log4shell_ioc_ips icon indicating copy to clipboard operation
log4shell_ioc_ips copied to clipboard

Please add networks in cidr notation

Open amoore2600 opened this issue 3 years ago • 3 comments

Please add networks in cidr notation this would help keep the list more efficient.

amoore2600 avatar Dec 15 '21 15:12 amoore2600

good point! but the original purpose of this repo was when I get a log4j DFIR I can easily grep through a list with that contains many many sources so I can investigate the findings in for example Firewall,WinEVTX bla bla

Maybe you can fork it and edit it yourself :)

hackinghippo avatar Dec 15 '21 23:12 hackinghippo

@amoore2600 Try adding this to whatever script you are using to gather this list: # cat log4j_ioc_ips.txt | aggregate -p 32 -m 32 -o 32 (only -p is needed, but for completeness Aggregate will (as the name suggests) aggregate all IPs into subnets to make the list smaller.

@hackinghippo May be you can generate 2 outputs? One single host list, and a second aggregated list of networks?

PS.: In the current list there are again RFC1918 addresses, as well as 9.9.9.11 (public non profit DNS resolver)

@Daywalker01, good idea I will add 2 outputs in the future. I also work at domains and hashes sadly I didnt have much time :( much incidents atm...

I can add a whitelist if I have a good base or listing from known IP adresses

hackinghippo avatar Dec 27 '21 22:12 hackinghippo