From b3b5af8e83305fa14fb48c62b9939b560e3c6278 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:03:06 +0200 Subject: [PATCH 1/7] Fix Mitre ATT&CK link --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index dc28725..769d95e 100644 --- a/README.md +++ b/README.md @@ -1733,7 +1733,7 @@ All kinds of reading material about Threat Intelligence. Includes (scientific) r - ATT&CK + ATT&CK Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) is a model and framework for describing the actions an adversary may take while operating within an enterprise network. ATT&CK is a constantly growing common reference for post-access techniques that brings greater awareness of what actions may be seen during a network intrusion. MITRE is actively working on integrating with related construct, such as CAPEC, STIX and MAEC. From 52e57937a1acf5802191f04a03d2bf45482432be Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:07:31 +0200 Subject: [PATCH 2/7] Remove zeustracker; zeus is no more :-) --- README.md | 8 -------- 1 file changed, 8 deletions(-) diff --git a/README.md b/README.md index 769d95e..f9d9ed2 100644 --- a/README.md +++ b/README.md @@ -674,14 +674,6 @@ The primary goal of Malpedia is to provide a resource for rapid identification a An open source repository with different Yara signatures that are compiled, classified and kept as up to date as possible. - - - ZeuS Tracker - - - The ZeuS Tracker by abuse.ch tracks ZeuS Command & Control servers (hosts) around the world and provides you a domain- and a IP-blocklist. - - 1st Dual Stack Threat Feed by MrLooquer From f37e0d2d35db52bad8138a5df3d87d89853f70f8 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:11:51 +0200 Subject: [PATCH 3/7] Remove Celerium Soltra --- README.md | 8 -------- 1 file changed, 8 deletions(-) diff --git a/README.md b/README.md index f9d9ed2..53a934b 100644 --- a/README.md +++ b/README.md @@ -1010,14 +1010,6 @@ Frameworks, platforms and services for collecting, analyzing, creating and shari Scumblr helps you streamline proactive security through an intelligent automation framework to help you identify, track, and resolve security issues faster. - - - Soltra - - - Soltra supports a community defense model that is highly interoperable and extensible. It is built with industry standards supported out of the box, including STIX (up to 2.1) and TAXII. - - STAXX (Anomali) From a326faf02cb0a15e970f6ddda7be15150d364ae3 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:14:13 +0200 Subject: [PATCH 4/7] Update actortrackr.com link --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 53a934b..de9874f 100644 --- a/README.md +++ b/README.md @@ -1122,10 +1122,10 @@ All kinds of tools for parsing, creating and editing Threat Intelligence. Mostly From a43048073956465668dab2cf7d9542dc71671a32 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:15:40 +0200 Subject: [PATCH 5/7] Update description for osint.bambenekconsulting.com --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index de9874f..dc3a3cb 100644 --- a/README.md +++ b/README.md @@ -88,7 +88,7 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea C&C Tracker From db7e5c025462684c80445ef62286dc90c130d797 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:18:50 +0200 Subject: [PATCH 6/7] Update DNSTrails link --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index dc3a3cb..3377caa 100644 --- a/README.md +++ b/README.md @@ -189,7 +189,7 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea
- ActorTrackr + ActorTrackr - ActorTrackr is an open source web application for storing/searching/linking actor related data. The primary sources are from users and various public repositories. Source available on GitHub. + ActorTrackr is an open source web application for storing/searching/linking actor related data. The primary sources are from users and various public repositories. Source available on GitHub.
- A feed of known, active and non-sinkholed C&C IP addresses, from Bambenek Consulting. + A feed of known, active and non-sinkholed C&C IP addresses, from Bambenek Consulting. Requires license for commercial use.
- DNSTrails + DNS Trails Free intelligence source for current and historical DNS information, WHOIS information, finding other websites associated with certain IPs, subdomain knowledge and technologies. There is a IP and domain intelligence API available as well. From 85a0c8689a9d11ee93fd044ded75c7612738b356 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Tue, 11 Oct 2022 00:23:38 +0200 Subject: [PATCH 7/7] Update VCDB GitHub repository link --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 3377caa..1a18ab2 100644 --- a/README.md +++ b/README.md @@ -758,7 +758,7 @@ Standardized formats for sharing Threat Intelligence (mostly IOCs). VERIS - The Vocabulary for Event Recording and Incident Sharing (VERIS) is a set of metrics designed to provide a common language for describing security incidents in a structured and repeatable manner. VERIS is a response to one of the most critical and persistent challenges in the security industry - a lack of quality information. In addition to providing a structured format, VERIS also collects data from the community to report on breaches in the Verizon Data Breach Investigations Report (DBIR) and publishes this database online at VCDB.org. + The Vocabulary for Event Recording and Incident Sharing (VERIS) is a set of metrics designed to provide a common language for describing security incidents in a structured and repeatable manner. VERIS is a response to one of the most critical and persistent challenges in the security industry - a lack of quality information. In addition to providing a structured format, VERIS also collects data from the community to report on breaches in the Verizon Data Breach Investigations Report (DBIR) and publishes this database online in a GitHub repository.org.