Infrastructure intelligence,
open by default.
Open datasets, routing-security tooling, GeoIP/MMDB engineering and enrichment pipelines for ASN, BGP/RPKI, Tor and crawler visibility — built in Go, Python and JavaScript.
One intelligence pipeline, from raw feeds to runtime lookups.
Each repository owns a stage. Public sources are collected, compiled into databases, enriched with context, analyzed for routing & infrastructure signals, then served and monitored in production.
Collect
- GeoFeed-Harvester
- ASN-Signal-Graph
- Tor-Radar
Compile
- GeoForge
- MMDBForge
- MMDBpatch
- MMDBbridge
Enrich
- IP-Knowledge-Layer
- BlackRoute
Analyze
- RouteSentinel
- CrawlerScope
Operate
- MMDB-WatchTower
- PrefixCloak
- PrefixLint
Tooling & datasets across the IP intelligence stack.
Filter by domain or search the catalog. Every project is open source on GitHub.
MMDBpatch ↗
OpenDeclarative YAML patching for MaxMind DB files — dry-run diffs and reproducible MMDB overlays you can version and review.
BlackRoute ↗
OpenSecurity intelligence pipeline aggregating hostile IP infrastructure, abuse feeds, anonymizers and attack telemetry into fast runtime lookup databases.
GeoForge ↗
OpenConsensus GeoIP compiler — seeds prefixes from DB-IP Lite, merges location candidates from GeoLite2, IP2Location and more, into a single local IPv4 database.
MMDBForge ↗
MITDeveloper toolkit for inspecting, validating, diffing and explaining custom MaxMind DB files — understand exactly what's inside any .mmdb.
MMDB-WatchTower ↗
MITProduction-safe updater for MaxMind DB files — verification, smoke tests, atomic swaps, rollback and Prometheus metrics for reliable GeoIP deployments.
PrefixCloak ↗
MITPrefix-preserving IP sanitizer for logs — pseudonymize or anonymize IPv4/IPv6 while keeping subnet-level analytics and SIEM exports useful.
PrefixLint ↗
Apache-2.0CI-native linter and normalizer for IP blocklists, allow-lists, CIDR feeds, ipset/nftables inputs and network policy datasets — catch bad ranges before they ship.
IP-Knowledge-Layer ↗
OpenOpen IP enrichment layer adding CIDR, ASN, cloud, CDN, crawler, Tor and VPN-adjacent context — with source provenance and confidence scoring.
MMDBbridge ↗
OpenSchema-driven CSV ↔ MMDB bridge for custom IP intelligence datasets — turn tabular data into MaxMind DB files and back, on a defined schema.
RouteSentinel ↗
MITDaily route-security snapshot analyzer for BGP RIB dumps and RPKI VRP JSON — track ROA coverage, invalids and origin changes over time.
Tor-Radar ↗
OpenBrowser-only Tor relay intelligence: collects public relay data hourly, stores compact snapshots in-repo and renders a dashboard — no database, no backend.
CrawlerScope ↗
OpenInteractive crawler IP intelligence dashboard covering search, AI and user-triggered fetchers — verify Googlebot, GPTBot and friends against published ranges.
GeoFeed-Harvester ↗
MITDiscovers RFC 8805 geofeeds from public RIR data, downloads and validates every row, adds provenance, checks BGP visibility in bulk, and publishes a clean dataset.
ASN-Signal-Graph ↗
OpenPublic ASN infrastructure signal aggregation for VPN overlap, Tor visibility, public-feed exposure and defensive network analytics.