IN PROGRESS
Technical summary
NEXUS plugin that enriches domains detected in tasks and comments with WHOIS, DNS history (IP History), subdomains and current IPs via the SecurityTrails v1 API, feeding the Intelligence Hub with severity signals. Queries with local TTL cache, a dedicated tab with lookup, history and settings, and automatic domain detection in texts.
Executed scope
- Registration:
plugin.jsonv1.0.0, lucideglobeicon,icon_bg #0ea5e9, customicon.png;registerTab('securitytrails','SecurityTrails','globe',tab.php,'OSINT & Enrichment')+registerDoc('securitytrails','SecurityTrails','globe',doc.md); nocronjob.json(on-demand plugin). - Dedicated tab (Alpine.js): 3 tabs (Lookup / History / Settings); API Online/Offline badge on top (validated via
GET /v1/ping); 4 cache stat cards (total, today, with history, with subdomains); lookup with a Force checkbox (bypasses the cache) and a result with registrar, org/registrant, created/expires, current IPs, subdomains (up to 24) and a DNS History table (first/last seen + IPs); clickable recent-cache history that re-queries with one click. - Configuration: API key in
DB::setConfig('plugin.securitytrails');enrich_tasks/enrich_comments/include_whois/include_subdomains/include_dns_historytoggles; cache TTL 1–168h (default 24h); an empty key field keeps the saved key. - v1 API via cURL: base
https://api.securitytrails.com/v1,APIKEYheader,NEXUS-SecurityTrails/1.0user agent, 8s connect and 30s total timeouts; endpointsGET /ping,/domain/{hostname},/domain/{hostname}/whois,/domain/{hostname}/subdomains(children_only=false) and/history/{hostname}/dns/a(page=1); handles 401/403 (invalid key), 429 (rate limit), 404 (not in the database). - Automatic detection:
st_extract_domains()extracts URLs and FQDNs from tasks/comments (skips localhost,example.*, IPs and file extensions), up to 3 domains per document; the enrichment injects a### SecurityTrails — OSINTblock with registrar, org, created/expires, NS, IPs, subdomains (up to 8 in the preview) and A-record history. - Local MySQL cache:
securitytrails_cachetable (unique domain withON DUPLICATE KEY UPDATE) storingcurrent_ips_json,subdomains_json,subdomains_count,whois_json,dns_history_json,summary_json,raw_responseandchecked_at; configurable TTL;forcebypasses; table creation/write failures handled silently. - Intelligence Hub enricher:
nx_intel_register_enricher('securitytrails', ['domain'], 'st_intel_enrich', 44)—ok/needs_key/error/skippedsignals; without a key →needs_key("API Key necessária"); budgetslice ≤ min(5, max_live_lookups); severity35when more than 50 subdomains, otherwise15; summary "N IP(s) · N subdomain(s) · N DNS hist. rec.". - Fast Responses:
/securitytrails <domain>(required argument) →st_lookup. - API with 6 actions:
st_lookup(cache-first +force),st_stats(cache totals +api_online),st_history(paginated recent cache, limit ≤ 100),st_settings(public config with masked key),st_settings_saveandst_delete(clears the cache of one domain). - Normalization:
st_normalize_domain(strips scheme, port, path andwww., validates FQDN, rejects IPs); normalized WHOIS (registrar, registrant, up to 12 name servers, contact email); DNS history with ≤ 15 records and ≤ 20 IPs per record; summary withalexa_rank,apex_domainand current NS/MX (≤ 8).
Stack and tools
- PHP 8 backend (no framework) + cURL (SecurityTrails API v1)
- Alpine.js + Tailwind CSS (dedicated tab in NEXUS)
- Internal Plugin API (actions + enricher +
fastr.json+ MySQL cache +system_settings)
Tags
SecurityTrails, OSINT, WHOIS, DNS, Subdomains, Intelligence Hub, NEXUS Plugin
Operational result
- OSINT in one click: domains quoted in tasks/comments become WHOIS, DNS and subdomains without leaving NEXUS.
- TTL cache: repeated lookups answer from the local cache without spending free-tier quota.
- No key? No noise: the hub signals "API Key necessária" and the task flow stays intact.
- Availability badge: API Online/Offline status visible at the top of the tab.
- Browsable history: clickable recent cache re-queries the domain with one click.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that enriches domains detected in tasks and comments with WHOIS, DNS history (IP History), subdomains and current IPs via the SecurityTrails v1 API, feeding the Intelligence Hub with severity signals. Queries with local TTL cache, a dedicated tab with lookup, history and settings, and automatic domain detection in texts.
Architecture and organization
- PHP 8
- cURL
- SecurityTrails API v1
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.