Zion Boggan zionboggan.com ↗

cti watchlists + active-response on flagged-ip rule

96cbe71   Zion Boggan committed on Mar 31, 2026 (2 months ago)
config/wazuh/lists/cti-malicious-domain +3 -0
@@ -0,0 +1,3 @@
+login-secure-update.com:phishing
+cdn-jquery-min.net:c2
+update-flashplayer.org:exploit-kit
config/wazuh/lists/cti-malicious-ip +3 -0
@@ -0,0 +1,3 @@
+185.220.101.45:tor-exit
+45.137.21.9:c2-cobaltstrike
+193.149.176.12:scanner
config/wazuh/lists/cti-malware-hash +2 -0
@@ -0,0 +1,2 @@
+5d41402abc4b2a76b9719d911017c592e1b2c3d4f5a6978899aabbccddeeff00:agent-tesla
+9b74c9897bac770ffc029102a200c5de7f3b88a0a3f7f0d7c1f2e3d4c5b6a798:redline-stealer