About BlackShield Core
An analyst-first threat intelligence platform unifying 20+ feeds, live ransomware tracking, and 40+ toolbox operations into a single unified console.
1. What BlackShield Core Is
BlackShield Core is an integrated threat intelligence workspace designed to eliminate context-switching during security investigations. Analysts frequently juggle dozens of browser tabs across VirusTotal, Shodan, AbuseIPDB, and leak sites to triage observables. BlackShield Core aggregates these data streams into a structured console.
Audience Scope: Built for practitioners across the entire security spectrum — from newcomers encountering threat concepts and IoCs for the first time to experienced SOC analysts, incident responders, red teamers, and threat researchers. Technical concepts and industry terms (such as CVEs, hashes, Autonomous System Numbers, and passive DNS) are paired with clear explanations so beginners learn standard terminology without slowing down seasoned experts.
2. Author & Independence
BlackShield Core is created and maintained by Pratham Badgujar.
Project Status & Disclaimer: BlackShield Core is a personal, independent research project built entirely outside of working hours. It is not affiliated with, endorsed by, or representative of any employer or commercial entity. All opinions, research notes, and codebase implementations are strictly the author's own.
3. Integrated Data Sources & Credits
BlackShield Core owes its utility to the public threat intelligence community and open API providers. Every integrated source is credited below with direct links:
| Source Name | Endpoint Domain | Data & Telemetry Provided |
|---|---|---|
| VirusTotal | virustotal.com | 70+ Antivirus engines, file/domain reputation, hash lookups |
| Shodan InternetDB | internetdb.shodan.io | Open ports, service banners, host CPEs, CVE associations |
| AbuseIPDB | abuseipdb.com | IP abuse reports, confidence scores, ISP & hosting attribution |
| ip-api | ip-api.com | Geolocation, ISP, AS numbers, organization, network coordinates |
| ransomware.live | ransomware.live | Active ransomware victim disclosures, group leak sites, feeds |
| ThreatFox | threatfox.abuse.ch | Community IoC database, malware family tagging, confidence scores |
| URLhaus | urlhaus.abuse.ch | Malicious URL database tracking malware payload distribution |
| AlienVault OTX | otx.alienvault.com | Threat intelligence pulses, actor indicators, campaign feeds |
| GreyNoise | greynoise.io | Internet scanner detection, benign noise vs targeted activity |
| NVD | nvd.nist.gov | NIST National Vulnerability Database, CVSS vectors, CVE details |
| CISA KEV | cisa.gov | Known Exploited Vulnerabilities catalog |
| crt.sh | crt.sh | Certificate Transparency logs, subdomains, SSL history |
| Cloudflare DoH | cloudflare-dns.com | DNS-over-HTTPS resolution (A, AAAA, MX, TXT, CNAME) |
| Pulsedive | pulsedive.com | IoC enrichment, WHOIS records, risk scoring, threat categories |
| MalShare | malshare.com | Malware repository, file sample hashes, detection strings |
| Hybrid Analysis | hybrid-analysis.com | Automated malware sandbox analysis, behavior tags, ATT&CK mapping |
| Triage | tria.ge | High-volume malware sandbox analysis, detonation reports |
| Qualys SSL Labs | ssllabs.com | SSL/TLS server configuration inspection and grade scoring |
| urlscan.io | urlscan.io | Webpage sandbox rendering, DOM snapshots, network connections |
| RDAP | rdap.org | Registration Data Access Protocol domain/IP WHOIS lookups |
| EPSS | first.org | Exploit Prediction Scoring System probabilities |
| Google Safe Browsing | safebrowsing.googleapis.com | Real-time URL phishing and malware status |
| CIRCL | circl.lu | Computer Incident Response Center Luxembourg threat data |
4. Legal Disclaimer & Privacy Notice
Public Data Aggregation: All threat observables, IP reputation scores, domain attributes, and ransomware victim records displayed across BlackShield Core are aggregated in real time from publicly available APIs and open threat feeds.
No Stolen Data Storage: BlackShield Core does not host, acquire, buy, sell, or redistribute stolen files, leaked PII, or raw extortion dumps. All ransomware disclosures consist solely of metadata (victim organization name, group identity, and disclosure timestamp).
Defensive Purpose: Information on this platform is provided strictly for defensive security operations, threat hunting, vulnerability management, and academic research. Accuracy is dependent on upstream third-party sources; users should verify findings independently before taking remediation actions.
Privacy & Removal Requests: If you represent an organization or domain listed in error or wish to submit a data correction/removal request, please use the contact channel below.
5. Contact & Support
Reach out to the author for threat feed suggestions, data corrections, privacy requests, or bug reports: