Skip to content

Instantly share code, notes, and snippets.

@mmguero
Created April 12, 2024 13:34
Show Gist options
  • Save mmguero/8546ddb2d5f77f255a5d8dcb50a14068 to your computer and use it in GitHub Desktop.
Save mmguero/8546ddb2d5f77f255a5d8dcb50a14068 to your computer and use it in GitHub Desktop.
sample Public STIX and MISP intel sources for testing Malcolm's Zeek Intelligence Framework integration

Zeek Intelligence Framework for Malcolm

  • /zeek/intel/MISP/.misp_input.txt
misp|https://www.circl.lu/doc/misp/feed-osint/manifest.json
misp|https://www.botvrij.eu/data/feed-osint/manifest.json
misp|https://osint.digitalside.it/Threat-Intel/digitalside-misp-feed/manifest.json
  • /zeek/intel/STIX/.stix_input.txt
taxii|2.0|https://cti-taxii.mitre.org/taxii/|*
taxii|2.0|https://limo.anomali.com/api/v1/taxii2/taxii/|CyberCrime|guest|guest
taxii|2.0|https://limo.anomali.com/api/v1/taxii2/taxii/|Abuse.ch Ransomware IPs|guest|guest
taxii|2.0|https://limo.anomali.com/api/v1/taxii2/taxii/|Abuse.ch Ransomware Domains|guest|guest
taxii|2.0|https://limo.anomali.com/api/v1/taxii2/taxii/|Malware Domain List - Hotlist|guest|guest
taxii|2.0|https://limo.anomali.com/api/v1/taxii2/taxii/|Emerging Threats C&C Server|guest|guest
taxii|2.0|https://limo.anomali.com/api/v1/taxii2/taxii/|Emerging Threats - Compromised|guest|guest
@mmguero
Copy link
Author

mmguero commented Apr 12, 2024

Screenshot 2024-04-12 at 07-47-02 Zeek Intelligence - Malcolm Dashboards

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment