Useful data sources: MISP Warning Lists
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
🗂 Useful Data Sources: MISP Warning Lists
Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant events, they spend countless hours performing complex checks. In large quantities, such checks can lead to analyst information overload and, ultimately, errors in analysis.
To avoid this, you can use initial filtering of the incoming security event stream to eliminate false positives using indicator whitelists. The open-source MISP Warning Lists repository is perfect for this purpose. It currently contains 89 different indicator sets, grouped into categories.
All indicator sets in this source can be roughly divided into two groups: “white” and “gray.”
☑️ “White” indicators are unequivocally legitimate. These include sets such as:
• dax30 — a list of known web pages of major German companies;
• security-provider-blogpost — a list of blog addresses from well-known security vendors;
• eicar.com — a list of hash sums for the EICAR test malware.
Such indicators are the most useful way to filter out false positives from security tools.
ℹ️ “Gray” indicators are legitimate in themselves but can be involved in malicious activity. Sets containing such indicators include, for example:
• amazon_aws — a list of Amazon Web Services IP address ranges;
• vpn-ipv4 — a list of IP address ranges belonging to common VPN providers;
• dynamic-dns — a list of known TLD and DDNS providers;
• url-shortener — a list of known URL shortening services.
You can apply such lists to “whitelist” incoming events based on your organization’s security policy and your own experience (for example, you might assume that all traffic between your infrastructure and cloud providers is “white”).
At the same time, these same lists can be used to highlight events that indicate a security policy violation (for example, if DNS resolution events for DDNS domains are observed on a DNS server, this is always suspicious).
💡 A few tips for use:
• Evaluate the usefulness of each specific list for your own infrastructure. Don’t load everything indiscriminately.
• Pay attention to how often lists are updated. Some are updated rarely or not at all.
#tool #tip #TI
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



