opencir/Opencir-Threat-Intelligence-IOCs

GitHub: opencir/Opencir-Threat-Intelligence-IOCs

一个自动化收集、整合和分发公开威胁情报源入侵指标(IOC)的统一管理平台,帮助安全团队将多源 OSINT 情报转化为可操作的防御规则。

Stars: 0 | Forks: 0

# 统一威胁情报 IOC 平台 自动收集、整合、验证和分发来自公开威胁情报源的入侵指标。 ## 收集的 IOC 类型 | 类型 | 格式 | 用例 | |---|---|---| | IP 地址 | IPv4/IPv6 | 防火墙黑名单 (C2 服务器、恶意主机) | | 文件哈希 | MD5, SHA1, SHA256 | EDR 阻断 (CrowdStrike, SentinelOne) | | 域名 | FQDN | DNS sinkholing, 代理拦截 | | URL | 完整 URL | Web 网关拦截 | ## 情报源 了解。您希望仅按以下高级类别组织 OSINT 来源: 1. **政府与 CERT** 2. **安全新闻媒体** 3. **安全研究博客** 以下是包含官方链接和来源类型的映射表。 # OSINT 威胁情报来源映射 ## 1. 政府与 CERT | 提供者 | 国家 / 地区 | 官方链接 | 来源类型 | 情报价值 | | ------------------ | ---------------- | -------------------------------------------------------------------------------------------------------------------- | ----------------- | ---------------------------------------------- | | CISA | 美国 | [https://www.cisa.gov/](https://www.cisa.gov/) | 通告 / 警报 | 漏洞、勒索软件、APT 活动、KEV | | FBI Cyber Division | 美国 | [https://www.fbi.gov/investigate/cyber](https://www.fbi.gov/investigate/cyber) | 通告 | 网络犯罪、威胁行为者警报 | | NSA Cybersecurity | 美国 | [https://www.nsa.gov/Cybersecurity/](https://www.nsa.gov/Cybersecurity/) | 通告 | 国家级威胁、防御指南 | | US-CERT | 美国 | [https://www.cisa.gov/topics/cyber-threats-and-advisories](https://www.cisa.gov/topics/cyber-threats-and-advisories) | 通告 | 安全警报 | | CERT-EU | 欧盟 | [https://cert.europa.eu/](https://cert.europa.eu/) | 通告 | 欧盟网络安全警报 | | ENISA | 欧盟 | [https://www.enisa.europa.eu/](https://www.enisa.europa.eu/) | 报告 / 通告 | 威胁格局报告 | | CERT Bund (BSI) | 德国 | [https://www.bsi.bund.de/](https://www.bsi.bund.de/) | 通告 | 漏洞、恶意软件、事件 | | ANSSI | 法国 | [https://www.ssi.gouv.fr/](https://www.ssi.gouv.fr/) | 通告 | 安全通告 | | NCSC UK | 英国 | [https://www.ncsc.gov.uk/](https://www.ncsc.gov.uk/) | 通告 | 威胁报告、指南 | | NCSC Canada | 加拿大 | [https://www.cyber.gc.ca/](https://www.cyber.gc.ca/) | 通告 | 加拿大网络警报 | | ACSC | 澳大利亚 | [https://www.cyber.gov.au/](https://www.cyber.gov.au/) | 通告 | 威胁情报、警报 | | JPCERT/CC | 日本 | [https://www.jpcert.or.jp/english/](https://www.jpcert.or.jp/english/) | 通告 | 事件报告 | | Singapore CSA | 新加坡 | [https://www.csa.gov.sg/](https://www.csa.gov.sg/) | 通告 | 网络警报 | | CERT.at | 奥地利 | [https://www.cert.at/](https://www.cert.at/) | 通告 | 安全事件 | | CERT Polska | 波兰 | [https://www.cert.pl/](https://www.cert.pl/) | 通告 | 恶意软件与钓鱼情报 | # 2. 