opencir/Opencir-Threat-Intelligence-IOCs
GitHub: opencir/Opencir-Threat-Intelligence-IOCs
一个自动化收集、整合和分发公开威胁情报源入侵指标(IOC)的统一管理平台,帮助安全团队将多源 OSINT 情报转化为可操作的防御规则。
Stars: 0 | Forks: 0
# 统一威胁情报 IOC 平台
自动收集、整合、验证和分发来自公开威胁情报源的入侵指标。
## 收集的 IOC 类型
| 类型 | 格式 | 用例 |
|---|---|---|
| IP 地址 | IPv4/IPv6 | 防火墙黑名单 (C2 服务器、恶意主机) |
| 文件哈希 | MD5, SHA1, SHA256 | EDR 阻断 (CrowdStrike, SentinelOne) |
| 域名 | FQDN | DNS sinkholing, 代理拦截 |
| URL | 完整 URL | Web 网关拦截 |
## 情报源
了解。您希望仅按以下高级类别组织 OSINT 来源:
1. **政府与 CERT**
2. **安全新闻媒体**
3. **安全研究博客**
以下是包含官方链接和来源类型的映射表。
# OSINT 威胁情报来源映射
## 1. 政府与 CERT
| 提供者 | 国家 / 地区 | 官方链接 | 来源类型 | 情报价值 |
| ------------------ | ---------------- | -------------------------------------------------------------------------------------------------------------------- | ----------------- | ---------------------------------------------- |
| CISA | 美国 | [https://www.cisa.gov/](https://www.cisa.gov/) | 通告 / 警报 | 漏洞、勒索软件、APT 活动、KEV |
| FBI Cyber Division | 美国 | [https://www.fbi.gov/investigate/cyber](https://www.fbi.gov/investigate/cyber) | 通告 | 网络犯罪、威胁行为者警报 |
| NSA Cybersecurity | 美国 | [https://www.nsa.gov/Cybersecurity/](https://www.nsa.gov/Cybersecurity/) | 通告 | 国家级威胁、防御指南 |
| US-CERT | 美国 | [https://www.cisa.gov/topics/cyber-threats-and-advisories](https://www.cisa.gov/topics/cyber-threats-and-advisories) | 通告 | 安全警报 |
| CERT-EU | 欧盟 | [https://cert.europa.eu/](https://cert.europa.eu/) | 通告 | 欧盟网络安全警报 |
| ENISA | 欧盟 | [https://www.enisa.europa.eu/](https://www.enisa.europa.eu/) | 报告 / 通告 | 威胁格局报告 |
| CERT Bund (BSI) | 德国 | [https://www.bsi.bund.de/](https://www.bsi.bund.de/) | 通告 | 漏洞、恶意软件、事件 |
| ANSSI | 法国 | [https://www.ssi.gouv.fr/](https://www.ssi.gouv.fr/) | 通告 | 安全通告 |
| NCSC UK | 英国 | [https://www.ncsc.gov.uk/](https://www.ncsc.gov.uk/) | 通告 | 威胁报告、指南 |
| NCSC Canada | 加拿大 | [https://www.cyber.gc.ca/](https://www.cyber.gc.ca/) | 通告 | 加拿大网络警报 |
| ACSC | 澳大利亚 | [https://www.cyber.gov.au/](https://www.cyber.gov.au/) | 通告 | 威胁情报、警报 |
| JPCERT/CC | 日本 | [https://www.jpcert.or.jp/english/](https://www.jpcert.or.jp/english/) | 通告 | 事件报告 |
| Singapore CSA | 新加坡 | [https://www.csa.gov.sg/](https://www.csa.gov.sg/) | 通告 | 网络警报 |
| CERT.at | 奥地利 | [https://www.cert.at/](https://www.cert.at/) | 通告 | 安全事件 |
| CERT Polska | 波兰 | [https://www.cert.pl/](https://www.cert.pl/) | 通告 | 恶意软件与钓鱼情报 |
# 2. 安全新闻媒体
| 提供者 | 官方链接 | 来源类型 | 情报价值 |
| --------------------- | -------------------------------------------------------------------------------- | ----------- | ------------------------------------ |
