Toplam Engellenen
5.019
Manuel + (USOM ayrı)
Manuel Kayıt
160
blacklist.txt
Onay Bekleyen
7
Pending → review
Whitelist
4
Beyaz liste
Beyaz Liste (Whitelist)
4 kayıt
| IP / CIDR | Tür | Tarih / Saat | Ekleyen | Yorum | İşlem |
|---|---|---|---|---|---|
| 192.0.2.10 | IP | 2026-08-03 05:35:49 | analyst | Corporate egress NAT (demo) | |
| 198.51.100.20 | IP | 2026-08-12 05:35:49 | analyst | Branch office uplink (demo) | |
| 203.0.113.0/24 | CIDR | 2026-08-19 05:35:49 | soc-tier2 | Partner VPN range (demo) | |
| 8.8.8.8 | IP | 2026-07-04 05:35:49 | automation | Google Public DNS |
Onay Bekleyen IP'ler 7
| IP / Domain | Kaynak | Tespit Tarihi | İşlem |
|---|---|---|---|
| 198.51.100.200 | Spamhaus_drop | 2026-09-02 05:35:49 | İncele & Karar Ver |
| 198.51.100.201 | Firehol_level1 | 2026-09-02 03:35:49 | İncele & Karar Ver |
| 198.51.100.202 | Ci_badguys | 2026-09-02 01:35:49 | İncele & Karar Ver |
| 198.51.100.203 | Urlhaus | 2026-09-01 23:35:49 | İncele & Karar Ver |
| 198.51.100.204 | Malwarebazaar | 2026-09-01 21:35:49 | İncele & Karar Ver |
| 198.51.100.205 | Usom | 2026-09-01 19:35:49 | İncele & Karar Ver |
| 198.51.100.206 | Threatfox | 2026-09-01 17:35:49 | İncele & Karar Ver |
USOM Toplam
0
API'den çekilen kayıt
Son Sync
—
-
Tam Sync (Aylık)
Her ayın 1'i · 01:00
Aktif
Artımlı (Günlük)
3 kez/gün · 07,13,19
7 gün/hafta
USOM Feed Dosyaları
Zamanlama Ayarları
Tam Sync
Artımlı Sync
Paz
Pzt
Sal
Çar
Per
Cum
Cmt
00
01
02
03
04
05
06
07
08
09
10
11
12
13
14
15
16
17
18
19
20
21
22
23
Yapılandırılmış Kaynaklar
8 kaynak
Crontab: Pasif
| Kaynak Adı | URL | Tip | Süre | Güven | Kayıt | Son Güncelleme | Durum | İşlem |
|---|---|---|---|---|---|---|---|---|
| CI Badguys
CINSScore CI Badguys IP listesi |
https://cinsscore.com/list/ci-badguys.txt | plain | 1h | 70 | 1.200 |
- dosya: 17.1KB |
Çalışıyor | |
| Firehol Level 1
FireHOL Level 1 IP listesi |
https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset | netset | 1h | 85 | 1.200 |
- dosya: 19.5KB |
Çalışıyor | |
| URLhaus Hosts (domain)
Domain — Malware host |
https://urlhaus.abuse.ch/downloads/hostfile/ | plain | 24h | 85 | 1.200 |
- dosya: 30.5KB |
Çalışıyor | |
| USOM TR-CERT (domain)
Domain — TR-CERT zararlı host listesi (450K+ domain) |
https://www.usom.gov.tr/url-list.txt | plain | 24h | 80 | 1.200 |
- dosya: 30.5KB |
Çalışıyor | |
| StevenBlack Hosts
Domain — Geniş malware/reklam listesi |
https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | plain | 1h | 60 | 1.200 |
- dosya: 27.1KB |
Çalışıyor | |
| Spamhaus DROP
IP — Tehlikeli ağ blokları |
https://www.spamhaus.org/drop/drop.txt | plain | 1h | 60 | 1.200 |
- dosya: 19.5KB |
Çalışıyor | |
| Spamhaus EDROP
IP — Uzantı (EDROP) |
https://www.spamhaus.org/drop/edrop.txt | plain | 1h | 60 | 412 |
- dosya: 6.7KB |
Çalışıyor | |
| MalwareBazaar Recent MD5
IoC — MD5 hash |
https://bazaar.abuse.ch/export/txt/md5/recent/ | plain | 1h | 60 | 990 |
- dosya: 32KB |
Çalışıyor |
Yeni Kaynak Ekle
Tavsiye Edilen Kaynaklar
Eklediğinizde aktif değil olarak gelir; tipine göre doğru dinamik dizine düşer.
