http://danger.rulez.sk/projects/bruteforceblocker/blist.php
dangerrulez provide blocklist of Ip used SSH bruteforce attacks via firewall
This feed includes Ip used in bruteforce attacks
The dangerrulez feed API is found on github at
https://github.com/dnif/enrich-dangerrulez
- ACCESS DNIF CONTAINER VIA SSH : Click To Know How
$cd /dnif/CnxxxxxxxxxxxxV8/enrichment_plugins/
git clone https://github.com/dnif/enrich-dangerrulez.git dangerrulez
Fields | Description |
---|---|
EvtType | An IP |
EvtName | The IOC |
IntelRef | Feed Name |
IntelRefURL | Feed URL |
ThreatType | DNIF Feed Identification Name |
An example of API feed output
{'EvtType': 'IPv4',
'EvtName': '85.255.1.106',
'AddFields': {
'IntelRef': ['DANGERRULEZ'],
'IntelRefURL': ['http://danger.rulez.sk/projects/bruteforceblocker/blist.php'],
'ThreatType': ['blacklist'] }}