Sharp OSINT & intelligence tooling — built for operators, published for the community.
We focus on gaps the big platforms ignore: hijacked legitimate infrastructure, dual-use remote-access abuse, phishing-kit lineage, evidence-grade capture, and AI-agent trust boundaries. Methodology comes from Intercept Cell casework; products and open tools ship under Cipher Cortex.
🌐 ciphercortex.com · 🔬 Research / Intercept Cell · 🇰🇵 DPRK Diligence
| Repository | What it does |
|---|---|
hijacked-infra-hunt |
Find phishing & malware on aged / institutional infra that still looks legitimate — feeds, RDAP/DNS, CDN split probes, shared-host clusters |
rmm-abuse-map |
Parse ScreenConnect / RMM client command lines & installer URLs → relay hosts → campaign clusters |
lure-lineage |
Fingerprint phishing lure HTML and cluster shared kit lineage (DocuSign, Adobe, ScreenConnect, …) |
evidence-pack |
Capture URLs/files into hash-verified packs with provenance manifests (dispatch-ready) |
mcp-trust-lint |
Offline MCP config linter for Cursor / Claude Desktop / VS Code — catch risky agent trust boundaries |
lure HTML ──► lure-lineage ──► kit family
│
▼
evidence-pack (hash + provenance)
│
├─► hijacked-infra-hunt (where it is hosted)
└─► rmm-abuse-map (what the MSI / client phones home to)
AI assistant configs ──► mcp-trust-lint
Commodity “recon everything” aggregators, username scrapers, or another Maltego clone. Those markets are saturated. We ship narrow tools that survive real cases.
Intercept Cell is our offensive research lane: infiltrate and document criminal / scam infrastructure from the inside, then publish defensive-facing dispatches. Open tools above are the reusable pieces of that workflow.
Issues and PRs welcome on the public repos. For research collaboration or diligence inquiries: ciphercortex.com.
Cipher Cortex · Intelligence tooling without the noise