IP / CIDR → Firewall (FortiGate / F5 AFM)
| Kaynak | Kategori | Format | URL | İşlem |
|---|---|---|---|---|
| Spamhaus DROP | IP — Tehlikeli ağ blokları | plain | https://www.spamhaus.org/drop/drop.txt | Eklendi |
| Spamhaus EDROP | IP — Uzantı (EDROP) | plain | https://www.spamhaus.org/drop/edrop.txt | Eklendi |
| FireHOL Level 1 | IP — Yüksek güven blocklist | netset | https://iplists.firehol.org/files/firehol_level1.netset | |
| Feodo Tracker IP Blocklist | IP — Bot C&C | plain | https://feodotracker.abuse.ch/downloads/ipblocklist.txt | |
| Emerging Threats Compromised IPs | IP — Ele geçirilmiş hostlar | plain | https://rules.emergingthreats.net/blockrules/compromised-ips.txt | |
| Blocklist.de All | IP — Saldırı kaynak IP havuzu | plain | https://lists.blocklist.de/lists/all.txt | |
| CINS Score Army | IP — Sentinel IPS | plain | https://cinsscore.com/list/ci-badguys.txt | Eklendi |
| Tor Exit Nodes | IP — Anonim trafik | plain | https://check.torproject.org/torbulkexitlist |
Domain / FQDN → DNS RPZ / WAF
| Kaynak | Kategori | Format | URL | İşlem |
|---|---|---|---|---|
| URLhaus Hosts (domain) | Domain — Malware host | plain | https://urlhaus.abuse.ch/downloads/hostfile/ | Eklendi |
| StevenBlack Hosts | Domain — Geniş malware/reklam listesi | plain | https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | Eklendi |
| OpenPhish Hosts | Domain — Phishing host | plain | https://openphish.com/feed.txt | |
| USOM TR-CERT (domain) | Domain — TR-CERT (450K+) | plain | https://www.usom.gov.tr/url-list.txt | Eklendi |
| Malware Domain List | Domain — Aktif malware host | plain | https://mirror1.malwaredomains.com/files/justdomains |
URL → WAF (F5 ASM / ModSecurity)
| Kaynak | Kategori | Format | URL | İşlem |
|---|---|---|---|---|
| URLhaus URL Feed | URL — Malware dağıtım URL'leri | plain | https://urlhaus.abuse.ch/downloads/text/ | |
| OpenPhish URLs | URL — Phishing URL feed | plain | https://openphish.com/feed.txt | |
| PhishTank Verified | URL — Doğrulanmış phishing | csv | https://data.phishtank.com/data/online-valid.csv |
IoC / Hash → SIEM / EDR
| Kaynak | Kategori | Format | URL | İşlem |
|---|---|---|---|---|
| MalwareBazaar Recent MD5 | IoC — MD5 hash | plain | https://bazaar.abuse.ch/export/txt/md5/recent/ | Eklendi |
| MalwareBazaar Recent SHA256 | IoC — SHA256 hash | plain | https://bazaar.abuse.ch/export/txt/sha256/recent/ |
Sistem Yönetimi
Crontab
Pasif
www-data crontab
Combined Output
/home/runner/work/BlockHarbor/BlockHarbor/cyberwebeyeosblacklist.txt
Whitelist Dosyası
/home/runner/work/BlockHarbor/BlockHarbor/whitelist.txt
Log Dosyası
/home/runner/work/BlockHarbor/BlockHarbor/ip_blocklist.log
Hızlı Referans Kataloğu
Yukarıdaki Sources Manager dinamik kaynak yönetimini yapar (config + fetch). Aşağıdaki tablo
kürate edilmiş popüler kaynakların hızlı referansıdır — URL'i kopyalayıp Sources Manager'a ekleyebilirsin.
