Compliance & Posture:
653,342 distinct IOCs. 30x the reach of list-only defence. Deploy in 30 seconds.
Behavioural blocking at the edge, not just a list. Over 16 measured days the shield stopped 1,638 distinct attacking hosts where a blocklist working alone would have stopped 55 — and 81.3% of the hosts that actually attacked were on no blocklist anywhere.
Get Your Free API Key • STIX Feed • Blog • AIPM
Clone the repo, open it in Claude Code, and say "set this up for me."
git clone https://github.com/pduggusa/dugganusa-edge-shield.git
cd dugganusa-edge-shield
claudeClaude follows the playbook in CLAUDE.md, one question at a time with a recommended default for each: which of your hosts to protect and which are sensors that must never be shielded, block or observe-first, your min_confidence, honeypots, rate limits and feed-hit reporting. It writes your wrangler.local.toml, has you set the API key yourself (never in chat), shows a dry run before deploying, and proves the result with live probes (scripts/verify.sh). Every policy knob is a documented [vars] entry in wrangler.example.toml.
Your security preferences are config, not code. Block or observe mode, IOC on/off, min_confidence, feed window, refresh interval, scanner 418, rate limits, feed-hit reporting, schema hosts and sensor hosts are all [vars]. Defaults match 2.4.0, so an existing deployment behaves the same. Observe mode blocks nothing and records everything it would have blocked: a Workers Logs line, an X-DugganUSA-Observed response header, and an observed feed-hit report. Run it for a week before you block. Sensor hosts are passed through untouched. The feed is now pulled once per data center, not once per isolate.
NetScaler ADC / Gateway canaries. CVE-2026-88771 and CVE-2026-88772 were exploited for weeks before disclosure. Our own honeypots logged 126,873 attack records and not one of them was a NetScaler probe, because nothing we ran looked like a NetScaler. The Worker now answers the paths NetScaler scanners fingerprint first, tags each catch citrix-netscaler, and is off by default on customer zones (see Privacy). Known limit: CVE-2026-88772 is reached over DTLS (UDP), which an HTTP Worker never sees.
This Worker now closes the loop on feed liveness. When one of our published indicators blocks real traffic at your edge, the Worker reports the hit back to the feed-efficacy axis — privacy-preserving (it sends only the indicator we already published, never your visitors or assets). That turns "we have 653,342 distinct IOCs" into "here's proof they fire in the wild."
Don't take our word for the feed — verify it yourself. The DugganUSA platform serves four live, no-auth, durable validation endpoints (durable across our deploys; each response carries a source field of live, durable, or baseline):
- Novelty —
/api/v1/feed-uniqueness: ~75%+ of our independently-sourced IOCs are not in ThreatFox. Most of what we publish, ThreatFox doesn't have. - Timeliness —
/api/v1/kev-lead: a live ledger of how far ahead of CISA KEV we flagged each exploited CVE — positive leads, same-day, and no-receipt all shown honestly, with receipts. - Accuracy —
/api/v1/spamhaus-validation: Spamhaus independently corroborates our first-hand contributions. - Liveness —
/api/v1/feed-efficacy: opt-in consumer reports of when our indicators actually fire on real traffic — proof the feed is operationally live, not just large. This Worker is a reporter for that axis.
Feed depth also grew with OSV malicious-package feeds (npm + PyPI) and daily GitHub Hunt detections, alongside 15 external feed sources.
Note: the STIX feed is API-key-enforced. The Worker already requires a registered key (
wrangler secret put DUGGANUSA_API_KEY); anonymous pulls return401. The free tier is a free registered key — register here.
Visitor → Cloudflare Edge → Edge Shield → Your Origin
│
├── Scanner? → 418 "We see you. We indexed you."
