MISP / misp-warninglists

Warning lists to inform users of MISP about potential false-positives or other information in indicators
http://misp.github.io/misp-warninglists/
520 stars 170 forks source link

Add List for Censys CIDR blocks #252

Closed TomOgs closed 1 year ago

TomOgs commented 1 year ago

Howdy

I've found this list to be useful in our organisations MISP instance as IP Addresses belonging to Censys are regularly reported for abuse due to their scanning of public facing systems, which while benign does tend to hit IPS Devices/Honeypots and be reported for abuse.

Unfortunately I couldn't create a generator script as I was only able to find these CIDR blocks on a Censys support page that didn't link to a flat txt/json file with the IP's.

adulau commented 1 year ago

Thank you very much for the contribution! I did some clean-up and renamed it to follow the default names for misp-warning.

TomOgs commented 1 year ago

No worries at all, thank you!
: )