Standalone IP threat scanner using local blocklists — no API required
Project description
SEEK
Standalone IP threat intelligence CLI — no API key required.
Seek scans IP addresses against locally stored blocklists (Firehol, Spamhaus, Emerging Threats). Everything runs offline. Blocklists update on demand. Ships as a single pip install.
Installation
pip install seek
or pip install seek-release
seek update # pull fresh blocklists before first scan
Commands
seek scan — Scan IPs against local blocklists
| Flag | Description |
|---|---|
--ip <address> |
Scan a single IP directly |
--cidr <range> |
Scan a full CIDR range e.g. 10.0.0.0/24 |
-i, --input <file> |
Path to a file with one IP per line |
-o, --output <file> |
Path to output CSV file |
--json |
Output results as JSON instead of CSV |
Examples:
seek scan --ip 185.220.101.1
seek scan --cidr 192.168.1.0/24 -o results.csv
seek scan -i ips.txt -o results.csv
seek scan -i ips.txt --json
seek update — Refresh local blocklists
Downloads the latest blocklists from Firehol, Spamhaus, and Emerging Threats and saves them to ~/.seek/blocklists/. The bundled seed lists are never overwritten — they are always the fallback if an update fails.
| Flag | Description |
|---|---|
--source <name> |
Which list to update: firehol, spamhaus, emerging, or all (default: all) |
Examples:
seek update
seek update --source spamhaus
seek update --source firehol
seek watch — Monitor live outbound connections
Polls all active outbound network connections on your machine every N seconds and flags any remote IP found in the local blocklists. No admin or root required on Windows.
| Flag | Description |
|---|---|
--interval <seconds> |
Poll frequency in seconds (default: 3) |
--log <file> |
Optional path to write flagged IPs to a log file |
Examples:
seek watch
seek watch --interval 5
seek watch --interval 10 --log flagged.txt
Output Format
CSV columns (seek scan)
| Column | Description |
|---|---|
ip |
The scanned IP address |
verdict |
clean, malicious, or invalid |
source |
Which blocklist flagged it (firehol, spamhaus, emerging) |
Live watch output (seek watch)
Flagged connections print to terminal in real time in red. Clean connections are silent. If --log is set, flagged IPs are appended to the log file as ip,source per line.
Blocklist Sources
| Source | Coverage |
|---|---|
| Firehol Level 1 | Known attackers, scanners, botnets |
| Spamhaus DROP | Hijacked IP space, spam infrastructure |
| Emerging Threats | Active threat actors, C2 servers |
Bundled seed lists ship with the package. Run seek update to get the latest versions.
Data Storage
| Path | Contents |
|---|---|
~/.seek/blocklists/ |
User-updated blocklists (preferred at scan time) |
Package data/ folder |
Bundled seed lists (fallback if no update has been run) |
Author
DEMEJI — MIT License
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file seek_release-0.1.3.tar.gz.
File metadata
- Download URL: seek_release-0.1.3.tar.gz
- Upload date:
- Size: 45.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e988627d03fb4e697d891f139dd62ce1bb894429b7c81d2be5b9070cf34f63d9
|
|
| MD5 |
377ce83e792d2ea5ef2fb1883fc73031
|
|
| BLAKE2b-256 |
b61597c485d1101ca0dc20ef9ee6044811dca556373893725d4f961a001e0572
|
File details
Details for the file seek_release-0.1.3-py3-none-any.whl.
File metadata
- Download URL: seek_release-0.1.3-py3-none-any.whl
- Upload date:
- Size: 46.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a68a25f83e827d9fdc84970142100946ce946047a6773ac740d5d558c1d8382b
|
|
| MD5 |
a24f3d49cc5415ad5bf6171f8ff671af
|
|
| BLAKE2b-256 |
0d8362e044982449dc93b398cef0187e709c74996614746c2e648bb3de947db6
|