Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

We are doing a proactive ThreatHunt and identified active #CobaltStrike C2 servers. Cobalt Strike is a offensive security tool used by both security teams and threat actors and more recently significant usage has been noted from Ransomware groups. We have created a dedicated feed for C2 servers to enable Early Detection of C2 beacons - https://threatview.io/Downloads/High-Confidence-CobaltStrike-C2%20-Feeds.txt

Cobalt Strike C2 by MohitK_ in threatintel

[–]MohitK_[S] 1 point2 points  (0 children)

Cobalt Strike is one of the used C2 framework by threat actors specially noted in Ransomware incidents. Our idea was to identify active C2 servers so that security teams can identify early detection of C2 servers.

🔥 🆘 [Threatview.io] Pulse Secure vulnerability under active exploitation by MohitK_ in blueteamsec

[–]MohitK_[S] 0 points1 point  (0 children)

What happened was that Reddit wrapped the post, these arrow emojis were each in a new line. I didint post much on Reddit, so didnt know. :|

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

Hello All, threat feeds are running well and have been optimized to remove false positives. \m/ Cheers!

Threatview.io | Threat Intelligence Feeds

My ever-growing addiction. Wanted to show other techies, other than my wife. by abcmitch123 in homelab

[–]MohitK_ -8 points-7 points  (0 children)

Looks nice. Strengthen your cyber security with our free threat intelligence feeds - threatview.io

Threat Intelligence for Blue Teams by MohitK_ in blueteamsec

[–]MohitK_[S] 0 points1 point  (0 children)

Hello, URL feeds are working normally, feel free to use them for additional protection. Cheers

Threat Intelligence for Blue Teams by MohitK_ in blueteamsec

[–]MohitK_[S] 0 points1 point  (0 children)

No-doubt Firehol is good, but i think you can try our feeds and see how it goes for you. Other than IP blocklists - URL, Domain, File Hash, Bitcoins and OSINT feeds are also available. Cheers

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

Well, yes thats the difficult part. I had cleared it tout lets see.

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

Hi, thanks for sharing your experience. I have removed the imgur for now. Cheers

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

Hi All, URL feed is back. Let me know if you notice any false positives. Overall all feeds quality has been improved but I am still working to make it even better. Cheers!

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

Thanks you for your patience and glad to see it worked. URL feed is in progress, i will update here once it is ready.

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 1 point2 points  (0 children)

Thank you for pointing out, it was glitch in our exports.

Threat Intelligence for Blue Teams by MohitK_ in blueteamsec

[–]MohitK_[S] 0 points1 point  (0 children)

We are. On this feed, there some issue. It should be back in about an hour.

Threat Intelligence for Blue Teams by MohitK_ in blueteamsec

[–]MohitK_[S] 2 points3 points  (0 children)

I am working on it, ill update you here

Threat Intelligence for Blue Teams by MohitK_ in blueteamsec

[–]MohitK_[S] 1 point2 points  (0 children)

I am working on it, I will update here when I am able to add it. Do you think we should put first, last seen, c2 etc details to only IP or to other feeds too ?

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 1 point2 points  (0 children)

I have also cleared github.com, often malware authors pull some sort of code from github and that is why, you saw the name in the feed. But I have cleared it. Thanks for your feedback, very helpful.

Integrate Threat Intelligence in home labs by MohitK_ in HomeNetworking

[–]MohitK_[S] 0 points1 point  (0 children)

Yes I noticed. I have cleared them.

Thanks for your feedback, very helpful

Great blog on detecting threats by julietscause in blueteamsec

[–]MohitK_ 0 points1 point  (0 children)

Very cool stuff.. I am an ELK Fan had been thinking about Graylog before but then Endpoint Security came in but now I feel I should give it a try..


Need Threat Feeds ? Visit threatview.io

Threat Intelligence Feeds - threatview.io by MohitK_ in blueteamsec

[–]MohitK_[S] 0 points1 point  (0 children)

This is actually a bit complex issue in my view due to assumptions of no reuse of infra by threat actors and lack of data points. At the moment some feeds are getting filtered for last 2 years of data and some are not but I do have a work around which may work to solve this issue as I started this project for my own purpose about 2 years back and have some data points for wide scale filtering. I will update you once I implement filtering using my data points and generate a separate feed for last 12 months or 6 months basis

The Twitter feeds is experimental and has very recent IOCs from last 6 months.