Projects
65 things we build and run — threat intelligence feeds, honeypots, recon tooling and offensive infrastructure, plus a few that are neither and were built for the fun of it. Most are live; each has its own page here and a link out to the real thing.
Threat intel
DarkWeb Monitor
Monitoring of onion services, leak sites and criminal marketplaces for exposure that matters.
details visit ↗THUGS(red) Blacklist
Curated blocklists of hostile infrastructure, ready to drop into a firewall or resolver.
details visit ↗THUGS(red) Live Activity Map wip
Live visualisation of the activity our sensors and honeypots are seeing.
details visit ↗THUGS(red) SMTP Latrine
An SMTP honeypot — catching what crawls into an open mail relay.
details visit ↗THUGS(red) Telegram Grabber
Collection from Telegram channels where leaks and criminal chatter surface first.
details visit ↗githubxhunter wip
A small kit of scripts for hunting fake accounts and malicious code on GitHub.
details visit ↗RansomWatch
Ransomware leak-site monitoring pointed at the Nordics — new DK/NO/SE victims land in Discord as they are posted, with worldwide stats on top.
details visit ↗THUGS(red) Threat Screensaver wip
A native macOS screensaver: a slowly rotating Metal-rendered 3D globe lit up with public threat-intelligence feeds — CISA KEV, DShield, AbuseIPDB — plus session stats and an optional dark ambient soundtrack.
details visit ↗Recon
THUGS(red) Wardrive
Wardriving data collection and mapping — wireless networks logged on the move and plotted for analysis.
details visit ↗THUGS(red) Dangling DNS
Hunting dangling DNS records and the subdomain takeovers they enable.
details visit ↗Gates of Valhalla
OSINT research platform — hand it an email, username, IP, domain or phone number and watch the intelligence graph build itself.
details visit ↗NetworkSambaScanner
Fast concurrent scan for SMB/Samba exposure across a range — dialect, share enumeration, real read/write testing, and a severity-rated report.
details visit ↗THUGS(red) Wardrive (Android)
The phone-in-your-pocket end of the Wardrive project — a WiFi and Bluetooth wardriving app for Android that streams sessions to wardrive.thugs.red.
details visit ↗RedJoust wip
A desktop recon workbench — feed it a target, pick passive or active mode, and the relevant OSINT, analysis and red-team gathering items surface themselves.
details visit ↗WiFi Jumper wip
A matchbox-sized ESP8266 that hops from one open WiFi network to the next and phones home the network details and a GPS fix each time it gets online.
details visit ↗THUGS(red) RF
A native Linux terminal workbench for HackRF and RTL-SDR: spectrum and waterfall views, wideband survey, modular protocol decoders, frequency OSINT and AM/FM listening, all from one full-colour TUI.
details visit ↗Offensive
Project MailChumHum
Credential phishing simulation infrastructure used in authorised engagements.
details visit ↗Project CupATM
Bitcoin, webcam and leak-themed phishing simulation — the classic extortion lure, rebuilt.
details visit ↗THUGS(red) Security Check
A standardised benchmark for whether your EDR, AV and SOC actually react when something hostile happens.
details visit ↗URL Bully wip
A desktop UI for leaning on a web server at the URL level — templated requests, variable substitution and live timing, somewhere between curl and Burp.
details visit ↗DuckyScript Payloads wip
The team's collection of DuckyScript / BadUSB payloads for Flipper Zero — keystroke-injection scripts for OSINT pulls and forensic automation off a target machine.
details visit ↗thugsflooder
A single-binary load generator for authorised lab exercises — sustained UDP/TCP/HTTP floods and traffic replay, built so a blue team and SOC find out whether they actually notice.
details visit ↗Tooling
THUGS(red) APT
Our Debian APT repository — the small binaries and tools we build, packaged and installable with apt.
details visit ↗Tools Overview
The team's collected tooling in one place — searchable, tagged, and open to member submissions.
details visit ↗THUGS(red) Dump File
Drop a suspicious file and have the team look at it.
details visit ↗THUGS(red) Suricata Rules
Detection rules for Suricata, written from what we actually see in the wild.
details visit ↗Canary Tokens
Plant a tripwire anywhere — a URL, a pixel, a document, a DNS name — and know the moment somebody touches it.
details visit ↗Filio File Sharing
Drag, drop, share — files up to 2 GB, no account, no trackers, every link deep-linkable.
details visit ↗ipdigger
Digs every IP address out of a file and enriches it — reverse DNS, threat intel, network info.
details visit ↗telegramdigger
The Telegram Bot API from your terminal — quick OSINT against a bot token, and the ability to act on it.
details visit ↗subdigger
Fast multi-threaded subdomain discovery — certificate transparency, wordlists, OSINT APIs and bruteforce.
details visit ↗SynapseIDS wip
A network IDS built as a pipeline, not a signature set — packets become flows, flows become a 48-feature vector, a neural net calls the traffic.
details visit ↗susfile
CLI file-forensics visualiser — draws a file as a defrag-style map of classified byte regions: magic, MIME, entropy, hashes, ELF/PE/Mach-O structure. Offline, no telemetry.
details visit ↗boop
A local-first AI client and agent runtime — provider-neutral models, a sandboxed tool executor, permissions enforced in code, and nothing that phones home.
details visit ↗LogIO Devlog
Drop-in PHP glue for LogIO — a real-time rolling log viewer for all the spam-and-debug output you want to watch but never keep.
details visit ↗theZoo WebUI
A browser front-end for theZoo, the live malware repository — sample search and retrieval, strictly for the homelab.
details visit ↗snmpdigger
A fully keyboard-driven terminal UI that walks, identifies, graphs and hunts SNMP agents — discover, graph, inform.
details visit ↗pcapdigger
Point it at a pcap and get three reports from one pass — network-engineering detail, security findings, and an executive summary.
details visit ↗The Digger Family
The overview page tying subdigger, ipdigger, telegramdigger, snmpdigger and pcapdigger together as one family, and explaining the principle behind all five.
details visit ↗aiusagemonitor
A terminal dashboard for AI API usage, cost and rate limits across OpenAI, Anthropic, Gemini and xAI — your tokens, your terminal, your rules.
details visit ↗Thugagotchi
A tiny gorilla in shades that lives on an ESP32-S3 screen, tracking Claude Code and Codex sessions in real time — then turns into a needy desk pet the moment you stop coding.
details visit ↗AI Hardware Monitor
A fullscreen Rust terminal dashboard for the machine running your models — CPU, GPU, NPU, Coral TPU, memory, disk and network — with an AI-process filter and six colour themes.
details visit ↗AI Worker
A self-hosted autonomous coding workshop for Claude Code and Codex: queue a brief, let the workers build, and follow it all from the browser.
details visit ↗AI Project Scaffold
A reusable starting point for AI-assisted projects — working rules, architecture guidance and templates, validated in CI and released as a single ZIP.
details visit ↗XXC Run
A private malware analysis lab: detonate a sample, watch processes, network and filesystem activity unfold, and keep the evidence.
details visit ↗SoundScope
A browser sound lab: drop in an audio file and get waveform, spectrogram, spectrum, stereo field, metadata and detected signal events — plus a live microphone view.
details visit ↗Flash wip
A browser firmware workbench: read and write flash chips through a hardware programmer, then inspect the dump in a hex editor with forensics and checksum tools.
details visit ↗Nulltongue
A terminal-safe hacker language and monospace font: ordinary UTF-8 drawn as an alien syllabary and logograph set.
details visit ↗XXC Network Topology Creator
Draw network topologies in the browser: drag devices onto a canvas, connect them, start from templates and export the result.
details visit ↗Infrastructure
THUGS(red) Takedown Authority
The seizure notice — where a domain ends up after a verified abuse or takedown action.
details visit ↗THUGS(red) BBS
A keyboard-driven ANSI/ASCII bulletin board system that runs inside a CRT — on the web. Messages, files, door games, node chat, all dial-up ritual included.
details visit ↗XXC Trust
A private certificate authority: root and intermediate CAs, CSR signing, ACME enrolment, a REST API, CRL/OCSP and expiry alerts, all in one workspace.
details visit ↗Fun and games
Bitbasher
Music Terminal Bonanza — a browser Eurorack rendered in ANSI, patched together one module at a time.
details visit ↗CRIT ZONE
Neon vector arena shooter — survive the swarm, solo or co-op, and put four letters on the global board.
details visit ↗Tank Wars
Massively multiplayer top-down tank combat — four letters, forty tonnes, one arena.
details visit ↗Egg Heist
A silly browser party game about stealing a golden egg — grab it, be holding it when the clock hits zero, win the round.
details visit ↗Stick Fight Arena
Two stick figures brawl on a procedurally generated street, and every move either one makes comes from a small neural network bred by evolutionary self-play.
details visit ↗Maze Runner AI
Generate a maze, then race it yourself, hand it to a search algorithm, script your own runner, or train a small neural network to escape it.
details visit ↗Signal / City
A traffic-engineering game: program the signal cycle for one intersection, run a trial, and clear a hundred vehicles before it gridlocks.
details visit ↗Foundry of Small Victories
A calm clockwork crafting game: turn scrap into gears, springs and fuel, fill six village orders, and bring an old workshop back to life.
details visit ↗Fart Away!
The world's least fragrant defence game: one fan, a room full of stink clouds, and a question of how long you can keep it fresh.
details visit ↗Hackers-MUD
A cyberpunk hacker MUD set in Night City — its own 2D browser client, and playable as pure text straight through the BBS.
details visit ↗Fish Tank Friends!
A little virtual aquarium: feed the fish, clean the glass, and watch them grow and learn.
details visit ↗