网络安全小助手

网络安全三分靠技术、七分靠管理,良好的网络安全意识加上全面的网络安全技术,才是降低网络安全风险的重点。

网络安全新闻

网络安全情报

网络安全应急响应资料

网络安全应急响应工具

网络安全事件验证

国外网络安全情报网站

Suricata/Snort规则集

测试数据包下载网站

规则SID规划表

SID范围 组织 备注
1000000-1999999本地自定义规则预留
2000000-2103999Emerging ThreatsEmerging Threats Open
2200000-2299999OISFSuricata Engine Events
2400000-2609999Emerging ThreatsEmerging Threats Open
2610000-2619999Travis GreenHunting Ruleset
2620000-26299993CORESecLateral Movement Ruleset
2700000-2799999Emerging ThreatsEmerging Threats
2800000-2899999Emerging ThreatsEmerging Threats Pro
3000000-3099999CorelightCorelight Github
3100000-3199999Stamus NetworksStamus Networks Detection
3200000-3299999DCSODCSO CyTec, DCSO Github
3300000-3399999PawpatrulesPAW Patrules
4000000-4099999ExtraHopExtraHop IDS
5000000-5000213Etnetera a.s.Etnetera aggressive IP blacklist
5000000-5000033MalSiloMalSilo
7724000-77260003CORESecSinkholes Ruleset
10000000-11999999Positive TechnologiesPT Security Attack Detection Team ruleset
27990000-27999999jpgviewDOH Rules
902200000-906200096Abuse.chAbuse.ch

近期攻击IP地址

国外第三方开源情报数据下载

序号 URL 操作
1

DOMAIN-High-Confidence-Feed.txt

2

domainC2s.csv

3

domainC2swithURL.csv

4

domainC2swithURLwithIP.csv

5

latestdomains.txt

6

gist raw

7

blocklist.de all.txt

8

bruteforceblocker

9

jamesbrine.com.au

10

ci-badguys.txt

11

ThreatMon-Daily-C2-Feeds

12

C2-Tracker

13

ellio.tech community-feed

14

latesthashes.txt

15

CIRCL MISP OSINT

16

URLhaus text feed

17

latestips.txt

18

FeodoTracker IP blocklist

19

stamparm ipsum

20

latesturls.txt

21

ipblocklist.csv

22

OpenPhish feed

23

Phishing Army

24

FeodoTracker blocklist

25

bots.txt

26

CoinBlockerLists

27

Tor Exit Nodes

28

Tor-IP-Addresses