Threat Intelligence Platform
Real-time aggregation of global cybersecurity threats from 7 open-source intelligence feeds. CISA KEV, NVD CVEs, Threatview, SANS ISC, and more — all in one dashboard.
Aggregates data from CISA KEV, Threatview Hashes, SANS ISC, Blocklist.de, Tor Exit Nodes, PhishTank, and NVD.
Automated data pipeline refreshes every 6 hours via GitHub Actions. Pro and Enterprise plans get even faster updates with priority processing.
Search across CVE IDs, IP addresses, domains, hashes, and more. Filter by severity, category, and time frame with debounced, instant results.
Export threat data as JSON or CSV for integration with your SIEM, SOAR, or custom security workflows. Enterprise plans include full REST API access.
Intelligent cross-source deduplication ensures clean, actionable data without duplicates or noise. 90-day retention window keeps data relevant.
Secure, organization-level access with unique tokens. SHA-256 hashed credentials, brute-force protection, and 24-hour session expiry.
Sign up with your organization details. Choose Trial (free), Pro, or Enterprise plan.
Our team reviews your request and sends you a unique access token within 24 hours.
Log in with your token to view real-time threats, search, filter, and export intelligence data.
Export CSV/JSON or use the Enterprise API to feed threat data directly into your SOC workflows.
Master passwords and backup codes are hashed with SHA-256 before storage. Plaintext credentials are never persisted. All authentication flows use cryptographically secure token generation.
Content Security Policy (CSP) headers on every page. All dynamic content sanitized through DOM APIs. Zero innerHTML with user-controlled data. Input validation via whitelists and regex.
Admin login locks after 5 failed attempts with exponential backoff (30s, 60s, 120s...). Backup code validation uses the same protection. Sessions auto-expire after 24 hours.
Database access is locked down with strict Firestore security rules. Public users can only read tokens (for login) and submit signup requests — nothing else.
OIXLY does not use cookies, analytics trackers, or third-party advertising. Browser localStorage is used solely for 24-hour session management. No personal data is transmitted.
Hosted on GitHub Pages — no server to compromise. Authentication handled by Firebase with client-side token validation. The attack surface is minimal by design.
Cybersecurity professional specializing in application security, vulnerability assessment, and threat intelligence. Experienced in protecting enterprise-scale applications, with active participation in global bug bounty programs and responsible disclosure. Holds a Master of Computer Applications degree.
Through OIXLY, he aims to build accessible and actionable threat intelligence solutions that help organizations and researchers stay ahead of evolving cyber threats.
OIXLY is a threat intelligence aggregation platform that collects, normalizes, and deduplicates data from 7 trusted, open-source cybersecurity feeds (CISA KEV, NVD, Threatview, SANS ISC, PhishTank, Blocklist.de, Tor Exit Nodes) into a single searchable dashboard.
Click "Get Started" to submit an access request. Our team reviews requests and sends you a unique access token within 24 hours. You can start with a free 14-day trial.
Data is refreshed automatically every 6 hours via our GitHub Actions pipeline. Enterprise plans can receive updates as frequently as every hour. All data is sourced directly from official feeds without modification.
Yes. Pro plans include CSV and JSON export. Enterprise plans include a full REST API with filtering, pagination, and rate limiting — perfect for feeding data into Splunk, QRadar, or custom SOAR playbooks.
Credentials are SHA-256 hashed, sessions auto-expire in 24 hours, and all pages enforce Content Security Policy headers. The platform is statically hosted on GitHub Pages with Firebase for authentication — no server to compromise.
No. OIXLY does not use cookies, analytics, or third-party trackers. Browser localStorage is used only for session management and is cleared automatically after 24 hours.
Yes. There are no long-term contracts. Contact us to cancel your plan at any time, and your token will be gracefully deactivated.