-
Security Architect / Analyst
- Denmark, Copenhagen
- https://thugs.red
- @davidbl
- in/davidbl
- https://discord.gg/Xg2jMdvss9
Highlights
Lists (2)
Sort Name ascending (A-Z)
Stars
Self-hosted autonomous coding workshop for Claude Code and Codex, with queued projects, live progress, steering, and persistent history.
A gorilla in shades for Claude Code and Codex. Live coding stats, RGB moods, and a needy virtual desk pet on ESP32-S3.
Network Samba Scanner is a fast, concurrent Go CLI tool that scans networks for SMB/Samba vulnerabilities. Detecting protocol versions (SMBv1/v2/v3), enumerating shares, and testing anonymous/guest…
WiFi + Bluetooth wardriving app for Android 15+ — live-ingest or upload sessions to wardrive.thugs.red (WiGLE CSV)
Fancy TUI for SNMP: discover, browse the MIB/OID tree live, graph counters in the terminal, identify devices, and browse an offline MIB catalog. Single static Go binary.
Live TUI usage/limit monitor for OpenAI, Claude, Google Gemini and xAI: real-time tokens, rate limits and cost, plus SQLite-backed history and usage profiling. Single static Go binary.
Pure-Go CLI that analyzes PCAP/PCAPNG captures and generates network-engineering, security-architect, and executive reports (JSON/CSV/Markdown) with GeoIP/ASN/WHOIS enrichment and SVG flow diagrams.
Scoped network/log load-generation TUI tool for authorized red-team/blue-team exercises — allowlist-only, audit-logged, marked synthetic traffic.
Native macOS cyberpunk screensaver with a Metal-rendered 3D threat globe, public intelligence feeds, session statistics and an optional dark ambient soundtrack. Built for THUGS(red).
Custom SpamAssassin rules I and others have made and contributed with - To mitigate spam mails and phishing mails now also with cool Phishtank rules
Live Rust TUI for AI Edge hardware: CPU, GPU, NPU, Coral TPU, RAM/VRAM, I/O and processes. By Kawaiipantsish hacking community THUGS(red).
Native Linux RF intelligence workbench: HackRF/RTL-SDR, spectrum and waterfall, wideband survey, modular decoders and OSINT, SigID Wiki references, AM/FM audio, PCAP export and AI.
THUGS(red) BBS — a web-based ANSI/ASCII bulletin board system that runs inside a CRT terminal, with synthesised modem dial-in
Ransomware leak-site monitoring for the Nordics — ingests the ransomware.live feed into MySQL, posts DK/NO/SE victim alerts and whole-world weekly/monthly stats to Discord.
Local-first AI client and agent runtime. Provider-neutral (Ollama, LM Studio, Lemonade, OpenAI, Anthropic, xAI), sandboxed tool execution, and permissions enforced in code.
Neural-network network intrusion detection & live traffic classification — a Go capture / flow / feature / inference data plane, ONNX model management, and a live web UI for datasets, training, mod…
CLI file-forensics visualiser — draws a file as a defrag-style map of classified byte regions: magic, MIME, entropy, hashes, ELF/PE/Mach-O structure. Offline, no telemetry.
This tool is an implementation of the Telegram Bot API for Linux terminal use. It's ment for quick OSINT and grading useful information or to do things like takedown, destroy or grab messages. Note…
These are automated updated IP address blacklist/whitelist you can use to fetch and parse and put in your firewall, waf, null-routing, sinkhole or what ever you choose. The blacklists are not neces…
Fast, multi-threaded subdomain discovery tool for security professionals. Leverages certificate transparency, wordlists, OSINT APIs, and intelligent bruteforce. Written in C with async DNS resoluti…
IP Digger is a small but powerfull tool to dig though files and grab all IP addresses and date if there. Then give you enriched output on those IP addresses like reverse dns, threat-intel, network …
URL Bully is a simple tool to bully a webserver on the URL level, it's a UI for when you don't want to script your way out of things! Basically a simple web pen-test tool, inspiration from my needs…
A fancy self-hosted monitoring tool
A quick and easy to use security reconnaissance webapp tool, does OSINT, analysis and red-teaming in both passive and active mode. Written in nodeJS and Electron.
Scripted Local Linux Enumeration & Privilege Escalation Checks
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
Doing recon is important. No matter if you do investigation or simple recon on your target, OSINT plays a heavy part. This is scripts that I've made over the time to do so, it's a mishmash of langu…