网络安全小助手

网络安全三分靠技术、七分靠管理,良好的网络安全意识加上全面的网络安全技术,才是降低网络安全风险的重点。

网络安全新闻

网络安全情报

网络安全应急响应资料

网络安全应急响应工具

网络安全事件验证

国外网络安全情报网站

Suricata/Snort规则集

测试数据包下载网站

规则SID规划表

SID范围 组织 备注
1000000-1999999本地自定义规则预留
2000000-2103999Emerging ThreatsEmerging Threats Open
2200000-2299999OISFSuricata Engine Events
2400000-2609999Emerging ThreatsEmerging Threats Open
2610000-2619999Travis GreenHunting Ruleset
2620000-26299993CORESecLateral Movement Ruleset
2700000-2799999Emerging ThreatsEmerging Threats
2800000-2899999Emerging ThreatsEmerging Threats Pro
3000000-3099999CorelightCorelight Github
3100000-3199999Stamus NetworksStamus Networks Detection
3200000-3299999DCSODCSO CyTec, DCSO Github
3300000-3399999PawpatrulesPAW Patrules
4000000-4099999ExtraHopExtraHop IDS
5000000-5000213Etnetera a.s.Etnetera aggressive IP blacklist
5000000-5000033MalSiloMalSilo
7724000-77260003CORESecSinkholes Ruleset
10000000-11999999Positive TechnologiesPT Security Attack Detection Team ruleset
27990000-27999999jpgviewDOH Rules
902200000-906200096Abuse.chAbuse.ch

近期攻击IP地址

国外第三方开源情报数据下载

序号 URL 操作
1DOMAIN-High-Confidence-Feed.txt
2domainC2s.csv
3domainC2swithURL.csv
4domainC2swithURLwithIP.csv
5latestdomains.txt
6gist raw
7blocklist.de all.txt
8bruteforceblocker
9jamesbrine.com.au
10ci-badguys.txt
11ThreatMon-Daily-C2-Feeds
12C2-Tracker
13ellio.tech community-feed
14latesthashes.txt
15CIRCL MISP OSINT
16URLhaus text feed
17latestips.txt
18FeodoTracker IP blocklist
19stamparm ipsum
20latesturls.txt
21ipblocklist.csv
22OpenPhish feed
23Phishing Army
24FeodoTracker blocklist
25bots.txt
26CoinBlockerLists
27Tor Exit Nodes
28Tor-IP-Addresses