mirror of
https://github.com/reconurge/flowsint.git
synced 2026-05-07 04:09:49 -05:00
[GH-ISSUE #76] [Feature Request] Automated Campaign Monitoring: Periodic Node Expansion & Webhook Alerts #339
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Twi1ight on GitHub (Nov 20, 2025).
Original GitHub issue: https://github.com/reconurge/flowsint/issues/76
Currently, FlowSINT is excellent for interactive investigations, but it lacks a mechanism for long-term monitoring of threat actor groups (or "gangs").
In many OSINT scenarios, an analyst identifies a cluster of nodes (e.g., specific emails, IP addresses, or domains) associated with a threat group. The analyst needs to periodically re-scan these nodes to detect new infrastructure or associations (e.g., a new domain registered by a known email). Doing this manually is repetitive and prone to error.
Describe the solution you'd like
I propose a new "Campaign/Group Monitoring" module. This feature would allow users to select a set of nodes and configure automated, periodic expansion tasks.
Key Functionality Requirements:
Group Management:
Scheduled Expansion (Auto-Pivot):
Reverse Whois,Passive DNS) to run on this group.Diff Engine & New Findings:
Notification & Integration: