MISP / misp-warninglists

Warning lists to inform users of MISP about potential false-positives or other information in indicators
http://misp.github.io/misp-warninglists/
516 stars 168 forks source link

Web cluster warninglists #92

Open ater49 opened 5 years ago

ater49 commented 5 years ago

With passive DNS data of CIRCL, it could be possible to determine which IP are used by a large number of hostname like in a Web cluster.

Could it be possible to extract these data in order to create an IP Warninglist ?

adulau commented 5 years ago

Indeed, we could generate list of IP addresses associated to a lot of domains/hostname (>10000 records). It's a good idea. I need to check how to do in the Passive DNS database.