Skip to content

Instantly share code, notes, and snippets.

@ddqp
Last active March 30, 2024 03:59
Show Gist options
  • Select an option

  • Save ddqp/06a2d8c95e3bb8f8e001e2452d542e09 to your computer and use it in GitHub Desktop.

Select an option

Save ddqp/06a2d8c95e3bb8f8e001e2452d542e09 to your computer and use it in GitHub Desktop.

Revisions

  1. ddqp revised this gist Mar 30, 2024. 1 changed file with 11 additions and 0 deletions.
    11 changes: 11 additions & 0 deletions falcon.list
    Original file line number Diff line number Diff line change
    @@ -2,6 +2,17 @@
    #!desc=自定义规则
    #!category=DDQP
    [Rule]

    # JCI
    DOMAIN-SUFFIX,go.johnsoncontrols.com,REJECT-DROP,extended-matching // JCI
    DOMAIN-SUFFIX,zscaler.com,REJECT,extended-matching
    DOMAIN-SUFFIX,zscloud.net,REJECT,extended-matching
    DOMAIN-KEYWORD,rapid7,REJECT,extended-matching
    DOMAIN-SUFFIX,dlpe.jci.com,REJECT
    IP-CIDR,180.167.3.68/32,REJECT,no-resolve
    IP-CIDR,165.225.116.38/32,REJECT,no-resolve
    IP-CIDR,165.225.110.28/32,REJECT,no-resolve
    # Falcon
    DOMAIN-SUFFIX, assets.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, assets-public.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, falconapi.us-2.crowdstrike.com, REJECT
  2. ddqp revised this gist Mar 30, 2024. 1 changed file with 1 addition and 0 deletions.
    1 change: 1 addition & 0 deletions falcon.list
    Original file line number Diff line number Diff line change
    @@ -1,5 +1,6 @@
    #!name=ddqp自定义
    #!desc=自定义规则
    #!category=DDQP
    [Rule]
    DOMAIN-SUFFIX, assets.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, assets-public.falcon.crowdstrike.com, REJECT
  3. ddqp revised this gist Mar 30, 2024. 1 changed file with 3 additions and 0 deletions.
    3 changes: 3 additions & 0 deletions falcon.list
    Original file line number Diff line number Diff line change
    @@ -1,3 +1,6 @@
    #!name=ddqp自定义
    #!desc=自定义规则
    [Rule]
    DOMAIN-SUFFIX, assets.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, assets-public.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, falconapi.us-2.crowdstrike.com, REJECT
  4. ddqp renamed this gist Mar 30, 2024. 1 changed file with 0 additions and 1 deletion.
    1 change: 0 additions & 1 deletion falcon.txt → falcon.list
    Original file line number Diff line number Diff line change
    @@ -1,4 +1,3 @@
    [Rule]
    DOMAIN-SUFFIX, assets.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, assets-public.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, falconapi.us-2.crowdstrike.com, REJECT
  5. ddqp renamed this gist Mar 28, 2024. 1 changed file with 1 addition and 7 deletions.
    8 changes: 1 addition & 7 deletions gistfile1.txt → falcon.txt
    Original file line number Diff line number Diff line change
    @@ -1,10 +1,4 @@
    #
    # Commercial cloud IPs
    # If you’re using GovCloud, see Falcon on GovCloud IPs. If you’re using EU Cloud, see Falcon on EU Cloud IPs.
    # You can use these IP addresses to whitelist SSL traffic by IP address instead of by FQDN.