| The Hacker News | [https://thehackernews.com/](https://thehackernews.com/) | 新闻 / RSS | 突发威胁、漏洞 |
| BleepingComputer | [https://www.bleepingcomputer.com/](https://www.bleepingcomputer.com/) | 新闻 / RSS | 恶意软件、勒索软件、事件 |
| SecurityWeek | [https://www.securityweek.com/](https://www.securityweek.com/) | 新闻 | 漏洞、企业安全 |
| Dark Reading | [https://www.darkreading.com/](https://www.darkreading.com/) | 新闻 | 企业安全新闻 |
| CyberScoop | [https://cyberscoop.com/](https://cyberscoop.com/) | 新闻 | 政府网络安全 |
| The Record | [https://therecord.media/](https://therecord.media/) | 新闻 | 网络犯罪调查 |
| KrebsOnSecurity | [https://krebsonsecurity.com/](https://krebsonsecurity.com/) | 博客 / 新闻 | 调查性安全报道 |
| Help Net Security | [https://www.helpnetsecurity.com/](https://www.helpnetsecurity.com/) | 新闻 | 安全行业动态 |
| SC Media | [https://www.scmagazine.com/](https://www.scmagazine.com/) | 新闻 | 网络安全新闻 |
| Infosecurity Magazine | [https://www.infosecurity-magazine.com/](https://www.infosecurity-magazine.com/) | 新闻 | 安全趋势 |
| Security Affairs | [https://securityaffairs.com/](https://securityaffairs.com/) | 新闻 | 威胁报告 |
| CSO Online | [https://www.csoonline.com/](https://www.csoonline.com/) | 新闻 | 安全运营 |
# 3. 安全研究博客
| 提供者 | 官方链接 | 来源类型 | 情报价值 |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------- | ------------------- | --------------------------------- |
| Palo Alto Unit 42 | [https://unit42.paloaltonetworks.com/](https://unit42.paloaltonetworks.com/) | 研究博客 | APT、恶意软件、IOC 报告 |
| Cisco Talos | [https://blog.talosintelligence.com/](https://blog.talosintelligence.com/) | 研究博客 | 恶意软件、僵尸网络、漏洞 |
| Google Mandiant Threat Intelligence | [https://cloud.google.com/blog/topics/threat-intelligence](https://cloud.google.com/blog/topics/threat-intelligence) | 研究博客 | 国家级、APT 情报 |
| Microsoft Security Blog | [https://www.microsoft.com/security/blog/](https://www.microsoft.com/security/blog/) | 研究博客 | 威胁行为者、漏洞 |
| Google TAG | [https://blog.google/threat-analysis-group/](https://blog.google/threat-analysis-group/) | 研究博客 | 高级威胁组织 |
| CrowdStrike Blog | [https://www.crowdstrike.com/blog/](https://www.crowdstrike.com/blog/) | 研究博客 | 威胁情报 |
| SentinelLabs | [https://www.sentinelone.com/labs/](https://www.sentinelone.com/labs/) | 研究博客 | 恶意软件分析 |
| Sophos X-Ops | [https://news.sophos.com/en-us/category/x-ops/](https://news.sophos.com/en-us/category/x-ops/) | 研究博客 | 威胁研究 |
| FortiGuard Labs | [https://www.fortiguard.com/blog](https://www.fortiguard.com/blog) | 研究博客 | 恶意软件与漏洞利用 |
| Check Point Research | [https://research.checkpoint.com/](https://research.checkpoint.com/) | 研究博客 | 威胁活动 |
