Skip to content

Add the following TI feeds in Slips #1880

@AlyaGomaa

Description

@AlyaGomaa
  • any feed related to Ads should be threat level info
  • add a parser for each of them
- name: AIP-Alpha-latest.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP-Alpha-latest.csv
  - name: AIP-Alpha7-latest.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP-Alpha7-latest.csv
  - name: AIP-Prioritize_Consistent-latest.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP-Prioritize_Consistent-latest.csv
  - name: AIP-Prioritize_New-latest.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP-Prioritize_New-latest.csv
  - name: AIP_blacklist_for_IPs_seen_last_24_hours.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP_blacklist_for_IPs_seen_last_24_hours.csv
  - name: AIP_historical_blacklist_prioritized_by_newest_attackers.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP_historical_blacklist_prioritized_by_newest_attackers.csv
  - name: AIP_historical_blacklist_prioritized_by_repeated_attackers.csv
    org: stratosphere
    url: https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/AIP_historical_blacklist_prioritized_by_repeated_attackers.csv
  - name: stalkerware-indicators-network.csv
    org: assoechap
    url: https://raw.githubusercontent.com/AssoEchap/stalkerware-indicators/master/generated/network.csv
  - name: threat-intel-lists-latestdomains.txt
    org: osint.digitalside.it
    url: https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
  - name: threat-intel-lists-latestips.txt
    org: osint.digitalside.it
    url: https://osint.digitalside.it/Threat-Intel/lists/latestips.txt
  - name: nerd-data-bad_ips.txt
    org: nerd.cesnet.cz
    url: https://nerd.cesnet.cz/nerd/data/bad_ips.txt
  - name: nerd-data-ip_rep.csv
    org: nerd.cesnet.cz
    url: https://nerd.cesnet.cz/nerd/data/ip_rep.csv
  - name: lists-all.txt
    org: lists.blocklist.de
    url: https://lists.blocklist.de/lists/all.txt
  - name: lists-ssh.txt
    org: lists.blocklist.de
    url: https://lists.blocklist.de/lists/ssh.txt
  - name: lists-mail.txt
    org: lists.blocklist.de
    url: https://lists.blocklist.de/lists/mail.txt
  - name: lists-bruteforcelogin.txt
    org: lists.blocklist.de
    url: https://lists.blocklist.de/lists/bruteforcelogin.txt
  - name: lists-bots.txt
    org: lists.blocklist.de
    url: https://lists.blocklist.de/lists/bots.txt
  - name: lists-strongips.txt
    org: lists.blocklist.de
    url: https://lists.blocklist.de/lists/strongips.txt
  - name: ipblocklist.csv
    org: feodotracker.abuse.ch
    url: https://feodotracker.abuse.ch/downloads/ipblocklist.csv
  - name: ipblocklist_recommended.txt
    org: feodotracker.abuse.ch
    url: https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
  - name: ipblocklist_aggressive.csv
    org: feodotracker.abuse.ch
    url: https://feodotracker.abuse.ch/downloads/ipblocklist_aggressive.csv
  - name: ipblocklist_aggressive.txt
    org: feodotracker.abuse.ch
    url: https://feodotracker.abuse.ch/downloads/ipblocklist_aggressive.txt
  - name: drop.txt
    org: spamhaus
    url: https://www.spamhaus.org/drop/drop.txt
  - name: edrop.txt
    org: spamhaus
    url: https://www.spamhaus.org/drop/edrop.txt
  - name: dropv6.txt
    org: spamhaus
    url: https://www.spamhaus.org/drop/dropv6.txt
  - name: asndrop.txt
    org: spamhaus
    url: https://www.spamhaus.org/drop/asndrop.txt

  - name: targetedthreats.csv
    org: botherder
    url: https://raw.githubusercontent.com/botherder/targetedthreats/master/targetedthreats.csv
  - name: ipsum.txt
    org: stamparm
    url: https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt
  - name: blocklist-ipsets-firehol-level1.netset
    org: firehol
    url: https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset
  - name: reputation.generic.txt
    org: alienvault
    url: https://reputation.alienvault.com/reputation.generic
  - name: blacklist-adservers.txt
    org: anudeepND
    url: https://raw.githubusercontent.com/anudeepND/blacklist/master/adservers.txt
  - name: hostsVN-domain.txt
    org: bigdargon
    url: https://github.com/bigdargon/hostsVN/blob/master/option/domain.txt
Hosts block ads of Vietnamese
  - name: Zeek-Intelligence-Feeds-binarydefense.intel
    org: CriticalPathSecurity
    url: https://raw.githubusercontent.com/CriticalPathSecurity/Zeek-Intelligence-Feeds/master/binarydefense.intel
  - name: hole-domains.json
    org: cert.pl
    url: https://hole.cert.pl/domains/domains.json
  - name: hole-domains_hosts.txt
    org: cert.pl
    url: https://hole.cert.pl/domains/domains_hosts.txt
  - name: OCD-Datalake-russia-ukraine_IOCs-ALL.csv
    org: Orange-Cyberdefense
    url: https://raw.githubusercontent.com/Orange-Cyberdefense/russia-ukraine_IOCs/main/OCD-Datalake-russia-ukraine_IOCs-ALL.csv
  - name: nixspam-ip.dump.gz
    org: nixspam.net
    url: http://ftp.indes.com/pub/mirrors/www.nixspam.net/download/nixspam-ip.dump.gz
  - name: open-suricata-edge-emerging-all.rules
    org: rules.emergingthreatspro.com
    url: https://rules.emergingthreatspro.com/open/suricata-edge/emerging-all.rules
  - name: fwrules-emerging-Block-IPs.txt
    org: rules.emergingthreats.net
    url: https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
  - name: SSC-Threat-Intel-IoCs-KillNet-DDoS-Blocklist-proxylist.txt
    org: securityscorecard
    url: https://github.com/securityscorecard/SSC-Threat-Intel-IoCs/blob/master/KillNet-DDoS-Blocklist/proxylist.txt
  - name: ellio-tech-community-feed
    org: ellio.tech
    url: https://cdn.ellio.tech/community-feed
  - name: sentinel-turris-cz_greylist-latest.csv
    org: sentinel.turris.cz
    url: https://view.sentinel.turris.cz/greylist-data/greylist-latest.csv
  - name: malwareworld_data_suspiciousDomains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/suspiciousDomains.txt
  - name: malwareworld_data_type_BadReputation_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_BadReputation_domains.txt
  - name: malwareworld_data_type_Malware_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_Malware_domains.txt
  - name: malwareworld_data_type_KnownAttacker_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_KnownAttacker_domains.txt
  - name: malwareworld_data_type_Spammer_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_Spammer_domains.txt
  - name: malwareworld_data_type_Phishing_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_Phishing_domains.txt
  - name: malwareworld_data_type_HideSource_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_HideSource_domains.txt
  - name: malwareworld_data_type_DGA_domains.txt
    org: malwareworld.com
    url: https://malwareworld.com/data/type_DGA_domains.txt
  - name: stopforumspam_downloads_listed-ip-1.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_1.zip
  - name: stopforumspam.com_downloads_listed-ip-7.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_7.zip
  - name: stopforumspam.com_downloads_listed-ip-30.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_30.zip
  - name: stopforumspam.com_downloads_listed-ip-90.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_90.zip
  - name: stopforumspam.com_downloads_listed-ip-180.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_180.zip
  - name: stopforumspam.com_downloads_listed-ip-365.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_365.zip
  - name: stopforumspam.com_downloads_listed_ip_1_ipv6.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_1_ipv6.zip
  - name: stopforumspam.com_downloads_listed_ip_7_ipv6.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_7_ipv6.zip
  - name: stopforumspam.com_downloads_listed_ip_30_ipv6.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_30_ipv6.zip
  - name: stopforumspam.com_downloads_listed_ip_90_ipv6.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_90_ipv6.zip
  - name: stopforumspam.com_downloads_listed_ip_180_ipv6.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_180_ipv6.zip
  - name: stopforumspam.com_downloads_listed_ip_365_ipv6.zip
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/listed_ip_365_ipv6.zip
  - name: stopforumspam.com_downloads_toxic_domains_whole_filtered_1000.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered_1000.txt
  - name: stopforumspam.com_downloads_toxic_domains_whole_filtered_10000.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered_10000.txt 
  - name: stopforumspam.com_downloads_toxic_domains_whole_filtered_50000.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered_50000.txt
  - name: stopforumspam.com_downloads_toxic_domains_whole_filtered_100000.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered_100000.txt
  - name: stopforumspam.com_downloads_toxic_domains_whole_filtered_250000.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered_250000.txt
  - name: stopforumspam.com_downloads_toxic_domains_whole_filtered.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered.txt
  - name: stopforumspam.com_downloads_toxic_domains_whole.txt
    org: stopforumspam.com
    url: https://www.stopforumspam.com/downloads/toxic_domains_whole.txt
  - name: openphish_public_feed.txt
    org: openphish
    url: https://raw.githubusercontent.com/openphish/public_feed/refs/heads/main/feed.txt
  - name: threatfox_domains_full.json
    org: threatfox.abuse.ch
    url: https://threatfox.abuse.ch/export/json/domains/full/
  - name: blocklistproject-abuse-nl.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/alt-version/abuse-nl.txt
  - name: blocklistproject-fraud.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/fraud.txt
  - name: blocklistproject-malware.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/malware.txt
  - name: blocklistproject-phishing.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/phishing.txt
  - name: blocklistproject-piracy.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/piracy.txt
  - name: blocklistproject-ransomware.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/ransomware.txt
  - name: blocklistproject-scam.txt
    org: blocklistproject
    url: https://blocklistproject.github.io/Lists/scam.txt
  - name: firebog-AdguardDNS.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/AdguardDNS.txt
  - name: firebog-Admiral.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/Admiral.txt
  - name: firebog-Easylist-Dutch.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/Easylist-Dutch.txt
  - name: firebog-Easylist.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/Easylist.txt
  - name: firebog-Prigent-Crypto.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/Prigent-Crypto.txt
  - name: firebog-Prigent-Malware.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/Prigent-Malware.txt
  - name: firebog-neohostsbasic.txt
    org: v.firebog.net
    url: https://v.firebog.net/hosts/neohostsbasic.txt

Metadata

Metadata

Assignees

No one assigned

    Labels

    Better DetectionTasks for making better detections of threats

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions