Skip to content

Latest commit

 

History

History
71 lines (36 loc) · 1.94 KB

IOC-vetting.md

File metadata and controls

71 lines (36 loc) · 1.94 KB

Network IOC Vetting

Bulk Domain/IP lookup - https://www.infobyip.com/ipbulklookup.php

Batch Domain/IP lookup - https://cybergordon.com/

IP/Domain owner - https://app.netlas.io/host/

IP/Domain owner - https://centralops.net/co/

WHOIS - https://whois.domaintools.com/

WHOIS - https://who.is/

Domain/IP lookup - https://search.dnslytics.com/

Domain/IP lookup - https://www.urlvoid.com/

Domain/IP lookup - https://labs.inquest.net/repdb

Scam database lookup - https://www.scamadviser.com/

Bulk IOC lookup/indexing - https://otx.alienvault.com/pulse/create

Single IOC lookup - https://www.virustotal.com/gui/home/search

Single IOC lookup - https://pulsedive.com/

IP reputation lookup - https://www.ipvoid.com/

IP or /24 subnet lookup - https://www.abuseipdb.com/

Sandbox submissions - https://app.any.run/

Blacklist checks - https://mxtoolbox.com/blacklists.aspx

Blacklist checks - https://check.spamhaus.org/

Botnet C2 checks- https://feodotracker.abuse.ch/browse/

Subdomains/DNS lookup - https://dnsdumpster.com/

Proxy check - https://www.ipqualityscore.com/

IP check - https://www.ipvoid.com/

URL check - https://www.urlvoid.com/

SSL check - https://sslbl.abuse.ch/ssl-certificates/

CDN check - https://www.cdnplanet.com/

URL check - https://urlhaus.abuse.ch/browse/ [query syntax required e.g. url: or domain:]

Single IOC lookup - https://threatfox.abuse.ch/browse/ [query syntax required e.g. ioc:]

IP lookup - https://www.greynoise.io/ [query syntax required e.g. ip:]

Sandbox submissions - https://urlscan.io/search [query syntax required e.g. ip: or domain:]

Sandbox submissions - https://tria.ge/s [query syntax required e.g. ip: or domain:]

Threat Intel Platform - https://opentip.kaspersky.com/

Threat Intel Platform - https://www.threatminer.org/index.php

Threat Intel Platform - https://pulsedive.com/analyze/

Threat Intel Platform - https://metadefender.opswat.com/

Firewall Lookup - https://urlfiltering.paloaltonetworks.com/query/