[THUGS(red)]

Projects

65 things we build and run — threat intelligence feeds, honeypots, recon tooling and offensive infrastructure, plus a few that are neither and were built for the fun of it. Most are live; each has its own page here and a link out to the real thing.

Threat intel

> darkweb-monitor

DarkWeb Monitor

Monitoring of onion services, leak sites and criminal marketplaces for exposure that matters.

details visit ↗
> blacklist

THUGS(red) Blacklist

Curated blocklists of hostile infrastructure, ready to drop into a firewall or resolver.

details visit ↗
> activity-map

THUGS(red) Live Activity Map wip

Live visualisation of the activity our sensors and honeypots are seeing.

details visit ↗
> smtp-latrine

THUGS(red) SMTP Latrine

An SMTP honeypot — catching what crawls into an open mail relay.

details visit ↗
> telegram-grabber

THUGS(red) Telegram Grabber

Collection from Telegram channels where leaks and criminal chatter surface first.

details visit ↗
> githubxhunter

githubxhunter wip

A small kit of scripts for hunting fake accounts and malicious code on GitHub.

details visit ↗
> ransomwatch

RansomWatch

Ransomware leak-site monitoring pointed at the Nordics — new DK/NO/SE victims land in Discord as they are posted, with worldwide stats on top.

details visit ↗
> threat-screensaver

THUGS(red) Threat Screensaver wip

A native macOS screensaver: a slowly rotating Metal-rendered 3D globe lit up with public threat-intelligence feeds — CISA KEV, DShield, AbuseIPDB — plus session stats and an optional dark ambient soundtrack.

details visit ↗

Recon

> wardrive

THUGS(red) Wardrive

Wardriving data collection and mapping — wireless networks logged on the move and plotted for analysis.

details visit ↗
> dangling-dns

THUGS(red) Dangling DNS

Hunting dangling DNS records and the subdomain takeovers they enable.

details visit ↗
> valhalla

Gates of Valhalla

OSINT research platform — hand it an email, username, IP, domain or phone number and watch the intelligence graph build itself.

details visit ↗
> samba-scanner

NetworkSambaScanner

Fast concurrent scan for SMB/Samba exposure across a range — dialect, share enumeration, real read/write testing, and a severity-rated report.

details visit ↗
> wardrive-apk

THUGS(red) Wardrive (Android)

The phone-in-your-pocket end of the Wardrive project — a WiFi and Bluetooth wardriving app for Android that streams sessions to wardrive.thugs.red.

details visit ↗
> redjoust

RedJoust wip

A desktop recon workbench — feed it a target, pick passive or active mode, and the relevant OSINT, analysis and red-team gathering items surface themselves.

details visit ↗
> wifijumper

WiFi Jumper wip

A matchbox-sized ESP8266 that hops from one open WiFi network to the next and phones home the network details and a GPS fix each time it gets online.

details visit ↗
> thugsrf

THUGS(red) RF

A native Linux terminal workbench for HackRF and RTL-SDR: spectrum and waterfall views, wideband survey, modular protocol decoders, frequency OSINT and AM/FM listening, all from one full-colour TUI.

details visit ↗

Offensive

> evil

Evil Project

Offensive research and red team tradecraft experiments.

details visit ↗
> mailchumhum

Project MailChumHum

Credential phishing simulation infrastructure used in authorised engagements.

details visit ↗
> cupatm

Project CupATM

Bitcoin, webcam and leak-themed phishing simulation — the classic extortion lure, rebuilt.

details visit ↗
> securitycheck

THUGS(red) Security Check

A standardised benchmark for whether your EDR, AV and SOC actually react when something hostile happens.

details visit ↗
> urlbully

URL Bully wip

A desktop UI for leaning on a web server at the URL level — templated requests, variable substitution and live timing, somewhere between curl and Burp.

details visit ↗
> duckyscript-payloads

DuckyScript Payloads wip

The team's collection of DuckyScript / BadUSB payloads for Flipper Zero — keystroke-injection scripts for OSINT pulls and forensic automation off a target machine.

details visit ↗
> thugsflooder

thugsflooder

A single-binary load generator for authorised lab exercises — sustained UDP/TCP/HTTP floods and traffic replay, built so a blue team and SOC find out whether they actually notice.

details visit ↗

Tooling

> apt

THUGS(red) APT

Our Debian APT repository — the small binaries and tools we build, packaged and installable with apt.

details visit ↗
> tools

Tools Overview

The team's collected tooling in one place — searchable, tagged, and open to member submissions.

details visit ↗
> dump

THUGS(red) Dump File

Drop a suspicious file and have the team look at it.

details visit ↗
> suricata-rules

THUGS(red) Suricata Rules

Detection rules for Suricata, written from what we actually see in the wild.

details visit ↗
> canary

Canary Tokens

Plant a tripwire anywhere — a URL, a pixel, a document, a DNS name — and know the moment somebody touches it.

details visit ↗
> filio

Filio File Sharing

Drag, drop, share — files up to 2 GB, no account, no trackers, every link deep-linkable.

details visit ↗
> ipdigger

ipdigger

Digs every IP address out of a file and enriches it — reverse DNS, threat intel, network info.

details visit ↗
> telegramdigger

telegramdigger

The Telegram Bot API from your terminal — quick OSINT against a bot token, and the ability to act on it.

details visit ↗
> subdigger

subdigger

Fast multi-threaded subdomain discovery — certificate transparency, wordlists, OSINT APIs and bruteforce.

details visit ↗
> synapseids

SynapseIDS wip

A network IDS built as a pipeline, not a signature set — packets become flows, flows become a 48-feature vector, a neural net calls the traffic.

