Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cyberbro — A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services. | Kitploit
Tools/GitHubGitHub/stanfrbd/cyberbro
Defensive ToolsIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Threat Feeds & AggregatorsVulnerability AnalysisHash AnalysisForensicsInformation GatheringThreat IntelligenceLearning & EducationIncident ResponseDNS Analysis
67771379 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHubstanfrbd/cyberbro

cyberbro

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

View RepositoryWebsite
Share
<h1 align="center">Cyberbro</h1>

<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/10725/4970c639439a60187e1ba39523b24c3343a5b6946445d8225e23c4060e002ff0.png" width="90" /><br />
<b><i>A simple application that extracts your IoCs from garbage input and checks their reputation using multiple services.</i></b>
<br />
<b>🌐 <a href="https://demo.cyberbro.net/">demo.cyberbro.net</a></b><br />

</p>

---

<p align="center">
  <a href="https://github.com/stanfrbd/cyberbro/stargazers">
    <img src="https://img.shields.io/github/stars/stanfrbd/cyberbro?style=social" alt="GitHub stars">
  </a>
  <a href="https://x.com/cyberbro_cti">
    <img src="https://img.shields.io/twitter/follow/cyberbro_cti?style=social" alt="Follow on X/Twitter">
  </a>
  <a href="https://infosec.exchange/@cyberbro">
    <img src="https://img.shields.io/badge/Follow_@cyberbro-23-blue?logo=mastodon" alt="Mastodon">
  </a>
  <a href="https://github.com/stanfrbd/cyberbro/issues">
    <img src="https://img.shields.io/github/issues/stanfrbd/cyberbro" alt="GitHub issues">
  </a>
  <a href="https://github.com/stanfrbd/cyberbro/blob/main/LICENSE">
    <img src="https://img.shields.io/github/license/stanfrbd/cyberbro" alt="License">
  </a>
  <a href="https://github.com/stanfrbd/cyberbro/actions/workflows/jobs.yml">
    <img src="https://github.com/stanfrbd/cyberbro/actions/workflows/jobs.yml/badge.svg" alt="build and test badge">
  </a>
  <a href="https://github.com/stanfrbd/cyberbro/actions/workflows/pre-commit-validation.yml">
    <img src="https://github.com/stanfrbd/cyberbro/actions/workflows/pre-commit-validation.yml/badge.svg" alt="pre-commit validation badge">
  </a>
  <a href="https://www.python.org/">
    <img src="https://img.shields.io/badge/Python-3.13-blue?logo=python" alt="Python">
  </a>
</p>

---

# About

Inspired by [Cybergordon](https://cybergordon.com/) and [IntelOwl](https://github.com/intelowlproject/IntelOwl).

This project aims to provide a simple and efficient way to check the reputation of your observables using multiple services,
without having to deploy a **complex** solution. Read the docs at https://docs.cyberbro.net/

> [!TIP]
> To build custom reports, use Cyberbro with your favorite **LLM** (Claude, OpenAI gpt-5...) via **MCP** (Model Context Protocol) \
> Checkout [Cyberbro MCP](https://github.com/stanfrbd/mcp-cyberbro) for more information.

# Demo

![graph_demo](https://assets.kitploit.com/production/public/readmes/10725/42293ee1b50ba63b53c12c77a24c60627781cced6b5756b304f7e8482ca361c1.gif)

# Features

* **Easy Input**: Paste raw logs or IoCs-automatic parsing and extraction.
* **Multi-Service Checks**: Reputation lookup for IPs, hashes, domains, URLs, and Chrome extension IDs across many threat intel services.
* **Comprehensive Reports**: Advanced search, filtering, and export to CSV/Excel.
* **Fast Processing**: Multithreaded for speed.
* **Automated Pivoting**: Discover related domains, URLs, and IPs via reverse DNS and RDAP / Whois.
* **Accurate Domain & Abuse Info**: RDAP / Whois and abuse contact lookups.
* **Integrations**: Microsoft Defender for Endpoint, CrowdStrike, OpenCTI, Grep.App, Hudson Rock, and more.
* **Proxy & Storage**: Proxy support and results stored in SQLite.
* **History & Graphs**: Analysis history and experimental graph view.
* **Cache**: Caching for faster repeat lookups (enabled at multi-engines level, not each engine).

