Cyberbro aims to provide a simple and efficient way to check the reputation of your observables using
multiple threat intelligence services, without having to deploy a complex solution.
Handles various input types: paste raw logs, IoCs, fanged IoCs, and they will be parsed using regex.
Checks if an observable (IP, hash, domain, URL) is malicious using services like VirusTotal, AbuseIPDB,
IPInfo, Spur.us, IP Quality Score, MDE, Google Safe Browsing, Shodan, Abusix, Phishtank, and more.
Generates comprehensive reports with search and filter features (type, country, risk, detection,
proxy/VPN).
Utilizes multithreading to speed up the process (artificially limited with time.sleep() due to free API
usage).
Performs reverse DNS lookups.
Checks abuse contacts for IPs, URLs, and domains (Abusix).
Allows exporting results to CSV and Excel files.
Verifies if the observable has been seen on the Microsoft Defender for Endpoint (MDE) platform (your
tenant).