Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cps-collected-iocs.intel TI feed has one of microsoft IPs #1194

Open
AlyaGomaa opened this issue Jan 29, 2025 · 0 comments
Open

cps-collected-iocs.intel TI feed has one of microsoft IPs #1194

AlyaGomaa opened this issue Jan 29, 2025 · 0 comments

Comments

@AlyaGomaa
Copy link
Collaborator

AlyaGomaa commented Jan 29, 2025

cmd: ./slips.py -e 1 -f /home/alya/Desktop/Dataset/CTU-Normal-33/capture-new-Windows-7-Full.pcap
FP: 1970-01-01T02:00:10.649964+02:00 (TW 1): Src IP 10.0.2.15 . Detected DNS answer with a blacklisted IP: 131.107.255.255 for query: dns.msftncsi.com Description: 131.107.255.255 Source: cps-collected-iocs.intel. threat level: medium. IP 131.107.255.255 appears in blacklist: cps-collected-iocs.intel.

do we have that IP in our microsoft IPs? if not we need to add it

@AlyaGomaa AlyaGomaa added this to Slips Jan 29, 2025
@AlyaGomaa AlyaGomaa converted this from a draft issue Jan 29, 2025
@AlyaGomaa AlyaGomaa moved this from Todo to Working on it in Slips Jan 29, 2025
@AlyaGomaa AlyaGomaa moved this from Working on it to Get back to it in Slips Jan 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Get back to it
Development

No branches or pull requests

1 participant