Fortinet white logo
Fortinet white logo

User Guide

Malware IPs

Malware IPs

The Malware IP Addresses page lists IP addresses that are known to generate spam, host botnets, create DDoS attacks, and generally contain malware. The default group included in your FortiSIEM deployment, Emerging Threat, contains IP addresses that are derived from the website rules.emergingthreats.net. Because malware IP addresses are constantly changing, FortiSIEM recommends maintaining a dynamically generated list of IP addresses provided by services such as Emerging Threat that are updated on a regular schedule, but you can also add or remove blocked IP addresses from these system-defined groups, and create your own groups based on manual entry of IP addresses or file upload. A Python Threat Feed Framework is also available, see here.

The following sections describe Malware IPs:

Malware IPs

Malware IPs

The Malware IP Addresses page lists IP addresses that are known to generate spam, host botnets, create DDoS attacks, and generally contain malware. The default group included in your FortiSIEM deployment, Emerging Threat, contains IP addresses that are derived from the website rules.emergingthreats.net. Because malware IP addresses are constantly changing, FortiSIEM recommends maintaining a dynamically generated list of IP addresses provided by services such as Emerging Threat that are updated on a regular schedule, but you can also add or remove blocked IP addresses from these system-defined groups, and create your own groups based on manual entry of IP addresses or file upload. A Python Threat Feed Framework is also available, see here.

The following sections describe Malware IPs: