This Add-on collects IPs and URLs from well known Open-source websites that can be used by Threat Intelligence analysts or Cyber Security Centres for better correlations of their use cases or searches. It is needed by any security team that do not use MISP and need to retrieve open source IPs and URLs.
The Add-on downloads IPs and URLs from Proof Point IP blocklist, Cisco Talos Snort blocklist, Abuse CNC blocklist and URLHAUS. All these lists are cleaned and placed into a CSV file that can be used for correlation.
Note: In order for the Add-on to start downloading new IOCs, a new input will need to be created after the installation.