SiberKapan REST API'si, tehdit istihbarat verilerine programatik erişim sağlar. IP listelerini indirme, saldırgan IP bildirimi ve BGP sorgulama işlemleri bu API üzerinden gerçekleştirilebilir. The SiberKapan REST API provides programmatic access to threat intelligence data. Downloading IP lists, reporting attacker IPs, and BGP lookups can all be performed through this API.
Feed gönderim endpoint'leri için HTTP header'ında API key gönderilmesi gerekmektedir. Feed submission endpoints require an API key to be sent in the HTTP header.
Onaylı saldırgan IP listelerini farklı formatlarda indirin. Tüm listeler ücretsizdir. Download approved attacker IP lists in different formats. All lists are free.
Tüm onaylı IP adreslerini satır başı ayrılmış plaintext formatında döndürür.Returns all approved IP addresses in newline-separated plaintext format.
API key olmadan temel alanları, API key ile BGP detaylarını (ASN, prefix, abuse contact) döndürür.Returns basic fields without API key, BGP details (ASN, prefix, abuse contact) with API key.
FortiGate CLI'ye doğrudan yapıştırılabilir address object formatında döndürür.Returns in address object format that can be pasted directly into FortiGate CLI.
Tespit ettiğiniz saldırgan IP'leri platforma bildirin. Doğrulanmış API key ile gönderilen IP'ler otomatik onaylanır. Report attacker IPs you have detected to the platform. IPs submitted with a verified API key are automatically approved.
| AlanField | Type | AçıklamaDescription |
|---|---|---|
| ip required | string | Saldırgan IP adresiAttacker IP address |
| attack_type | string | brute_force, port_scan, honeypot_hit ... |
| port | integer | Hedef port numarasıTarget port number |
| severity | string | low, medium, high, critical |
| proto | string | Protokol (tcp/udp/icmp)Protocol (tcp/udp/icmp) |
| src_country | string | Kaynak IP ülke kodu (FortiGate tarafından doldurulur)Source IP country code (filled by FortiGate) |
| device | string | FortiGate cihaz adıFortiGate device name |
| policy | string | Tetiklenen firewall policy adıTriggered firewall policy name |
HoneypotKapan sensörlerinden gelen saldırgan verisi. Genellikle HoneypotKapan agent'ı tarafından otomatik gönderilir, manuel kullanım için tasarlanmamıştır.Attacker data from HoneypotKapan sensors. Typically sent automatically by the HoneypotKapan agent, not intended for manual use.
| AlanField | Type | AçıklamaDescription |
|---|---|---|
| ip required | string | Saldırgan IP adresiAttacker IP address |
| attack_type | string | honeypot_ssh, honeypot_ftp, honeypot_rdp ... |
| port | integer | Honeypot port numarasıHoneypot port number |
| sensor | string | Sensör adı (varsayılan: HoneypotKapan)Sensor name (default: HoneypotKapan) |
| username | string | Yakalanan kullanıcı adı (varsa)Captured username (if any) |
Fail2Ban'ın actionban direktifine eklenecek basit bir webhook. Bir IP banlandığında SiberKapan'a otomatik bildirir.A simple webhook to add to Fail2Ban's actionban directive. Automatically notifies SiberKapan when an IP is banned.
| AlanField | Type | AçıklamaDescription |
|---|---|---|
| ip required | string | Banlanan IP adresiBanned IP address |
| action | string | ban / unban unban yoksayılır |
Nginx access log'larından tespit edilen saldırı paternlerini bildirir. Genellikle Nginx Watcher agent'ı tarafından otomatik gönderilir.Reports attack patterns detected from nginx access logs. Typically sent automatically by the Nginx Watcher agent.
| AlanField | Type | AçıklamaDescription |
|---|---|---|
| ip required | string | Saldırgan IP adresiAttacker IP address |
| pattern_type | string | 404_flood, auth_flood, rate_flood, path_signature, ua_signature |
| detail | object | path, status, hit_count, window_s gibi pattern detaylarıPattern details such as path, status, hit_count, window_s |
API key gerektirmez. Gönderilen IP'ler moderasyon kuyruğuna alınır, incelendikten sonra yayınlanır.No API key required. Submitted IPs enter the moderation queue and are published after review.
Bir IP adresi hakkında ASN, ülke, tehdit skoru ve kaynak geçmişi bilgisi alın. Get ASN, country, threat score and source history information about an IP address.
