Skip to content

Commit 84f0610

Browse files
authored
Merge pull request #360 from achrinzafork/new/palo-alto-cortex-cloud
new: [palo-alto-networks-cortex-cloud] create list
2 parents 9ceb8aa + 8703123 commit 84f0610

4 files changed

Lines changed: 334 additions & 3 deletions

File tree

README.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,7 @@ There is also a standalone software project called [misp-feedback](https://githu
8787
- [microsoft-azure-germany/list.json](./lists/microsoft-azure-germany/list.json) - **List of known Microsoft Azure Germany Datacenter IP Ranges** - _Microsoft Azure Germany Datacenter IP Ranges_
8888
- [microsoft-azure-us-gov/list.json](./lists/microsoft-azure-us-gov/list.json) - **List of known Microsoft Azure US Government Cloud Datacenter IP Ranges** - _Microsoft Azure US Government Cloud Datacenter IP Ranges_
8989
- [microsoft-azure/list.json](./lists/microsoft-azure/list.json) - **List of known Microsoft Azure Datacenter IP Ranges** - _Microsoft Azure Datacenter IP Ranges_
90+
- [microsoft-mdca-proxy/list.json](./lists/microsoft-mdca-proxy/list.json) - **List of known Microsoft Defender for Cloud Apps (MDCA/MCAS) proxy hostnames** - _Microsoft Defender for Cloud Apps (MDCA/MCAS) hostnames (https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-url)_
9091
- [microsoft-office365-cn/list.json](./lists/microsoft-office365-cn/list.json) - **List of known Office 365 IP address ranges in China** - _Office 365 IP address ranges in China_
9192
- [microsoft-office365-ip/list.json](./lists/microsoft-office365-ip/list.json) - **List of known Office 365 IP address ranges** - _Office 365 IP address ranges_
9293
- [microsoft-office365/list.json](./lists/microsoft-office365/list.json) - **List of known Office 365 URLs** - _Office 365 URLs and IP address ranges_
@@ -105,7 +106,8 @@ There is also a standalone software project called [misp-feedback](https://githu
105106
- [onyphe-scanner/list.json](./lists/onyphe-scanner/list.json) - **List of published IP address ranges for Onyphe Scanner** - _Onyphe Scanner (https://www.onyphe.io/)_
106107
- [openai-gptbot/list.json](./lists/openai-gptbot/list.json) - **List of known IP address ranges for OpenAI GPT crawler bot** - _OpenAI gptbot crawler (https://openai.com/gptbot-ranges.txt)_
107108
- [oracle-oci/list.json](./lists/oracle-oci/list.json) - **List of known Oracle Cloud Infrastructure (OCI) IP address ranges** - _Oracle Cloud Infrastructure (OCI) IP address ranges (https://docs.oracle.com/en-us/iaas/Content/General/Concepts/addressranges.htm)_
108-
- [ovh-cluster/list.json](./lists/ovh-cluster/list.json) - **List of known Ovh Cluster IP** - _OVH Cluster IP address (https://docs.ovh.com/fr/hosting/liste-des-adresses-ip-des-clusters-et-hebergements-web/)_
109+
- [ovh-cluster/list.json](./lists/ovh-cluster/list.json) - **List of known OVH Cluster IPs** - _OVH Cluster IP address (https://docs.ovhcloud.com/en/guides/web-cloud/web-hosting/clusters-and-shared-hosting-ip)_
110+
- [palo-alto-networks-cortex-cloud/list.json](./lists/palo-alto-networks-cortex-cloud/list.json) - **List of known Palo Alto Cortex Cloud IP ranges** - _Palo Alto Cortex Cloud IP address ranges (https://docs.ovhcloud.com/en/guides/web-cloud/web-hosting/clusters-and-shared-hosting-ip)_
109111
- [palo-alto-networks-cortex-xpanse/list.json](./lists/palo-alto-networks-cortex-xpanse/list.json) - **List of known IP address ranges for Palo Alto Networks Cortex Xpanse** - _Palo Alto Networks Cortex Xpanse (https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity)_
110112
- [parking-domain-ns/list.json](./lists/parking-domain-ns/list.json) - **Parking domains name server** - _List of parking domain's name server_
111113
- [parking-domain/list.json](./lists/parking-domain/list.json) - **Parking domains** - _List of parking domain's ip adresses_
@@ -152,7 +154,7 @@ There is also a standalone software project called [misp-feedback](https://githu
152154
- [vpn-ipv4/list.json](./lists/vpn-ipv4/list.json) - **Specialized list of vpn-ipv4 addresses belonging to common VPN providers and datacenters** - _Specialized list of vpn-ipv4 addresses belonging to common VPN providers and datacenters_
153155
- [vpn-ipv6/list.json](./lists/vpn-ipv6/list.json) - **Specialized list of IPv6 addresses belonging to common VPN providers and datacenters** - _Specialized list of IPv6 addresses belonging to common VPN providers and datacenters_
154156
- [whats-my-ip/list.json](./lists/whats-my-ip/list.json) - **List of known domains to know external IP** - _Event contains one or more entries of known 'what's my ip' domains_
155-
- [wikimedia/list.json](./lists/wikimedia/list.json) - **List of known Wikimedia address ranges** - _Wikimedia address ranges (http://noc.wikimedia.org/conf/reverse-proxy.php.txt)_
157+
- [wikimedia/list.json](./lists/wikimedia/list.json) - **List of known Wikimedia address ranges** - _Wikimedia address ranges (https://wikitech.wikimedia.org/w/api.php?action=parse&page=IP_and_AS_allocations&format=json&prop=wikitext)_
156158
- [windows-binary-hashes/list.json](./lists/windows-binary-hashes/list.json) - **List of known hashes for Windows binaries** - _List of known Windows binaries based on hashes from winbindex (https://github.com/m417z/winbindex)_
157159
- [zscaler/list.json](./lists/zscaler/list.json) - **List of known Zscaler IP address ranges** - _Zscaler IP address ranges (https://config.zscaler.com/api/zscaler.net/hubs/cidr/json/recommended)_
158160

