These free feeds suitable for ingestion into a CTI platform such as OpenCTI or MISP
These feeds are designed to be proactive in that we will attempt to identify subdomains and unusual platforms used which can be blocked by typical Australian and New Zealand companies without causing business impact.
We could push hundreds of IPs into our lists each day but prefer to focus on persistent IPs/domains or ones with high relevance as most EDR platforms come with limits to the number of IOCs you can ingest.
ThreatIntel.co.nz recommends blocking these IOCs for 90 days as more and more phishing campaigns have continued to revisit old infrastructure.
As always these IOCs should be analyzed by your organisation to ensure they are of value to you.
| Description | Feed Link |
|---|---|
| Malicious IP Addresses targeting New Zealand Organisations updated multiple times a day | CSV |
| Malicious domains targeting New Zealand Organisations updated multiple times a day | CSV |
Later we will look to make this data available via TAXII/STIX