pduggusa/DugganUSA Threat Intel Scan

Scan code for IPs, domains, hashes, and CVEs against 1.5M+ threat indicators. Block PRs containing known-bad indicators.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
api-keyDugganUSA API key — free registered key from analytics.dugganusa.com/stix/register (feed is key-enforced)no""
scan-patternsGlob pattern for files to scanno**/*.{js,ts,py,json,yml,yaml,conf,cfg,ini,env,md,txt,tf,hcl}
fail-on-matchFail the action (exit 1) if threat indicators are foundnotrue
fail-on-unknownFail the action if an indicator could not be checked (expired key, rate limit, timeout, API outage). An unverified indicator is not a clean one -- a gate that could not run should not report a pass. Defaults to the value of fail-on-match. Set to false to let outages through.no""
report-hitsReport confirmed indicators back to the DugganUSA feed-efficacy (liveness) axis. Indicator-only — never repo/file/actor context. Requires api-key. Set to false to opt out.notrue
formatOutput format: table, json, or markdownnotable
namedescription
foundNumber of threat indicators found
scannedNumber of IOC candidates scanned
cleanNumber of IOC candidates successfully verified as clean
unknownNumber of IOC candidates that could NOT be checked (lookup failed). These are unverified, not clean.