BlackShieldCore
Platform overview

About BlackShield Core

An analyst-first threat intelligence platform unifying 20+ feeds, live ransomware tracking, and 40+ toolbox operations into a single unified console.

1. What BlackShield Core Is

BlackShield Core is an integrated threat intelligence workspace designed to eliminate context-switching during security investigations. Analysts frequently juggle dozens of browser tabs across VirusTotal, Shodan, AbuseIPDB, and leak sites to triage observables. BlackShield Core aggregates these data streams into a structured console.

Audience Scope: Built for practitioners across the entire security spectrum — from newcomers encountering threat concepts and IoCs for the first time to experienced SOC analysts, incident responders, red teamers, and threat researchers. Technical concepts and industry terms (such as CVEs, hashes, Autonomous System Numbers, and passive DNS) are paired with clear explanations so beginners learn standard terminology without slowing down seasoned experts.

2. Author & Independence

BlackShield Core is created and maintained by Pratham Badgujar.

Project Status & Disclaimer: BlackShield Core is a personal, independent research project built entirely outside of working hours. It is not affiliated with, endorsed by, or representative of any employer or commercial entity. All opinions, research notes, and codebase implementations are strictly the author's own.

3. Integrated Data Sources & Credits

BlackShield Core owes its utility to the public threat intelligence community and open API providers. Every integrated source is credited below with direct links:

Source NameEndpoint DomainData & Telemetry Provided
VirusTotalvirustotal.com70+ Antivirus engines, file/domain reputation, hash lookups
Shodan InternetDBinternetdb.shodan.ioOpen ports, service banners, host CPEs, CVE associations
AbuseIPDBabuseipdb.comIP abuse reports, confidence scores, ISP & hosting attribution
ip-apiip-api.comGeolocation, ISP, AS numbers, organization, network coordinates
ransomware.liveransomware.liveActive ransomware victim disclosures, group leak sites, feeds
ThreatFoxthreatfox.abuse.chCommunity IoC database, malware family tagging, confidence scores
URLhausurlhaus.abuse.chMalicious URL database tracking malware payload distribution
AlienVault OTXotx.alienvault.comThreat intelligence pulses, actor indicators, campaign feeds
GreyNoisegreynoise.ioInternet scanner detection, benign noise vs targeted activity
NVDnvd.nist.govNIST National Vulnerability Database, CVSS vectors, CVE details
CISA KEVcisa.govKnown Exploited Vulnerabilities catalog
crt.shcrt.shCertificate Transparency logs, subdomains, SSL history
Cloudflare DoHcloudflare-dns.comDNS-over-HTTPS resolution (A, AAAA, MX, TXT, CNAME)
Pulsedivepulsedive.comIoC enrichment, WHOIS records, risk scoring, threat categories
MalSharemalshare.comMalware repository, file sample hashes, detection strings
Hybrid Analysishybrid-analysis.comAutomated malware sandbox analysis, behavior tags, ATT&CK mapping
Triagetria.geHigh-volume malware sandbox analysis, detonation reports
Qualys SSL Labsssllabs.comSSL/TLS server configuration inspection and grade scoring
urlscan.iourlscan.ioWebpage sandbox rendering, DOM snapshots, network connections
RDAPrdap.orgRegistration Data Access Protocol domain/IP WHOIS lookups
EPSSfirst.orgExploit Prediction Scoring System probabilities
Google Safe Browsingsafebrowsing.googleapis.comReal-time URL phishing and malware status
CIRCLcircl.luComputer Incident Response Center Luxembourg threat data

4. Legal Disclaimer & Privacy Notice

Public Data Aggregation: All threat observables, IP reputation scores, domain attributes, and ransomware victim records displayed across BlackShield Core are aggregated in real time from publicly available APIs and open threat feeds.

No Stolen Data Storage: BlackShield Core does not host, acquire, buy, sell, or redistribute stolen files, leaked PII, or raw extortion dumps. All ransomware disclosures consist solely of metadata (victim organization name, group identity, and disclosure timestamp).

Defensive Purpose: Information on this platform is provided strictly for defensive security operations, threat hunting, vulnerability management, and academic research. Accuracy is dependent on upstream third-party sources; users should verify findings independently before taking remediation actions.

Privacy & Removal Requests: If you represent an organization or domain listed in error or wish to submit a data correction/removal request, please use the contact channel below.

5. Contact & Support

Reach out to the author for threat feed suggestions, data corrections, privacy requests, or bug reports: