Repository navigation
Expand file tree
/
Copy pathREADME.Rmd
More file actions
78 lines (52 loc) · 1.8 KB
/
Copy pathREADME.Rmd
File metadata and controls
78 lines (52 loc) · 1.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
---
title: "README"
author: "Bob Rudis"
date: "August 30, 2014"
output:
md_document:
variant: markdown_github
---
Version 1.2 adds the [Zeus](https://zeustracker.abuse.ch/blocklist.php) and [Nothink](http://www.nothink.org/) blocklists
Version 1.1 brings a significant update to the core components of the `netinel` package. Every function has been re-written to be as fast as possible without resorting to `Rcpp` functions. The intent of the package is to provide as many IP & ASN intelligence routines to those using R for Security Data Science and security intel/ops/IR work.
It relies on `httr`, `plyr` & `data.table`.
Current function list:
- `Alien.Vault.Reputation` - Retrieves Alien Vault's IP reputation database
- `BulkOrigin` - Retrieves BGP Origin ASN info for a list of IPv4 addresses
- `BulkOriginASN` - Retrieves BGP Origin ASN info for a list of ASN ids
- `BulkPeer` - Retrieves BGP Peer ASN info for a list of IPv4 addresses
- `CIRCL.BGP.Rank` - Retrieves CIRCL aggregated, historical/current BGP rank data
- `SANS.ASN.Detail` - Retrieves SANS ASN intel currently tracked IP detail
- `Zeus.Blocklist` - Retrieves Zeus Blocklist (IP/FQDN/URL)
- `Nothink.Blocklist` - Retrieves Nothink Malware DNS network traffic blacklist (IP/FQDN)
### Installation
```{r eval=FALSE}
devtools::install_github("hrbrmstr/netintel")
library(netintel)
```
### Usage
```{r}
library(netintel)
# current verison
packageVersion("netintel")
# Bulk stuff
BulkOrigin("162.243.111.4")
BulkOriginASN(62567)
BulkPeer("162.243.111.4")
# CIRCL
head(CIRCL.BGP.Rank(62567))
# SANS was flaky so no example
# SANS.ASN.Detail(62567)
# AlienVault
head(Alien.Vault.Reputation())
# Zeus
str(Zeus.Blocklist())
# Nothink
str(Nothink.Blocklist())
```
### Test Results
```{r}
library(netintel)
library(testthat)
date()
test_dir("tests/")
```