安全新闻媒体 | 提供者 | 官方链接 | 来源类型 | 情报价值 | | --------------------- | -------------------------------------------------------------------------------- | ----------- | ------------------------------------ | | The Hacker News | [https://thehackernews.com/](https://thehackernews.com/) | 新闻 / RSS | 突发威胁、漏洞 | | BleepingComputer | [https://www.bleepingcomputer.com/](https://www.bleepingcomputer.com/) | 新闻 / RSS | 恶意软件、勒索软件、事件 | | SecurityWeek | [https://www.securityweek.com/](https://www.securityweek.com/) | 新闻 | 漏洞、企业安全 | | Dark Reading | [https://www.darkreading.com/](https://www.darkreading.com/) | 新闻 | 企业安全新闻 | | CyberScoop | [https://cyberscoop.com/](https://cyberscoop.com/) | 新闻 | 政府网络安全 | | The Record | [https://therecord.media/](https://therecord.media/) | 新闻 | 网络犯罪调查 | | KrebsOnSecurity | [https://krebsonsecurity.com/](https://krebsonsecurity.com/) | 博客 / 新闻 | 调查性安全报道 | | Help Net Security | [https://www.helpnetsecurity.com/](https://www.helpnetsecurity.com/) | 新闻 | 安全行业动态 | | SC Media | [https://www.scmagazine.com/](https://www.scmagazine.com/) | 新闻 | 网络安全新闻 | | Infosecurity Magazine | [https://www.infosecurity-magazine.com/](https://www.infosecurity-magazine.com/) | 新闻 | 安全趋势 | | Security Affairs | [https://securityaffairs.com/](https://securityaffairs.com/) | 新闻 | 威胁报告 | | CSO Online | [https://www.csoonline.com/](https://www.csoonline.com/) | 新闻 | 安全运营 | # 3. 安全研究博客 | 提供者 | 官方链接 | 来源类型 | 情报价值 | | ----------------------------------- | -------------------------------------------------------------------------------------------------------------------- | ------------------- | --------------------------------- | | Palo Alto Unit 42 | [https://unit42.paloaltonetworks.com/](https://unit42.paloaltonetworks.com/) | 研究博客 | APT、恶意软件、IOC 报告 | | Cisco Talos | [https://blog.talosintelligence.com/](https://blog.talosintelligence.com/) | 研究博客 | 恶意软件、僵尸网络、漏洞 | | Google Mandiant Threat Intelligence | [https://cloud.google.com/blog/topics/threat-intelligence](https://cloud.google.com/blog/topics/threat-intelligence) | 研究博客 | 国家级、APT 情报 | | Microsoft Security Blog | [https://www.microsoft.com/security/blog/](https://www.microsoft.com/security/blog/) | 研究博客 | 威胁行为者、漏洞 | | Google TAG | [https://blog.google/threat-analysis-group/](https://blog.google/threat-analysis-group/) | 研究博客 | 高级威胁组织 | | CrowdStrike Blog | [https://www.crowdstrike.com/blog/](https://www.crowdstrike.com/blog/) | 研究博客 | 威胁情报 | | SentinelLabs | [https://www.sentinelone.com/labs/](https://www.sentinelone.com/labs/) | 研究博客 | 恶意软件分析 | | Sophos X-Ops | [https://news.sophos.com/en-us/category/x-ops/](https://news.sophos.com/en-us/category/x-ops/) | 研究博客 | 威胁研究 | | FortiGuard Labs | [https://www.fortiguard.com/blog](https://www.fortiguard.com/blog) | 研究博客 | 恶意软件与漏洞利用 | | Check