{"repo":"tryhackmeacct-netizen/Advanced-Threat-Intelligence-Platform-Dynamic-Policy-Enforcer","free":true,"listed":false,"github":"https://github.com/tryhackmeacct-netizen/Advanced-Threat-Intelligence-Platform-Dynamic-Policy-Enforcer","clone":"git clone https://github.com/tryhackmeacct-netizen/Advanced-Threat-Intelligence-Platform-Dynamic-Policy-Enforcer.git","description":"Finance & Banking - Advanced Threat Intelligence Plt. & Dynamic Policy Enforcer that ingests OSINT threat feeds, normalizes & scores indicators, stores intelligence in MongoDB, integrates with ELK SIEM, and automatically enforces firewall rules using Linux iptables for real-time threat mitigation.","language":"Python","stars":14,"topics":["cybeersecurity","elasticsearch","firewall-rules","iptables","kibana","kibana-dashboard","mongodb","osint","python3","security-automation"],"license":null,"category":"security-tools","readme_excerpt":"Advanced Threat Intelligence Platform & Dynamic Policy Enforcer A production-ready threat intelligence automation platform that ingests malicious IOC data from OSINT feeds, normalizes and deduplicates indicators, assigns risk scores, stores them in MongoDB, automatically enforces firewall blocking via iptables, and generates SIEM-ready audit logs for SOC compliance. 🎯 Project Overview This platform automates the entire threat intelligence lifecycle: - Ingest malicious IOCs from VirusTotal, AlienVault OTX, and AbuseIPDB - Normalize indicator format and validate indicators - Deduplicate entries before storage - Score threats based on feed reputation and metadata - Store data in MongoDB for persistence and auditing - Forward security events to Elasticsearch for Kibana visualization - Enforce firewall policies automatically for high-risk threats 💼 Architecture The core processing flow is: ✨ Features - ✅ Multi-Feed OSINT Integration - VirusTotal, AlienVault OTX, AbuseIPDB - ✅ IOC Normalization - Supports IP addresses, domains, and file hashes - ✅ Intelligent Deduplication - MongoDB-based duplicate detection - ✅ Dynamic Risk Scoring - 60-95 point scale based on feed source - ✅ MongoDB Persistence - Proper schema with timestamps and metadata - ✅ Automatic Firewall Enforcement - iptables rules for high-risk IPs - ✅ SIEM-Ready Logging - Structured security events for ELK/Kibana - ✅ TLS-safe Elasticsearch Forwarding - CA certificate validation with diagnostics - ✅ Rollback CLI - Comm","default_branch":null,"files":null,"tree":[],"storefront":"/r/tryhackmeacct-netizen","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tryhackmeacct-netizen/Advanced-Threat-Intelligence-Platform-Dynamic-Policy-Enforcer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}