Filter list from the public FilterLists directory. Format: CIDRs (IPv6). See the project homepage for details and inclusion criteria.
Blocklists for Suricata / IDS
Intrusion detection systems can read IP reputation lists as datasets.
Adding a blocklist to Suricata / IDS
curl -fsSL "https://www.team-cymru.org/Services/Bogons/fullbogons-ipv6.txt" -o /var/lib/suricata/data/blocklist.txt Reference the file from a rule using a dataset:
alert ip [!$HOME_NET] any -> $HOME_NET any (msg:"Team Cymru Fullbogons (IPv6) match";
ip.src; dataset:isset,blocklist, type string, load blocklist.txt; sid:1000001;)The address shown above is an example. Every list in the directory has its own URL, which you can copy with one click.
Recommended lists for Suricata / IDS
By topic
All 135 lists for Suricata / IDS
ShadowWhisperer – BruteForce Extreme
Filter list from the public FilterLists directory. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and […]
ShadowWhisperer – BruteForce High
Filter list from the public FilterLists directory. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and […]
ShadowWhisperer – BruteForce Low
Filter list from the public FilterLists directory. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and […]
ShadowWhisperer – BruteForce Medium
Filter list from the public FilterLists directory. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and […]
ShadowWhisperer – Malware Browser
Filter list covering malware. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
ShadowWhisperer – Malware Hackers
Filter list covering malware. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
ShadowWhisperer – Malware Hackers_Old
Filter list covering malware. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
ShadowWhisperer – Malware Hosting
Filter list covering malware. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
ShadowWhisperer – Other Ads
Filter list covering ads. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
ShadowWhisperer – Other Trackers
Filter list covering privacy. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
ShadowWhisperer – Other Tunnel
Filter list covering proxy. Format: IPs (IPv4). Maintained by ShadowWhisperer. See the project homepage for details and inclusion criteria.
Shub’s Whitelist
Filter list covering allowlist. Format: IPs (IPv4). Maintained by DevShubam. See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: CIDRs (IPv4). See the project homepage for details and inclusion criteria.
Network ranges controlled by criminals or taken over by fraud.
Filter list covering malware. Format: CIDRs (IPv4). See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: CIDRs (IPv6). See the project homepage for details and inclusion criteria.
Filter list from the public FilterLists directory. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
StopForumSpam
Filter list from the public FilterLists directory. Format: IPs (IPv4). Maintained by StopForumSpam.com. See the project homepage for details and […]
Ranges that produce almost nothing but spam sign-ups.
Filter list from the public FilterLists directory. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Filter list covering ads. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Syncthing Relay Server IPs
Filter list covering allowlist. Format: IPs (IPv4). Maintained by Wu Tingfeng. See the project homepage for details and inclusion criteria.
Filter list from the public FilterLists directory. Format: CIDRs (IPv4). See the project homepage for details and inclusion criteria.
Filter list from the public FilterLists directory. Format: CIDRs (IPv4). See the project homepage for details and inclusion criteria.
