Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Zeek-Intelligence-Feeds — 聚合的 Zeek 格式威胁情报订阅源,整合来自公开及精选来源的指标,用于持续进行 IDS 与网络威胁检测。 | Kitploit
工具/GitHubGitHub/criticalpathsecurity/zeek-intelligence-feeds
威胁源与聚合器钓鱼攻击网络安全命令与控制威胁情报入侵检测
GitHubcriticalpathsecurity/zeek-intelligence-feeds

Zeek-Intelligence-Feeds

聚合的 Zeek 格式威胁情报订阅源,整合来自公开及精选来源的指标,用于持续进行 IDS 与网络威胁检测。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
398501天前Kitploit 审核通过

Critical Path Security 标志

Zeek 威胁情报源(含组合指标)

这是一个基于公共威胁源和 CRITICAL PATH SECURITY 收集的数据的公开订阅源。 此订阅源将尽可能频繁地更新。

快速开始

以下说明将帮助你获得项目副本并使其运行起来。

依赖项

  • ZEEK 3.0 或更高版本

安装

安装 Zeek 依赖项

root@kitploit:~

sudo apt-get install cmake make gcc g++ flex bison libpcap-dev libssl-dev python-dev swig zlib1g-dev

将仓库克隆到 /opt

root@kitploit:~
cd /opt
git clone --recursive https://github.com/zeek/zeek
./configure && make && sudo make install

安装 Zeek

root@kitploit:~

./configure && make && sudo make install

安装威胁情报源

将仓库克隆到 /usr/local/zeek/share/zeek/site/Zeek-Intelligence-Feeds

root@kitploit:~
cd /opt
git clone https://github.com/CriticalPathSecurity/Zeek-Intelligence-Feeds.git /usr/local/zeek/share/zeek/site/Zeek-Intelligence-Feeds
echo "@load Zeek-Intelligence-Feeds" >> /usr/local/zeek/share/zeek/site/local.zeek

使用方法

进入 /usr/local/zeek/bin/

root@kitploit:~
./zeekctl deploy

定时更新

可以使用一个简单的 bash 脚本进行更新。示例如下。

root@kitploit:~
vi /opt/zeek_update.sh

添加以下内容:

root@kitploit:~
#!/bin/sh
cd /usr/local/zeek/share/zeek/site/Zeek-Intelligence-Feeds && git fetch origin master
git reset --hard FETCH_HEAD
git clean -df

将该脚本设为可执行。

root@kitploit:~
chmod +x /opt/zeek_update.sh

添加以下 cron 条目以实现每 24 小时更新。

root@kitploit:~
5 * * * * sh /opt/zeek_update.sh >/dev/null 2>&1

日志将写入:

root@kitploit:~
/usr/local/zeek/logs/current/intel.log

来源:

下载工具
文件名提供方主页列表 URL许可证/使用条款
Amnesty_NSO_Domains.intelAmnesty NSO Domainshttps://github.com/AmnestyTech/investigationshttps://github.com/AmnestyTech/investigations/tree/master/2021-07-18_nso未定义
abuse-ch-ipblocklist.intelAbuse.CH Blacklisthttps://sslbl.abuse.ch/blacklist/https://sslbl.abuse.ch/blacklist/https://sslbl.abuse.ch/blacklist/
abuse-ch-malware.intelAbuse.CH Malwarehttps://bazaar.abuse.ch/https://bazaar.abuse.ch/https://bazaar.abuse.ch/
abuse-ch-threatfox-ip.intelAbuse.CH ThreatFoxhttps://threatfox.abuse.ch/https://threatfox.abuse.ch/https://threatfox.abuse.ch/
abuse-ch-urlhaus.intelAbuse.CH URLHaushttps://urlhaus.abuse.ch/https://urlhaus.abuse.ch/https://urlhaus.abuse.ch/
alienvault.intelAlienVaulthttps://www.alienvault.com/http://reputation.alienvault.com/reputation.datahttps://otx.alienvault.com/
binarydefense.intelBinary Defensehttps://www.binarydefense.com/https://www.binarydefense.com/banlist.txthttps://www.binarydefense.com/
censys.intelCensyshttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
cobaltstrike_ips.intelCobaltStrike IPhttps://threatview.io/https://threatview.io/Downloads/High-Confidence-CobaltStrike-C2%20-Feeds.txthttps://threatview.io/
compromised-ips.intelEmerging Threatshttps://rules.emergingthreats.net/https://rules.emergingthreats.net/blockrules/compromised-ips.txthttps://rules.emergingthreats.net/OPEN_download_instructions.html
cps-collected-iocs.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
cps_cobaltstrike_domain.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
cps_cobaltstrike_ip.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
ellio.intelEllio Techhttps://www.ellio.techhttps://www.ellio.techhttps://www.ellio.tech
fangxiao.intelCyjaxhttps://www.cyjax.com/https://www.cyjax.com/app/uploads/2022/11/fangxiao-a-chinese-threat-actor.txthttps://www.cyjax.com/2022/11/14/fangxiao-a-chinese-threat-actor/
filetransferportals.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
illuminate.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
inversion.intelGoogle / Inversionhttps://github.com/elliotwutingfeng/Inversion-DNSBL-BlocklistsGithubhttps://github.com/elliotwutingfeng/Inversion-DNSBL-Blocklists/blob/main/LICENSE
lockbit_ip.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
log4j_ip.intelMultiple Sourceshttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
openphish.intelOpenPhishhttps://openphish.comhttps://openphish.com/feed.txthttps://openphish.com/terms.html
predict_intel.intelGeorgia Tech Research Institute (GTRI)https://www.gatech.edu/https://www.gatech.edu/https://www.gatech.edu/
ragnar.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
sans.intelSANShttps://isc.sans.edu/https://isc.sans.edu/api/intelfeedhttps://isc.sans.edu/data/threatfeed.html
scumbots.intelScumBots无无经 Paul Melson 许可 - 免费使用
stalkerware.intelCritical Path Securityhttps://www.criticalpathsecurity.com/Githubhttps://www.criticalpathsecurity.com/
tor-exit.intelTor Projecthttps://www.torproject.org/https://check.torproject.org/exit-addresseshttps://www.torproject.org/
Mon Aug 3 21:02:33 UTC 2026