nzinga
Authorized open-source intelligence from the terminal. Public-source collection, cross-source correlation, and evidence-backed reporting with an offline simulator.
The seven stages
- DISCOVER, validate and normalize the target, recording honest discovery hints without fabricating observations
- COLLECT, run enabled public sources (crt.sh CT logs, WHOIS, infrastructure, org, relationships) with bounded concurrency
- NORMALIZE, normalize source payloads into typed observations with provenance: source, observed_at, collected_at, raw_reference
- CORRELATE, link observations across sources into entities and a typed relationship graph
- ANALYZE, evaluate evidence-backed claims against deterministic rules (OSINT-001..004) with confidence and severity
- VALIDATE, confirm every finding traces to collected evidence; no absence is ever reported as absence-proof
- REPORT, render terminal tables plus schema-versioned JSON, Markdown, HTML, YAML, and JSONL event streams
Authorization guarantee
nzinga collects only from public, open sources and performs authorized reconnaissance only. Live collection requires explicit authorization (--authorized / -y, config, or QYVORA_AUTHORIZED=true); the built-in simulator (--sim) runs offline against a deterministic dataset without network activity.
Install
curl -fsSL https://raw.githubusercontent.com/QYVORA/qyvora-nzinga/main/install.sh | bash
Usage
- nzinga assess --sim
- nzinga assess -y domain:example.com --profile standard -o json
- nzinga sources list
- nzinga findings -f json
- nzinga relationship graph