chg: Add ip-src|dst and ip-dst|port as matching attr types to cidr lists
parent
fcbcf65795
commit
e48c2539c2
|
@ -273,9 +273,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Akamai IP ranges",
|
"name": "List of known Akamai IP ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20210613
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -2669,9 +2669,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Amazon AWS IP address ranges",
|
"name": "List of known Amazon AWS IP address ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -6,9 +6,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Apple IP ranges",
|
"name": "List of known Apple IP ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20210610
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -25,11 +25,13 @@
|
||||||
"2c0f:f248::/32"
|
"2c0f:f248::/32"
|
||||||
],
|
],
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-dst",
|
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"domain|ip"
|
"ip-dst",
|
||||||
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Cloudflare IP ranges",
|
"name": "List of known Cloudflare IP ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -260,9 +260,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "CRL and OCSP IP addresses",
|
"name": "CRL and OCSP IP addresses",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -24,9 +24,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Fastly IP address ranges",
|
"name": "List of known Fastly IP address ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20201106
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -304,9 +304,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known GCP (Google Cloud Platform) IP address ranges",
|
"name": "List of known GCP (Google Cloud Platform) IP address ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -32,9 +32,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Gmail sending IP ranges",
|
"name": "List of known Gmail sending IP ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -71,9 +71,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)",
|
"name": "List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240402
|
||||||
}
|
}
|
||||||
|
|
|
@ -205,9 +205,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Microsoft Azure China Datacenter IP Ranges",
|
"name": "List of known Microsoft Azure China Datacenter IP Ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -41,9 +41,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Microsoft Azure Germany Datacenter IP Ranges",
|
"name": "List of known Microsoft Azure Germany Datacenter IP Ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -181,9 +181,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Microsoft Azure US Government Cloud Datacenter IP Ranges",
|
"name": "List of known Microsoft Azure US Government Cloud Datacenter IP Ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -2416,9 +2416,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Microsoft Azure Datacenter IP Ranges",
|
"name": "List of known Microsoft Azure Datacenter IP Ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -78,9 +78,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Office 365 IP address ranges in China",
|
"name": "List of known Office 365 IP address ranges in China",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -89,9 +89,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Office 365 IP address ranges",
|
"name": "List of known Office 365 IP address ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240418
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -21,9 +21,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of RFC 5771 multicast CIDR blocks",
|
"name": "List of RFC 5771 multicast CIDR blocks",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 3
|
"version": 4
|
||||||
}
|
}
|
||||||
|
|
|
@ -7,9 +7,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known IP address ranges for OpenAI GPT crawler bot",
|
"name": "List of known IP address ranges for OpenAI GPT crawler bot",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -436,9 +436,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Ovh Cluster IP",
|
"name": "List of known Ovh Cluster IP",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20180222
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -105,11 +105,13 @@
|
||||||
"99.83.154.118/32"
|
"99.83.154.118/32"
|
||||||
],
|
],
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"domain|ip",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"ip-src"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "Parking domains",
|
"name": "Parking domains",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20221024
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -62745,9 +62745,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known IPv4 public DNS resolvers",
|
"name": "List of known IPv4 public DNS resolvers",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -267,9 +267,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known IPv6 public DNS resolvers",
|
"name": "List of known IPv6 public DNS resolvers",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -111,9 +111,12 @@
|
||||||
],
|
],
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst"
|
"ip-dst",
|
||||||
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known sinkholes",
|
"name": "List of known sinkholes",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 1
|
"version": 2
|
||||||
}
|
}
|
||||||
|
|
|
@ -261,9 +261,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known SMTP receiving IP addresses",
|
"name": "List of known SMTP receiving IP addresses",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -926,9 +926,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known SMTP sending IP ranges",
|
"name": "List of known SMTP sending IP ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -250,11 +250,13 @@
|
||||||
"98.190.94.128/25"
|
"98.190.94.128/25"
|
||||||
],
|
],
