Intrigue-Core – Discover Your Attack Surface

Intrigue-core is a framework for automated attack surface discovery. There are a number of use cases:Application and Infrastructure (Asset) DiscoverySecurity Research and Vulnerability DiscoveryMalware Campaign Research & Indicator EnrichmentExploratory OSINT ResearchIf you’d like assistance getting started or have development-related questions, feel free to join to the chat.UsersIf you just want to get started and play around with an instance, have a look at the Getting Started GuideDevelopersTo get started setting up a development environment, follow the instructions below!Setting up a development environmentFollow the appropriate setup guide:Vagrant (preferred) – – setup guides (may be out of date!)Ubuntu Linux – Linux – X – that you have a working environment, browse to the web interface.Using the web interfaceTo use the web interface, browse to Once you’re able to connect, you can follow the instructions here: the systemMany tasks work via external APIs and thus require configuration of keys. To set them up, browse to the “Configure" tab and click on the name of the module. You will be taken to the relevant signup page where you can provision an API key. These keys are ultimately stored in the file: config/config.json.The APIIntrigue-core is built API-first, allowing all functions in the UI to be easily automated. The following methods for automation are provided.API usage via core-cliA command line utility has been added for convenience, core-cli.List all available tasks:$ bundle exec ./core-cli.rb listStart a task:## core-cli.rb start [Project Name] [Task] [Type#Entity] [Depth] [Option1=Value1#…#…] [Handlers] [Strategy Name] [Auto Enrich]$ bundle exec ./core-cli.rb start new_project create_entity 3Got entity: {"type"=>"DnsRecord", "name"=>"", "details"=>{"name"=>""}}Task Result: {"result_id":66103}API usage via curlYou can use curl to drive the framework. See the example below:$ curl -s -X POST -H "Content-Type: application/json" -d ‘{ "task": "create_entity", "entity": { "type": "DnsRecord", "attributes": { "name": "" } }, "options": {} }’ Intrigue-Core