mirror of
https://github.com/JGoyd/ShadowShells.git
synced 2026-08-17 10:00:25 +02:00
Update blocklist file format in README
This commit is contained in:
@@ -10,7 +10,7 @@ All data here is **metadata only**. No raw logs, PCAPs, or sensitive artifacts a
|
|||||||
|
|
||||||
## Intended Use
|
## Intended Use
|
||||||
- Ingest `iocs.csv` into monitoring tooling, SIEM rules, DNS tracking, or threat-hunting routines.
|
- Ingest `iocs.csv` into monitoring tooling, SIEM rules, DNS tracking, or threat-hunting routines.
|
||||||
- Apply `blocklist.txt` for defensive blocking or sinkholing.
|
- Apply `blocklist.csv` for defensive blocking or sinkholing.
|
||||||
- Consult `key_hits.txt` to track behaviors or patterns: shell anomalies, proxy/tunnel strings, beacon pulses.
|
- Consult `key_hits.txt` to track behaviors or patterns: shell anomalies, proxy/tunnel strings, beacon pulses.
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user