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-dst",
|
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"domain|ip"
|
"ip-dst",
|
||||||
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Stackpath CDN IP ranges",
|
"name": "List of known Stackpath CDN IP ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -44,9 +44,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Tenable Cloud Sensors IPv4",
|
"name": "List of known Tenable Cloud Sensors IPv4",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -22,9 +22,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Tenable Cloud Sensors IPv6",
|
"name": "List of known Tenable Cloud Sensors IPv6",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -11,9 +11,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "cisco-umbrella-blockpage-ipv4",
|
"name": "cisco-umbrella-blockpage-ipv4",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -11,9 +11,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "cisco-umbrella-blockpage-ipv6",
|
"name": "cisco-umbrella-blockpage-ipv6",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -24048,9 +24048,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "Specialized list of vpn-ipv4 addresses belonging to common VPN providers and datacenters",
|
"name": "Specialized list of vpn-ipv4 addresses belonging to common VPN providers and datacenters",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -1255,9 +1255,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "Specialized list of IPv6 addresses belonging to common VPN providers and datacenters",
|
"name": "Specialized list of IPv6 addresses belonging to common VPN providers and datacenters",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20220324
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -67,9 +67,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Wikimedia address ranges",
|
"name": "List of known Wikimedia address ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20240405
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -71,9 +71,11 @@
|
||||||
"matching_attributes": [
|
"matching_attributes": [
|
||||||
"ip-src",
|
"ip-src",
|
||||||
"ip-dst",
|
"ip-dst",
|
||||||
"domain|ip"
|
"domain|ip",
|
||||||
|
"ip-src|port",
|
||||||
|
"ip-dst|port"
|
||||||
],
|
],
|
||||||
"name": "List of known Zscaler IP address ranges",
|
"name": "List of known Zscaler IP address ranges",
|
||||||
"type": "cidr",
|
"type": "cidr",
|
||||||
"version": 20230810
|
"version": 20240422
|
||||||
}
|
}
|
||||||
|
|
|
@ -72,7 +72,7 @@ if __name__ == '__main__':
|
||||||
'description': 'Akamai IP ranges from BGP search',
|
'description': 'Akamai IP ranges from BGP search',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(networks),
|
'list': consolidate_networks(networks),
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
write_to_file(warninglist, "akamai")
|
write_to_file(warninglist, "akamai")
|
||||||
|
|
||||||
|
|
|
@ -23,7 +23,7 @@ def process(file, dst):
|
||||||
'description': 'Amazon AWS IP address ranges (https://ip-ranges.amazonaws.com/ip-ranges.json)',
|
'description': 'Amazon AWS IP address ranges (https://ip-ranges.amazonaws.com/ip-ranges.json)',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(l),
|
'list': consolidate_networks(l),
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
write_to_file(warninglist, dst)
|
write_to_file(warninglist, dst)
|
||||||
|
|
|
@ -20,7 +20,7 @@ def process(file, dst):
|
||||||
'description': 'check-host IP addresses (https://check-host.net/nodes/ips)',
|
'description': 'check-host IP addresses (https://check-host.net/nodes/ips)',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(l),
|
'list': consolidate_networks(l),
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
write_to_file(warninglist, dst)
|
write_to_file(warninglist, dst)
|
||||||
|
|
|
@ -11,7 +11,7 @@ def process(files, dst):
|
||||||
'description': "List of known Cloudflare IP ranges (https://www.cloudflare.com/ips/)",
|
'description': "List of known Cloudflare IP ranges (https://www.cloudflare.com/ips/)",
|
||||||
'type': "cidr",
|
'type': "cidr",
|
||||||
'list': [],
|
'list': [],
|
||||||
'matching_attributes': ["ip-dst", "ip-src", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
for file in files:
|
for file in files:
|
||||||
|
|
|
@ -99,7 +99,7 @@ def process(file):
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': 'IP addresses that belongs to CRL or OCSP',
|
'description': 'IP addresses that belongs to CRL or OCSP',
|
||||||
'list': get_ips_from_domains(crl_ocsp_domains),
|
'list': get_ips_from_domains(crl_ocsp_domains),
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
}
|
}
|
||||||
write_to_file(warninglist, "crl-ip")
|
write_to_file(warninglist, "crl-ip")
|
||||||
|
|
|
@ -15,7 +15,7 @@ if __name__ == '__main__':
|
||||||
'name': 'List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)',
|
'name': 'List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)',
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': "Google Bot IP address ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)",
|
'description': "Google Bot IP address ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)",
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(ranges),
|
'list': consolidate_networks(ranges),
|
||||||
}
|
}
|
||||||
|
|
|
@ -15,7 +15,7 @@ if __name__ == '__main__':
|
||||||
'name': "List of known GCP (Google Cloud Platform) IP address ranges",
|
'name': "List of known GCP (Google Cloud Platform) IP address ranges",
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': "GCP (Google Cloud Platform) IP address ranges (https://www.gstatic.com/ipranges/cloud.json)",
|
'description': "GCP (Google Cloud Platform) IP address ranges (https://www.gstatic.com/ipranges/cloud.json)",
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(ranges),
|
'list': consolidate_networks(ranges),
|
||||||
}
|
}
|
||||||
|
|
|
@ -9,7 +9,7 @@ if __name__ == '__main__':
|
||||||
