PaloAltoNetworks / SafeNetworking

Read only mirror. To contribute or submit issues, please go to the website link --->
https://gitlab.com/panw-gse/as/SafeNetworking/
Apache License 2.0
12 stars 10 forks source link

Creation of EDLs from IoT Domain files generated by honeypot team - manual #27

Open punisherVX opened 6 years ago

punisherVX commented 6 years ago

When the honeypot team gives us a list of bad IoT domains/IPs, we will need to append these to the current EDL.

First iteration can be a manual script-run, upload to EDL.

Ticket #28: IoT Safe Networking Processing -- Domains

We need to add to SN the ability to identify IoT C2 activity via DNS that we have learned from our Honeypots.

High level requirements include