| Kaynak | Tip | Açıklama | Lisans | Kayıt | İşlem |
|---|---|---|---|---|---|
|
USOM (TR-CERT) https://www.usom.gov.tr/api/address/index |
ipdomainurl | Türkiye Ulusal Siber Olaylara Müdahale Merkezi — devlet onaylı zararlı adres listesi. | Açık | ~473K | Eklenmiş |
|
Spamhaus DROP https://www.spamhaus.org/drop/drop.txt |
ipv4 CIDR | Don't Route Or Peer — known hijacked netblocks. | Free/Comm | ~1.2K | Eklenmiş |
|
Spamhaus EDROP https://www.spamhaus.org/drop/edrop.txt |
ipv4 CIDR | Extended DROP — additional hijacked blocks. | Free/Comm | ~200 | Eklenmiş |
|
Emerging Threats — Compromised https://rules.emergingthreats.net/blockrules/compromised-ips.txt |
ipv4 | Bilinen compromise edilmiş IP'ler (Proofpoint). | Açık | ~500 | |
|
CINS Score Army https://cinsscore.com/list/ci-badguys.txt |
ipv4 | Sentinel IPS — pozitif IDS skoru yüksek IP'ler. | Açık | ~15K | Eklenmiş |
|
FireHOL Level 1 https://iplists.firehol.org/files/firehol_level1.netset |
ipv4 CIDR | En sıkı FireHOL listesi — false-positive riski düşük. | Açık | ~600 | |
|
FireHOL Level 2 https://iplists.firehol.org/files/firehol_level2.netset |
ipv4 CIDR | Saatlik güncellenen, daha agresif liste. | Açık | ~2K | |
|
AbuseIPDB Blacklist https://api.abuseipdb.com/api/v2/blacklist |
ipv4 | Topluluk raporlu kötüye kullanım IP'leri. | API key | ~10K | |
|
Feodo Tracker — Botnet C2 https://feodotracker.abuse.ch/downloads/ipblocklist.txt |
ipv4 | Emotet/Dridex/TrickBot C2 IP listesi (abuse.ch). | Açık | ~400 | |
|
URLhaus — Malware URL'leri https://urlhaus.abuse.ch/downloads/text/ |
urldomain | Aktif malware dağıtım URL'leri (abuse.ch). | Açık | ~3K | |
|
OpenPhish https://openphish.com/feed.txt |
url | Doğrulanmış aktif phishing URL'leri. | Free tier | ~2K | |
|
PhishTank http://data.phishtank.com/data/online-valid.csv |
url | Topluluk doğrulamalı phishing URL veritabanı. | Açık | ~25K | |
|
Malware Domain List https://mirror1.malwaredomains.com/files/justdomains |
domain | Aktif malware barındıran alan adları. | Açık | ~5K | |
|
AlienVault OTX https://otx.alienvault.com/api |
ipv4domainurl | Open Threat Exchange (community + AT&T pulses). | API key | Değişken | |
|
Tor Exit Nodes https://check.torproject.org/torbulkexitlist |
ipv4 | Anonim trafiği engellemek için aktif Tor exit IP'leri. | Açık | ~1.5K |
Notlar
- USOM şu an aktif olarak çekiliyor (cron + USOM API). Diğer kaynaklar F2 fazında otomatik fetcher ile entegre edilecek.
- Lisans sütunu: "Açık" = ücretsiz public, "API key" = ücretsiz tier veya kayıt gerekli, "Free/Comm" = küçük org için ücretsiz, kurumsal için ücretli.
- Performans: Çok büyük feed'leri (URLhaus gibi) eklemek RAM/disk gerektirir. Production'da kategorize edilmeli.
- False positive: Spamhaus DROP, FireHOL L1 ve USOM düşük risk; AbuseIPDB ve PhishTank topluluk-bazlı, yanlış pozitif daha yüksek.
⚙ Vendor Watchlist Tuning (admin-only)
Manuel Listeler
10 liste
Birden fazla isimlendirilmiş manuel liste oluşturabilirsin. Her liste belirli tipte
(IP/Domain/URL/IoC) veya birleşik (merged) olabilir. Her birinin kendi feed URL'i olur,
firewall/DNS RPZ/WAF ayrı ayrı çekebilir.