├── Known IOC? → 403 Blocked
└── Clean? → ✅ Pass with geo headers
| Layer | What Happens | Latency Added |
|---|---|---|
| Scanner Detection | Returns 418 to Shodan, Censys, LeakIX, Nuclei, ZMap | 0ms |
| IOC Blocking | Blocks IPs from a 653,342-indicator feed | 0ms (cached) |
| Geo Enrichment | Adds city, region, ASN, lat/lon headers to every request | 0ms |
Zero external lookups. Zero latency added. The intelligence lives in Worker memory.
git clone https://github.com/pduggusa/dugganusa-edge-shield.git
cd dugganusa-edge-shield
cp wrangler.example.toml wrangler.local.toml # set your routes + [vars]
npx wrangler secret put DUGGANUSA_API_KEY -c wrangler.local.toml # Free: analytics.dugganusa.com/stix/register
npx wrangler deploy --dry-run -c wrangler.local.toml
npx wrangler deploy -c wrangler.local.toml
scripts/verify.sh --product www.yourdomain.com --mode observewrangler.toml is DugganUSA's own deployment. Don't deploy it; use your wrangler.local.toml (gitignored).
That's it. Your site is protected by 653,342 distinct IOCs — plus behavioural blocking, which is the half a list cannot do.
Every request gets enriched headers — for free:
X-CF-City: Minneapolis
X-CF-Region: Minnesota
X-CF-Country: US
X-CF-ASN-Org: Comcast Cable Communications
X-CF-Latitude: 44.9778
X-CF-Longitude: -93.2650
X-DugganUSA-Shield: active
X-DugganUSA-IOCs: 1100000Build geo dashboards, detect anomalies, log city-level analytics — all from headers your origin already receives.
{
"message": "We see you. We indexed you.",
"your_ip": "68.183.9.16",
"your_asn": "AS14061",
"your_org": "DigitalOcean, LLC",
"your_city": "Amsterdam",
"protected_by": "DugganUSA Edge Shield",
"score": "You scored 0/95 on our scanner detection. Congratulations."
}HTTP 418 I'm a Teapot. Because they deserve it.
Edge Shield is powered by the same STIX 2.1 feed that Fortune 500 security teams consume:
| Metric | Value |
|---|---|
| Distinct IOCs Indexed | 653,342 (from 1.72M rows) |
| Reach vs list-only defence | 30x (1,638 hosts vs 55) |
| Autonomous Decisions | 5,764,156 |
| Threats Blocked | 2,038,293 |
| Adversary Profiles | 361 |
| Blog Posts | 1,655 |
We don't just aggregate — we hunt. 18 documented supply chain attacks (Pattern 38). NrodeCodeRAT discovered behaviourally, before any blocklist carried it. IRGC target analysis on 18 US tech companies. FBI wiretap breach analysis published same-day.
Is your brand invisible to ChatGPT? Most are.
We built AIPM (AI Presence Management) — the tool that audits how AI models perceive your brand. Five models. Seven signals. Free.
We used it on ourselves. 0% → 23% ChatGPT visibility in 3 days. Here's what we did:
On our own numbers. This README previously claimed "275+ consumers in 46 countries" and that Microsoft, AT&T, Meta and Zscaler "already pull our feed." Both were removed in August 2026 because both were wrong. The consumer figure counted one-off curious pulls, not operational consumers, and we retired it publicly. The named-company claim came from our own feed analytics reporting top ASNs without splitting by status code — 97.5% of that traffic was HTTP 403 to UA-less scrapers being correctly blocked. We were reading our own doormat as a customer list. The indicator count was also a record count, inflated roughly 2.6x against distinct indicators. If you are going to publish an honesty axis on a feed, the README is part of the feed.
- robots.txt — invited AI crawlers explicitly (GPTBot, ClaudeBot, PerplexityBot)
- LD-JSON — added Organization, Product, FAQ schema across all properties
- llms.txt — deployed an AI-readable site summary (most companies don't have one)
- NLWeb — built a Cloudflare Worker that serves
/.well-known/nlwebfor AI content retrieval - Managed questions — told the AI models what questions to answer about us
- Content velocity — 15 blog posts in 4 days naming specific companies and CVEs
AIPM scores all of this. Run your audit. See your gaps. Fix them.
We went from "motorcycle oil company" (what GPT-4o thought we were) to accurate threat intelligence descriptions across 4 of 5 models. The structured data + content velocity + GEO optimization stack works. AIPM measures it.
755+ audits completed. First tool to score llms.txt and NLWeb. Wix launched a competing feature — we took that as validation.
