
Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan, AbuseIPDB.
Investigate IPs, domains, hashes, and CVEs across 6 free threat intel APIs โ without switching between browser tabs.
Quick Start ยท Usage ยท Architecture ยท API Keys ยท Screenshots ยท Contributing
๐ Proudly featured in the official Awesome OSINT repository.
ThreatLens is a single command-line tool that unifies threat intelligence lookups across the most trusted free OSINT sources. Instead of pasting an IP into five different websites, ThreatLens queries them all in parallel, normalizes the results, and gives you a clear verdict โ in the terminal, or in a polished, color-coded Excel/JSON/CSV report.
Built for SOC analysts, incident responders, threat hunters, and anyone who wants fast, reliable IOC enrichment without leaving the shell.
|
Why ThreatLens
|
Not for
|
| Feature | Details |
|---|---|
| ๐ฏ IOC Types | IP, Domain, URL, File Hash (MD5 / SHA1 / SHA256), CVE |
| ๐ Integrated APIs | AbuseIPDB, VirusTotal, AlienVault OTX, Shodan, URLScan.io, NVD, CISA KEV, EPSS |
| ๐ Log Parsing | Auto-extract IOCs from plain text/log files, plus native support for Zeek, Suricata eve.json, Sysmon (JSON), and generic JSONL |
| ๐งญ CVE Decision Cards | Deterministic, explainable Patch / Isolate / Monitor / Not affected recommendation per CVE, driven by CISA KEV, EPSS, CVSS, and correlated asset exposure |
| ๐๏ธ Asset Inventory | Import a CSV of hosts/IPs with criticality and internet-facing status; correlated against CVE results |
| ๐ค SIEM Export | Opt-in export to Splunk HEC, Elastic _bulk, and Microsoft Sentinel (modern Logs Ingestion API) |
| ๐งพ Evidence Packs | ZIP export of an investigation with a SHA-256 manifest for basic chain-of-custody |
| ๐ Reports | Excel (color-coded), JSON, CSV |
| ๐พ Local Cache | SQLite cache with configurable TTL โ skip re-querying known IOCs, plus a cached CISA KEV feed (24h TTL) |
| ๐ก๏ธ Security | Redirect blocking, host allow-listing, API-key redaction in logs, spreadsheet-formula neutralisation, CSV/log DoS limits |
| ๐ Lockfile | requirements.lock with SHA-256 hashes for reproducible installs |
| ๐ป CLI Experience | Rich progress bars, colored tables, and a clean verdict summary |
| ๐งฉ Architecture | Modular enrichers/parsers/exporters, typed models, strict separation of concerns |
| โ Tested | 155 unit & integration tests with pytest; CI via GitHub Actions |
| โก Resilient | One failing API or SIEM destination never blocks the others โ errors are isolated and logged |
# 1. Clone & install
git clone https://github.com/AbdaullahAG/threatlens.git
cd threatlens
pip install -r requirements.txt
# 2. Configure your API keys
cp config/keys.env.example config/keys.env
# โ edit config/keys.env and fill in your keys
# 3. Run your first scan
python main.py -i 45.33.32.156
๐ก NVD (CVE lookups) works out of the box with no API key. Every other API offers a free tier that takes under 2 minutes to sign up for โ see API Keys below.
pip install --require-hashes -r requirements.lock
| Basic single-IOC lookup |
| Mix and match IOC types in one run |
| Bulk investigate straight from raw logs |
| Machine-readable output for pipelines |
| Restrict enrichment to selected sources |
| Excel + JSON + CSV in a single run |
| CVE enrichment via NIST NVD (free, no key) |
| Full request/response logging for troubleshooting |
| Patch / Isolate / Monitor / Not-affected recommendation |
| SOC log ingestion โ SIEM export |
| ZIP with a SHA-256 manifest for chain-of-custody |