Original Summary

Hey folks, A while back I shared ThreatLens here a little CLI tool that pulls IOC enrichment (IPs, domains, hashes, CVEs) from free threat intel APIs like AbuseIPDB, VirusTotal, OTX, Shodan, and NVD, all in one command instead of ten browser tabs. Just pushed a decent-sized update (v2.2) and figured I'd share in case anyone wants to kick the tires: CVE triage that actually tells you what to do checks CISA KEV + EPSS alongside CVSS and spits out Patch / Isolate / Monitor / Not-affected, with the reasoning behind it (not a black-box score) Asset inventory import a CSV of your hosts and it'll factor in whether something's internet-facing/critical before deciding Log parsing for Zeek, Suricata eve.json , Sysmon, and generic JSONL — not just plain text logs anymore SIEM export to Splunk, Elastic, and Sentinel (opt-in, off by default) Evidence packs zips up an investigation with a SHA-256 manifest if you need a paper trail It's still 100% free-tier friendly (no paid API required),and the whole thing is like 150+ tests deep at this point so it shouldn't randomly eat your terminal. Repo's here: https://github.com/AbdaullahAG/ThreatLens If you try it out I'd genuinely love to hear what breaks, what's confusing, or what you wish it did differently this started as a personal project so outside eyes are super helpful. Issues/PRs/roasts all welcome 🙂   submitted by   /u/Strict-Result-7039 [link]   [comments]

中文概览

中文标题: ThreatLens v2.2发布:新增CVE分级、日志解析和SIEM导出

作者更新了ThreatLens命令行工具,可一条命令从AbuseIPDB、VirusTotal、OTX、Shodan、NVD等免费威胁情报API获取IP、域名、哈希和CVE的富化信息。v2.2新增结合CISA KEV、EPSS和CVSS的CVE处置建议、资产清单导入、Zeek/Suricata/Sysmon日志解析、可选SIEM导出和证据包功能,工具免费使用。


  • 情报分类:开源项目与落地
  • 分类依据:开源安全CLI工具更新发布
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/9/18 06:04:19