Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
badBANANA-threat-observatory — Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export. | Kitploit
도구/GitLabGitLab/gnomeman/badbanana-threat-observatory
Defensive ToolsIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Threat Feeds & AggregatorsVulnerability AnalysisInformation GatheringThreat Intelligence
GitLab

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
gnomeman/badbanana-threat-observatory

badBANANA-threat-observatory

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

저장소 보기웹사이트
6716일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

badBANANA // THREAT OBSERVATORY

Inspect exploited vulnerabilities and threat indicators, check their source evidence, and review retained changes.

Open the live Observatory · Try the KEV walkthrough · Source coverage · Run it yourself

The Observatory brings CISA KEV, ThreatFox, URLhaus, and MalwareBazaar into one analyst workspace. Use it to inspect source records, distinguish source dates from collection times, and export bounded current-state results. Missing, stale, disabled, or unavailable data stays visibly labeled.

badBANANA Observatory eye

Try it: inspect one exploited vulnerability

  1. Open the live Observatory and select Sources to check CISA's availability and freshness.
  2. Select Exploited, then RECENT KEV / DAY-GRANULAR and 7D. This scope uses CISA's date added, at day precision.
  3. Open a returned CVE row. Inspect the source-specific vendor, product, required action, and ransomware-use fields alongside the record's provenance.
  4. Compare OBSERVATION TIME, FIRST INGESTED, and LAST MATERIAL CHANGE. They answer different questions; a fresh fetch does not prove a new exploit.
  5. Use OPEN VALIDATED UPSTREAM SOURCE PAGE when available to inspect the original reference.

If the seven-day view returns no matches, use CURRENT KEV CATALOG to inspect an existing entry. A successful empty result, a stale source, and an unavailable read have different meanings. None establishes that your systems are unaffected.

Result: a source-backed CVE record you can inspect and reference, with the date basis and collection limits visible. This workflow does not determine whether your own assets are vulnerable.

Export a scoped current-state page

Export is a separate workflow. Start in Pulse, Infrastructure, URLs, or Malware, choose a time window, and apply the available search or filters. Then select Export, review the source selection and visible-page counts, choose JSONL, CSV, STIX 2.1, defanged text, or a manifest, and download the result.

Exports cover the loaded page after the selected policy is applied. Review emitted and unsupported counts. The dedicated Exploited workspace's KEV filters do not carry directly into Export.

What the evidence means

Current source state, material-change events, and fetch telemetry remain separate. The interface never substitutes demo records or inferred attribution. Collection is demand-driven; this deployment does not claim continuous monitoring.

The implementation and limitations are documented below, including source coverage, retention, provenance, and export semantics.

Production views

badBANANA Threat Observatory Pulse relationship view

Pulse — cross-source relationships, source health, and current-state analysis.

badBANANA Threat Observatory Transition Replay

Replay — page-bounded reconstruction of retained NEW, UPDATED, and REMOVED transitions.

Additional live surfaces include approximate public-IP infrastructure geography and first-party URLhaus / MalwareBazaar evidence views. Those surfaces are intentionally not represented by placeholder or duplicated screenshots in this README.

Production captures are source-preserving screenshots from the live v1.2.0 Observatory. They are cropped and resized/compressed for presentation; displayed evidence, timestamps, counts, IOC values, and interface states are not regenerated or substituted.

Live deployment

  • Production: https://badbanana-threat-observatory.badbanana6969.workers.dev
  • Current source: https://github.com/GnomeMan4201/badBANANA-threat-observatory/tree/main
  • Frozen v1.2.2 source: https://github.com/GnomeMan4201/badBANANA-threat-observatory/tree/release/v1.2.2

The production Worker is backed by Cloudflare D1. Feed credentials remain server-only Cloudflare Worker secrets and are never required in the browser.

Release status

  • Version: 1.2.2
  • Runtime: Node.js 22.13.0 or newer
  • Deployment: Next.js on Cloudflare Workers through vinext and the Cloudflare Vite plugin
  • Persistence: Cloudflare D1 with explicitly labeled isolate-memory degradation
  • Production dependency audit: enforced in CI at high severity

Ingestion mode

This deployment runs in demand-driven mode. The repository now targets standard Cloudflare Workers directly; scheduled triggers are intentionally not enabled in v1.2.2, so the application does not claim continuous collection. A future scheduler can call the same runIngestionCycle() operation after separate correctness and operational verification.

The browser makes an explicit bounded maintenance request on initial use and every five minutes while open:

POST /api/ingest
        ↓
runIngestionCycle()
        ↓
configuration → TTL → backoff → D1 lease → fetch → normalize → validate
        ↓
snapshot cache + current observations + material events + cycle statistics

Ordinary reads are separate and local:

GET /api/observations → D1 current state, scoped before pagination
GET /api/search       → D1 current state, scoped before pagination
GET /api/kev          → D1 current CISA catalog
GET /api/events       → D1 material change ledger
GET /api/geo          → local observations + bounded cached IP enrichment

None of those GET routes calls a source adapter. If this project later gains a genuinely supported scheduler, it can call the same runIngestionCycle() operation without creating a second refresh implementation.

Source coverage

SourceCredentialTTLActual coverage
CISA KEVNone30 minutesFull current validated catalog
ThreatFoxTHREATFOX_AUTH_KEY15 minutesRequested 24-hour IOC window
URLhausURLHAUS_AUTH_KEY15 minutesLatest 500 records returned by the recent endpoint
MalwareBazaarMALWAREBAZAAR_AUTH_KEY15 minutesLatest 100 metadata records returned by the endpoint

Coverage is displayed per source. Bounded APIs are never presented as complete catalogs.

Storage model

The DB binding owns distinct datasets:

도구 다운로드