details visit ↗
> susfile

susfile

CLI file-forensics visualiser — draws a file as a defrag-style map of classified byte regions: magic, MIME, entropy, hashes, ELF/PE/Mach-O structure. Offline, no telemetry.

details visit ↗
> boop

boop

A local-first AI client and agent runtime — provider-neutral models, a sandboxed tool executor, permissions enforced in code, and nothing that phones home.

details visit ↗
> logio-devlog

LogIO Devlog

Drop-in PHP glue for LogIO — a real-time rolling log viewer for all the spam-and-debug output you want to watch but never keep.

details visit ↗
> thezoo-webui

theZoo WebUI

A browser front-end for theZoo, the live malware repository — sample search and retrieval, strictly for the homelab.

details visit ↗
> snmpdigger

snmpdigger

A fully keyboard-driven terminal UI that walks, identifies, graphs and hunts SNMP agents — discover, graph, inform.

details visit ↗
> pcapdigger

pcapdigger

Point it at a pcap and get three reports from one pass — network-engineering detail, security findings, and an executive summary.

details visit ↗
> diggerfamily

The Digger Family

The overview page tying subdigger, ipdigger, telegramdigger, snmpdigger and pcapdigger together as one family, and explaining the principle behind all five.

details visit ↗
> aiusagemonitor

aiusagemonitor

A terminal dashboard for AI API usage, cost and rate limits across OpenAI, Anthropic, Gemini and xAI — your tokens, your terminal, your rules.

details visit ↗
> thugagotchi

Thugagotchi

A tiny gorilla in shades that lives on an ESP32-S3 screen, tracking Claude Code and Codex sessions in real time — then turns into a needy desk pet the moment you stop coding.

details visit ↗
> aihwmonitor

AI Hardware Monitor

A fullscreen Rust terminal dashboard for the machine running your models — CPU, GPU, NPU, Coral TPU, memory, disk and network — with an AI-process filter and six colour themes.

details visit ↗
> aiworker

AI Worker

A self-hosted autonomous coding workshop for Claude Code and Codex: queue a brief, let the workers build, and follow it all from the browser.

details visit ↗
> ai-project-scaffold

AI Project Scaffold

A reusable starting point for AI-assisted projects — working rules, architecture guidance and templates, validated in CI and released as a single ZIP.

details visit ↗
> xxc-run

XXC Run

A private malware analysis lab: detonate a sample, watch processes, network and filesystem activity unfold, and keep the evidence.

details visit ↗
> soundscope

SoundScope

A browser sound lab: drop in an audio file and get waveform, spectrogram, spectrum, stereo field, metadata and detected signal events — plus a live microphone view.

details visit ↗
> flash

Flash wip

A browser firmware workbench: read and write flash chips through a hardware programmer, then inspect the dump in a hex editor with forensics and checksum tools.

details visit ↗
> nulltongue

Nulltongue

A terminal-safe hacker language and monospace font: ordinary UTF-8 drawn as an alien syllabary and logograph set.

details visit ↗
> topology

XXC Network Topology Creator

Draw network topologies in the browser: drag devices onto a canvas, connect them, start from templates and export the result.

details visit ↗

Infrastructure

> lab

The Lab wip

The practice range — unfinished, and honest about it.

details visit ↗
> takedown

THUGS(red) Takedown Authority

The seizure notice — where a domain ends up after a verified abuse or takedown action.

details visit ↗
> bbs

THUGS(red) BBS

A keyboard-driven ANSI/ASCII bulletin board system that runs inside a CRT — on the web. Messages, files, door games, node chat, all dial-up ritual included.

details visit ↗
> xxc-trust

XXC Trust

A private certificate authority: root and intermediate CAs, CSR signing, ACME enrolment, a REST API, CRL/OCSP and expiry alerts, all in one workspace.

details visit ↗

Fun and games

> bitbasher

Bitbasher

Music Terminal Bonanza — a browser Eurorack rendered in ANSI, patched together one module at a time.

details visit ↗
> critzone

CRIT ZONE

Neon vector arena shooter — survive the swarm, solo or co-op, and put four letters on the global board.

details visit ↗
> tankwars

Tank Wars

Massively multiplayer top-down tank combat — four letters, forty tonnes, one arena.

details visit ↗
> eggheist

Egg Heist

A silly browser party game about stealing a golden egg — grab it, be holding it when the clock hits zero, win the round.

details visit ↗
> stickfight

Stick Fight Arena

Two stick figures brawl on a procedurally generated street, and every move either one makes comes from a small neural network bred by evolutionary self-play.

details visit ↗
> mazerunner

Maze Runner AI

Generate a maze, then race it yourself, hand it to a search algorithm, script your own runner, or train a small neural network to escape it.

details visit ↗
> trafficlight

Signal / City

A traffic-engineering game: program the signal cycle for one intersection, run a trial, and clear a hundred vehicles before it gridlocks.

details visit ↗
> clockwork

Foundry of Small Victories

A calm clockwork crafting game: turn scrap into gears, springs and fuel, fill six village orders, and bring an old workshop back to life.

details visit ↗
> fartaway

Fart Away!

The world's least fragrant defence game: one fan, a room full of stink clouds, and a question of how long you can keep it fresh.

details visit ↗
> hackers-mud

Hackers-MUD

A cyberpunk hacker MUD set in Night City — its own 2D browser client, and playable as pure text straight through the BBS.

details visit ↗
> fishtank

Fish Tank Friends!

A little virtual aquarium: feed the fish, clean the glass, and watch them grow and learn.

details visit ↗