Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Thread Feed Agregator for Command and Control Servers #2

Open
rothoma2 opened this issue Apr 7, 2024 · 1 comment
Open

Thread Feed Agregator for Command and Control Servers #2

rothoma2 opened this issue Apr 7, 2024 · 1 comment
Labels
good first issue Good for newcomers help wanted Extra attention is needed top-level-task

Comments

@rothoma2
Copy link
Contributor

rothoma2 commented Apr 7, 2024

The Problem.

There are several existing projects in GitHub that aggregate several sources to come up with a list of Command and Control Servers. This IP Address, are useful to be integrated into SIEM or alerting solutions as IOCs.

This service is usually commercialized on "Next Generation Firewalls" When new connections been established are matched to private list of known malicious IP Address.

Therefore is important to separate the Threat Feed, from the Network Flow information. Having such a Thread feed can be integrated into other networks via Netflow, Logs or other means.

Requirements

@rothoma2 rothoma2 added good first issue Good for newcomers help wanted Extra attention is needed labels Apr 7, 2024
@rothoma2
Copy link
Contributor Author

@rothoma2 rothoma2 moved this from Todo to In Progress in Collaboration Request May 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers help wanted Extra attention is needed top-level-task
Projects
Status: In Progress
Development

When branches are created from issues, their pull requests are automatically linked.

2 participants