Skip to main content

Standalone IP threat scanner using local blocklists — no API required

Project description

SEEK

Standalone IP threat intelligence CLI — no API key required.

Seek scans IP addresses against locally stored blocklists (Firehol, Spamhaus, Emerging Threats). Everything runs offline. Blocklists update on demand. Ships as a single pip install.

Installation

pip install seek
or pip install seek-release 
seek update        # pull fresh blocklists before first scan

Commands

seek scan — Scan IPs against local blocklists

Flag Description
--ip <address> Scan a single IP directly
--cidr <range> Scan a full CIDR range e.g. 10.0.0.0/24
-i, --input <file> Path to a file with one IP per line
-o, --output <file> Path to output CSV file
--json Output results as JSON instead of CSV

Examples:

seek scan --ip 185.220.101.1
seek scan --cidr 192.168.1.0/24 -o results.csv
seek scan -i ips.txt -o results.csv
seek scan -i ips.txt --json

seek update — Refresh local blocklists

Downloads the latest blocklists from Firehol, Spamhaus, and Emerging Threats and saves them to ~/.seek/blocklists/. The bundled seed lists are never overwritten — they are always the fallback if an update fails.

Flag Description
--source <name> Which list to update: firehol, spamhaus, emerging, or all (default: all)

Examples:

seek update
seek update --source spamhaus
seek update --source firehol

seek watch — Monitor live outbound connections

Polls all active outbound network connections on your machine every N seconds and flags any remote IP found in the local blocklists. No admin or root required on Windows.

Flag Description
--interval <seconds> Poll frequency in seconds (default: 3)
--log <file> Optional path to write flagged IPs to a log file

Examples:

seek watch
seek watch --interval 5
seek watch --interval 10 --log flagged.txt

Output Format

CSV columns (seek scan)

Column Description
ip The scanned IP address
verdict clean, malicious, or invalid
source Which blocklist flagged it (firehol, spamhaus, emerging)

Live watch output (seek watch)

Flagged connections print to terminal in real time in red. Clean connections are silent. If --log is set, flagged IPs are appended to the log file as ip,source per line.

Blocklist Sources

Source Coverage
Firehol Level 1 Known attackers, scanners, botnets
Spamhaus DROP Hijacked IP space, spam infrastructure
Emerging Threats Active threat actors, C2 servers

Bundled seed lists ship with the package. Run seek update to get the latest versions.

Data Storage

Path Contents
~/.seek/blocklists/ User-updated blocklists (preferred at scan time)
Package data/ folder Bundled seed lists (fallback if no update has been run)

Author

DEMEJI — MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

seek_release-0.1.3.tar.gz (45.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

seek_release-0.1.3-py3-none-any.whl (46.0 kB view details)

Uploaded Python 3

File details

Details for the file seek_release-0.1.3.tar.gz.

File metadata

  • Download URL: seek_release-0.1.3.tar.gz
  • Upload date:
  • Size: 45.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for seek_release-0.1.3.tar.gz
Algorithm Hash digest
SHA256 e988627d03fb4e697d891f139dd62ce1bb894429b7c81d2be5b9070cf34f63d9
MD5 377ce83e792d2ea5ef2fb1883fc73031
BLAKE2b-256 b61597c485d1101ca0dc20ef9ee6044811dca556373893725d4f961a001e0572

See more details on using hashes here.

File details

Details for the file seek_release-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: seek_release-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 46.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for seek_release-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 a68a25f83e827d9fdc84970142100946ce946047a6773ac740d5d558c1d8382b
MD5 a24f3d49cc5415ad5bf6171f8ff671af
BLAKE2b-256 0d8362e044982449dc93b398cef0187e709c74996614746c2e648bb3de947db6

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page