Montysecurity

From GCA ACT
Revision as of 03:00, 4 July 2024 by Globalcyberalliance (talk | contribs) (Created via script)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

Description

Free to use IOC feed for various tools/malware. It started out for just C2 tools but has morphed into tracking infostealers and botnets as well. It uses Shodan searches to collect the IPs. The most recent collection is always stored in data; the IPs are broken down by tool and there is an all.txt.


The feed should update daily. Actively working on making the backend more reliable


Honorable Mentions


Many of the Shodan queries have been sourced from other CTI researchers:


  • BushidoToken
  • Michael Koczwara
  • ViriBack
  • Gi7W0rm
  • @Glacius_


Huge shoutout to them!


Thanks to BertJanCyber for creating the KQL query for ingesting this feed


And finally, thanks to Y_nexro for creating C2Live in order to visualize the data

More Information

URL: https://github.com/montysecurity/C2-Tracker/tree/main

Maintenance Status: Active

Last Updated Date: < 1 year

Formats Available: TXT

Social Media Links: https://twitter.com/_montysecurity

Contact Information: Unknown

Single or Multiple: Single

License Information: See website.