Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
FortiGate

Güvenlik Duvarınız Topluluğu Korusun Let Your Firewall Protect the Community

FortiGate Automation Stitch ile SiberKapan'ı entegre edin — saldırı tespit edildiği anda IP otomatik olarak platforma bildirilir, topluluğun tüm üyeleriyle paylaşılır ve blocklist'lere dahil edilir. Kurulum 5 dakika sürer. Integrate SiberKapan with FortiGate Automation Stitch — the moment an attack is detected, the IP is automatically reported to the platform, shared with the entire community, and added to blocklists. Setup takes 5 minutes.

Canlı FortiGate İstatistikleri Live FortiGate Statistics
45205
Toplam Saldırı Bildirimi Total Attack Reports
9432
Anomali Tespit Edilen IP IPs with Anomaly Detection
1
Doğrulanmış Saldırgan IP Verified Attacker IPs
10
Katkı Sağlayan FortiGate Contributing FortiGates

Saldırı Türü Dağılımı Attack Type Breakdown

UDP FLOOD
34696
IP DST SESSION
5568
UDP DST SESSION
3673
TCP PORT SCAN
1039
IP SRC SESSION
76
TCP SRC SESSION
69
UDP SRC SESSION
32
UDP SCAN
26
⚠ FortiGate DoS anomaly sayaçları (UDP Flood, Session sayaçları vb.) protokolden bağımsız eşik-bazlı ölçümlerdir — kaynak IP spoof edilmiş olabilir. Yalnızca ✓ işaretli tipler, tam TCP bağlantısı gerektiren ve kaynak IP'si doğrulanabilir tespitlerdir. ⚠ FortiGate DoS anomaly counters (UDP Flood, session counters, etc.) are protocol-agnostic threshold measurements — the source IP may be spoofed. Only ✓ marked types are detections requiring a full TCP connection with a verifiable source IP.
Nasıl Çalışır? How Does It Work?
1
🛡️
Tespit Detect
FortiGate, Anomaly Logs ile bir saldırı/anormallik tespit eder. FortiGate detects an attack/anomaly via Anomaly Logs.
2
Otomatik Bildirim Automatic Report
Automation Stitch tetiklenir, webhook ile saldırgan IP SiberKapan'a anında gönderilir. Automation Stitch fires, sending the attacker IP to SiberKapan instantly via webhook.
3
🌐
Topluluğu Koru Protect Community
IP, blocklist'lere ve MISP/OTX/AbuseIPDB'ye dahil edilerek tüm toplulukla paylaşılır. The IP is added to blocklists and shared with the community via MISP/OTX/AbuseIPDB.
Saldırgan          FortiGate            Automation Stitch     SiberKapan
    │                   │                    │                    │
    │── Anomali/Saldırı ▶│                    │                    │
    │                   │── Anomaly Logs ────▶│                    │
    │                   │                    │── POST /feed/ ────▶│
    │                   │                    │   fortigate         │
    │                   │                    │                    │── DB'ye ekle
    │                   │                    │                    │── MISP / OTX / AbuseIPDB
                                                                   Tüm topluluk korunur
Kurulum Adımları Setup Steps
1

Webhook Action OluşturunCreate Webhook Action

FortiGate GUI'de Security Fabric → Automation → Action menüsüne gidin, "Create New" ile yeni bir Webhook action oluşturun.Go to Security Fabric → Automation → Action in FortiGate GUI, create a new Webhook action with "Create New".

# Action Ayarları Name: SiberKapanWebhook Protocol: HTTPS Method: POST
2

HTTP Header EkleyinAdd HTTP Headers

Webhook action'ına aşağıdaki iki header'ı ekleyin.Add the following two headers to the webhook action.

Content-Type: application/json X-SiberKapan-Key: SiberKapan_token_buraya
3

HTTP Body YapılandırınConfigure HTTP Body

Webhook body'sini FortiGate log değişkenleriyle yapılandırın.Configure the webhook body with FortiGate log variables.

{ "ip": "%%log.srcip%%", "attack_type": "%%log.attack%%", "port": %%log.dstport%%, "severity": "%%log.severity%%", "proto": "%%log.proto%%", "src_country": "%%log.srccountry%%", "device": "%%log.devname%%" }
4

Automation Stitch OluşturunCreate Automation Stitch

Security Fabric → Automation → Stitch menüsünden yeni bir stitch oluşturun. Trigger olarak Anomaly Logs seçin, action olarak az önce oluşturduğunuz SiberKapanWebhook'u atayın.Create a new stitch from Security Fabric → Automation → Stitch. Select Anomaly Logs as trigger, and assign the SiberKapanWebhook action you just created.

Trigger: Anomaly Logs Action: SiberKapanWebhook
5

Test EdinTest

Stitch'i manuel olarak tetikleyerek SiberKapan API'nin yanıt verdiğini doğrulayın.Trigger the stitch manually to verify the SiberKapan API responds correctly.

# Beklenen yanıt / Expected response: {"status":"accepted","approved":true}

Başlamak İçin API Anahtarı Gerekiyor An API Key Is Required to Get Started

SiberKapan'a ücretsiz kayıt olun, API anahtarınızı alın ve kuruluma başlayın. Register for free on SiberKapan, get your API key, and start the installation.