
Autonomous 22-Source Zero-Cost OSINT, Data Breach/Leak, Infostealer & Threat Intelligence CLI Engine + Unbiased Cyber Warfare Encyclopedia (11 Languages, Zero Dependencies)
CyberCodex is an autonomous, self-updating, 22-Source Zero-Cost OSINT, Data Breach/Leak & Threat Intelligence Engine, Unbiased Cyber Warfare Encyclopedia (Incident Codex), MITRE ATT&CK Knowledge Base, and Dual-Perspective Technical Lexicon engineered for Windows CMD, PowerShell, and Linux terminals with zero external dependencies.
git clone https://github.com/prox0959/CyberCodex.git
cd CyberCodex
# 1. Synchronize live threat feeds (CISA KEV, Feodo C2, Tor Exit Nodes, Live Ransomware, MITRE)
python cybercodex.py update --lang tr
# 2. Run 22-source zero-cost OSINT, Breach/Leak, Stealer & Security Header scan on any Website/IP
python cybercodex.py intel linkedin.com --lang tr
python cybercodex.py intel adobe.com --lang en
# 3. Dedicated Data Breach History, Infostealer Exposure, COMB & K-Anonymity Password Leak Audit
python cybercodex.py leak adobe.com --lang tr
python cybercodex.py leak adobe.com --download --lang tr
python cybercodex.py leak user:admin --lang tr
python cybercodex.py leak pass:password123 --lang tr
# 4. Analyze any CVE with MITRE + FIRST EPSS + CISA KEV + Live GitHub PoC Exploit Hunter
python cybercodex.py cve CVE-2024-3094 --lang tr
# 5. Hunt Malware Hashes (SHA256 / MD5) & C2 Indicators via ThreatFox & Malware Vault
python cybercodex.py ioc 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 --lang tr
# 6. Query Official MITRE ATT&CK Enterprise Techniques & SOC Detection Logic
python cybercodex.py mitre T1055.012 --lang tr
# 7. Read unbiased forensic engineering anatomy of major cyber operations
python cybercodex.py attack solarwinds --lang tr
python cybercodex.py compare stuxnet notpetya --lang tr
# 8. Query APT Threat Actor dossiers & Live Global Ransomware feed
python cybercodex.py apt lazarus --lang tr
python cybercodex.py ransom --lang de
# 9. Lookup technical OSINT, DFIR, Red/Blue Team & LOLBAS concepts
python cybercodex.py dict catroot-winsxs --lang tr
# 10. Generate OSINT Dorks (Google, GitHub, Shodan) & SIEM Rules (Wazuh, Sigma, KQL, Splunk)
python cybercodex.py dork example.com --lang ja
# 11. Launch Interactive Metasploit-style Console (`codex [TR] >`)
python cybercodex.py shell
python -m unittest discover -s tests -v
Released under the MIT License. Engineered by Çınar (prox0959).
| # | Intelligence Source | Endpoint / Protocol | Telemetry Extracted | Cost / Key |
|---|
| 1 | HaveIBeenPwned Breaches | haveibeenpwned.com/api/v3/breaches | Latest leak date, largest leak volume (PwnCount), leaked DataClasses & incident summary | $0 / No Key |
| 2 | Hudson Rock Cavalier | cavalier.hudsonrock.com/api/json/v2 | Real-world Infostealer (RedLine, Raccoon, Vidar) compromises, stolen URLs, AVs & password stats | $0 / No Key |
| 3 | ProxyNova COMB (3.2B) | api.proxynova.com/comb | 3.2 Billion Compilation of Many Breaches credential exposure lookup & sample dump | $0 / No Key |
| 4 | HIBP K-Anonymity Passwords | api.pwnedpasswords.com/range/{sha1[:5]} | 850M+ breached password frequency check (only 5 SHA-1 hex chars transmitted) | $0 / No Key |
| 5 | HTTP Security & RFC 9116 | Live HTTPS + /.well-known/security.txt | HSTS, CSP, X-Frame-Options, Server banner & Security Posture Grade (A+ to F) | $0 / No Key |
| 6 | Shodan InternetDB | internetdb.shodan.io/{ip} | Open ports, CPEs, hostnames, tags, exposed CVEs | $0 / No Key |
| 7 | FIRST.org EPSS | api.first.org/data/v1/epss | 30-day exploitation probability (%) & percentile | $0 / No Key |
| 8 | MITRE CVE AWG v5 | cveawg.mitre.org/api/cve/{id} | Official CVE description, CVSS v3.1/v4.0 metrics | $0 / No Key |
| 9 | CIRCL.lu CVE API | cve.circl.lu/api/cve/{id} | Secondary CVE metadata & CVSS fallback | $0 / No Key |
| 10 | GitHub Exploit/PoC Hunter | api.github.com/search/repositories | Live public Proof-of-Concept (PoC) exploit repos & stars | $0 / No Key |
| 11 | CISA KEV Catalog | cisa.gov/.../known_exploited_vulnerabilities.json | 1,300+ actively exploited CVEs & ransomware campaign use | $0 / No Key |
| 12 | abuse.ch Feodo C2 | feodotracker.abuse.ch/.../ipblocklist | Active QakBot, Emotet, Pikabot, Dridex C2 servers | $0 / No Key |
| 13 | abuse.ch ThreatFox | threatfox-api.abuse.ch/api/v1/ | Malware SHA256/MD5 hash & C2 IOC attribution | $0 / No Key |
| 14 | CyberCodex Malware Vault | Local + Live Hash Engine | Instant attribution of famous APT/wiper SHA-256 hashes | $0 / No Key |
| 15 | Official Tor Exit List | check.torproject.org/torbulkexitlist | Live verification against ~1,500 active Tor Exit Nodes | $0 / No Key |
| 16 | RIPE NCC Stat BGP | stat.ripe.net/data/network-info | Announced BGP CIDR prefix & Origin ASN routing | $0 / No Key |
| 17 | ip-api / RDAP Telemetry | ip-api.com / rdap.arin.net | ASN, ISP, Organization, Reverse DNS, Datacenter/Proxy | $0 / No Key |
| 18 | Cloudflare DoH DNS/DMARC | cloudflare-dns.com/dns-query | Live MX, NS, SPF, DMARC & Email Spoofing vulnerability audit | $0 / No Key |
| 19 | Live TLS/SSL Socket | Native X.509 TCP/443 Handshake | SHA-256 cert fingerprint, serial, TLS version & C2 heuristics | $0 / No Key |
| 20 | crt.sh CT Logs | crt.sh/?q=%.{domain}&output=json | SSL Certificate Transparency subdomain discovery | $0 / No Key |
| 21 | Wayback Machine CDX | web.archive.org/cdx/search/cdx | Historical archived URLs and direct raw snapshot links | $0 / No Key |
| 22 | Ransomware & PhishStats | api.ransomware.live / phishstats.info | Real-time global ransomware victims & active phishing URLs | $0 / No Key |