
Autônomo 22-Fontes Custo Zero OSINT, Violação de Dados/Vazamento, Infostealer & Mecanismo CLI de Inteligência de Ameaças + Enciclopédia Imparcial de Guerra Cibernética (11 Idiomas, Zero Dependências)
CyberCodex é um Motor Autônomo e Auto-atualizável de OSINT, Vazamentos/Data Breach e Threat Intelligence com 22 Fontes de Custo Zero, Enciclopédia Imparcial de Guerra Cibernética (Incident Codex), Base de Conhecimento MITRE ATT&CK e Léxico Técnico de Perspectiva Dupla projetado para Windows CMD, PowerShell e terminais Linux com zero dependências externas.
| # | Fonte de Inteligência | Endpoint / Protocolo | Telemetria Extraída | Custo / Chave |
|---|---|---|---|---|
| 1 | HaveIBeenPwned Breaches | haveibeenpwned.com/api/v3/breaches | Data do vazamento mais recente, maior volume de vazamento (PwnCount), DataClasses vazadas e resumo do incidente | $0 / Sem Chave |
| 2 | Hudson Rock Cavalier | cavalier.hudsonrock.com/api/json/v2 | Comprometimentos reais de Infostealer (RedLine, Raccoon, Vidar), URLs roubadas, AVs e estatísticas de senhas | $0 / Sem Chave |
| 3 | ProxyNova COMB (3.2B) | api.proxynova.com/comb | Consulta de exposição de credenciais da Compilation of Many Breaches de 3,2 Bilhões e dump de amostra | $0 / Sem Chave |
| 4 | HIBP K-Anonymity Passwords | api.pwnedpasswords.com/range/{sha1[:5]} | Verificação de frequência de senhas vazadas em mais de 850M (apenas 5 caracteres hex SHA-1 transmitidos) | $0 / Sem Chave |
| 5 | HTTP Security & RFC 9116 | HTTPS ao vivo + /.well-known/security.txt | HSTS, CSP, X-Frame-Options, banner do Server e Nota de Postura de Segurança (A+ a F) | $0 / Sem Chave |
| 6 | Shodan InternetDB | internetdb.shodan.io/{ip} | Portas abertas, CPEs, hostnames, tags, CVEs expostas | $0 / Sem Chave |
git clone https://github.com/prox0959/CyberCodex.git
cd CyberCodex
# 1. Synchronize live threat feeds (CISA KEV, Feodo C2, Tor Exit Nodes, Live Ransomware, MITRE)
python cybercodex.py update --lang tr
# 2. Run 22-source zero-cost OSINT, Breach/Leak, Stealer & Security Header scan on any Website/IP
python cybercodex.py intel linkedin.com --lang tr
python cybercodex.py intel adobe.com --lang en
# 3. Dedicated Data Breach History, Infostealer Exposure, COMB & K-Anonymity Password Leak Audit
python cybercodex.py leak adobe.com --lang tr
python cybercodex.py leak adobe.com --download --lang tr
python cybercodex.py leak user:admin --lang tr
python cybercodex.py leak pass:password123 --lang tr
# 4. Analyze any CVE with MITRE + FIRST EPSS + CISA KEV + Live GitHub PoC Exploit Hunter
python cybercodex.py cve CVE-2024-3094 --lang tr
# 5. Hunt Malware Hashes (SHA256 / MD5) & C2 Indicators via ThreatFox & Malware Vault
python cybercodex.py ioc 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 --lang tr
# 6. Query Official MITRE ATT&CK Enterprise Techniques & SOC Detection Logic
python cybercodex.py mitre T1055.012 --lang tr
# 7. Read unbiased forensic engineering anatomy of major cyber operations
python cybercodex.py attack solarwinds --lang tr
python cybercodex.py compare stuxnet notpetya --lang tr
# 8. Query APT Threat Actor dossiers & Live Global Ransomware feed
python cybercodex.py apt lazarus --lang tr
python cybercodex.py ransom --lang de
# 9. Lookup technical OSINT, DFIR, Red/Blue Team & LOLBAS concepts
python cybercodex.py dict catroot-winsxs --lang tr
# 10. Generate OSINT Dorks (Google, GitHub, Shodan) & SIEM Rules (Wazuh, Sigma, KQL, Splunk)
python cybercodex.py dork example.com --lang ja
# 11. Launch Interactive Metasploit-style Console (`codex [TR] >`)
python cybercodex.py shell
python -m unittest discover -s tests -v
Lançado sob a Licença MIT. Desenvolvido por Çınar (prox0959).
| FIRST.org EPSS |
api.first.org/data/v1/epss |
| Probabilidade de exploração em 30 dias (%) e percentil |
| $0 / Sem Chave |
| 8 | MITRE CVE AWG v5 | cveawg.mitre.org/api/cve/{id} | Descrição oficial da CVE, métricas CVSS v3.1/v4.0 | $0 / Sem Chave |
| 9 | CIRCL.lu CVE API | cve.circl.lu/api/cve/{id} | Metadados secundários de CVE e fallback de CVSS | $0 / Sem Chave |
| 10 | GitHub Exploit/PoC Hunter | api.github.com/search/repositories | Repositórios públicos ao vivo de exploits Proof-of-Concept (PoC) e estrelas | $0 / Sem Chave |
| 11 | CISA KEV Catalog | cisa.gov/.../known_exploited_vulnerabilities.json | Mais de 1.300 CVEs ativamente exploradas e uso em campanhas de ransomware | $0 / Sem Chave |
| 12 | abuse.ch Feodo C2 | feodotracker.abuse.ch/.../ipblocklist | Servidores C2 ativos de QakBot, Emotet, Pikabot, Dridex | $0 / Sem Chave |
| 13 | abuse.ch ThreatFox | threatfox-api.abuse.ch/api/v1/ | Hash SHA256/MD5 de malware e atribuição de IOC de C2 | $0 / Sem Chave |
| 14 | CyberCodex Malware Vault | Motor de Hash Local + Ao Vivo | Atribuição instantânea de hashes SHA-256 famosos de APT/wiper | $0 / Sem Chave |
| 15 | Official Tor Exit List | check.torproject.org/torbulkexitlist | Verificação ao vivo contra ~1.500 Nós de Saída Tor ativos | $0 / Sem Chave |
| 16 | RIPE NCC Stat BGP | stat.ripe.net/data/network-info | Prefixo CIDR BGP anunciado e roteamento de ASN de Origem | $0 / Sem Chave |
| 17 | ip-api / RDAP Telemetry | ip-api.com / rdap.arin.net | ASN, ISP, Organização, DNS Reverso, Datacenter/Proxy | $0 / Sem Chave |
| 18 | Cloudflare DoH DNS/DMARC | cloudflare-dns.com/dns-query | Auditoria ao vivo de MX, NS, SPF, DMARC e vulnerabilidade de Spoofing de E-mail | $0 / Sem Chave |
| 19 | Live TLS/SSL Socket | Handshake X.509 TCP/443 Nativo | Impressão digital do certificado SHA-256, serial, versão TLS e heurísticas de C2 | $0 / Sem Chave |
| 20 | crt.sh CT Logs | crt.sh/?q=%.{domain}&output=json | Descoberta de subdomínios via SSL Certificate Transparency | $0 / Sem Chave |
| 21 | Wayback Machine CDX | web.archive.org/cdx/search/cdx | URLs arquivadas históricas e links diretos de snapshots brutos | $0 / Sem Chave |
| 22 | Ransomware & PhishStats | api.ransomware.live / phishstats.info | Vítimas globais de ransomware em tempo real e URLs de phishing ativas | $0 / Sem Chave |