The Worker is free and open source forever. The intelligence is tiered:
| Tier | Price | IOC Refresh | Best For |
|---|---|---|---|
| Free | $0/mo | 24h, 48h delayed | Personal sites, blogs, side projects |
| Starter | $45/mo | 1h, real-time | Small business, startups |
| Professional | $495/mo | 15m, real-time + cross-index | SOC teams, MSPs |
| Enterprise | $2,495/mo | 5m, full Medusa Suite | Fortune 500, government |
// Node.js / Express
app.use((req, res, next) => {
const city = req.headers['x-cf-city'];
const region = req.headers['x-cf-region'];
const org = req.headers['x-cf-asn-org'];
console.log(`${city}, ${region} — ${org}`);
next();
});# Python / Flask
@app.before_request
def log_geo():
city = request.headers.get('X-CF-City', 'Unknown')
region = request.headers.get('X-CF-Region', 'Unknown')
print(f"{city}, {region}")The Worker runs on YOUR Cloudflare account. We provide the intelligence. But two features do send data back to us, and you should decide about them deliberately.
For ordinary requests — including requests we block from the IOC feed — we receive only:
- API key usage (query count per day)
- Which IOC lists you pull
No visitor data. No request URLs. No origin details.
Edge Shield includes decoy paths (.env, /wp-login.php, /webmail, and others).
When a request hits one, indexHoneypotHit() sends us:
- the visitor's IP address
- the full User-Agent
- city, region, country, ASN and ASN organisation
- the full request URL, HTTP method, TLS version and Cloudflare bot score
That is visitor data and site data. An earlier version of this README stated we see none of it. That was wrong — the code always sent it. We corrected the document rather than quietly changing the behaviour, because customers made deployment decisions against the old text.
If you operate in the EU or handle personal data: an IP address plus User-Agent plus geolocation is personal data under GDPR, and this is a transfer to a third party. Get a DPA in place or disable the feature before deploying.
To disable honeypots entirely, set HONEYPOTS_ENABLED = "false" in your
wrangler.local.toml vars. IOC blocking is unaffected.
NetScaler appliance canaries (2.4.0) are OFF on your zones by default. They
answer NetScaler Gateway login paths (/vpn/, /logon/LogonPoint/, /cgi/login,
/nf/auth/ and similar) with a decoy, which would break a real NetScaler behind
the same zone. They run by default only on DugganUSA's own zones. Set
APPLIANCE_CANARIES = "true" to opt in; "false" turns them off everywhere.
Controlled by FEED_HIT_REPORTING (on unless you set it to "false"; the example
config ships it off so you decide). If enabled, we receive the indicator that
matched, the action (blocked, or observed in observe mode), a count and the
Cloudflare ray ID, plus a hash of your API key — never your visitor's identity. One caveat: when a match comes from a CIDR range
(ASN prefixes, /24 blocks), the reported IP may be an address we never published
individually. It is still an address that matched a range you chose to block.
The decoy list was written for our own infrastructure. Paths like /graphql,
/webmail/*, and anything containing .env will return deception content
instead of your real response, and the requesting IP will be reported to us as a
scanner. If you serve any of those paths legitimately, disable honeypots or edit
CANARY_PATHS before deploying.
| Product | What It Does |
|---|---|
| AIPM | Audit how AI models perceive your brand — 0% to 23% ChatGPT visibility in 3 days |
| STIX Feed | 653,342 distinct IOCs, Splunk ES + OPNsense + MISP, TAXII 2.1 (discovery is open, no key needed) |
| Epstein Files | 400,750 DOJ documents, full-text searchable, free |
| Butterbot Tank | Autonomous site survey robot — WiFi heatmaps, NDAA detection, AR HUD |
| Blog | 1,655 threat intelligence posts and counting |
DugganUSA LLC — Minneapolis, MN • v2.5.0
Cybersecurity threat intelligence. Built with Claude.
D-U-N-S: 14-363-3562 • SAM.gov UEI: TP9FY7262K87
CMMC Level 2: 78/110 NIST SP 800-171 controls on $600/month
"The boring architecture is the safe architecture."
Same threat corpus, surfaced wherever you live. Open source, MIT licensed, receipts on every repo.
0 comments
log in to comment.