Nimentus · Micro-utilities for infrastructure
Sharp tools for the gaps the big platforms leave behind.
Nimentus designs and engineers focused micro-utilities that resolve the stubborn infrastructure gaps left behind by major platforms — dead IPs, firewall sprawl, and config drift. Focused tools, built to do one thing completely.
The Studio
Every organization carries the same hidden weight: small, specific problems too narrow to ever reach a major vendor’s roadmap. They get worked around, never fixed, and quietly drain time and attention. Nimentus exists to close those gaps — one focused micro app service at a time, each taking a single overlooked problem and carrying it all the way to a finished, production-quality tool.
Everything is open source, built in public, and meant to be useful on day one. Fino alla fine — until the very end. It’s the standard every product is held to.
Products
Each Nimentus product targets a single, well-defined problem and solves it end to end. Here’s what we’ve built so far.
Product 01 · Live
ReclaimNet
Confidence-scored liveness for IP address space. Your IPAM says an address is in use. The wire says nothing’s there. ReclaimNet reconciles the two — gathering evidence from independent collectors over time, scoring how alive each address really is, and writing the verdict back into NetBox.
It never declares an IP dead on a hunch. It watches, accumulates proof, and only commits when it’s confident — and a human always approves the write.
- Temporal confidence — days of multi-collector evidence, not a single snapshot.
- Two-sided reconciliation — documented-but-dead, and alive-but-undocumented.
- Pluggable collectors — ARP, active probe, NetFlow next; add a source, the core never changes.
- Human-in-the-loop — review every change before it touches your source of truth.
- Browser-based setup — point it at your gateway and IPAM, test the connection, tune the scoring — no config files, no SSH.
Product 02 · Live
snabridge
Threat intelligence, synced into Cisco Secure Network Analytics. SNA can’t natively ingest a TAXII feed or a threat-intel API — so indicators get loaded by hand, and worse, never retired when they go stale. snabridge reconciles your feeds into SNA continuously: pulling IPs from ThreatFox, OpenCTI, or any TAXII 2.1 source, grouping them by threat, and writing the complete desired state into SNA.
Stale intel is dangerous intel. snabridge doesn’t just add indicators — it clears out the ones that have aged out, so detection reflects the threat landscape now, not last month. And every change is reviewed before it applies.
- Declarative reconciliation — the feed is the desired state; snabridge makes SNA match it, additions and retirements alike.
- TAXII 2.1 native — one standards-based adapter unlocks OpenCTI, MISP, and commercial feeds; ThreatFox supported out of the box.
- Grouped by threat — indicators land in SNA host groups by malware family or label, not one undifferentiated blob.
- Review-then-apply — see every create, update, and retire before a single change touches SNA.
- Ships as Docker — images for API and GUI, one host or split across VMs, configured entirely from the browser.
Work with Nimentus
Available for consulting and contract work on network automation, security architecture, and tooling. Or send a message directly — consulting, contract work, a question about a tool, or a feature you wish one of them had.