Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
IP-reputation-snort-rule-generator — 一个基于公共IP信誉数据生成Snort规则的工具。 | Kitploit
工具/GitHubGitHub/nccgroup/ip-reputation-snort-rule-generator
IDS/IPS规避网络安全威胁情报入侵检测DNS 分析
GitHubnccgroup/ip-reputation-snort-rule-generator

IP-reputation-snort-rule-generator

一个基于公共IP信誉数据生成Snort规则的工具。

查看仓库
56151713年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

IP-reputation-snort-rule-generator

基于公共IP/域名信誉数据生成Snort规则或Cisco IDS签名的工具

由NCC Group Plc以开源形式发布 - http://www.nccgroup.com/

由Will Alexander开发,will dot alexander at nccgroup dot com

https://github.com/nccgroup/IP-reputation-snort-rule-generator

以AGPL协议发布,详见LICENSE文件了解更多信息

用法

./tepig.pl [ [--file=LOCAL_FILE] | [--url=URL] ] [--csv=FIELD_NUM] [--sid=INITIAL_SID] [--ids=[snort|cisco]] | --help

LOCAL_FILE 是本地存储的文件,包含恶意域名、IP地址和/或URL的列表。如果省略,则假定提供了URL。 URL 是包含恶意域名、IP地址或URL列表的URL。默认值为 https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist。 FIELD_NUM 是包含目标信息的字段编号(从0开始索引)。如果省略,则文件被视为简单列表。 INITIAL_SID 是应用于第一条规则的SID。后续每条规则的SID值递增。默认值为9000000。

示例

恶意IP地址

./tepig.pl --url=https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist

https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist 是一个纯文本文件,包含已知恶意IP地址列表。在撰写本文时,第一个条目是108.161.130.191。输出的第一条规则如下:

alert ip any any <> 108.161.130.191 any (msg:"Traffic to known bad IP (108.161.130.191)"; reference:"url,https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist"; sid:9000000; rev:0;)

此规则查找任何去往或来自该恶意IP地址的流量。

恶意域名

./tepig.pl --url=http://doc.emergingthreats.net/pub/Main/RussianBusinessNetwork/Storm_2_domain_objects_3-11-2011.txt

http://doc.emergingthreats.net/pub/Main/RussianBusinessNetwork/Storm_2_domain_objects_3-11-2011.txt 是一个纯文本文件,包含已知恶意域名列表。在撰写本文时,第一个条目是 *.bethira.com。输出的第一条规则如下:

alert udp any any -> any 53 (msg:"Suspicious DNS lookup for *.bethira.com"; reference:"url,http://doc.emergingthreats.net/pub/Main/RussianBusinessNetwork/Storm_2_domain_objects_3-11-2011.txt"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth: 10; offset: 2; content:"|07|bethira|03|com"; nocase; distance:0; sid:9000000; rev:0;)

此规则查找任何对该恶意域名的DNS查询。

下载工具