| Trend Micro Research | [https://www.trendmicro.com/en_us/research.html](https://www.trendmicro.com/en_us/research.html) | 研究博客 | 恶意软件研究 |
| ESET Research | [https://www.welivesecurity.com/](https://www.welivesecurity.com/) | 研究博客 | APT 与恶意软件 |
| Securelist (Kaspersky) | [https://securelist.com/](https://securelist.com/) | 研究博客 | 恶意软件情报 |
| Elastic Security Labs | [https://www.elastic.co/security-labs](https://www.elastic.co/security-labs) | 研究博客 | 检测研究 |
| Rapid7 Labs | [https://www.rapid7.com/blog/](https://www.rapid7.com/blog/) | 研究博客 | 漏洞与威胁 |
| Huntress | [https://www.huntress.com/blog](https://www.huntress.com/blog) | 研究博客 | 威胁狩猎 |
| Red Canary | [https://redcanary.com/blog/](https://redcanary.com/blog/) | 研究博客 | 检测工程 |
| Proofpoint Threat Research | [https://www.proofpoint.com/us/blog/threat-insight](https://www.proofpoint.com/us/blog/threat-insight) | 研究博客 | 电子邮件威胁、APT |
| Arctic Wolf Labs | [https://arcticwolf.com/resources/blog/](https://arcticwolf.com/resources/blog/) | 研究博客 | MDR 威胁研究 |
| VMware Threat Labs | [https://blogs.vmware.com/security/](https://blogs.vmware.com/security/) | 研究博客 | 云与端点威胁 |
| SANS Internet Storm Center | [https://isc.sans.edu/](https://isc.sans.edu/) | 研究博客 | 互联网威胁监控 |
| Project Zero | [https://googleprojectzero.blogspot.com/](https://googleprojectzero.blogspot.com/) | 研究博客 | 零日漏洞 |
| DFIR Report | [https://thedfirreport.com/](https://thedfirreport.com/) | 研究博客 | 真实入侵分析 |
| Malware Traffic Analysis | [https://www.malware-traffic-analysis.net/](https://www.malware-traffic-analysis.net/) | 研究博客 | PCAP 与 IOC 分析 |
| VX-Underground | [https://vx-underground.org/](https://vx-underground.org/) | 研究仓库 | 恶意软件样本 |
# OSINT 收集优先级建议
| 优先级 | 类别 | 示例 |
| -------- | ----------------------- | ------------------------------------ |
| Tier 1 | 政府与 CERT | CISA, CERT-EU, NCSC, CERT Bund |
| Tier 2 | 安全研究博客 | Unit 42, Talos, Mandiant, Microsoft |
| Tier 3 | 安全新闻 | BleepingComputer, Hacker News, Krebs |
| Tier 4 | 社区来源 | GitHub, Reddit, X/Twitter |
# 数据接入方法建议
| 来源类型 | 收集方法 |
| --------------- | ------------------------------------------------ |
| 政府 CERT | RSS, TAXII, API, STIX |
| 安全新闻 | RSS, 网页抓取 |
| 研究博客 | RSS, HTML 提取, IOC 解析器 |
| 报告 | PDF 提取, NLP 富化 |
| IOC 文章 | 自动化 IOC 提取 (IP, 域名, 哈希, CVE) |
此结构适用于**威胁情报平台 OSINT 接入层**,可直接映射到 OpenCTI/MISP 连接器中。
| 来源 | 情报源 | IOC 类型 | 更新频率 |
|---|---|---|---|
| [Microsoft 威胁情报](https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/?sort-by=newest-oldest) | 威胁情报博客 IOC | IP, 域名, 哈希, URL | 每月 |
