Feeds wishlist¶
This is a list with various feeds, which are either currently not supported or the usage is not clearly documented in IntelMQ.
If you want to contribute documenting how to configure existing bots in order to collect new feeds or by creating new parsers, here is a list of potentially interesting feeds. See Feeds documentation for more information on this.
This list evolved from the issue Contribute: Feeds List (#384).
- Lists of feeds: - threatfeeds.io - TheCyberThreat - sbilly: Awesome Security
- Some third party intelmq bots: NRDCS’ IntelMQ fork
- List of potentially interesting data sources:
- Abuse.ch SSL Blacklists
- Adblock Plus Malwaredomains
- apivoid IP Reputation API
- APWG’s ecrimex
- Bad IPs
- Berkeley
- Binary Defense
- Bot Invaders Realtime tracker
- Botscout Last Caught
- Carbon Black Feeds
- CERT.pl Phishing Warning List
- Chaos Reigns
- Critical Stack
- Cruzit
- Cyber Crime Tracker
- DNS DB API
- Dyn DNS
- Facebook Threat Exchange
- FilterLists
- Firehol IPLists
- Google Webmaster Alerts
- GPF Comics DNS Blacklist
- Greensnow
- HP Feeds
- IBM X-Force Exchange
- ISC SANS
- ISightPartners
- James Brine
- Joewein
- Malshare
- Malware Config
- Malware DB (cert.pl)
- MalwareDomainList
- MalwareDomains
- MalwareInt
- Manity Spam IP addresses
- Marc Blanchard DGA Domains
- MaxMind Proxies
- mIRC Servers
- Monzymerza
- Multiproxy
- MVPS
- Null Secure
- OpenBugBounty
- Payload Security
- Project Honeypot (#284)
- RST Threat Feed (offers a free and a commercial feed)
- ShadowServer Sandbox API
- Shodan search API
- Snort
- Spamhaus BGP feed (BGPf)
- SteveBlack Hosts File
- TheCyberThreat
- The Haleys
- Threat Crowd
- Threat Grid
- Threatstream
- TOR Project Exit addresses
- TotalHash
- UCE Protect
- URI BL
- urlscan.io
- Virustotal
- virustream
- VoIP Blacklist
- Wordpress Callback Domains
- YourCMC