From 69a0e3aab9e18797b97af00afac65c1e2f851a6b Mon Sep 17 00:00:00 2001 From: Johnny Date: Tue, 1 Aug 2017 14:43:36 -0700 Subject: [PATCH 1/5] Adds list of disposable email account domains. --- README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/README.md b/README.md index 9810d83..d651bf9 100644 --- a/README.md +++ b/README.md @@ -115,6 +115,14 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea Cymon is an aggregator of indicators from multiple sources with history, so you have a single interface to multiple threat feeds. It also provides an API to search a database along with a pretty web interface. + + + Disposable Email Domains + + + A collection of anonymous or disposable email domains commonly used to spam/abuse services. + + Emerging Threats Firewall Rules From 9d55e814ff7054cc650f93f356ec8d09dabf980d Mon Sep 17 00:00:00 2001 From: x-x-x-x Date: Tue, 8 Aug 2017 11:36:50 -0400 Subject: [PATCH 2/5] Added GOSINT for IOC consumption --- README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/README.md b/README.md index 9810d83..4fb401a 100644 --- a/README.md +++ b/README.md @@ -170,6 +170,14 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea FraudGuard is a service designed to provide an easy way to validate usage by continuously collecting and analyzing real-time internet traffic. + + + + GOSINT + + + The GOSINT framework is a free project used for collecting, processing, and exporting high quality public indicators of compromise (IOCs). + From 8556bd565ba028c782205dd33696cf2b37e4e40e Mon Sep 17 00:00:00 2001 From: Thomas Chopitea Date: Thu, 10 Aug 2017 19:19:20 +0200 Subject: [PATCH 3/5] Added Yeti --- README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/README.md b/README.md index 9810d83..5bf4fc0 100644 --- a/README.md +++ b/README.md @@ -674,6 +674,14 @@ Frameworks, platforms and services for collecting, analyzing, creating and shari DPS' Lightweight Investigation Notebook. + + + Yeti + + + The open, distributed, machine and analyst-friendly threat intelligence repository. Made by and for incident responders. + + XFE - X-Force Exchange From 0076ecc9ec50f25ddc94f78e5bf9f61ce65a8920 Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Sun, 13 Aug 2017 22:32:45 +0200 Subject: [PATCH 4/5] Update YETI entry --- README.md | 24 ++++++++---------------- 1 file changed, 8 insertions(+), 16 deletions(-) diff --git a/README.md b/README.md index 5bf4fc0..9e41640 100644 --- a/README.md +++ b/README.md @@ -674,14 +674,6 @@ Frameworks, platforms and services for collecting, analyzing, creating and shari DPS' Lightweight Investigation Notebook. - - - Yeti - - - The open, distributed, machine and analyst-friendly threat intelligence repository. Made by and for incident responders. - - XFE - X-Force Exchange @@ -690,6 +682,14 @@ Frameworks, platforms and services for collecting, analyzing, creating and shari The X-Force Exchange (XFE) by IBM XFE is a free SaaS product that you can use to search for threat intelligence information, collect your findings, and share your insights with other members of the XFE community. + + + Yeti + + + The open, distributed, machine and analyst-friendly threat intelligence repository. Made by and for incident responders. + + @@ -1101,14 +1101,6 @@ All kinds of tools for parsing, creating and editing Threat Intelligence. Mostly YETI is a proof-of-concept implementation of TAXII that supports the Inbox, Poll and Discovery services defined by the TAXII Services Specification. - - - yeti - - - Your Everyday Threat Intelligence (YETI). - - sqhunter From e3925479834f223a3334eeeb2422067c3c266eee Mon Sep 17 00:00:00 2001 From: Herman Slatman Date: Sun, 13 Aug 2017 22:35:04 +0200 Subject: [PATCH 5/5] Move gosint entry --- README.md | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/README.md b/README.md index 494fc94..e8ed2ab 100644 --- a/README.md +++ b/README.md @@ -170,14 +170,6 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea FraudGuard is a service designed to provide an easy way to validate usage by continuously collecting and analyzing real-time internet traffic. - - - - GOSINT - - - The GOSINT framework is a free project used for collecting, processing, and exporting high quality public indicators of compromise (IOCs). - @@ -820,6 +812,14 @@ All kinds of tools for parsing, creating and editing Threat Intelligence. Mostly GoatRider is a simple tool that will dynamically pull down Artillery Threat Intelligence Feeds, TOR, AlienVaults OTX, and the Alexa top 1 million websites and do a comparison to a hostname file or IP file. + + + GOSINT + + + The GOSINT framework is a free project used for collecting, processing, and exporting high quality public indicators of compromise (IOCs). + + Harbinger Threat Intelligence