# What Makes Cyberbro Unique

* **Beginner-Friendly**: Accessible for all skill levels.
* **Chrome Extension ID Lookup**: Get extension names and CTI data from IDs.
* **Lightweight Deployment**: Simple setup and use.
* **Advanced TLD Extraction**: Accurate root domain detection for better lookups.
* **Pragmatic Data Gathering**: Uses GitHub and Google to find overlooked IoCs.
* **CTI Report Integration**: Fetches IoC-related reports from IoC.One.
* **EDR Integration**: Checks observables against your own security tools (MDE, CrowdStrike).

# Getting Started - TL;DR

> [!TIP]
> If you are lazy, you need Docker. \
> Do a `git clone` ; copy `.env.sample` to `.env` ; `docker compose up` then go to `localhost:5000`. Yep, that's it!

# Getting Started

* To get started, clone the repository

```bash
git clone https://github.com/stanfrbd/cyberbro
cd cyberbro
```

## Edit the config file (mandatory)

```
cp .env.sample .env
```

> [!NOTE]
> Don't have API keys? No problem, just copy `.env.sample` to `.env` and leave optional values empty. Be careful if a proxy is used. \
> You will be able to use **all free engines!**

* Fill values (including proxy if needed) in the `.env` file.

> [!WARNING]
> `.env` contains sensitive secrets and must never be committed.
> For production/team deployments, use SOPS, Vault, or an equivalent secret manager workflow.

```bash
ABUSEIPDB=token_here
ALIENVAULT=token_here
CRIMINALIP_API_KEY=token_here
CROWDSTRIKE_CLIENT_ID=client_id_here
CROWDSTRIKE_CLIENT_SECRET=client_secret_here
DFIR_IRIS_API_KEY=token_here
DFIR_IRIS_URL=https://dfir-iris.local
DFIR_IRIS_SEARCH_NOTES=false
GOOGLE_CSE_CX=cx_here
GOOGLE_CSE_KEY=key_here
GOOGLE_CSE_URL=https://www.googleapis.com/customsearch/v1
GOOGLE_SAFE_BROWSING=token_here
HISTER_TOKEN=token_here
HISTER_BASE_URL=https://hister.example.com
IPAPI=token_here
IPINFO=token_here
MDE_CLIENT_ID=client_id_here
MDE_CLIENT_SECRET=client_secret_here
MDE_TENANT_ID=tenant_here
MISP_API_KEY=token_here
MISP_URL=https://misp.local
MISP_FEEDBACK_SERVER_URL=https://misp-feedback.local
MISP_FEEDBACK_TOKEN=token_here
OPENCTI_API_KEY=token_here
OPENCTI_URL=https://demo.opencti.io
PROXY_URL=
RANSOMWARE_LIVE_API_KEY=token_here
RL_ANALYZE_API_KEY=token_here
RL_ANALYZE_URL=https://spectra_analyse_url_here
ROSTI_API_KEY=token_here
SHODAN=token_here
SPUR_US=token_here
THREATFOX=token_here
VIRUSTOTAL=token_here
WEBSCOUT=token_here
```

> [!IMPORTANT]
> Starting with version `v0.13.0`, Cyberbro no longer supports `secrets.json` and the `/config` page. Cf. [discussion 165](https://github.com/stanfrbd/cyberbro/discussions/165).\
> If you already have a legacy `secrets.json`, convert it to `.env` with:
> `python3 scripts/secrets_json_to_env.py`

See [Advanced options for deployment](https://docs.cyberbro.net/quick-start/Advanced-options-for-deployment) in the docs.

# Launch the app

## Lazy and easy - use docker

> [!WARNING]
> Make sure you install the `compose` plugin as `docker compose` and not `docker-compose`.
> In Docker, the app binds to `0.0.0.0` inside the container even if your local `.env` sets `FLASK_HOST=127.0.0.1`.

```bash
docker compose up # use -d to run in background and use --build to rebuild the image
```

* Go to http://127.0.0.1:5000 and Enjoy.

> Don't forget to edit `.env` before building the image.

See [Advanced options for deployment](https://docs.cyberbro.net/quick-start/Advanced-options-for-deployment) in the docs to get all Docker deployment options.

## The old way

* Clone the repository and install the requirements.