STIX 2.1 (Structured Threat Information eXpression) formatında tehdit istihbarat bundle. Kurumsal CTI platformları ve SIEM sistemleri ile doğrudan entegre edilebilir. Threat intelligence bundle in STIX 2.1 (Structured Threat Information eXpression) format. Directly integrable with enterprise CTI platforms and SIEM systems.
| Parametre | Type | Default | Açıklama |
|---|---|---|---|
| limit | integer | 100 | Maksimum IP sayısı (max 500)Maximum IP count (max 500) |
| min_score | integer | 0 | Minimum tehdit skoru filtresiMinimum threat score filter |
TAXII 2.1 (Trusted Automated eXchange of Intelligence Information) protokolü üzerinden STIX 2.1 tehdit istihbaratı. Kurumsal SIEM/SOAR sistemleri, Anomali, ThreatConnect ve CERT sistemleriyle native entegrasyon. STIX 2.1 threat intelligence over TAXII 2.1 (Trusted Automated eXchange of Intelligence Information) protocol. Native integration with enterprise SIEM/SOAR systems, Anomali, ThreatConnect and CERT platforms.
https://siberkapan.org/taxii/ ·
Content-Type: application/taxii+json;version=2.1
TAXII sunucusu hakkında temel bilgi ve API root listesi.
Mevcut koleksiyonlar: all-threats, high-risk, honeypot
| Parametre | Type | Default | Açıklama |
|---|---|---|---|
| limit | integer | 100 | Maksimum obje sayısı (max 1000) |
| added_after | datetime | - | Bu tarihten sonra eklenen objeler (ISO 8601) |
a1b2c3d4-0001-4000-8000-siberkapan01 (all-threats) ·
a1b2c3d4-0002-4000-8000-siberkapan02 (high-risk) ·
a1b2c3d4-0003-4000-8000-siberkapan03 (honeypot)
Koleksiyondaki tüm objelerin ID ve versiyon bilgisi. TAXII istemcilerinin delta sync için kullandığı endpoint.
Suricata IDS ve Wazuh SIEM sistemlerine doğrudan entegre edilebilir export formatları. min_score ve since parametreleri desteklenir.
Export formats directly integrable with Suricata IDS and Wazuh SIEM. Supports min_score and since parameters.
Suricata IDS için hazır drop/alert kuralları. Score 75+ için drop, 40-74 için drop, altı için alert.Ready-to-use drop/alert rules for Suricata IDS. Score 75+ generates drop rules, below generates alert rules.
| Parametre | Type | Default | Açıklama |
|---|---|---|---|
| min_score | integer | 40 | Minimum tehdit skoruMinimum threat score |
| since | datetime | - | Delta — bu tarihten sonraki IP'ler (ISO 8601)Delta — IPs added after this date (ISO 8601) |
Wazuh SIEM için CDB (Constant Database) formatında IP listesi. ossec.conf ile entegre edin.IP list in CDB (Constant Database) format for Wazuh SIEM. Integrate via ossec.conf.
| Parametre | Type | Default | Açıklama |
|---|---|---|---|
| min_score | integer | 40 | Minimum tehdit skoruMinimum threat score |
| since | datetime | - | Delta — bu tarihten sonraki IP'ler (ISO 8601)Delta — IPs added after this date (ISO 8601) |
CVE özetleri ve IOC listelerini RSS/Atom formatında alın. SIEM ve izleme sistemlerinize entegre edin. Receive CVE summaries and IOC lists in RSS/Atom format. Integrate into your SIEM and monitoring systems.
CISA KEV veritabanından alınan kritik CVE'leri RSS formatında döndürür. Her gün güncellenir.Returns critical CVEs from the CISA KEV database in RSS format. Updated daily.
Son eklenen 100 saldırgan IP'yi RSS formatında döndürür. Saatlik güncellenir.Returns the last 100 added attacker IPs in RSS format. Updated hourly.
FortiGate Automation Stitch ile SiberKapan'ı entegre edin: saldırı tespitinde otomatik IP bildirimi yapın. Integrate SiberKapan with FortiGate Automation Stitch: automatically report IPs upon attack detection.
Automation Action OluşturunCreate Automation Action
FortiGate GUI'de Security Fabric → Automation → Actions menüsüne gidin. "Create New" ile yeni bir Webhook action oluşturun.Go to Security Fabric → Automation → Actions in FortiGate GUI. Create a new Webhook action with "Create New".
Header EkleyinAdd Header
Webhook action'ına API key header'ı ekleyin.Add the API key header to the webhook action.
Body YapılandırınConfigure Body
Webhook body'sini FortiGate event değişkenleriyle yapılandırın.Configure the webhook body with FortiGate event variables.
Automation Stitch OluşturunCreate Automation Stitch
Security Fabric → Automation → Stitches menüsünden yeni bir stitch oluşturun. Trigger olarak Anomaly Logs veya IPS Event seçin, action olarak az önce oluşturduğunuz SiberKapan-Report action'ını atayın.Create a new stitch from Security Fabric → Automation → Stitches. Select IPS Event or Anomaly Logs as trigger, and assign the SiberKapan-Report action you just created.
Test EdinTest
Stitch'i manuel olarak tetikleyerek SiberKapan API'nin yanıt verdiğini doğrulayın.Trigger the stitch manually to verify the SiberKapan API responds correctly.