Cover image for project: URLhaus (abuse.ch) IN PROGRESS

Technical summary

Queries the collaborative abuse.ch API to classify URLs, hosts and hashes as malicious or clean. Auto type detection (URL/host/hash), 24h MySQL cache, Intel Hub enricher (priority 41) with live lookup budget and severity signals. API requires free Auth-Key (auth.abuse.ch). Red-themed 4-tab UI with KPI cards and paginated history.

Executed scope

  • plugin.php (45 lines): "URLhaus" tab under "Threat Intel" with link icon, doc, Intel Hub enricher (type url, priority 41), 6 API actions.
  • backend.php (338 lines): lazy urlhaus_cache table install, uh_api_query() POST to abuse.ch API v1, uh_verify() with auto type detection and 24h cache, uh_intel_enrich() with live lookup budget, uh_stats() with API health check, paginated uh_history(), uh_alerts() filtering malicious status.
  • tab.php (408 lines): Alpine.js 4-tab UI (URL Lookup, History, Alerts, Configuration), red theme, auto-detect search input, KPI cards (total, malicious, clean, today), paginated history table, alert list, password Auth-Key input.
  • fastr.json: /urlhaus <url> slash command for direct URL verification via uh_verify.
  • doc.md (53 lines): author's technical documentation (PT).
  • icon.svg: link brand icon.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Malicious URL lookup via abuse.ch URLhaus API with automatic type detection (URL/host/hash), 24h MySQL cache, Intel Hub enrichment for URLs detected in tasks and comments, threat alerts and paginated history — all in one table and a red-themed 4-tab UI.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.