Liste İçeriği Ara
Kullanıcılar
1 kullanıcı
| Kullanıcı | E-posta | Rol | Oluşturma | Son Giriş | Durum | İşlem |
|---|---|---|---|---|---|---|
|
D
demo
|
demo@example.com | Viewer | 2026-01-01 00:00 | 2026-09-02 05:35:49 | Aktif |
Kullanıcı Aktivite Takibi
Audit log AKTİF ✓
→ Durum & Loglar tab'a git — her kullanıcı işlemi (giriş, IP ekleme/silme/onay vs.) loglu.
Blacklist
—
Whitelist
—
Pending
—
Expired
—
FP Raporları
—
Son 30 Gün — IoC Trendi
IoC Tipi Dağılımı
TLP Dağılımı
Kaynak Katkısı
Son güncelleme: yükleniyor...
Açık CVE
0
KEV (Aktif Sömürü)
0
Kritik (CVSS≥9)
0
Dismissed
0
Toplam
0
Last sync:
-
· Watch: cisco,fortinet,microsoft,vmware,apache,palo alto,checkpoint,f5,citrix,linux
Zafiyetler
—Henüz CVE çekilmedi
Admin'sen Sync butonuna bas. CLI:
php cve_fetch.php --bootstrap🚨 Action Required 0
Yükleniyor…
…
Sighting Tracker
toplam 0 match · 0 unique IoCHenüz sighting yok. SIEM'iniz IoC match event'lerini /sighting.php'a POST etmeli.
📡 SIEM entegrasyon notu
SIEM **sadece IoC match event'lerini** buraya POST etmeli — ham firewall event'leri gönderme (DB şişer).
Endpoint: POST /sighting.php
Auth: X-API-Key: <key>
Single:
{"value":"1.2.3.4","source":"wazuh","observed_at":"2026-05-21 13:00:00","count":1}
Batch:
{"sightings":[{"value":"1.2.3.4","source":"wazuh","count":3},{"value":"evil.com","source":"wazuh","count":1}]}
Wazuh integrator örneği (/var/ossec/etc/ossec.conf):
<integration> <name>custom-cwe-sighting</name> <hook_url>https://blockharbor.example.com/sighting.php</hook_url> <api_key>cwe_xxx</api_key> <rule_id>100100</rule_id> <!-- sadece "IoC match" rule'u --> <alert_format>json</alert_format> </integration>
Rate limit: 100 req / 10s per key. Toplu batch tercih edilir.
Source Reliability Score
FP rate düşük = güvenilir kaynak| Kaynak | IoC sayısı | FP rapor | FP oranı | Reliability | Default Conf | Son FP |
|---|---|---|---|---|---|---|
| feed:ci-badguys | 1,200 | 0 | 0.00% | 100 | 70 | - |
| feed:firehol | 1,200 | 0 | 0.00% | 100 | 85 | - |
| feed:source_6a061cf23c508 | 1,200 | 0 | 0.00% | 100 | 85 | - |
| feed:source_6a061f0dcc467 | 1,200 | 0 | 0.00% | 100 | 80 | - |
| feed:source_6a0ee74b0dd5b | 1,200 | 0 | 0.00% | 100 | 60 | - |
| feed:source_6a0ee74b0e639 | 1,200 | 0 | 0.00% | 100 | 60 | - |
| feed:source_6a0ee76143079 | 990 | 0 | 0.00% | 100 | 60 | - |
| feed:source_6a0ee75899dfd | 412 | 0 | 0.00% | 100 | 60 | - |
| manual:analyst | 40 | 0 | 0.00% | 100 | — | - |
| manual:automation | 38 | 0 | 0.00% | 100 | — | - |
| manual:soc-tier1 | 35 | 0 | 0.00% | 100 | — | - |
| manual:soc-tier2 | 35 | 0 | 0.00% | 100 | — | - |
| manual:malwarebazaar | 12 | 0 | 0.00% | 100 | — | - |
ℹ️ Reliability = (1 - FP oranı) × 100. 95+ ideal, <60 gözden geçirilmeli.
Default Conf kaynak admin tarafından atanır (T2.5).
Audit Log (Son İşlemler)
son 50 kayıt| Zaman | Kullanıcı | Aksiyon | Detay | IP |
|---|---|---|---|---|
| 2026-09-02 05:35:49 | demo | login_success | {"user":"demo","role":"viewer"} | 127.0.0.1 |