[THUGS(red)]

Projects

26 things we build and run — threat intelligence feeds, honeypots, recon tooling and offensive infrastructure, plus a few that are neither and were built for the fun of it. Most are live; each has its own page here and a link out to the real thing.

Threat intel

> darkweb-monitor

DarkWeb Monitor

Monitoring of onion services, leak sites and criminal marketplaces for exposure that matters.

details visit ↗
> blacklist

THUGS(red) Blacklist

Curated blocklists of hostile infrastructure, ready to drop into a firewall or resolver.

details visit ↗
> activity-map

THUGS(red) Live Activity Map wip

Live visualisation of the activity our sensors and honeypots are seeing.

details visit ↗
> smtp-latrine

THUGS(red) SMTP Latrine

An SMTP honeypot — catching what crawls into an open mail relay.

details visit ↗
> telegram-grabber

THUGS(red) Telegram Grabber

Collection from Telegram channels where leaks and criminal chatter surface first.

details visit ↗

Recon

> wardrive

THUGS(red) Wardrive

Wardriving data collection and mapping — wireless networks logged on the move and plotted for analysis.

details visit ↗
> dangling-dns

THUGS(red) Dangling DNS

Hunting dangling DNS records and the subdomain takeovers they enable.

details visit ↗
> valhalla

Gates of Valhalla

OSINT research platform — hand it an email, username, IP, domain or phone number and watch the intelligence graph build itself.

details visit ↗

Offensive

> evil

Evil Project

Offensive research and red team tradecraft experiments.

details visit ↗
> mailchumhum

Project MailChumHum

Credential phishing simulation infrastructure used in authorised engagements.

details visit ↗
> cupatm

Project CupATM

Bitcoin, webcam and leak-themed phishing simulation — the classic extortion lure, rebuilt.

details visit ↗
> securitycheck

THUGS(red) Security Check

A standardised benchmark for whether your EDR, AV and SOC actually react when something hostile happens.

details visit ↗

Tooling

> apt

THUGS(red) APT

Our Debian APT repository — the small binaries and tools we build, packaged and installable with apt.

details visit ↗
> tools

Tools Overview

The team's collected tooling in one place — the utilities we reach for on an engagement.

details visit ↗
> dump

THUGS(red) Dump File

Drop a suspicious file and have the team look at it.

details visit ↗
> suricata-rules

THUGS(red) Suricata Rules

Detection rules for Suricata, written from what we actually see in the wild.

details visit ↗
> canary

Canary Tokens

Plant a tripwire anywhere — a URL, a pixel, a document, a DNS name — and know the moment somebody touches it.

details visit ↗
> filio

Filio File Sharing

Drag, drop, share — files up to 2 GB, no account, no trackers, every link deep-linkable.

details visit ↗
> ipdigger

ipdigger

Digs every IP address out of a file and enriches it — reverse DNS, threat intel, network info.

details visit ↗
> telegramdigger

telegramdigger

The Telegram Bot API from your terminal — quick OSINT against a bot token, and the ability to act on it.

details visit ↗
> subdigger

subdigger

Fast multi-threaded subdomain discovery — certificate transparency, wordlists, OSINT APIs and bruteforce.

details visit ↗

Infrastructure

> lab

The Lab wip

The practice range — unfinished, and honest about it.

details visit ↗
> takedown

THUGS(red) Takedown Authority

The seizure notice — where a domain ends up after a verified abuse or takedown action.

details visit ↗

Fun and games

> bitbasher

Bitbasher

Music Terminal Bonanza — a browser Eurorack rendered in ANSI, patched together one module at a time.

details visit ↗
> critzone

CRIT ZONE

Neon vector arena shooter — survive the swarm, solo or co-op, and put four letters on the global board.

details visit ↗
> tankwars

Tank Wars

Massively multiplayer top-down tank combat — four letters, forty tonnes, one arena.

details visit ↗