category: Data Enrichment & Threat Intelligence provider: SANS Institute sectionorder: - Connect - Collect commonfields: id: abuse.ch SSL Blacklist Feed version: -1 configuration: - displaypassword: Auth Key hiddenusername: true name: credentials type: 9 section: Connect required: false additionalinfo: Starting June 30th 2025 this parameter is mandatory. - display: Services name: url options: - https://sslbl.abuse.ch/blacklist/sslipblacklist.csv - https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.csv - https://sslbl.abuse.ch/blacklist/sslblacklist.csv required: true type: 16 section: Collect - display: Fetch indicators name: feed type: 8 section: Collect defaultvalue: 'true' required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation. defaultvalue: Bad display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 section: Collect required: false - defaultvalue: B - Usually reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect additionalinfo: Reliability of the source providing the intelligence data - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 section: Collect required: false - defaultvalue: indicatorType display: "" name: feedExpirationPolicy type: 17 section: Collect options: - never - interval - indicatorType - suddenDeath required: false - display: "" name: feedExpirationInterval type: 1 section: Collect defaultvalue: "20160" required: false - defaultvalue: '60' display: Feed Fetch Interval name: feedFetchInterval section: Collect type: 19 required: false - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList section: Collect type: 8 required: false - additionalinfo: Time in seconds before http requests timeout. defaultvalue: '20' display: Request Timeout name: polling_timeout required: true section: Collect type: 0 - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect required: false - display: Use system proxy settings name: proxy type: 8 section: Connect required: false - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 section: Collect required: false description: The SSL IP Blacklist contains all hosts (IP addresses) that SSLBL has seen in the past 30 days and identified as being associated with a malicious SSL certificate. display: abuse.ch SSL Blacklist Feed name: abuse.ch SSL Blacklist Feed script: commands: - arguments: - defaultValue: '50' description: The maximum number of results to return. The default value is 50. name: limit - description: The indicator type. name: indicator_type description: Gets the feed indicators. name: sslbl-get-indicators dockerimage: demisto/python3:3.12.13.10116658 feed: true runonce: false script: '-' subtype: python3 type: python fromversion: 5.5.0 tests: - No tests (auto formatted)