals "API Key necessária" and the task flow stays intact.
  • Availability badge: API Online/Offline status visible at the top of the tab.
  • Browsable history: clickable recent cache re-queries the domain with one click.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that enriches domains detected in tasks and comments with WHOIS, DNS history (IP History), subdomains and current IPs via the SecurityTrails v1 API, feeding the Intelligence Hub with severity signals. Queries with local TTL cache, a dedicated tab with lookup, history and settings, and automatic domain detection in texts.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.