Building a threat intelligence feed using the Twitter API and a bit of code
grimminck.medium.com
grimminck.medium.com
curl https://twitter.threatintel.rocks/ --silent | jq -r '.malicious_urls | .[]'
For example: https://xunmaus.xn--rvg
In the meantime, I'm using a modified command like so: `curl https://twitter.threatintel.rocks/ --silent | jq -r '.malicious_urls | .[]' | sort -u | grep -v …`
In this day and age, if people don’t put emphasis on TTPs and still only rely on old style threat intel, they will become obsolete.
I got banned for posting too hard or something, I'm not clear on the specifics, I'm probably just gonna stand up a domain or join mastadon rather than try to crowd into some musky space.
Disclaimer: I’m the founder ;)