File tree Expand file tree Collapse file tree 1 file changed +65
-0
lines changed
crowdsec-docs/unversioned/cti_api Expand file tree Collapse file tree 1 file changed +65
-0
lines changed Original file line number Diff line number Diff line change @@ -48,6 +48,8 @@ On the next page you can create an API key by clicking the `+ New Key` button.
4848
4949## Accessing the API
5050
51+ ### cURL
52+
5153You can test your newly created API key by running the following command in your terminal:
5254
5355:::info
@@ -216,6 +218,69 @@ And the default output looks something like this:
216218
217219</details >
218220
221+ ### ipdex
222+
223+ You can interact with the CrowdSec CTI API with the [ ` ipdex ` ] ( https://github.com/crowdsecurity/ipdex ) tool.
224+
225+ First, initiliaze the tool with your API key:
226+
227+ ``` console
228+ ipdex init
229+ ```
230+
231+ And then analyze an IP or a file of IPs:
232+
233+ ``` console
234+ ipdex 193.105.134.155
235+ ```
236+
237+ <details >
238+
239+ <summary >Command Output</summary >
240+
241+ ``` console
242+ IP Information
243+
244+ IP 193.105.134.155
245+ Reputation malicious
246+ Confidence high
247+ Country SE 🇸🇪
248+ Autonomous System w1n ltd
249+ Reverse DNS N/A
250+ Range 193.105.134.0/24
251+ First Seen 2023-06-23T01:15:00
252+ Last Seen 2025-05-11T11:15:00
253+ Console URL https://app.crowdsec.net/cti/193.105.134.155
254+ Last Local Refresh 2025-05-12 16:44:21
255+
256+ Threat Information
257+
258+ Behaviors
259+ HTTP Scan
260+ HTTP Bruteforce
261+ SSH Bruteforce
262+ ... and 2 more
263+
264+
265+ Classifications
266+ Spoofed User Agent
267+ TOR exit node
268+ VPN or Proxy
269+ ... and 1 more
270+
271+
272+ Blocklists
273+ Extended AI-Detected VPN/Proxy
274+ CrowdSec Intelligence Blocklist
275+
276+ Target countries
277+ 🇺🇸 US 29%
278+ 🇩🇪 DE 15%
279+ 🇵🇱 PL 12%
280+ ... and 2 more
281+ ```
282+ </details >
283+
219284<AcademyPromo
220285 image = " crowdsec_threat_intelligence.svg"
221286 description = " Watch a short series of videos on how to get the most out of CrowdSec’s Cyber Threat Intelligence database"
You can’t perform that action at this time.
0 commit comments