Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
Metodoloji Methodology

Veri Metodolojisi Data Methodology

SiberKapan'ın tehdit verilerini nasıl topladığı, doğruladığı, skorladığı ve yayınladığı bu sayfada belgelenmiştir. Şeffaflık, platformun temel ilkelerinden biridir. This page documents how SiberKapan collects, validates, scores, and publishes threat data. Transparency is one of the platform's core principles.

Veri İşleme Süreci Data Processing Pipeline
1

Veri ToplamaData Collection

Veriler üç kanaldan toplanır: (1) Katılımcı ağı — FortiGate Automation Stitch webhook'ları aracılığıyla doğrulanmış kurumlardan gelen gerçek saldırı tespitleri. (2) Harici feed'ler — Feodo Tracker, URLhaus ve Emerging Threats 6 saatte bir otomatik çekilir. (3) CISA KEV — kritik CVE kayıtları günlük güncellenir.Data is collected from three channels: (1) Participant network — real attack detections from verified organizations via FortiGate Automation Stitch webhooks. (2) External feeds — Feodo Tracker, URLhaus, and Emerging Threats are automatically pulled every 6 hours. (3) CISA KEV — critical CVE records are updated daily.

FortiGate Webhook Feodo Tracker URLhaus Emerging Threats CISA KEV 6s güncelleme / update
2

DoğrulamaValidation

Her gelen IP için format doğrulaması (RFC 791) yapılır. Özel ağ adresleri (RFC 1918), loopback ve multicast adresleri otomatik reddedilir. Harici feed kaynaklı IP'ler otomatik onaylanır. Topluluk bildirimleri iki aşamada işlenir: API key'li doğrulanmış üyelerden gelen bildirimleri otomatik onaylanır; kayıtsız topluluk bildirimleri moderasyon kuyruğuna alınır.Format validation (RFC 791) is performed for each incoming IP. Private network addresses (RFC 1918), loopback, and multicast addresses are automatically rejected. IPs from external feed sources are automatically approved. Community submissions are processed in two stages: submissions from verified API key members are automatically approved; unregistered community reports enter the moderation queue.

RFC 791 Doğrulama Moderasyon Kuyruğu Otomatik Onay (API Key)
3

SkorlamaScoring

Her IP adresine 0-100 arası tehdit skoru atanır. Skor, kaynak tipi ve severity'e göre hesaplanır. Birden fazla kaynaktan gelen raporlar skoru kümülatif olarak artırır (maksimum 100). 30 gün boyunca yeni bir tespit gelmezse skor günlük olarak düşürülür (aging); skor 15'in altına inerse IP otomatik olarak blocklist'ten çıkarılır (kayıt silinmez, sadece onay durumu kaldırılır). Bu, dinamik IP atayan ağlarda zamanla masum kullanıcılara geçen adreslerin süresiz olarak listelenmesini önler.Each IP address is assigned a threat score between 0-100. The score is calculated based on source type and severity. Reports from multiple sources cumulatively increase the score (maximum 100). If no new detection occurs within 30 days, the score decays daily; if it drops below 15, the IP is automatically removed from the blocklist (the record is not deleted, only its approval status is revoked). This prevents addresses that later pass to innocent users on dynamic-IP networks from remaining listed indefinitely.

0-100 SkorScore KümülatifCumulative
4

GeoIP ZenginleştirmeEnrichment

ip-api.com servisi kullanılarak her IP için ülke kodu, AS numarası, organizasyon adı ve datacenter/proxy tespiti yapılır. Bu bilgi blocklist'e dahil edilir ve BGP sorgulama sayfasında görüntülenir. GeoIP verisi tahmini olup %100 doğruluk garantisi verilmez.Using the ip-api.com service, country code, AS number, organization name, and datacenter/proxy detection is performed for each IP. This information is included in the blocklist and displayed on the BGP lookup page. GeoIP data is approximate and 100% accuracy is not guaranteed.

ip-api.com ASN / BGP Tahmini veriApproximate data
5

YayınlamaPublication

Onaylı IP'ler REST API üzerinden TXT, JSON, CIDR, FortiGate CLI ve iptables formatlarında sunulur. Ülke ve platform bazlı listeler RIPE NCC API'sinden anlık çekilir. CVE feed'i RSS/Atom formatında vendor bazında filtrelenmiş olarak yayınlanır.Approved IPs are served via REST API in TXT, JSON, CIDR, FortiGate CLI, and iptables formats. Country and platform-based lists are pulled in real time from the RIPE NCC API. CVE feed is published in RSS/Atom format with vendor-based filtering.