| [CISA KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) | 被利用的 CVE | CVE | 每月 |
这是一份全面的参考——从截图中可见的内容开始,然后扩展到社区使用的完整威胁情报和 IOC 生态系统。以下是截图内容及更广泛生态系统的详细说明:
**从您的截图来看**,该工具似乎监控六个类别——政府 (CISA, CERT Bund, JPCERT, Cyber.mil),新闻媒体 (THN, TechPoint, Dark Reading),安全博客 (ZDNet, Trend Micro 和一个研究员博客),漏洞数据库 (NVD, MalwareBazaar, Qualys),供应商通告 (Microsoft, AWS, Cisco, Oracle),以及社交媒体 (X, YouTube, Mastodon, Reddit)。
**在截图之外**,社区在威胁狩猎和获取最新 IOC 时最常引用的来源包括:
**abuse.ch 生态系统** (ThreatFox, URLhaus, MalwareBazaar) 可能是使用最广泛的免费社区 IOC 来源。**AlienVault OTX** 是获取结构化威胁的另一个主要来源。**VirusTotal** 和 **Any.run** 是用于文件/URL 富化的标准工具。
对于**内嵌 IOC 的高质量研究博客**,主要的来源包括 Microsoft 安全博客(您提到的 URL 就是一个很好的例子)、Mandiant/Google TAG、Palo Alto Unit 42、Cisco Talos、SentinelOne Labs 和 Elastic Security Labs——它们经常发布附带哈希、IP 和 YARA 规则的完整攻击活动报告。
专门用于 **APT 追踪**方面,Malpedia 和 MITRE ATT&CK 框架是必不可少的参考点,此外还有 Recorded Future 和 CrowdStrike 的对手情报。
X/Twitter 上的 **#threatintel** 标签对于在 IOC 进入正式情报源数小时前捕捉到它们确实非常有用,尽管质量因研究员而异。
## 仓库结构
```
threat-intel-iocs/
├── feeds/
│ ├── msft_threat_intel.json
│ └── cisa_kev.json
├── consolidated/
│ ├── malicious_ips.txt
│ ├── malicious_domains.txt
│ ├── malicious_urls.txt
│ ├── malicious_hashes.csv
│ ├── cve_watchlist.txt
│ ├── ioc_master.json
│ ├── stix_bundle.json
│ └── run_stats.json
├── scripts/
│ ├── config.py
│ ├── fetch_msft.py
│ ├── fetch_cisa.py
│ ├── consolidate.py
│ └── validate.py
├── .github/workflows/
│ └── update_iocs.yml
├── requirements.txt
└── README.md
```
## 快速开始
### 本地运行
```
pip install -r requirements.txt
# 从所有 feeds 获取
python scripts/fetch_msft.py
python scripts/fetch_cisa.py
# 可选的 validation summary
python scripts/validate.py
# 合并为统一列表
python scripts/consolidate.py
```
### GitHub Actions
`.github/workflows/update_iocs.yml` 中的工作流每月
自动运行。
## 用于集成的输出格式
### 防火墙 (Palo Alto, Fortinet, pfSense)
使用 `consolidated/malicious_ips.txt` 的原始 URL 作为外部动态列表:
```
https://raw.githubusercontent.com///main/consolidated/malicious_ips.txt
```
### EDR 平台 (CrowdStrike, SentinelOne)
通过自定义 IOC 上传或 API 集成导入 `consolidated/malicious_hashes.csv`。该 CSV 使用的列包括:
```
hash,type,malware,source,first_seen
```
### SIEM (Splunk, Elastic)
通过计划查找或 API 拉取接入 `consolidated/ioc_master.json`。
## 验证逻辑
`validate.py` 会过滤掉格式错误或低价值的数据,包括:
- 私有/保留的 IP 范围和常见的公共解析器 IP
- 已知的良性基础设施域名
- 格式错误的域名、URL、哈希和 CVE 标识符
- 占位符哈希值
## 路线图
- [x] 阶段 1 — 情报源研究与架构
- [x] 阶段 2 — 基于 GitHub 的 IOC 收集
- [ ] 阶段 3 — 使用 STIX/TAXII 部署 OpenCTI
- [ ] 阶段 4 — 分发 API 与集成
- [ ] 阶段 5 — 富化、评分与 MITRE ATT&CK 标记
标签:ESC4, IOC, OSINT, 威胁情报, 安全, 开发者工具, 自动化收集, 超时处理, 逆向工具