Skip to content

Latest commit

 

History

History
31 lines (27 loc) · 1011 Bytes

TI Feed - AbuseCHIPBlacklistFeed.md

File metadata and controls

31 lines (27 loc) · 1011 Bytes

Abuse.ch Botnet C2 IP Blacklist to detect external C2 connections

Source: Abuse.ch

Defender For Endpoint

let ThreatIntelFeed = externaldata(DestIP: string)[@"https://sslbl.abuse.ch/blacklistsslipblacklist.txt"] with (format="txt", ignoreFirstRecord=True);
let IPRegex = '[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}';
let MaliciousIP = materialize (
     ThreatIntelFeed
     | where DestIP matches regex IPRegex
     | distinct DestIP
     );
DeviceNetworkEvents
| where RemoteIP in (MaliciousIP)

Sentinel

let ThreatIntelFeed = externaldata(DestIP: string)[@"https://sslbl.abuse.ch/blacklistsslipblacklist.txt"] with (format="txt", ignoreFirstRecord=True);
let IPRegex = '[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}';
let MaliciousIP = materialize (
     ThreatIntelFeed
     | where DestIP matches regex IPRegex
     | distinct DestIP
     );
DeviceNetworkEvents
| where RemoteIP in (MaliciousIP)