You might want to create a [`venv`](https://docs.python.org/3/library/venv.html) before installing the dependencies.

```bash
pip install -r requirements.txt
```

* Run the app with `gunicorn` (clean mode).

```bash
gunicorn -c prod/gunicorn.conf.py app:app
```

* Run the app with in development mode.

```bash
python3 app.py
```

# Screenshots

<details>
<summary>See all screenshots</summary>

<img width="1897" height="909" alt="image" src="https://assets.kitploit.com/production/public/readmes/10725/b3a07f1e163ae260b2a5f908a70d571a145f702ad50b524725ce4b3562f7c367.png" />

<img width="1883" height="907" alt="image" src="https://assets.kitploit.com/production/public/readmes/10725/3d3404a7e55b688b497db428ecb7fa01b6a23ec8879e2c2c751c68a92545a334.png" />

<img width="1887" height="906" alt="image" src="https://assets.kitploit.com/production/public/readmes/10725/cd57a214ae604ed83ca50d119b49391afc0a66c03b3ed93feecfbb59578f5984.png" />

</details>

<img width="1788" height="1536" alt="image" src="https://assets.kitploit.com/production/public/readmes/10725/2e6051fe1ad7fadde5ff9074dbb4d96528dd2c8ab8262ea10e1fe49fee031153.png" />

<img width="1873" height="900" alt="image" src="https://assets.kitploit.com/production/public/readmes/10725/5201b888fdaa97465f141379e9f5caedb0bdd847b1e31a08b3e236df8b663ed6.png" />

> [!CAUTION]
> If you intend to use this in a **production environment**, use well configured **Reverse Proxy** + **WAF** to prevent **security issues**.

# Cyberbro browser extension

<p>
<a href="https://addons.mozilla.org/addon/cyberbro-analyzer/"><img src="https://assets.kitploit.com/production/public/readmes/10725/7e7e7002c8f357304f16d1d06ff840c40e92c66f6ed072b18da36329502c7a13.png" alt="Get Cyberbro Analyzer for Firefox"></a>
<a href="https://chromewebstore.google.com/detail/cyberbro-analyzer/nfcfigpaollodajabegcdobhmgaclbbm"><img src="https://assets.kitploit.com/production/public/readmes/10725/28dd6378e71c68b4f21b54ad99bb1225f978b8f2bacfa3c46444f988c09ace1c.png" alt="Get Cyberbro Analyzer for Chromium"></a>
<a href="https://microsoftedge.microsoft.com/addons/detail/cyberbro-analyzer/lbponbmcggcepflackehgpbceehagiam"><img src="https://assets.kitploit.com/production/public/readmes/10725/0a301e6c3048478ead36dfbccdba2e5263de7fbeb3de9d22a9f159f64f378273.png" alt="Get Cyberbro Analyzer for Microsoft Edge"></a>
</p>

# Cyberbro API

* The API is available at `/api/` and can be accessed via the GUI or command-line.

**There are currently 3 endpoints:**

* `/api/analyze` - Analyze a text and return analysis ID (JSON).
* `/api/is_analysis_complete/<analysis_id>` - Check if the analysis is complete (JSON).
* `/api/results/<analysis_id>` - Retrieve the results of a previous analysis (JSON).

```bash
curl -X POST "http://localhost:5000/api/analyze" -H "Content-Type: application/json" -d '{"text": "cyberbro.net", "engines": ["reverse_dns", "rdap_whois"]}'
```

```json
{
  "analysis_id": "e88de647-b153-4904-91e5-8f5c79174854",
  "link": "/results/e88de647-b153-4904-91e5-8f5c79174854"
}
```

```bash
curl "http://localhost:5000/api/is_analysis_complete/e88de647-b153-4904-91e5-8f5c79174854"
```

```json
{
  "complete": true
}
```

```bash
curl "http://localhost:5000/api/results/e88de647-b153-4904-91e5-8f5c79174854"
```

```json
[
  {
    "observable": "cyberbro.net",
    "rdap_whois": {
      "abuse_contact": "[email protected]",
      "creation_date": "2024-12-20",
      "data_source": "rdap",
      "emails": [
        "[email protected]"
      ],
      "expiration_date": "2026-12-20",
      "link": "https://rdap.verisign.com/net/v1/domain/CYBERBRO.NET",
      "name_servers": [
        "anderson.ns.cloudflare.com",
        "lisa.ns.cloudflare.com"
      ],
      "organization": null,
      "registrant": null,
      "registrant_country": null,
      "registrant_email": null,
      "registrar": "Cloudflare, Inc.",
      "update_date": "2025-11-20"
    },
    "reverse_dns": {
      "reverse_dns": [
        "172.67.197.226",
        "104.21.42.7"
      ]
    },
    "reversed_success": true,
    "type": "FQDN"
  }
]
```

> [!NOTE]
> The [dedicated docs page](https://docs.cyberbro.net/quick-start/API-usage-and-engine-names) gives all the names of usable engines.