    #
    # Last Updated 20211208
    #
    [Rule]
    DOMAIN-SUFFIX, assets.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, assets-public.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, falconapi.us-2.crowdstrike.com, REJECT
  6. ddqp created this gist Mar 28, 2024.
    173 changes: 173 additions & 0 deletions gistfile1.txt
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,173 @@
    #
    # Commercial cloud IPs
    # If you’re using GovCloud, see Falcon on GovCloud IPs. If you’re using EU Cloud, see Falcon on EU Cloud IPs.
    # You can use these IP addresses to whitelist SSL traffic by IP address instead of by FQDN.
    #
    # Last Updated 20211208
    #
    DOMAIN-SUFFIX, assets.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, assets-public.falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, falconapi.us-2.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, falcon.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, ffc.eu-1.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, ffc.laggar.gcw.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, ffc.us-1.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, ffc.us-2.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, firehose.us-2.crowdstrike.com, REJECT
    DOMAIN-SUFFIX, lfodown01-b.cloudsink.net, REJECT
    DOMAIN-SUFFIX, lfodown01-gyr-maverick.cloudsink.net, REJECT
    DOMAIN-SUFFIX, ts01-b.cloudsink.net, REJECT
    DOMAIN-SUFFIX, ts01-gyr-maverick.cloudsink.net, REJECT
    IP-CIDR, 100.20.109.43/32, REJECT, no-resolve
    IP-CIDR, 100.20.76.137/32, REJECT, no-resolve
    IP-CIDR, 13.56.121.58/32, REJECT, no-resolve
    IP-CIDR, 13.56.127.239/32, REJECT, no-resolve
    IP-CIDR, 13.57.54.63/32, REJECT, no-resolve
    IP-CIDR, 15.200.14.201/32, REJECT, no-resolve
    IP-CIDR, 160.1.78.140/32, REJECT, no-resolve
    IP-CIDR, 18.193.144.218/32, REJECT, no-resolve
    IP-CIDR, 3.127.43.50/32, REJECT, no-resolve
    IP-CIDR, 34.209.79.111/32, REJECT, no-resolve
    IP-CIDR, 34.210.186.129/32, REJECT, no-resolve
    IP-CIDR, 35.162.224.228/32, REJECT, no-resolve
    IP-CIDR, 35.162.239.174/32, REJECT, no-resolve
    IP-CIDR, 3.64.81.130/32, REJECT, no-resolve
    IP-CIDR, 44.224.200.221/32, REJECT, no-resolve
    IP-CIDR, 44.225.216.237/32, REJECT, no-resolve
    IP-CIDR, 44.227.134.78/32, REJECT, no-resolve
    IP-CIDR, 44.241.254.47/32, REJECT, no-resolve
    IP-CIDR, 50.18.194.39/32, REJECT, no-resolve
    IP-CIDR, 50.18.198.237/32, REJECT, no-resolve
    IP-CIDR, 52.10.219.156/32, REJECT, no-resolve
    IP-CIDR, 52.52.117.52/32, REJECT, no-resolve
    IP-CIDR, 52.52.119.33/32, REJECT, no-resolve
    IP-CIDR, 52.52.149.168/32, REJECT, no-resolve
    IP-CIDR, 52.52.239.58/32, REJECT, no-resolve
    IP-CIDR, 52.52.60.244/32, REJECT, no-resolve
    IP-CIDR, 52.53.77.89/32, REJECT, no-resolve
    IP-CIDR, 52.8.134.130/32, REJECT, no-resolve
    IP-CIDR, 52.8.141.1/32, REJECT, no-resolve
    IP-CIDR, 52.8.160.82/32, REJECT, no-resolve
    IP-CIDR, 52.8.172.89/32, REJECT, no-resolve
