Projects
26 things we build and run — threat intelligence feeds, honeypots, recon tooling and offensive infrastructure, plus a few that are neither and were built for the fun of it. Most are live; each has its own page here and a link out to the real thing.
Threat intel
DarkWeb Monitor
Monitoring of onion services, leak sites and criminal marketplaces for exposure that matters.
details visit ↗THUGS(red) Blacklist
Curated blocklists of hostile infrastructure, ready to drop into a firewall or resolver.
details visit ↗THUGS(red) Live Activity Map wip
Live visualisation of the activity our sensors and honeypots are seeing.
details visit ↗THUGS(red) SMTP Latrine
An SMTP honeypot — catching what crawls into an open mail relay.
details visit ↗THUGS(red) Telegram Grabber
Collection from Telegram channels where leaks and criminal chatter surface first.
details visit ↗Recon
THUGS(red) Wardrive
Wardriving data collection and mapping — wireless networks logged on the move and plotted for analysis.
details visit ↗THUGS(red) Dangling DNS
Hunting dangling DNS records and the subdomain takeovers they enable.
details visit ↗Gates of Valhalla
OSINT research platform — hand it an email, username, IP, domain or phone number and watch the intelligence graph build itself.
details visit ↗Offensive
Project MailChumHum
Credential phishing simulation infrastructure used in authorised engagements.
details visit ↗Project CupATM
Bitcoin, webcam and leak-themed phishing simulation — the classic extortion lure, rebuilt.
details visit ↗THUGS(red) Security Check
A standardised benchmark for whether your EDR, AV and SOC actually react when something hostile happens.
details visit ↗Tooling
THUGS(red) APT
Our Debian APT repository — the small binaries and tools we build, packaged and installable with apt.
details visit ↗Tools Overview
The team's collected tooling in one place — the utilities we reach for on an engagement.
details visit ↗THUGS(red) Dump File
Drop a suspicious file and have the team look at it.
details visit ↗THUGS(red) Suricata Rules
Detection rules for Suricata, written from what we actually see in the wild.
details visit ↗Canary Tokens
Plant a tripwire anywhere — a URL, a pixel, a document, a DNS name — and know the moment somebody touches it.
details visit ↗Filio File Sharing
Drag, drop, share — files up to 2 GB, no account, no trackers, every link deep-linkable.
details visit ↗ipdigger
Digs every IP address out of a file and enriches it — reverse DNS, threat intel, network info.
details visit ↗telegramdigger
The Telegram Bot API from your terminal — quick OSINT against a bot token, and the ability to act on it.
details visit ↗subdigger
Fast multi-threaded subdomain discovery — certificate transparency, wordlists, OSINT APIs and bruteforce.
details visit ↗Infrastructure
THUGS(red) Takedown Authority
The seizure notice — where a domain ends up after a verified abuse or takedown action.
details visit ↗Fun and games
Bitbasher
Music Terminal Bonanza — a browser Eurorack rendered in ANSI, patched together one module at a time.
details visit ↗CRIT ZONE
Neon vector arena shooter — survive the swarm, solo or co-op, and put four letters on the global board.
details visit ↗Tank Wars
Massively multiplayer top-down tank combat — four letters, forty tonnes, one arena.
details visit ↗