Skip to content

Commit c56349a

Browse files
Daily TI-feed status update [07-06-2026]
1 parent 2c04550 commit c56349a

2 files changed

Lines changed: 16 additions & 16 deletions

File tree

README.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -430,7 +430,7 @@ Status legend: 🟢 Active – 🔴 Offline – 🔒 Restricted (requires API ke
430430
| --- | --- | :---: | --- |
431431
| CISA | Known Exploited Vulnerabilities Catalog (CSV) | <abbr title="Active">🟢</abbr> | [](https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv) |
432432
| CISA | Known Exploited Vulnerabilities Catalog (JSON) | <abbr title="Active">🟢</abbr> | [](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json) |
433-
| eCrimeLabs | Vulnerabilities with Metasploit exploit available | <abbr title="Active">🟢</abbr> | [](https://feeds.ecrimelabs.net/data/metasploit-cve) |
433+
| eCrimeLabs | Vulnerabilities with Metasploit exploit available | <abbr title="Offline">🔴</abbr> | [](https://feeds.ecrimelabs.net/data/metasploit-cve) |
434434
| NIST | National Vulnerability Database CVEs | <abbr title="Active">🟢</abbr> | [](https://services.nvd.nist.gov/rest/json/cves/2.0) |
435435

436436
### RANSOMWARELEAK (1)
@@ -446,7 +446,7 @@ Status legend: 🟢 Active – 🔴 Offline – 🔒 Restricted (requires API ke
446446
| abuse.ch | MalwareBazaar MISP feed (hashes + metadata) | <abbr title="Active">🟢</abbr> | [](https://bazaar.abuse.ch/downloads/misp/) |
447447
| abuse.ch | ThreatFox MISP feed (IOCs) | <abbr title="Active">🟢</abbr> | [](https://threatfox.abuse.ch/downloads/misp/) |
448448
| Botvrij.eu | Botvrij.eu OSINT MISP feed | <abbr title="Active">🟢</abbr> | [](https://www.botvrij.eu/data/feed-osint) |
449-
| MISP CIRCL | MISP CIRCL OSINT Feed – Hashes | <abbr title="Offline">🔴</abbr> | [](https://www.circl.lu/doc/misp/feed-osint/) |
449+
| MISP CIRCL | MISP CIRCL OSINT Feed – Hashes | <abbr title="Active">🟢</abbr> | [](https://www.circl.lu/doc/misp/feed-osint/) |
450450
| MISP Feed CERT-FR | MISP Feed CERT-FR Hashes | <abbr title="Active">🟢</abbr> | [](https://misp.cert.ssi.gouv.fr/feed-misp/hashes.csv) |
451451

452452
### IOC (34)
@@ -464,20 +464,20 @@ Status legend: 🟢 Active – 🔴 Offline – 🔒 Restricted (requires API ke
464464
| mthcht | Suspicious User-agent | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv) |
465465
| mthcht | Suspicious USB Ids | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_usb_ids_list.csv) |
466466
| mthcht | Suspicious mutex names | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_mutex_names_list.csv) |
467-
| mthcht | Suspicious MAC address | <abbr title="Offline">🔴</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_mac_address_list.csv) |
467+
| mthcht | Suspicious MAC address | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_mac_address_list.csv) |
468468
| mthcht | Suspicious Hostname | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_hostnames_list.csv) |
469469
| mthcht | Microsoft App IDs List (BEC Detection) | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/microsoft_apps_list.csv) |
470470
| mthcht | Metadata Executables | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Windows%20Metadata/executables_metadata_informations_list.csv) |
471471
| mthcht | DNS over HTTPS server list | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/dns_over_https_servers_list.csv) |
472472
| mthcht | Dynamic DNS domains list | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/DYNDNS/dyndns_list.csv) |
473473
| mthcht | Sinkholed Domains | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Domains/sinkholed_servers/sinkholed_domains.csv) |
474-
| mthcht | Hijacklibs | <abbr title="Offline">🔴</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Hijacklibs/hijacklibs_list.csv) |
474+
| mthcht | Hijacklibs | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Hijacklibs/hijacklibs_list.csv) |
475475
| mthcht | LOLDriver List | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Drivers/loldrivers_only_hashes_list.csv) |
476-
| mthcht | Malicious Bootloader List | <abbr title="Offline">🔴</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Drivers/malicious_bootloaders_only_hashes_list.csv) |
476+
| mthcht | Malicious Bootloader List | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/Drivers/malicious_bootloaders_only_hashes_list.csv) |
477477
| mthcht | Malicious SSL Certificates List | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/SSL%20CERTS/ssl_certificates_malicious_list.csv) |
478478
| mthcht | Ransomware known file extensions | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/ransomware_extensions_list.csv) |
479479
| mthcht | Ransomware known file name ransom notes | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/ransomware_notes_list.csv) |
480-
| mthcht | Windows ASR rules | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/windows_asr_rules.csv) |
480+
| mthcht | Windows ASR rules | <abbr title="Offline">🔴</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/windows_asr_rules.csv) |
481481
| mthcht | GeoIP services Lists | <abbr title="Active">🟢</abbr> | [](https://github.com/mthcht/awesome-lists/blob/main/Lists/GeoIP/ip_location_sites_list.csv) |
482482
| rosti.bin | Public threat intelligence reports feed | <abbr title="Active">🟢</abbr> | [](https://rosti.bin.re/feeds) |
483483
| SentinelPhishFeed | File hash IOCs (MD5/SHA) | <abbr title="Active">🟢</abbr> | [](https://raw.githubusercontent.com/rjn32s/SentinelPhishFeed/main/hashes.txt) |
@@ -626,8 +626,8 @@ Status legend: 🟢 Active – 🔴 Offline – 🔒 Restricted (requires API ke
626626

