Feodo Tracker IP Blocklist Feed
Gets a list of bad IPs from Feodo Tracker.
Data Enrichment & Threat Intelligence · FeodoTracker Feed · Feed
Details
| ID | Feodo Tracker IP Blocklist Feed |
|---|---|
| Provider | Abusech |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Feodo Tracker is a project of abuse.ch with the goal of sharing botnet C&C servers associated with Dridex, Emotet (aka Heodo), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor).
For more information, visit: https://feodotracker.abuse.ch/
Create an Auth Key for abuse.ch
Note: If you already have a profile, you can skip steps 1 and 2.
-
Sign up for an abuse.ch account. You can do this easily by using an existing account that you may already have on X, LinkedIn, Google or Github. Just log in with the authentication provider of your choice here: https://auth.abuse.ch/
-
Once you are authenticated on abuse.ch, ensure that you connect at least one additional authentication provider. This will ensure that you have access to abuse.ch platforms, even if one of the authentication providers you use shuts down (yes, it happened with Twitter!)
-
Ensure that you hit the “Save profile” button. In the “Optional” section, you can now generate an “Auth-Key”. This is your personal Auth-Key that you can now use in the integration.
Configure Feodo Tracker IP Blocklist Feed in Cortex
| Parameter | Description | Required |
|---|---|---|
| Auth Key | Auth Key for authentication with abuse.ch | True |
| Fetch indicators | False | |
| Indicator Reputation | Indicators from this integration instance will be marked with this reputation | False |
| Source Reliability | Reliability of the source providing the intelligence data | True |
| Traffic Light Protocol Color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed | False |
| False | ||
| False | ||
| Feed Fetch Interval | False | |
| Bypass exclusion list | When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. | False |
| Tags | Supports CSV values. | False |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Create relationships | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
feodotracker-ipblocklist-get-indicators
Gets the feed indicators.
Base Command
feodotracker-ipblocklist-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. The default value is 50. Default is 50. | Optional |
Context Output
There is no context output for this command.
Configuration parameters
feed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—cidr_32_to_ip— Set /32 CIDRs as IP IndicatorsfeedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedBypassExclusionList— Bypass exclusion listfeedTags— Tagscredentials—insecure— Trust any certificate (not secure)proxy— Use system proxy settingscreate_relationships— Create relationships
Commands (1)
-
feodotracker-ipblocklist-get-indicatorsGets the feed indicators.
category: Data Enrichment & Threat Intelligence provider: Abusech sectionorder: - Connect - Collect commonfields: id: Feodo Tracker IP Blocklist Feed version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: Bad display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: B - Usually reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false section: Collect - defaultvalue: suddenDeath display: '' name: feedExpirationPolicy options: - never - interval - indicatorType - suddenDeath type: 17 required: false section: Collect - additionalinfo: When enabled, each /32 CIDR will also be returned as an IP indicator. Only relevant if the integration fetches /32 CIDR indicators. display: Set /32 CIDRs as IP Indicators name: cidr_32_to_ip required: false type: 8 advanced: true section: Collect - defaultvalue: '20160' display: '' name: feedExpirationInterval type: 1 required: false section: Collect - defaultvalue: '60' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false section: Collect - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false section: Collect - displaypassword: Auth Key hiddenusername: true name: credentials type: 9 required: false section: Connect additionalinfo: Starting June 30th 2025 this parameter is mandatory. - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - defaultvalue: 'true' display: Create relationships name: create_relationships type: 8 required: false section: Collect description: Gets a list of bad IPs from Feodo Tracker. display: Feodo Tracker IP Blocklist Feed name: Feodo Tracker IP Blocklist Feed script: commands: - arguments: - defaultValue: '50' description: The maximum number of results to return. The default value is 50. name: limit description: Gets the feed indicators. name: feodotracker-ipblocklist-get-indicators dockerimage: demisto/python3:3.12.13.10116658 feed: true runonce: false script: '-' subtype: python3 type: python tests: - playbook-feodotrackeripblock_test fromversion: 5.5.0