Overview

ir-scripts

Random scripts for log mining, intel gathering, network querying, and other incident response-ish activities. Unless otherwise indicated, all files in this project are governed by the GPLv3 license. For reference, you should have received a LICENSE file when cloning this repository.

ioc-intel.sh

This script performs some quick lookups against a list of ip address or FQDN IOCs

reverselook.sh

performs reverse lookups on a list of IP addresses

cif-lookup.sh

performs lookups on multiple cif servers and reports on hit or no hit cif servers are based on local user's .cif* files