627627
| Vendor | Description | Status | URL |
628628
| --- | --- | :---: | --- |
629-
| CERT-UA | CERT UA RSS Feed | <abbr title="Active">🟢</abbr> | [](https://cert.gov.ua/api/articles/rss) |
630-
| Checkpoint | Checkpoint Research Feed | <abbr title="Active">🟢</abbr> | [](https://research.checkpoint.com/feed) |
629+
| CERT-UA | CERT UA RSS Feed | <abbr title="Offline">🔴</abbr> | [](https://cert.gov.ua/api/articles/rss) |
630+
| Checkpoint | Checkpoint Research Feed | <abbr title="Offline">🔴</abbr> | [](https://research.checkpoint.com/feed) |
631631
| CISA | CISA Cybersecurity Advisories | <abbr title="Active">🟢</abbr> | [](https://www.cisa.gov/cybersecurity-advisories/all.xml) |
632632
| Cisco | Talos Intelligence Feed | <abbr title="Active">🟢</abbr> | [](https://feeds.feedburner.com/feedburner/Talos) |
633633
| Google | Google Threat Intelligence Feed | <abbr title="Active">🟢</abbr> | [](https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v) |

threat-intelligence-feeds.csv

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ Phishing Army;Phishing Army Blocklist Extended;URL;https://phishing.army/downloa
5959
Binarydefense;Binary Defense Artillery Threat Intelligence Banlist;IP;https://www.binarydefense.com/banlist.txt;Active
6060
CISA;Known Exploited Vulnerabilities Catalog (CSV);CVEID;https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv;Active
6161
CISA;Known Exploited Vulnerabilities Catalog (JSON);CVEID;https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json;Active
62-
eCrimeLabs;Vulnerabilities with Metasploit exploit available;CVEID;https://feeds.ecrimelabs.net/data/metasploit-cve;Active
62+
eCrimeLabs;Vulnerabilities with Metasploit exploit available;CVEID;https://feeds.ecrimelabs.net/data/metasploit-cve;Offline
6363
MISP Feed CERT-FR;MISP Feed CERT-FR Hashes;MISP;https://misp.cert.ssi.gouv.fr/feed-misp/hashes.csv;Active
6464
OpenPhish;Phishing URLs;URL;https://openphish.com/feed.txt;Active
6565
Cert.PL;Malicious Domains;DNS;https://hole.cert.pl/domains/domains.csv;Active
@@ -99,7 +99,7 @@ DataPlane;VNC RFB Source IPs;IP;https://dataplane.org/vncrfb.txt;Active
9999
CriticalPathSecurity;Abuse.ch IP Blocklist Feed;IP;https://raw.githubusercontent.com/CriticalPathSecurity/Public-Intelligence-Feeds/master/abuse-ch-ipblocklist.txt;Active
100100
CriticalPathSecurity;Log4j Scanners and Exploiters;IP;https://raw.githubusercontent.com/CriticalPathSecurity/Public-Intelligence-Feeds/master/log4j.txt;Active
101101
MISP Project;MISP Default Feeds (metadata);URL;https://raw.githubusercontent.com/MISP/MISP/2.4/app/files/feed-metadata/defaults.json;Active
102-
MISP CIRCL;MISP CIRCL OSINT Feed – Hashes;MISP;https://www.circl.lu/doc/misp/feed-osint/;Offline
102+
MISP CIRCL;MISP CIRCL OSINT Feed – Hashes;MISP;https://www.circl.lu/doc/misp/feed-osint/;Active
103103
MISP Abuse.ch;MISP Abuse.ch URLhaus;URL;https://urlhaus.abuse.ch/downloads/misp/;Active
104104
TorProject;Tor Exit Addresses (TorProject official);IP;https://check.torproject.org/exit-addresses;Active
105105
darklist.de;Darklist.de IP Blacklist;IP;http://www.darklist.de/raw.php;Active
@@ -343,20 +343,20 @@ mthcht;Suspicious Firewall rules;IOC;https://github.com/mthcht/awesome-lists/blo
343343
mthcht;Suspicious User-agent;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv;Active
344344
mthcht;Suspicious USB Ids;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_usb_ids_list.csv;Active
345345
mthcht;Suspicious mutex names;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_mutex_names_list.csv;Active
346-
mthcht;Suspicious MAC address;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_mac_address_list.csv;Offline
346+
mthcht;Suspicious MAC address;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_mac_address_list.csv;Active
347347
mthcht;Suspicious Hostname;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_hostnames_list.csv;Active
348348
mthcht;Microsoft App IDs List (BEC Detection);IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/microsoft_apps_list.csv;Active
