This is a work-in-progress repository dedicated to sharing Indicators of Compromise (IOCs) from production systems experiencing security incidents and OSINT feeds.
-
Updated
Feb 19, 2025
This is a work-in-progress repository dedicated to sharing Indicators of Compromise (IOCs) from production systems experiencing security incidents and OSINT feeds.
A script that automates the process of polling IOCs from a STIX/TAXII server and ingesting them into CrowdStrike Falcon using the Falcon Intelligence API. It supports transforming domain names, IP addresses, and file hashes from STIX format into CrowdStrike-compatible IOCs for threat detection and response.
Add a description, image, and links to the ioc-feed topic page so that developers can more easily learn about it.
To associate your repository with the ioc-feed topic, visit your repo's landing page and select "manage topics."