'name': "List of known Gmail sending IP ranges",
|
'name': "List of known Gmail sending IP ranges",
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': "List of known Gmail sending IP ranges (https://support.google.com/a/answer/27642?hl=en)",
|
'description': "List of known Gmail sending IP ranges (https://support.google.com/a/answer/27642?hl=en)",
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(spf.get_ip_ranges_from_spf("gmail.com")),
|
'list': consolidate_networks(spf.get_ip_ranges_from_spf("gmail.com")),
|
||||||
}
|
}
|
||||||
|
|
|
@ -19,7 +19,7 @@ def process(file, dst):
|
||||||
'description': 'OpenAI gptbot crawler (https://openai.com/gptbot-ranges.txt)',
|
'description': 'OpenAI gptbot crawler (https://openai.com/gptbot-ranges.txt)',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(l),
|
'list': consolidate_networks(l),
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
write_to_file(warninglist, dst)
|
write_to_file(warninglist, dst)
|
||||||
|
|
|
@ -20,7 +20,7 @@ def process(file, dst, name: str, description: str):
|
||||||
'name': name,
|
'name': name,
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': description,
|
'description': description,
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr'
|
'type': 'cidr'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
@ -23,7 +23,7 @@ def process(url):
|
||||||
'name': 'List of known Office 365 IP address ranges',
|
'name': 'List of known Office 365 IP address ranges',
|
||||||
'description': 'Office 365 IP address ranges',
|
'description': 'Office 365 IP address ranges',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
generate(consolidate_networks(lips), office365_ips_dst, office365_ips_warninglist)
|
generate(consolidate_networks(lips), office365_ips_dst, office365_ips_warninglist)
|
||||||
|
|
||||||
|
@ -65,6 +65,6 @@ if __name__ == '__main__':
|
||||||
'name': 'List of known Office 365 IP address ranges in China',
|
'name': 'List of known Office 365 IP address ranges in China',
|
||||||
'description': 'Office 365 IP address ranges in China',
|
'description': 'Office 365 IP address ranges in China',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
generate(consolidate_networks(lips), "microsoft-office365-cn", warninglist)
|
generate(consolidate_networks(lips), "microsoft-office365-cn", warninglist)
|
||||||
|
|
|
@ -79,7 +79,7 @@ if __name__ == '__main__':
|
||||||
'name': "List of known SMTP sending IP ranges",
|
'name': "List of known SMTP sending IP ranges",
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': "List of IP ranges for known SMTP servers.",
|
'description': "List of IP ranges for known SMTP servers.",
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(spf_ranges),
|
'list': consolidate_networks(spf_ranges),
|
||||||
}
|
}
|
||||||
|
@ -93,7 +93,7 @@ if __name__ == '__main__':
|
||||||
'name': "List of known SMTP receiving IP addresses",
|
'name': "List of known SMTP receiving IP addresses",
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': "List of IP addresses for known SMTP servers.",
|
'description': "List of IP addresses for known SMTP servers.",
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': map(str, mx_ips),
|
'list': map(str, mx_ips),
|
||||||
}
|
}
|
||||||
|
|
|
@ -74,7 +74,7 @@ def process(files, dst):
|
||||||
'description': "List of known Stackpath (Highwinds) CDN IP ranges (https://support.stackpath.com/hc/en-us/articles/360001091666-Whitelist-CDN-WAF-IP-Blocks)",
|
'description': "List of known Stackpath (Highwinds) CDN IP ranges (https://support.stackpath.com/hc/en-us/articles/360001091666-Whitelist-CDN-WAF-IP-Blocks)",
|
||||||
'type': "cidr",
|
'type': "cidr",
|
||||||
'list': [],
|
'list': [],
|
||||||
'matching_attributes': ["ip-dst", "ip-src", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
for file in files:
|
for file in files:
|
||||||
|
|
|
@ -10,7 +10,7 @@ def process(file, dst, name: str, description: str, prefixlist: str, prefixitem:
|
||||||
'name': name,
|
'name': name,
|
||||||
'version': get_version(),
|
'version': get_version(),
|
||||||
'description': description,
|
'description': description,
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"],
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
|
||||||
'type': 'cidr'
|
'type': 'cidr'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
@ -11,7 +11,7 @@ def process(url, dst):
|
||||||
'description': 'Specialized list of {} addresses belonging to common VPN providers and datacenters'.format(dst),
|
'description': 'Specialized list of {} addresses belonging to common VPN providers and datacenters'.format(dst),
|
||||||
'list': consolidate_networks(process_stream(url)),
|
'list': consolidate_networks(process_stream(url)),
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
write_to_file(warninglist, dst)
|
write_to_file(warninglist, dst)
|
||||||
|
|
|
@ -15,7 +15,7 @@ def process(url, dst):
|
||||||
'description': 'Wikimedia address ranges (http://noc.wikimedia.org/conf/reverse-proxy.php.txt)',
|
'description': 'Wikimedia address ranges (http://noc.wikimedia.org/conf/reverse-proxy.php.txt)',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': [],
|
'list': [],
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
matched = re.findall(
|
matched = re.findall(
|
||||||
|
|
|
@ -20,7 +20,7 @@ def process(file, dst):
|
||||||
'description': 'Zscaler IP address ranges (https://config.zscaler.com/api/zscaler.net/hubs/cidr/json/required)',
|
'description': 'Zscaler IP address ranges (https://config.zscaler.com/api/zscaler.net/hubs/cidr/json/required)',
|
||||||
'type': 'cidr',
|
'type': 'cidr',
|
||||||
'list': consolidate_networks(l),
|
'list': consolidate_networks(l),
|
||||||
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"]
|
'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
|
||||||
}
|
}
|
||||||
|
|
||||||
write_to_file(warninglist, dst)
|
write_to_file(warninglist, dst)
|
||||||
|
|
Loading…
Reference in New Issue