certtools / intelmq

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
https://docs.intelmq.org/latest/
GNU Affero General Public License v3.0
976 stars 296 forks source link

Contribute: Feeds List #384

Closed SYNchroACK closed 4 years ago

SYNchroACK commented 9 years ago

If you want to contribute creating some bots in order to collect more information, pick one of these feeds:

helderfernandes1279 commented 8 years ago

OMG!! So much juice.......!!!!!!

Tomas i'm wondering, how can we evaluate the false positives or false negatives with this huge amount of intel.....this kind of stuff makes me think that the event record structure should have some kind of field that would represent the level of trust the collected info.....

SYNchroACK commented 8 years ago

I think @mauroasilva is one step ahead heheh :)

https://github.com/certtools/intelmq/pull/381

helderfernandes1279 commented 8 years ago

Always late hehehe:)

SYNchroACK commented 8 years ago
sebix commented 8 years ago

I converted the original list to a checklist and marked the implemented ones, so have a better overview.

aaronkaplan commented 8 years ago

cool, thx. Added n6

sebix commented 8 years ago
aaronkaplan commented 8 years ago
sebix commented 7 years ago
sebix commented 7 years ago
SYNchroACK commented 7 years ago
ghost commented 7 years ago

New shadowserver feeds:

ghost commented 7 years ago
dmth commented 7 years ago

@cert-bund has done this. Currently I'm reviewing the config. PR will come soon. PR https://github.com/certtools/intelmq/pull/1028

chorsley commented 7 years ago

PR for Zone-H's CSV email feed: #1015 (note this is a country-code specific feed, rather than scraping the public RSS feed - that may be separate if there's demand).

kruisdraad commented 7 years ago

Hi,

Vir BL https://virbl.bit.nl/download/virbl.dnsbl.bit.nl.bind

no longer exists

ghost commented 7 years ago

@kruisdraad Thanks, removed it from the list

kruisdraad commented 7 years ago

these dont work either:

http://abusix.org/service/spamfeeds http://qwe.affairedhonneur.us/depqfie59y https://github.com/animus-project/threat_data https://1d4.us/archive/ http://www.blade-defender.org/eval-lab/ http://www.infiltrated.net/ [all of them]

either 404, no DNS or perm loading screen

ghost commented 7 years ago

@kruisdraad Thanks for checking them. I marked them as offline in the above list.

ghost commented 6 years ago
ghost commented 6 years ago
ghost commented 6 years ago

List of feeds: https://threatfeeds.io/

SYNchroACK commented 6 years ago

bitcash is terminated https://bitcash.cz/misc/log/blacklist

ghost commented 5 years ago

https://github.com/NRDCS/intelmq/tree/certlt/intelmq/bots

ghost commented 5 years ago

https://github.com/ntddk/virustream

ghost commented 5 years ago

shodan search API

ghost commented 5 years ago

http://www.marc-blanchard.com/BotInvaders/index.php

ghost commented 4 years ago

Added:

ghost commented 4 years ago

Added:

pettai commented 4 years ago

Arbor FastFlux is no more...

bernhardreiter commented 4 years ago

Shouldn't we place this in a wiki page or in a file, so we get a consolidated list and the ability of more people to edit it? :)

ghost commented 4 years ago

Arbor FastFlux is no more...

Thanks, updated the list

Shouldn't we place this in a wiki page or in a file, so we get a consolidated list and the ability of more people to edit it? :)

I don't really like the idea of keeping it in a file, as the list is independent of the rest and doesn't need versioning etc. It's also much easier to comment here instead of creating pull requests.

For the wiki: I'm in favor of it, but the wiki here has been deactivated a few years ago. @aaronkaplan what do you think about it?

bernhardreiter commented 4 years ago

A file could be the best available solution to get

And it is related to the IntelMQ code base, because it shows the current state of wished-for additional feeds. ;)