REST API RSS/Atom FortiGate CLI iptables RIPE NCC
Tehdit Skoru Hesaplama Threat Score Calculation
Kaynak / OlaySource / Event Skor ArtışıScore Bump SeviyeLevel AçıklamaNotes
FortiGate — Critical +40 Critical API key'li, kritik severityAPI key, critical severity
FortiGate — High +30 High API key'li, yüksek severityAPI key, high severity
FortiGate — Medium +20 Medium API key'li, orta severityAPI key, medium severity
FortiGate — Low / BilinmiyorUnknown +10 Low API key'li veya düşük severityAPI key or low severity
Honeypot +30 Honeypot Doğrudan honeypot tespitiDirect honeypot detection
Bulk API +15 Bulk Toplu bildirimBulk submission
Harici FeedExternal Feed +50 External Başlangıç skoru, kaynağa bağlıInitial score, source dependent
Veri Kaynakları Data Sources
Community

FortiGate Webhook

Doğrulanmış API key sahibi üyelerden Automation Stitch webhook'ları ile gelen gerçek saldırı tespitleri.Real attack detections from verified API key members via Automation Stitch webhooks.

External

Feodo Tracker

Abuse.ch — Emotet, Dridex, TrickBot botnet C2 sunucuları. 6 saatte bir güncellenir.Abuse.ch — Emotet, Dridex, TrickBot botnet C2 servers. Updated every 6 hours.

External

URLhaus

Abuse.ch — Malware dağıtan URL ve IP adresleri. 6 saatte bir güncellenir.Abuse.ch — Malware distributing URLs and IP addresses. Updated every 6 hours.

External

Emerging Threats

Proofpoint — Aktif tehdit aktörleri IP listesi. 12 saatte bir güncellenir.Proofpoint — Active threat actors IP list. Updated every 12 hours.

External

CISA KEV

ABD Siber Güvenlik Ajansı bilinen istismar edilen zafiyet kataloğu. Günlük güncellenir.US Cybersecurity Agency known exploited vulnerabilities catalog. Updated daily.

RIPE NCC

RIPE NCC Stat API

Ülke bazlı IP prefix listeleri için kullanılır. Veriler anlık çekilir, cache'lenmez.Used for country-based IP prefix lists. Data is pulled in real time, not cached.

AbuseIPDB Karşılaştırma Analizi AbuseIPDB Comparison Analysis

SiberKapan veritabanındaki IP'ler periyodik olarak AbuseIPDB ile karşılaştırılmaktadır. Bu analiz, platformun global feed'lere kıyasla özgün katkısını ölçmektedir. IPs in the SiberKapan database are periodically compared with AbuseIPDB. This analysis measures the platform's original contribution compared to global feeds.

38372
Kontrol edilen IPIPs checked
6580
AbuseIPDB'de yokNot in AbuseIPDB
%17
Özgün tespit oranıOriginal detection rate
20168
Yüksek riskli (score≥50)High risk (score≥50)
%30
SiberKapan daha güncelSiberKapan more recent
107
Ort. gün farkıAvg. days difference
29146
AbuseIPDB'ye raporlandıReported to AbuseIPDB
Bu veriler 6 saatte bir otomatik olarak güncellenmektedir. AbuseIPDB'de bulunmayan veya SiberKapan'ın daha güncel gördüğü IP'ler, FortiGate topluluk ağının global feed'lere kıyasla özgün katkısını göstermektedir. This data is automatically updated every 6 hours. IPs not found in AbuseIPDB are threats detected by SiberKapan ahead of global feeds through the FortiGate community network.
Ekosistem Entegrasyonları Ecosystem Integrations

SiberKapan, kendi platformunda kalmak yerine tespit ettiği tehdit verisini global siber güvenlik topluluğuyla paylaşmaktadır. Bu, hem verinin gerçek dünyada doğrulanmasını sağlar hem de Türkiye merkezli tehdit istihbaratının uluslararası ekosistemde görünür olmasına katkıda bulunur. Rather than remaining siloed, SiberKapan shares the threat data it detects with the global cybersecurity community. This both validates the data in the real world and contributes to the international visibility of Turkey-centric threat intelligence.

MISP

MISP Feed Entegrasyonu MISP Feed Integration

Standart MISP feed formatında (manifest tabanlı), kimlik doğrulama gerektirmeden gerçek zamanlı tehdit verisi sunulur. Herhangi bir MISP kurulumu feed'i doğrudan ekleyip platformun tespitlerinden faydalanabilir. Veri bütünlüğü için iki önlem alınmıştır: (1) her IP-attribute'u tarih ve IP değerinden deterministik olarak üretilen bir UUID'ye sahiptir, böylece feed periyodik olarak yeniden üretildiğinde aynı gösterge için her zaman aynı UUID korunur ve alıcı MISP sunucularında correlation/sighting geçmişi kaybolmaz; (2) feed'e eklenmeden önce her IP, bilinen CDN/bulut sağlayıcı (Cloudflare, Fastly, AWS CloudFront, Google) aralıklarına karşı kontrol edilir, bu sayede altyapı IP'lerinin yanlışlıkla gösterge olarak yayınlanması önlenir. Real-time threat data is served in standard MISP feed format (manifest-based), requiring no authentication. Any MISP instance can add the feed directly and benefit from the platform's detections. Two measures protect data integrity: (1) each IP attribute has a UUID generated deterministically from its date and IP value, so when the feed is regenerated periodically the same indicator always keeps the same UUID, preventing receiving MISP instances from losing correlation/sighting history; (2) before being added to the feed, every IP is checked against known CDN/cloud provider ranges (Cloudflare, Fastly, AWS CloudFront, Google), preventing infrastructure IPs from being mistakenly published as indicators.

