intrigue-core

Discover Your Attack Surface

Github星跟蹤圖

Welcome!

Intrigue-core is a framework for external attack surface discovery and automated OSINT. The framework is designed for use cases such as:

  • Asset Discovery (Application and Infrastructure)
  • Security Research and Vulnerability Scanning
  • Exploratory OSINT (People, Systems, Entities)
  • Malware IOC Enrichment
  • Security-Oriented Data Gathering Pipelines

If you'd like assistance getting started or have development-related questions, feel free to join us in slack channel, simply drop a line to hello@intrigue.io

Users

To get started quickly and play around with an instance, head on over to the Getting Started Guide. We suggest the Docker image as a first place to start. It's actively built on the master branch of Intrigue Core.

Using the web interface

To use the web interface, browse to http://127.0.0.1:7777. Once you're able to connect, you can follow the instructions here: http://core.intrigue.io/up-and-running/

Configuring the system

Many tasks work via external APIs and thus require configuration of keys. To set them up, browse to the "Configure" tab and click on the name of the module. You will be taken to the relevant signup page where you can provision an API key. These keys are ultimately stored in the file: config/config.json.

The API

Intrigue-core is built API-first, allowing all functions in the UI to be automated. The following methods for automation are provided.

API usage via curl

You can use curl to drive the framework. See the example below:

$ curl -s -X POST -H "Content-Type: application/json" -d '{ "task": "create_entity", "entity": { "type": "DnsRecord", "attributes": { "name": "intrigue.io" } }, "options": {} }' http://127.0.0.1:7777/results

API usage via command line (core-cli)

A command line utility has been added for convenience, core-cli.

List all available tasks:

$ bundle exec ./core-cli.rb list

Start a task:

## core-cli.rb start [Project Name] [Task] [Type#Entity] [Depth] [Option1=Value1#...#...] [Handlers] [Strategy Name] [Auto Enrich]
$ bundle exec ./core-cli.rb start new_project create_entity DnsRecord#intrigue.io 3
Got entity: {"type"=>"DnsRecord", "name"=>"intrigue.io", "details"=>{"name"=>"intrigue.io"}}
Task Result: {"result_id":66103}

API SDK (Ruby)

A Ruby gem is available for your convenience: Gem Version

Setting up a development environment

To get started setting up a development environment, follow the instructions below!

While you can build a local setup and develop, we'd suggest starting with one of the following setup guides:

You'll probably want to take a look at the following resources:

Contributors

Intrigue Core would not be possible without hard work, time, and attention from the following contributors:

主要指標

概覽
名稱與所有者intrigueio/intrigue-core
主編程語言Ruby
編程語言Ruby (語言數: 8)
平台
許可證Other
所有者活动
創建於2015-07-06 08:06:49
推送於2022-11-11 18:01:53
最后一次提交
發布數8
最新版本名稱v1.0.0 (發布於 )
第一版名稱v0.2 (發布於 )
用户参与
星數1.4k
關注者數76
派生數271
提交數5.4k
已啟用問題?
問題數114
打開的問題數3
拉請求數293
打開的拉請求數3
關閉的拉請求數43
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?