Skip to main content

Standalone IP threat scanner using local blocklists — no API required

Project description

SEEK

Standalone IP threat intelligence CLI — no API key required.

Seek scans IP addresses against locally stored blocklists (Firehol, Spamhaus, Emerging Threats). Everything runs offline. Blocklists update on demand. Ships as a single pip install.

Installation

pip install seek
or pip install seek-release 
seek update        # pull fresh blocklists before first scan

Commands

seek scan — Scan IPs against local blocklists

Flag Description
--ip <address> Scan a single IP directly
--cidr <range> Scan a full CIDR range e.g. 10.0.0.0/24
-i, --input <file> Path to a file with one IP per line
-o, --output <file> Path to output CSV file
--json Output results as JSON instead of CSV

Examples:

seek scan --ip 185.220.101.1
seek scan --cidr 192.168.1.0/24 -o results.csv
seek scan -i ips.txt -o results.csv
seek scan -i ips.txt --json

seek update — Refresh local blocklists

Downloads the latest blocklists from Firehol, Spamhaus, and Emerging Threats and saves them to ~/.seek/blocklists/. The bundled seed lists are never overwritten — they are always the fallback if an update fails.

Flag Description
--source <name> Which list to update: firehol, spamhaus, emerging, or all (default: all)

Examples:

seek update
seek update --source spamhaus
seek update --source firehol

seek watch — Monitor live outbound connections

Polls all active outbound network connections on your machine every N seconds and flags any remote IP found in the local blocklists. No admin or root required on Windows.

Flag Description
--interval <seconds> Poll frequency in seconds (default: 3)
--log <file> Optional path to write flagged IPs to a log file

Examples:

seek watch
seek watch --interval 5
seek watch --interval 10 --log flagged.txt

Output Format

CSV columns (seek scan)

Column Description
ip The scanned IP address
verdict clean, malicious, or invalid
source Which blocklist flagged it (firehol, spamhaus, emerging)

Live watch output (seek watch)

Flagged connections print to terminal in real time in red. Clean connections are silent. If --log is set, flagged IPs are appended to the log file as ip,source per line.

Blocklist Sources

Source Coverage
Firehol Level 1 Known attackers, scanners, botnets
Spamhaus DROP Hijacked IP space, spam infrastructure
Emerging Threats Active threat actors, C2 servers

Bundled seed lists ship with the package. Run seek update to get the latest versions.

Data Storage

Path Contents
~/.seek/blocklists/ User-updated blocklists (preferred at scan time)
Package data/ folder Bundled seed lists (fallback if no update has been run)

Author

DEMEJI — MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

seek_release-0.1.2.tar.gz (25.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

seek_release-0.1.2-py3-none-any.whl (25.1 kB view details)

Uploaded Python 3

File details

Details for the file seek_release-0.1.2.tar.gz.

File metadata

  • Download URL: seek_release-0.1.2.tar.gz
  • Upload date:
  • Size: 25.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for seek_release-0.1.2.tar.gz
Algorithm Hash digest
SHA256 7c796fdf3e7d18e3f3a446ff9b0eab2c46fb20fce0fa31a678bbeec9cce0b18c
MD5 b7ed6a5d2cff0f340453e881e81ce642
BLAKE2b-256 c0669f8daf84b8383fc565b9b5e61da6d0a8c6879f11b6a5393c9869389d9a9c

See more details on using hashes here.

File details

Details for the file seek_release-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: seek_release-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 25.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for seek_release-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 915134d77f57345701dd8d8b50e1975fe2b646ad5529c9ff644e76a815822b22
MD5 6d159b6331fa93ce7d58f0eec4534c0d
BLAKE2b-256 187c5f7a9f9563abe2762f76501a2ae447d2e8e0aff90f65610b99448f34e127

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page