misp-warninglists icon indicating copy to clipboard operation
misp-warninglists copied to clipboard

Web cluster warninglists

Open ater49 opened this issue 6 years ago • 1 comments

With passive DNS data of CIRCL, it could be possible to determine which IP are used by a large number of hostname like in a Web cluster.

Could it be possible to extract these data in order to create an IP Warninglist ?

ater49 avatar Mar 01 '19 12:03 ater49

Indeed, we could generate list of IP addresses associated to a lot of domains/hostname (>10000 records). It's a good idea. I need to check how to do in the Passive DNS database.

adulau avatar Mar 09 '19 16:03 adulau