Threat Feeds Collections

Threat Feeds Collections

Here I list and share threat feeds I collected over the years for FortiOS and other systems...

FortiGate has the ability to add threat feeds from external sources. This function significantly increases FortiGate's capability of catching and blocking threats in real-time. According to the FortiOS Cookbook:

Threat feeds dynamically import an external block lists from an HTTP server in the form of a text file. Block lists can be used to enforce special security requirements, such as long term policies to always block access to certain websites, or short term requirements to block access to known compromised locations. The lists are dynamically imported, so that any changes are immediately imported by FortiOS.

FortiOS supports four types of threat feeds:

FortiGuard Category

Example:
http://example/com.url
https://example.com/url
http://example.com:8080/url

IP Address

Example:
192.168.2.100
172.200.1.4/16
172.16.1.2/24
172.16.8.1-172.16.8.100
2001:0db8::eade:27ff:fe04:9a01/120
2001:0db8::eade:27ff:fe04:aa01-2001:0db8::eade:27ff:fe04:ab01

Domain Name

Example:
mail.*.example.com
*-special.example.com
www.*example.com
example.com

Malware Hash

Example:
292b2e6bb027cd4ff4d24e338f5c48de
dda37961870ce079defbf185eeeef905 Trojan-Ransom.Win32.Locky.abfl
3fa86717650a17d075d856a41b3874265f8e9eab Trojan-Ransom.Win32.Locky.abfl
c35f705df9e475305c0984b05991d444450809c35dd1d96106bb8e7128b9082f Trojan-Ransom.Win32.Locky.abfl

List of Threat Feeds

https://secureupdates.che..int.com/IP-list/TOR.txt

https://www.dan.me.uk/torlist

https://s3.us-east-2.amaz...om/ip-blacklist/ip.txt

http://rules.emergingthre...emerging-Block-IPs.txt

https://talosintelligence../documents/ip-blacklist

https://lists.blocklist.de/lists/all.txt

Blocklist Collection ¦ Firebog

https://www.team-cymru.com/blocklist

abuseipdb.com

https://raw.githubusercontent.com/stamparm/ipsum/master/levels/3.txt

abuse.ch - Figthing malware and botnets
abuse.ch is providing community driven threat intelligence on cyber threats
Automated Indicator Sharing (AIS) | CISA
AlienVault - Open Threat Exchange
Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today’s emerging threats.
www.blocklist.de -- Fail2Ban-Reporting Service (we sent Reports from Attacks on Postfix, SSH, Apache-Attacks, Spambots, irc-Bots, Reg-Bots, DDos and more) from Fail2Ban via X-ARF.
www.blocklist.de -- Fail2Ban-Reporting Service (we sent Reports from Attacks on Postfix, SSH, Apache-Attacks, Spambots, irc-Bots, Reg-Bots, DDos and more) from Fail2Ban via X-ARF. we report SSH-, Mail-, FTP-, Apache- and other Attacks from fail2ban via X-ARF
PhishTank > Developer Information
Proofpoint Emerging Threats Rules
CINSscore.com
SANS.edu Internet Storm Center - SANS Internet Storm Center
SANS.edu Internet Storm Center. Today’s Top Story: YARA: Detect The Unexpected ...;
VirusTotal API v3 Overview
API version 3 is now the default and encouraged way to programmatically interact with VirusTotal. It greatly improves API version 2, which, for the time being, will not be deprecated. This new API was designed with ease of use and uniformity in mind and it is inspired in the http://jsonapi.org/ spec…
Cisco Talos Intelligence Group - Comprehensive Threat Intelligence
Cisco Talos Intelligence Group is one of the largest commercial threat intelligence teams in the world. Comprised of world-class cyber security researchers, analysts and engineers and supported by unrivaled telemetry, Talos defends Cisco customers against known and emerging threats, discovers new vu…
VirusShare.com