Point Research | [https://research.checkpoint.com/](https://research.checkpoint.com/) | 研究博客 | 威胁活动 | | Trend Micro Research | [https://www.trendmicro.com/en_us/research.html](https://www.trendmicro.com/en_us/research.html) | 研究博客 | 恶意软件研究 | | ESET Research | [https://www.welivesecurity.com/](https://www.welivesecurity.com/) | 研究博客 | APT 与恶意软件 | | Securelist (Kaspersky) | [https://securelist.com/](https://securelist.com/) | 研究博客 | 恶意软件情报 | | Elastic Security Labs | [https://www.elastic.co/security-labs](https://www.elastic.co/security-labs) | 研究博客 | 检测研究 | | Rapid7 Labs | [https://www.rapid7.com/blog/](https://www.rapid7.com/blog/) | 研究博客 | 漏洞与威胁 | | Huntress | [https://www.huntress.com/blog](https://www.huntress.com/blog) | 研究博客 | 威胁狩猎 | | Red Canary | [https://redcanary.com/blog/](https://redcanary.com/blog/) | 研究博客 | 检测工程 | | Proofpoint Threat Research | [https://www.proofpoint.com/us/blog/threat-insight](https://www.proofpoint.com/us/blog/threat-insight) | 研究博客 | 电子邮件威胁、APT | | Arctic Wolf Labs | [https://arcticwolf.com/resources/blog/](https://arcticwolf.com/resources/blog/) | 研究博客 | MDR 威胁研究 | | VMware Threat Labs | [https://blogs.vmware.com/security/](https://blogs.vmware.com/security/) | 研究博客 | 云与端点威胁 | | SANS Internet Storm Center | [https://isc.sans.edu/](https://isc.sans.edu/) | 研究博客 | 互联网威胁监控 | | Project Zero | [https://googleprojectzero.blogspot.com/](https://googleprojectzero.blogspot.com/) | 研究博客 | 零日漏洞 | | DFIR Report | [https://thedfirreport.com/](https://thedfirreport.com/) | 研究博客 | 真实入侵分析 | | Malware Traffic Analysis | [https://www.malware-traffic-analysis.net/](https://www.malware-traffic-analysis.net/) | 研究博客 | PCAP 与 IOC 分析 | | VX-Underground | [https://vx-underground.org/](https://vx-underground.org/) | 研究仓库 | 恶意软件样本 | # OSINT 收集优先级建议 | 优先级 | 类别 | 示例 | | -------- | ----------------------- | ------------------------------------ | | Tier 1 | 政府与 CERT | CISA, CERT-EU, NCSC, CERT Bund | | Tier 2 | 安全研究博客 | Unit 42, Talos, Mandiant, Microsoft | | Tier 3 | 安全新闻 | BleepingComputer, Hacker News, Krebs | | Tier 4 | 社区来源 | GitHub, Reddit, X/Twitter | # 数据接入方法建议 | 来源类型 | 收集方法 | | --------------- | ------------------------------------------------ | | 政府 CERT | RSS, TAXII, API, STIX | | 安全新闻 | RSS, 网页抓取 | | 研究博客 | RSS, HTML 提取, IOC 解析器 | | 报告 | PDF 提取, NLP 富化 | | IOC 文章 | 自动化 IOC 提取 (IP, 域名, 哈希, CVE) | 此结构适用于**威胁情报平台 OSINT 接入层**,可直接映射到 OpenCTI/MISP 连接器中。 | 来源 | 情报源 | IOC 类型 | 更新频率 | |---|---|---|---| | [Microsoft 威胁情报](https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/?sort-by=newest-oldest) | 威胁情报博客 IOC | IP, 域名, 哈希, URL | 每月 | | [CISA KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) | 被利用的 CVE | CVE | 每月 | 这是一份全面的参考——从截图中可见的内容开始,然后扩展到社区使用的完整威胁情报和 IOC 生态系统。以下是截图内容及更广泛生态系统的详细说明: **从您的截图来看**,该工具似乎监控六个类别——政府 (CISA, CERT Bund, JPCERT, Cyber.mil),新闻媒体 (THN, TechPoint, Dark Reading),安全博客 (ZDNet, Trend Micro 和一个研究员博客),漏洞数据库 (NVD, MalwareBazaar, Qualys),供应商通告 (Microsoft, AWS, Cisco, Oracle),以及社交媒体 (X, YouTube, Mastodon, Reddit)。 **在截图之外**,社区在威胁狩猎和获取最新 IOC 时最常引用的来源包括: **abuse.ch 生态系统** (ThreatFox, URLhaus, MalwareBazaar) 可能是使用最广泛的免费社区 IOC 来源。**AlienVault OTX** 是获取结构化威胁的另一个主要来源。**VirusTotal** 和 **Any.run** 是用于文件/URL 富化的标准工具。 对于**内嵌 IOC 的高质量研究博客**,主要的来源包括 Microsoft 安全博客(您提到的 URL 就是一个很好的例子)、Mandiant/Google TAG、Palo Alto Unit 42、Cisco Talos、SentinelOne Labs 和 Elastic Security Labs——它们经常发布附带哈希、IP 和 YARA 规则的完整攻击活动报告。 专门用于 **APT 追踪**方面,Malpedia 和 MITRE ATT&CK 框架是必不可少的参考点,此外还有 Recorded Future 和 CrowdStrike 的对手情报。 X/Twitter 上的 **#threatintel** 标签对于在 IOC 进入正式情报源数小时前捕捉到它们确实非常有用,尽管质量因研究员而异。 ## 仓库结构 ``` threat-intel-iocs/ ├── feeds/ │ ├── msft_threat_intel.json │ └── cisa_kev.json ├── consolidated/ │ ├── malicious_ips.txt │ ├── malicious_domains.txt │ ├── malicious_urls.txt │ ├── malicious_hashes.csv │ ├── cve_watchlist.txt │ ├── ioc_master.json │ ├── stix_bundle.json │ └── run_stats.json ├── scripts/ │ ├── config.py │ ├── fetch_msft.py │ ├── fetch_cisa.py │ ├── consolidate.py │ └── validate.py ├── .github/workflows/ │ └── update_iocs.yml ├── requirements.txt └── README.md ``` ## 快速开始 ### 本地运行 ``` pip install -r requirements.txt # 从所有 feeds 获取 python scripts/fetch_msft.py python scripts/fetch_cisa.py # 可选的 validation summary python scripts/validate.py # 合并为统一列表 python scripts/consolidate.py ``` ### GitHub Actions `.github/workflows/update_iocs.yml` 中的工作流每月 自动运行。 ## 用于集成的输出格式 ### 防火墙 (Palo Alto, Fortinet, pfSense) 使用 `consolidated/malicious_ips.txt` 的原始 URL 作为外部动态列表: ``` https://raw.githubusercontent.com///main/consolidated/malicious_ips.txt ``` ### EDR 平台 (CrowdStrike, SentinelOne) 通过自定义 IOC 上传或 API 集成导入 `consolidated/malicious_hashes.csv`。该 CSV 使用的列包括: ``` hash,type,malware,source,first_seen ``` ### SIEM (Splunk, Elastic) 通过计划查找或 API 拉取接入 `consolidated/ioc_master.json`。 ## 验证逻辑 `validate.py` 会过滤掉格式错误或低价值的数据,包括: - 私有/保留的 IP 范围和常见的公共解析器 IP - 已知的良性基础设施域名 - 格式错误的域名、URL、哈希和 CVE 标识符 - 占位符哈希值 ## 路线图 - [x] 阶段 1 — 情报源研究与架构 - [x] 阶段 2 — 基于 GitHub 的 IOC 收集 - [ ] 阶段 3 — 使用 STIX/TAXII 部署 OpenCTI - [ ] 阶段 4 — 分发 API 与集成 - [ ] 阶段 5 — 富化、评分与 MITRE ATT&CK 标记
标签:ESC4, IOC, OSINT, 威胁情报, 安全, 开发者工具, 自动化收集, 超时处理, 逆向工具