CrowdSec Threat Intelligence CDF
The web format of this guide reflects the most current release. Guides for older iterations are available in PDF format.
Integration Details
ThreatQuotient provides the following details for this integration:
| Current Integration Version | 2.0.0 |
| Compatible with ThreatQ Versions | >= 5.25.0 |
| Support Tier | ThreatQ Supported |
Introduction
The CrowdSec Threat Intelligence integration allows a user to ingest the latest IPs belonging to the CrowdSec community-blocklist.
The integration provides the following feeds:
- CrowdSec Threat Intelligence Indicators - ingests the latest IPs belonging to the CrowdSec community-blocklist.
- CrowdSec Smoke CTI - ingests IP intelligence matching a user-supplied CrowdSec Lucene query.
The integration ingests the following system object types:
- Attack Patterns
- Indicators
- Indicator Attributes
- Vulnerabilities
Prerequisites
The following is required to run the integration:
- A CrowdSec CTI API key with access to the selected endpoint is required. Programmatic access to Lucene search may require an Advanced CTI plan.
Installation
Perform the following steps to install the integration:
The same steps can be used to upgrade the integration to a new version.
- Log into https://marketplace.threatq.com/.
- Locate and download the integration file.
- Navigate to the integrations management page on your ThreatQ instance.
- Click on the Add New Integration button.
- Upload the integration file using one of the following methods:
- Drag and drop the file into the dialog box
- Select Click to Browse to locate the integration file on your local machine
- If prompted, select the individual feeds to install and click Install. The feed will be added to the integrations page.
You will still need to configure and then enable the feed.
Configuration
ThreatQuotient does not issue API keys for third-party vendors. Contact the specific vendor to obtain API keys and other integration-related credentials.
To configure the integration:
- Navigate to your integrations management page in ThreatQ.
- Select the Commercial option from the Category dropdown (optional).
If you are installing the integration for the first time, it will be located under the Disabled tab.
- Click on the integration entry to open its details page.
- Enter the following parameters under the Configuration tab:
CrowdSec Threat Intelligence Indicators Parameters
Parameter Description API Key Enter your CrowdSec API Key. Enable SSL Certificate Verification Enable this parameter if the feed should validate the host-provided SSL certificate. Disable Proxies Enable this parameter if the feed should not honor proxies set in the ThreatQ UI. Ingest CVE Data as Select whether to ingest CVEs as indicators of vulnerabilities. The Vulnerabilities option is selected by default. CrowdSec Smoke CTI Parameters
Parameter Description API Key Enter your CrowdSec API Key. Search Query Enter the CrowdSec Lucene query used to identify the IP addresses to ingest. Enable SSL Certificate Verification Enable this parameter if the feed should validate the host-provided SSL certificate. Disable Proxies Enable this parameter if the feed should not honor proxies set in the ThreatQ UI. Ingest CVE Data as Select whether to ingest CVEs as indicators of vulnerabilities. The Vulnerabilities option is selected by default. - Review any additional settings, make any changes if needed, and click on Save.
- Click on the toggle switch, located above the Additional Information section, to enable it.
ThreatQ Mapping
CrowdSec Threat Intelligence Indicators
The CrowdSec Threat Intelligence Indicators feed retrieves and ingests the latest IPs belonging to the CrowdSec community-blocklist.
Duration is calculated in minutes and represents the last duration minutes for which the data are returned.
GET https://cti.api.crowdsec.net/v2/fire?page=1&since={duration}
Sample Response (truncated):
{
"ip": "216.73.161.91",
"ip_range": "216.73.160.0/22",
"as_name": "Ipxo Limited",
"as_num": 206092,
"reputation": "malicious",
"location": {
"country": "US",
"city": "New York"
},
"behaviors": [
{
"name": "http:exploit",
"label": "HTTP Exploit"
}
],
"history": {
"first_seen": "2022-08-24T12:15:00+00:00",
"last_seen": "2024-02-03T11:00:00+00:00"
},
"attack_details": [
{
"name": "crowdsecurity/http-sqli-probbing-detection",
"label": "SQL Injection Attempt"
}
],
"state": "validated",
"background_noise": "medium",
"mitre_techniques": [
{
"name": "T1595",
"label": "Active Scanning"
}
],
"cves": [
"CVE-2023-49103"
],
"scores": {
"overall": {
"aggressiveness": 5,
"threat": 1,
"trust": 5,
"anomaly": 1,
"total": 4
}
}
}
CrowdSec Smoke CTI
The CrowdSec Smoke CIT feed retrieves and ingests CrowdSec IP intelligence that matches a user-supplied Lucene query.
GET https://cti.api.crowdsec.net/v2/smoke/search?query={query}&page=1&since={duration}
The feed calculates duration in minutes from the ThreatQ run interval and follows CrowdSec's _links.next URL until all pages are processed. CrowdSec requires Boolean operators such as AND and OR to be uppercase.
Example queries:
classifications.classifications.name:"profile:web_hosting" AND (reputation:malicious OR reputation:suspicious)
classifications.classifications.name:/.*:mirai/ OR classifications.classifications.name:/.*:mozi/
The Smoke feed uses the shared CrowdSec mapping above, excluding the Fire-only state and expiration attributes.
