Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
IPsum logo

IPsum

Automatic deploy
Supported by Filigran
Infrastructure & Attack Surface Visibility

Overview

IPsum connector imports malicious IP addresses from 30+ aggregated blacklists into OpenCTI as indicators, with confidence scoring based on cross-list occurrence count.

IPsum is a threat intelligence feed based on 30+ different publicly available lists of suspicious and/or malicious IP addresses. All lists are automatically retrieved and parsed on a daily basis. The feed provides IP addresses together with a total number of blacklist occurrences — the greater the number, the lesser the chance of false positive detection.

This connector fetches malicious IP addresses from the IPsum feed and imports them into OpenCTI as IPv4-Addr observables and STIX 2.1 Indicators. It supports configurable threat levels (1-8), custom scoring, and TLP markings.

Basic information

IPsum
Connectors
6.8.13
0

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".