Skip to content

A TA to pull IOCS about COVID attacks from various open source locations

License

Notifications You must be signed in to change notification settings

splunk/ta-covidiocs

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 

Repository files navigation

TA-covidiocs

This TA is designed for Linux systems (and most likely OSX) to download IPs, newly created Domains, and hashes, and URLs related to COVID attacks. This was inspired by data provided on the Repo: https://github.com/parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs) but now includes data from http://cti-league.com/ and RiskIQ (https://www.riskiq.com/blog/external-threat-management/discovering-unknowns-investigating-threats-covid19/). Sometimes the data has some #s, are FalsePositives, and/or is broken. So use at your risk. You probably should use this in dev environments to verify the info. Special thanks to LilyLily Lee @splunk for cleaning up all of my bad TA hygiene AND fixing a scripting problem :-)

License

Distributed under the terms of the Apache Software License 2.0 license, "TA-covidiocs" is free and open source software

About

A TA to pull IOCS about COVID attacks from various open source locations

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Languages