Skip to content

Threat intelligence API / integrations

Suricata

Suricata has a reputation feature built for lists of addresses. Load the ThreatCluster IP feed as a reputation list and two rules raise an alert for any traffic to or from an address on it. The feed is a public text file, so this needs no API key.

Prerequisites

  1. Suricata with a rules directory you can write to. The screenshots are from Suricata 8.0.7, run in Docker on 29 September 2026.
  2. The feed address: https://threatcluster.io/api/iocs/public/ips.txt

Setup

  1. Create a category file. The number is the category id, the short name is what rules refer to.

    echo "1,ThreatCluster,Confirmed malicious address from the ThreatCluster feed" \
      > /etc/suricata/iprep/categories.txt
  2. Download the feed and turn each address into a reputation line: address, category id, score.

    curl -s https://threatcluster.io/api/iocs/public/ips.txt \
      | grep -E '^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$' | sort -u \
      | awk '{print $1",1,100"}' > /etc/suricata/iprep/threatcluster.list
    A terminal counting 97 lines in the reputation list and printing the first three, each an address followed by category 1 and score 100
    97 addresses, each in category 1 with a score of 100.
  3. Point Suricata at both files in suricata.yaml:

    reputation-categories-file: /etc/suricata/iprep/categories.txt
    default-reputation-path: /etc/suricata/iprep
    reputation-files:
      - threatcluster.list
  4. Add two rules, for example in /etc/suricata/rules/threatcluster.rules, and list that file under rule-files:

    alert ip any any -> any any (msg:"ThreatCluster: traffic to a confirmed malicious address"; iprep:dst,ThreatCluster,>,50; classtype:trojan-activity; sid:9100001; rev:1;)
    alert ip any any -> any any (msg:"ThreatCluster: traffic from a confirmed malicious address"; iprep:src,ThreatCluster,>,50; classtype:trojan-activity; sid:9100002; rev:1;)

    Restart Suricata.

  5. Check the alert log. We tested by replaying a small capture made for the purpose: one connection to an address on the feed and one to an address that is not.

    One line of the Suricata fast log: an alert named ThreatCluster traffic to a confirmed malicious address, priority 1, for a TCP connection from 192.168.1.50 to 103.101.85.123 port 443
    One alert, for the connection to the feed address. The other connection raised nothing.

Keeping it current

Run the download from step 2 daily, then restart Suricata so it reads the new list.

Worth knowing

  1. Alert or drop. These rules alert. In inline mode, change alert to drop to block instead.
  2. Shared addresses. An address can host many sites. Start with alerts and look at what fires before you drop.
  3. If a block is wrong. Tell us at /corrections so it comes off the feed for everyone.