// EVIL-DB · ANNIVERSARY DOSSIER · DECLASSIFIED_

ONEYEAR

From a scrappy FastAPI prototype to a 0-threat intelligence platform — hunting the internet's worst, every day for 365 of them.

JUN 19 2025 JUN 19 2026
01

THE NUMBERS

0
Threat indicators
0
Malicious IPs
0
Malicious domains
0
File hashes
0
CVEs catalogued
0
Known-exploited (KEV)
0
Live feeds
0
Intel sources
0
CVEs at EPSS ≥ 0.90
02

WHAT WE CAUGHT

proxy
0
malicious
0
attacks
0
phishing
0
tracking
0
bruteforce
0
spam
0
abuse
0
03

THE ORIGIN STORY

  1. JUN 19, 2025

    Born as “EvilWatch”

    A scrappy FastAPI + SQLite backend with a Next.js frontend, enriching threats through NeutrinoAPI. The first commit lands at 19:21 UTC — 6 seconds before the repo even existed on GitHub.

  2. DEC 7, 2025

    The great rewrite

    Rebuilt from the ground up: FastAPI → Next.js App Router, raw sqlite3 → Prisma, NeutrinoAPI → AbuseIPDB / ip-api / Shodan. The platform Evil-DB runs on today.

  3. APR–JUN 2026

    CVE intelligence

    NVD 2.0 + EPSS + CISA KEV land — 356K CVEs with exploit-prediction scoring, wired into the threat graph. The chunkiest feature of the year.

04

HALL OF INFAMY

MOST WANTED
201.16.194.227

21,888 reports — the single most-reported indicator in the database.

FRESHEST KEV
CVE-2026-20253

Splunk Enterprise Missing Authentication for Critical Function Vulnerability

NEAR-CERTAIN
757 CVEs

scored EPSS ≥ 0.90 — vulnerabilities almost certain to be exploited in the wild.

05

BEHIND THE DOSSIER

One operator. Two repositories. A whole lot of late nights.

0
Commits, both repos
0
API routes
0
Prisma models
0
React components

Here's to year two.

Same mission, more threats, faster lookups. Thanks for being part of it.

// END OF FILE