# API and third-party services

* [AbuseIPDB](https://docs.abuseipdb.com/)
* [Abusix](https://abusix.com/)
* [Alienvault](https://otx.alienvault.com/)
* [CriminalIP](https://www.criminalip.io/)
* [CrowdStrike](https://www.crowdstrike.com/)
* [crt.sh](https://crt.sh/)
* [DFIR Iris](https://www.dfir-iris.org/)
* [Github](https://github.com/)
* [Google Safe Browsing](https://developers.google.com/safe-browsing)
* [Google](https://google.com/)
* [Google DNS](https://dns.google/)
* [Grep.App](https://grep.app/)
* [Hister](https://hister.org/)
* [Hudson Rock](https://hudsonrock.com/)
* [ICANN](https://lookup.icann.org/)
* [IPapi](https://ipapi.is/)
* [IPinfo](https://ipinfo.io/developers)
* [IPquery](https://ipquery.gitbook.io/ipquery-docs)
* [Ioc.One](https://ioc.one/)
* [Microsoft Defender for Endpoint](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-for-endpoint-api)
* [Microsoft Entra ID (OpenID Configuration)](https://login.microsoftonline.com/)
* [MISP](https://www.misp-project.org/)
* [MISP Feedback](https://github.com/MISP/misp-feedback/)
* [OpenCTI](https://www.opencti.io/)
* [OpenRDAP](https://www.openrdap.org/)
* [Phishtank](https://www.phishtank.com/)
* [Ransomware.Live](https://ransomware.live/)
* [ReversingLabs Spectra Analyze](https://www.reversinglabs.com/products/spectra-analyze)
* [Rösti](https://rosti.bin.re/) - Repackaged Open Source Threat Intelligence
* [ScanMalware](https://scanmalware.com/)
* [Shodan](https://developer.shodan.io/)
* [Spur.us](https://spur.us/)
* [ThreatFox](https://threatfox.abuse.ch/api/)
* [URLscan](https://urlscan.io/)
* [VirusTotal](https://developers.virustotal.com/v3.0/reference)
* [WebScout](https://webscout.io/)

> [!NOTE]
> Any questions? Check the https://docs.cyberbro.net or raise an [issue](https://github.com/stanfrbd/cyberbro/issues/new) \
> For the advanced config (tuning of `supervisord.conf` before deployment, selection of visible engines, change `/api/` prefix...), check the [dedicated docs page](https://docs.cyberbro.net/quick-start/Advanced-options-for-deployment).

# Special thanks

A huge thank you to all the amazing contributors who made pull requests and helped improve this project:

* [Florian PILLOT](https://github.com/Harukunnn) who reworked engines (refactoring and optimizations).
* [Axel](https://github.com/botlabsDev) who develops [Ioc.One](https://ioc.one/) and added a specific User-Agent allowing scraping of Ioc[.]One.
* [Jon Mark Allen](https://github.com/ubahmapk/) who added a better secret management and tests. He refactored a lot and made many improvements to the codebase, including CriminalIP. 
* [cirosec GmbH - Felix Friedberger](https://github.com/cirosec) for adding crt.sh engine.
* [Stig Dahl](https://github.com/sdaaish) for enhancing crt.sh engine, adding DFIR IRIS search and fixing Bandit issues, correcting MISP engine, adding MISP Feedback engine.
* [0xffr](https://github.com/0xffr) for fixing issue #98 - Grep.app engine broken and commenting properly in CriminalIP engine.
* [Maxime Berthault - Maxou56800](https://github.com/Maxou56800) for developing Cyberbro CLI.
* [Jonas Lejon](https://github.com/jonaslejon) for adding ScanMalware engine.
* [egeoguz04](https://github.com/egeoguz04) for allowing the config of the Google CSE endpoint. This will be useful for the upcoming Google changes.

Your contributions are greatly appreciated!

# License

```
MIT License

Copyright (c) 2024-2026 stanfrbd

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included
in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
DEALINGS IN THE SOFTWARE.
```

# Logo

The logo used in this project is free for personal and commercial use and can be found [here](https://www.veryicon.com/icons/object/material_design_icons/web-39.html).
Download Tool