Shared Mapping
ThreatQuotient provides the following default mapping for both feeds:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Notes |
|---|---|---|---|---|
items[].ip |
Indicator Value |
IP Address |
items[].history.first_seen |
|
items[].as_name |
Indicator Attribute |
Name |
items[].history.first_seen |
Updates at ingestion |
items[].as_num |
Indicator Attribute |
ASN |
items[].history.first_seen |
Updates at ingestion |
items[].reputation |
Indicator Attribute |
Reputation |
items[].history.first_seen |
Updates at ingestion |
items[].confidence |
Indicator Attribute |
Confidence |
items[].history.first_seen |
Updates at ingestion |
items[].ip_range |
Indicator Attribute |
IP Range |
items[].history.first_seen |
Updates at ingestion |
items[].ip_range_score |
Indicator Attribute |
IP Range Score |
items[].history.first_seen |
Updates at ingestion |
items[].ip_range_24 |
Indicator Attribute |
IP Range /24 |
items[].history.first_seen |
Updates at ingestion |
items[].ip_range_24_reputation |
Indicator Attribute |
IP Range /24 Reputation |
items[].history.first_seen |
Updates at ingestion |
items[].ip_range_24_score |
Indicator Attribute |
IP Range /24 Score |
items[].history.first_seen |
Updates at ingestion |
items[].location.country |
Indicator Attribute |
Country Code |
items[].history.first_seen |
Updates at ingestion |
items[].location.city |
Indicator Attribute |
City |
items[].history.first_seen |
Updates at ingestion |
items[].location.latitude |
Indicator Attribute |
Latitude |
items[].history.first_seen |
Updates at ingestion |
items[].location.longitude |
Indicator Attribute |
Longitude |
items[].history.first_seen |
Updates at ingestion |
items[].reverse_dns |
Indicator Attribute |
rDNS |
items[].history.first_seen |
Updates at ingestion |
items[].history.last_seen |
Indicator Attribute |
Last seen |
items[].history.first_seen |
Updates at ingestion |
items[].state |
Indicator Attribute |
Indicator State |
items[].history.first_seen |
Fire endpoint only |
items[].target_countries |
Indicator Attribute |
Target Country Code |
items[].history.first_seen |
Country codes are joined into one value |
items[].target_countries |
Indicator Attribute |
Target Country Distribution |
items[].history.first_seen |
Preserves CrowdSec's per-country percentages |
items[].expiration |
Indicator Attribute |
Expiration date |
items[].history.first_seen |
Fire endpoint only |
items[].scores.overall.aggressiveness |
Indicator Attribute |
Aggressiveness Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.overall.threat |
Indicator Attribute |
Threat Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.overall.trust |
Indicator Attribute |
Trust Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.overall.anomaly |
Indicator Attribute |
Anomaly Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.overall.total |
Indicator Attribute |
Overall Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.last_day.total |
Indicator Attribute |
Last Day Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.last_week.total |
Indicator Attribute |
Last Week Score |
items[].history.first_seen |
Updates at ingestion |
items[].scores.last_month.total |
Indicator Attribute |
Last Month Score |
items[].history.first_seen |
Updates at ingestion |
items[].background_noise |
Indicator Attribute |
Noise |
items[].history.first_seen |
Updates at ingestion |
items[].background_noise_score |
Indicator Attribute |
Background Noise Score |
items[].history.first_seen |
Updates at ingestion |
items[].proxy_or_vpn |
Indicator Attribute |
Proxy or VPN |
items[].history.first_seen |
Mapped when supplied by CrowdSec |
items[].behaviors[].name |
Indicator Attribute |
CrowdSec Behavior |
items[].history.first_seen |
Multi-value |
items[].classifications.classifications[].name |
Indicator Attribute |
CrowdSec Classification |
items[].history.first_seen |
Multi-value |
items[].classifications.false_positives[].name |
Indicator Attribute |
CrowdSec False Positive |
items[].history.first_seen |
Multi-value |
items[].attack_details[].name |
Indicator Attribute |
CrowdSec Attack Detail |
items[].history.first_seen |
Multi-value |
items[].references[].name |
Indicator Attribute |
CrowdSec Reference |
items[].history.first_seen |
Multi-value |
items[].cves |
Related Vulnerabilities/Indicators |
CVE |
items[].history.first_seen |
Controlled by Ingest CVEs as |
items[].mitre_techniques |
Related Attack Patterns |
MITRE ATT&CK technique |
items[].history.first_seen |
Links to existing ThreatQ Attack Patterns |
Average Feed Run
Object counts and Feed runtime are supplied as generalities only - objects returned by a provider can differ based on credential configurations and Feed runtime may vary based on system resources and load.
CrowdSec Threat Intelligence Indicators
| Metric | Result |
|---|---|
| Run Time | 8 minute |
| Indicators | 10,232 |
| Indicator Attributes | 92,799 |
| Vulnerabilities | 32 |
| Attack Pattern | 1 |
CrowdSec Smoke CTI
| Metric | Result |
|---|---|
| Run Time | 1 minute |
| Indicators | 451 |
| Indicator Attributes | 19,043 |
Change Log
- Version 2.0.0
- Added the CrowdSec Smoke CTI feed, enabling customers to ingest CrowdSec Smoke threat intelligence into ThreatQ.
- Expanded CrowdSec CTI data mappings and standardized shared processing across CrowdSec feeds to provide more complete and consistent data ingestion.
- Version 1.0.1
Added User-Agentto the request.
- Version 1.0.0
- Initial release
PDF Guides
| Document | ThreatQ Version |
|---|---|
| CrowdSec Threat Intelligence CDF Guide v2.0.0 | 5.25.0 or Greater |
| CrowdSec Threat Intelligence CDF Guide v1.0.1 | 5.25.0 or Greater |
| CrowdSec Threat Intelligence CDF Guide v1.0.0 | 5.25.0 or Greater |