Feed'i görüntüleView feed
ABUSEIPDB

AbuseIPDB Topluluk Entegrasyonu AbuseIPDB Community Integration

İki yönlü entegrasyon: tespit edilen kötü amaçlı IP'ler otomatik raporlanır, AbuseIPDB verisi de kendi tespitlerle çapraz kontrol edilir. Yukarıdaki analiz bu karşılaştırmanın canlı sonucudur. Two-way integration: detected malicious IPs are automatically reported, and AbuseIPDB data is cross-checked against our own detections. The analysis above is the live result of this comparison.

Contributor profiliContributor profile
OTX

AlienVault OTX (LevelBlue) Entegrasyonu AlienVault OTX (LevelBlue) Integration

Honeypot, Fail2ban ve FortiGate Security Fabric kaynaklarından tespit edilen kötü amaçlı IP'ler, dünyanın en büyük açık tehdit istihbaratı topluluklarından biri olan OTX'e günlük pulse'lar halinde otomatik yayınlanır. Malicious IPs detected from Honeypot, Fail2ban, and FortiGate Security Fabric sources are automatically published as daily pulses to OTX, one of the world's largest open threat intelligence communities.

Canlı pulse'larLive pulses

Açık Kaynak Topluluk Tanınırlığı Open-Source Community Recognition

SiberKapan, dünya çapında kabul gören açık kaynak tehdit istihbaratı kaynak listelerinde (awesome-threat-intelligence) yer almak üzere değerlendirme sürecindedir. MISP projesinin (Malware Information Sharing Platform) resmi varsayılan feed listesine eklenme başvurusu kabul edilmiş ve feed'imiz, MISP projesinin kurucusu Andras Iklody tarafından bizzat incelenip onaylanarak ana depoya (core repository) dahil edilmiştir. SiberKapan is under review for inclusion in globally recognized open-source threat intelligence resource lists (awesome-threat-intelligence). Our application for inclusion in the official default feed list of the MISP (Malware Information Sharing Platform) project has been accepted, and the feed was personally reviewed and merged into the core repository by Andras Iklody, founder of the MISP project.

Bilinen Sınırlamalar Known Limitations

  • Coğrafi kapsam: SiberKapan global kapsam iddiasında bulunmaz. Türkiye'ye yönelik tehditlere odaklanır; Türkiye'den gönderilen FortiGate webhook'ları ve Türkiye altyapısını hedefleyen saldırı örüntüleri önceliklendirilir.Geographic coverage: SiberKapan does not claim global coverage. It focuses on threats targeting Turkey; FortiGate webhooks sent from Turkey and attack patterns targeting Turkish infrastructure are prioritized.
  • GeoIP doğruluğu: IP-API.com GeoIP verileri yaklaşık değerlerdir. VPN, proxy ve Tor exit node'ları yanlış konumlandırılabilir.GeoIP accuracy: IP-API.com GeoIP data is approximate. VPNs, proxies, and Tor exit nodes may be mislocated.
  • Harici feed bağımlılığı: Feodo, URLhaus gibi harici feed'ler erişilemez olduğunda ilgili kategori güncellenemez. Bu durumlar loglanır ancak kullanıcıya bildirilmez.External feed dependency: When external feeds like Feodo or URLhaus are unavailable, the relevant category cannot be updated. These cases are logged but not notified to users.
  • False positive riski: Özellikle topluluk bildirimleri yanlış pozitif içerebilir. IP detay sayfasındaki kaynak bilgisi ve itiraz formu bu riski azaltmak için mevcuttur.False positive risk: Community submissions in particular may contain false positives. Source information on the IP detail page and the delisting form exist to mitigate this risk.

Her IP Kaydında Bulunan Bilgiler (Provenance) Information Available for Each IP Record (Provenance)

IP AdresiIP Address ip_address
Tehdit Skoru (0-100)Threat Score (0-100) score
İlk Görülme TarihiFirst Seen Date first_seen
Son Görülme TarihiLast Seen Date last_seen
Rapor SayısıReport Count report_count
Kaynak TipiSource Type source_type (fortigate / external / honeypot)
Kaynak Feed AdıSource Feed Name source_name (feodo / urlhaus / ...)
Saldırı TürüAttack Type attack_type
Ülke / ASNCountry / ASN country_code, asn, asn_org