349349
mthcht;Metadata Executables;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Windows%20Metadata/executables_metadata_informations_list.csv;Active
350350
mthcht;DNS over HTTPS server list;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/dns_over_https_servers_list.csv;Active
351351
mthcht;Dynamic DNS domains list;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/DYNDNS/dyndns_list.csv;Active
352352
mthcht;Sinkholed Domains;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Domains/sinkholed_servers/sinkholed_domains.csv;Active
353-
mthcht;Hijacklibs;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Hijacklibs/hijacklibs_list.csv;Offline
353+
mthcht;Hijacklibs;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Hijacklibs/hijacklibs_list.csv;Active
354354
mthcht;LOLDriver List;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Drivers/loldrivers_only_hashes_list.csv;Active
355-
mthcht;Malicious Bootloader List;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Drivers/malicious_bootloaders_only_hashes_list.csv;Offline
355+
mthcht;Malicious Bootloader List;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/Drivers/malicious_bootloaders_only_hashes_list.csv;Active
356356
mthcht;Malicious SSL Certificates List;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/SSL%20CERTS/ssl_certificates_malicious_list.csv;Active
357357
mthcht;Ransomware known file extensions;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/ransomware_extensions_list.csv;Active
358358
mthcht;Ransomware known file name ransom notes;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/ransomware_notes_list.csv;Active
359-
mthcht;Windows ASR rules;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/windows_asr_rules.csv;Active
359+
mthcht;Windows ASR rules;IOC;https://github.com/mthcht/awesome-lists/blob/main/Lists/windows_asr_rules.csv;Offline
360360
mthcht;VPN NordVPN IPs;IP;https://github.com/mthcht/awesome-lists/blob/main/Lists/VPN/NordVPN/nordvpn_ips_list.csv;Active
361361
mthcht;VPN SurfShark IPs;IP;https://github.com/mthcht/awesome-lists/blob/main/Lists/VPN/SurfSharkVPN/surfshark_vpn_servers_domains_and_ips_list.csv;Active
362362
mthcht;VPN MullVad IPs;IP;https://github.com/mthcht/awesome-lists/blob/main/Lists/VPN/MullVad/mullvad_relay_servers_ips_list.csv;Active
@@ -397,14 +397,14 @@ lolc2;LOLC2;REPO;https://github.com/lolc2/lolc2.github.io;Active
397397
LOLESXi-Project;LOLESXI;REPO;https://github.com/LOLESXi-Project/LOLESXi;Active
398398
LOLOLFarm;LOLOLFarm;URL;https://lolol.farm/;Active
399399
BushidoUK;Tools used by Russian APT;REPO;https://github.com/BushidoUK/Russian-APT-Tool-Matrix;Active
400-
CERT-UA;CERT UA RSS Feed;RSS;https://cert.gov.ua/api/articles/rss;Active
400+
CERT-UA;CERT UA RSS Feed;RSS;https://cert.gov.ua/api/articles/rss;Offline
401401
CISA;CISA Cybersecurity Advisories;RSS;https://www.cisa.gov/cybersecurity-advisories/all.xml;Active
402402
Microsoft;Microsoft Threat Intel Feed;RSS;https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/feed;Active
403403
Google;Google Threat Intelligence Feed;RSS;https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v;Active
404404
Palo Alto;Unit42 Threat Intel RSS;RSS;https://unit42.paloaltonetworks.com/feed/;Active
405405
Cisco;Talos Intelligence Feed;RSS;https://feeds.feedburner.com/feedburner/Talos;Active
406406
TheDFIRReport;The DFIR Report Feed;RSS;https://thedfirreport.com/feed/;Active
407-
Checkpoint;Checkpoint Research Feed;RSS;https://research.checkpoint.com/feed;Active
407+
Checkpoint;Checkpoint Research Feed;RSS;https://research.checkpoint.com/feed;Offline
408408
Kaspersky;Securelist APT Attacks Feed;RSS;https://securelist.com/threat-category/apt-targeted-attacks/feed/;Active
409409
MITRE;MITRE ATT&CK Matrix Navigator;FRAMEWORK;https://mitre-attack.github.io/attack-navigator/;Active
410410
MITRE;CVE Vulnerability Database;FRAMEWORK;https://cve.mitre.org/;Active

0 commit comments

Comments
 (0)