    IP-CIDR, 52.8.173.58/32, REJECT, no-resolve
    IP-CIDR, 52.8.19.75/32, REJECT, no-resolve
    IP-CIDR, 52.8.32.113/32, REJECT, no-resolve
    IP-CIDR, 52.8.45.162/32, REJECT, no-resolve
    IP-CIDR, 52.8.5.240/32, REJECT, no-resolve
    IP-CIDR, 52.8.54.244/32, REJECT, no-resolve
    IP-CIDR, 52.8.61.206/32, REJECT, no-resolve
    IP-CIDR, 52.9.104.148/32, REJECT, no-resolve
    IP-CIDR, 52.9.212.176/32, REJECT, no-resolve
    IP-CIDR, 52.9.77.209/32, REJECT, no-resolve
    IP-CIDR, 52.9.82.94/32, REJECT, no-resolve
    IP-CIDR, 52.9.87.98/32, REJECT, no-resolve
    IP-CIDR, 54.183.105.3/32, REJECT, no-resolve
    IP-CIDR, 54.183.120.141/32, REJECT, no-resolve
    IP-CIDR, 54.183.122.156/32, REJECT, no-resolve
    IP-CIDR, 54.183.135.80/32, REJECT, no-resolve
    IP-CIDR, 54.183.140.32/32, REJECT, no-resolve
    IP-CIDR, 54.183.142.105/32, REJECT, no-resolve
    IP-CIDR, 54.183.148.116/32, REJECT, no-resolve
    IP-CIDR, 54.183.148.43/32, REJECT, no-resolve
    IP-CIDR, 54.183.215.154/32, REJECT, no-resolve
    IP-CIDR, 54.183.234.42/32, REJECT, no-resolve
    IP-CIDR, 54.183.24.162/32, REJECT, no-resolve
    IP-CIDR, 54.183.252.86/32, REJECT, no-resolve
    IP-CIDR, 54.183.34.154/32, REJECT, no-resolve
    IP-CIDR, 54.183.39.68/32, REJECT, no-resolve
    IP-CIDR, 54.183.51.31/32, REJECT, no-resolve
    IP-CIDR, 54.183.51.69/32, REJECT, no-resolve
    IP-CIDR, 54.183.52.221/32, REJECT, no-resolve
    IP-CIDR, 54.188.85.187/32, REJECT, no-resolve
    IP-CIDR, 54.193.117.199/32, REJECT, no-resolve
    IP-CIDR, 54.193.196.61/32, REJECT, no-resolve
    IP-CIDR, 54.193.27.226/32, REJECT, no-resolve
    IP-CIDR, 54.193.29.47/32, REJECT, no-resolve
    IP-CIDR, 54.193.67.98/32, REJECT, no-resolve
    IP-CIDR, 54.193.86.245/32, REJECT, no-resolve
    IP-CIDR, 54.193.87.57/32, REJECT, no-resolve
    IP-CIDR, 54.193.90.171/32, REJECT, no-resolve
    IP-CIDR, 54.193.93.19/32, REJECT, no-resolve
    IP-CIDR, 54.200.109.111/32, REJECT, no-resolve
    IP-CIDR, 54.215.131.232/32, REJECT, no-resolve
    IP-CIDR, 54.215.154.80/32, REJECT, no-resolve
    IP-CIDR, 54.215.169.199/32, REJECT, no-resolve
    IP-CIDR, 54.215.169.38/32, REJECT, no-resolve
    IP-CIDR, 54.215.170.42/32, REJECT, no-resolve
    IP-CIDR, 54.215.176.108/32, REJECT, no-resolve
    IP-CIDR, 54.215.183.157/32, REJECT, no-resolve
    IP-CIDR, 54.215.193.131/32, REJECT, no-resolve
    IP-CIDR, 54.215.202.179/32, REJECT, no-resolve
    IP-CIDR, 54.215.226.55/32, REJECT, no-resolve
    IP-CIDR, 54.218.244.79/32, REJECT, no-resolve
    IP-CIDR, 54.219.112.243/32, REJECT, no-resolve
    IP-CIDR, 54.219.115.12/32, REJECT, no-resolve
    IP-CIDR, 54.219.137.54/32, REJECT, no-resolve
    IP-CIDR, 54.219.140.50/32, REJECT, no-resolve
    IP-CIDR, 54.219.141.250/32, REJECT, no-resolve
    IP-CIDR, 54.219.145.181/32, REJECT, no-resolve
    IP-CIDR, 54.219.147.253/32, REJECT, no-resolve
    IP-CIDR, 54.219.148.161/32, REJECT, no-resolve
    IP-CIDR, 54.219.149.89/32, REJECT, no-resolve
    IP-CIDR, 54.219.149.92/32, REJECT, no-resolve
    IP-CIDR, 54.219.151.1/32, REJECT, no-resolve
    IP-CIDR, 54.219.151.27/32, REJECT, no-resolve
    IP-CIDR, 54.219.153.248/32, REJECT, no-resolve
    IP-CIDR, 54.219.158.53/32, REJECT, no-resolve
    IP-CIDR, 54.219.159.84/32, REJECT, no-resolve
    IP-CIDR, 54.219.161.141/32, REJECT, no-resolve
    IP-CIDR, 54.219.179.25/32, REJECT, no-resolve
    IP-CIDR, 54.241.138.180/32, REJECT, no-resolve
    IP-CIDR, 54.241.146.67/32, REJECT, no-resolve
    IP-CIDR, 54.241.148.127/32, REJECT, no-resolve
    IP-CIDR, 54.241.150.134/32, REJECT, no-resolve
    IP-CIDR, 54.241.161.242/32, REJECT, no-resolve
    IP-CIDR, 54.241.161.60/32, REJECT, no-resolve
    IP-CIDR, 54.241.162.180/32, REJECT, no-resolve
    IP-CIDR, 54.241.162.64/32, REJECT, no-resolve
    IP-CIDR, 54.241.164.212/32, REJECT, no-resolve
    IP-CIDR, 54.241.175.140/32, REJECT, no-resolve
    IP-CIDR, 54.241.175.52/32, REJECT, no-resolve
    IP-CIDR, 54.241.179.52/32, REJECT, no-resolve
    IP-CIDR, 54.241.181.242/32, REJECT, no-resolve
    IP-CIDR, 54.241.181.78/32, REJECT, no-resolve
    IP-CIDR, 54.241.182.78/32, REJECT, no-resolve
    IP-CIDR, 54.241.183.151/32, REJECT, no-resolve
    IP-CIDR, 54.241.183.229/32, REJECT, no-resolve
    IP-CIDR, 54.241.183.232/32, REJECT, no-resolve
    IP-CIDR, 54.241.184.161/32, REJECT, no-resolve
    IP-CIDR, 54.241.185.201/32, REJECT, no-resolve
    IP-CIDR, 54.241.186.124/32, REJECT, no-resolve
    IP-CIDR, 54.241.197.58/32, REJECT, no-resolve
    IP-CIDR, 54.67.105.202/32, REJECT, no-resolve
    IP-CIDR, 54.67.108.17/32, REJECT, no-resolve
    IP-CIDR, 54.67.114.188/32, REJECT, no-resolve
    IP-CIDR, 54.67.119.89/32, REJECT, no-resolve
    IP-CIDR, 54.67.122.238/32, REJECT, no-resolve
    IP-CIDR, 54.67.123.100/32, REJECT, no-resolve
    IP-CIDR, 54.67.123.150/32, REJECT, no-resolve
    IP-CIDR, 54.67.123.234/32, REJECT, no-resolve
    IP-CIDR, 54.67.17.131/32, REJECT, no-resolve
    IP-CIDR, 54.67.24.156/32, REJECT, no-resolve
    IP-CIDR, 54.67.26.184/32, REJECT, no-resolve
    IP-CIDR, 54.67.33.233/32, REJECT, no-resolve
    IP-CIDR, 54.67.37.234/32, REJECT, no-resolve
    IP-CIDR, 54.67.37.78/32, REJECT, no-resolve
    IP-CIDR, 54.67.4.108/32, REJECT, no-resolve
    IP-CIDR, 54.67.41.192/32, REJECT, no-resolve
    IP-CIDR, 54.67.48.56/32, REJECT, no-resolve
    IP-CIDR, 54.67.51.32/32, REJECT, no-resolve
    IP-CIDR, 54.67.5.136/32, REJECT, no-resolve
    IP-CIDR, 54.67.54.116/32, REJECT, no-resolve
    IP-CIDR, 54.67.6.201/32, REJECT, no-resolve
    IP-CIDR, 54.67.64.61/32, REJECT, no-resolve
    IP-CIDR, 54.67.68.88/32, REJECT, no-resolve
    IP-CIDR, 54.67.72.218/32, REJECT, no-resolve
    IP-CIDR, 54.67.78.134/32, REJECT, no-resolve
    IP-CIDR, 54.67.80.244/32, REJECT, no-resolve
    IP-CIDR, 54.67.8.240/32, REJECT, no-resolve
    IP-CIDR, 54.67.92.206/32, REJECT, no-resolve
    IP-CIDR, 54.67.96.255/32, REJECT, no-resolve
    IP-CIDR, 54.67.99.247/32, REJECT, no-resolve
    IP-CIDR, 54.69.20.169/32, REJECT, no-resolve
    IP-CIDR, 96.127.77.135/32, REJECT, no-resolve