Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Threat Intelligence Feeds #63

Open
scafroglia93 opened this issue Jan 17, 2024 · 23 comments
Open

Threat Intelligence Feeds #63

scafroglia93 opened this issue Jan 17, 2024 · 23 comments

Comments

@scafroglia93
Copy link

Enjoy

https://github.com/scafroglia93/blocklists

@SkewedZeppelin
Copy link
Member

SkewedZeppelin commented Jan 17, 2024

Hi!

Hypatia works on file hashes, not on domains.

But I have a project for that too! https://divested.dev/pages/dnsbl

And I already uses your lists 🙂 https://github.com/divestedcg/Simple_Hosts_Merger/blob/master/blocklists-nc.txt#L135-L151

Seems you've added a license and more lists, I can move them over to the regular not-nc-only list. Thanks!

@scafroglia93
Copy link
Author

I need to figure out if I can insert the hashes into the lists

@SkewedZeppelin
Copy link
Member

SkewedZeppelin commented Jan 17, 2024

This repo already tracks many of those blogs/sources: https://raw.githubusercontent.com/Neo23x0/signature-base/master/iocs/hash-iocs.txt

I have some more I'll push to a new repo soon

@SkewedZeppelin
Copy link
Member

Latest combined list now includes all of your lists: divestedcg/Simple_Hosts_Merger@af6a65e

Thank you!

@scafroglia93
Copy link
Author

Is it a problem if I use the lists with domains to insert IP and hash?

do you need a separate thing?

@SkewedZeppelin
Copy link
Member

SkewedZeppelin commented Jan 17, 2024

nah, your lists your rules: keep whatever works best/easiest for yourself first

my simple hosts merger already has regex for domain matching and should filter anything else out correctly, and the hypatia merger has hexadecimal hash matching regex too, so they should both work just fine and I can always adjust them if necessary

@scafroglia93
Copy link
Author

scafroglia93 commented Jan 17, 2024

I can proceed with entering the IP and hash without causing problems for other lists.

Is there a specific format for adding hash and ip ?

is this correct for you ?

scafroglia93/blocklists@1fda4f7

@SkewedZeppelin
Copy link
Member

I think everyone just makes up their own format :)

What you have works just fine

@scafroglia93
Copy link
Author

Microsoft Threat List Is ready the other in the next day

You can use it

@scafroglia93
Copy link
Author

Let me know so I can proceed with the additions

telegram -> @scafroglia93

@SkewedZeppelin
Copy link
Member

SkewedZeppelin commented Jan 18, 2024

I've added them 🚀

Stats: https://divested.dev/MalwareScannerSignatures/
Processor update: f02e355

	blocklists-microsoft.txt
		md5: 0, sha1: 0, sha256: 15
	blocklists-qianxin.txt
		md5: 14, sha1: 0, sha256: 0
	blocklists-tag.txt
		md5: 0, sha1: 0, sha256: 9

@scafroglia93
Copy link
Author

Nice let's do it

@scafroglia93
Copy link
Author

It's work

I hope to be useful for the project

@SkewedZeppelin
Copy link
Member

Thank you again @scafroglia93 🙂

@scafroglia93 scafroglia93 reopened this Jan 21, 2024
@scafroglia93
Copy link
Author

scafroglia93 commented Jan 21, 2024

[securiteinfo]

@SkewedZeppelin
Copy link
Member

@scafroglia93 I suspect those are released under a restrictive license and can't be used.

I emailed them a few years ago for permission to no response.

@scafroglia93
Copy link
Author

You can use it without mention LOL

@scafroglia93
Copy link
Author

Last questione -> it's possible download the signature for clamav ?

@SkewedZeppelin
Copy link
Member

SkewedZeppelin commented Jan 22, 2024

@scafroglia93 previously yes, but now no: the generated database is a serialized Guava bloom filter Java object processed on server side to reduce the download amount and speedup app loading

@scafroglia93
Copy link
Author

I'm redoing the repo; Can you reset the indicators you currently have?

@SkewedZeppelin
Copy link
Member

I froze my copy to 526b3922ee0e59a99123829acbdb296386f66840

@scafroglia93
Copy link
Author

You can use fresh source

I'm working on it now

It's better format that i found some missed entries related to the new assestment

@scafroglia93
Copy link
Author

Source are now ok, you can reset and follow the actual git history

thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants