Skip to content
View FoxSecIntel's full-sized avatar

Block or report FoxSecIntel

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
FoxSecIntel/README.md

Greetings, I appreciate you checking out my profile. 👋    Buy Me A Coffee

🦊 FoxSecIntel

Operational security tooling for modern SOC teams.

Focused on:

  • Domain and email security validation
  • Phishing analysis and investigation tooling
  • BGP and ASN exposure intelligence
  • Reconnaissance workflows
  • Analyst productivity automation

Practical by Design. Modular by Nature. Structured for the SOC.


Tool Portfolio

Tool Primary Use Case Language Interface JSON Output CI Enabled
foxsec-intel-pipeline Analyst-first domain intelligence enrichment and risk scoring pipeline Python CLI Yes Partial
soc-incident-playbooks SOC runbooks for 2026 incidents, including AI, agent hijack, browser extension abuse, and campaign-first response workflows Markdown Playbook Library No Partial
link-inspector-chrome-extension Browser link extraction, filtering, risk highlighting, and export for fast triage JavaScript Chrome Extension Partial Partial
Openclaw-audit Independent OpenClaw configuration and deployment security auditing Python CLI Yes Partial
quantum-auditor Remote TLS quantum risk auditing with HNDL, Grover, and Shor posture checks Python CLI No Partial
BGP-Intel ASN and prefix exposure analysis for hijack and route-leak detection Python / Bash CLI Partial Partial
cloud-hun Cloud IAM and public exposure hunting for AWS and GCP environments Bash / Python CLI Yes Partial
DNS-analysis DNS posture checks including NS, CAA, DMARC, SPF, and Cloudflare detection Bash / Python CLI Yes Partial
Vulnerability-Analysis CVE enrichment, update checks, and analyst-focused vulnerability workflows Bash CLI Partial Partial
GoogleAndShodanDorking Tier-1 reconnaissance query framework for Google and Shodan Markdown / Python Reference + CLI Partial Partial
WebPage-Analysis Web investigation toolkit for URL expansion, header analysis, security.txt checks, and link extraction workflows Bash / Python CLI Partial Partial
dmarc.exe Validate DMARC, SPF and MX posture for a given domain Python CLI Partial Partial
PhishSense Local phishing email analysis with structured scoring and report generation Python CLI Yes Partial
sensitive-info-scanner-chrome-extension Browser-side page scanner for sensitive patterns with CSV and JSON export JavaScript Chrome Extension Yes Partial
linkscrub Context-menu clean-link copier that strips tracking parameters before clipboard copy JavaScript Chrome Extension No Partial
pomodoro-timer Focus sprint timer to structure analyst deep-work blocks for security investigations and threat-hunting sessions JavaScript Chrome Extension No Partial

Design Principles

  • Modular tools, not monoliths
  • Human-readable output plus structured export
  • Report-first philosophy (minimal destructive automation)
  • Designed for analysts under time pressure
  • Composable into pipelines and SOAR workflows

Security tooling should feel like a well-organised workshop: predictable, sharp, and ready when needed.


Roadmap Direction

  • Unified foxsec meta-CLI wrapper
  • Output format standardisation across all tools
  • Dockerised builds for deployability
  • SIEM and SOAR integration adapters
  • CI coverage expansion across repositories

Documentation Standard

Portfolio README conventions are maintained in STYLE_GUIDE.md. Use this for consistent hero sections, demo media, and formatting across repositories.


Contributing

Pull requests are welcome. Issues tagged good-first-issue are ideal entry points.

Pinned Loading

  1. dmarc.exe dmarc.exe Public

    Python 1

  2. WebPage-Analysis WebPage-Analysis Public

    Shell

  3. BGP-Intel BGP-Intel Public

    Python

  4. Vulnerability-Analysis Vulnerability-Analysis Public

    Python 1

  5. DNS-analysis DNS-analysis Public

    Python

  6. GoogleAndShodanDorking GoogleAndShodanDorking Public

    SOC-ready list of Google and Shodan dorks built for Tier 1 analysts to triage, enrich, and pivot on real-world alerts and incidents.

    Python 3