generate_all.sh

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,8 +48,9 @@ python3 generate-internetcleanup-scanner.py
4848
#python3 generate-umich-cse-connection-attempts.py # ON HOLD DUE TO 403 (due to User-Agent)
4949
python3 generate-icloud-private-relay.py
5050
python3 generate-bunny-net.py
51-
python generate-ovh.py
51+
python3 generate-ovh.py
5252
python3 generate-microsoft-mdca.py
53+
python3 generate-palo-alto-networks-cortex-cloud.py
5354
popd
5455

5556
./jq_all_the_things.sh
Lines changed: 291 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,291 @@
1+
{
2+
"description": "Palo Alto Cortex Cloud IP address ranges (https://docs.ovhcloud.com/en/guides/web-cloud/web-hosting/clusters-and-shared-hosting-ip)",
3+
"list": [
4+
"104.155.131.72",
5+
"104.199.223.229",
6+
"136.110.132.208",
7+
"136.110.146.246",
8+
"159.183.150.248",
9+
"34.101.101.170",
10+
"34.101.125.66",
11+
"34.101.155.198",
12+
"34.101.158.32",
13+
"34.101.214.157",
14+
"34.101.218.184",
15+
"34.101.79.159",
16+
"34.102.139.110",
17+
"34.102.140.103",
18+
"34.102.237.151",
19+
"34.105.137.22",
20+
"34.105.173.229",
21+
"34.105.227.146",
22+
"34.107.129.254",
23+
"34.107.161.143",
24+
"34.107.213.85",
25+
"34.107.3.224",
26+
"34.107.57.23",
27+
"34.107.61.141",
28+
"34.107.83.197",
29+
"34.111.129.144",
30+
"34.111.134.57",
31+
"34.111.188.248",
32+
"34.111.58.152",
33+
"34.111.6.153",
34+
"34.116.176.97",
35+
"34.116.202.235",
36+
"34.116.213.71",
37+
"34.116.216.55",
38+
"34.116.223.119",
39+
"34.116.67.90",
40+
"34.117.211.129",
41+
"34.117.240.208",
42+
"34.118.124.130",
43+
"34.118.48.171",
44+
"34.118.62.80",
45+
"34.118.71.237",
46+
"34.118.92.214",
47+
"34.120.102.147",
48+
"34.120.119.85",
49+
"34.120.142.18",
50+
"34.120.213.187",
51+
"34.120.213.188",
52+
"34.120.229.65",
53+
"34.120.31.199",
54+
"34.120.87.77",
55+
"34.126.183.208",
56+
"34.126.212.40",
57+
"34.128.115.238",
58+
"34.128.126.138",
59+
"34.128.156.84",
60+
"34.128.157.130",
61+
"34.128.82.158",
62+
"34.131.101.138",
63+
"34.131.111.87",
64+
"34.131.116.135",
65+
"34.131.131.141",
66+
"34.131.165.103",
67+
"34.131.207.151",
68+
"34.131.47.126",
69+
"34.132.108.184",
70+
"34.142.3.42",
71+
"34.142.44.136",
72+
"34.146.181.233",
73+
"34.146.60.215",
74+
"34.147.107.51",
75+
"34.147.67.188",
76+
"34.149.165.12",
77+
"34.149.180.250",
78+
"34.149.248.76",
79+
"34.151.236.197",
80+
"34.151.83.236",
81+
"34.154.154.5",
82+
"34.154.168.139",
83+
"34.154.173.134",
84+
"34.154.186.12",
85+
"34.154.195.120",
86+
"34.154.208.247",
87+
"34.154.229.60",
88+
"34.154.23.156",
89+
"34.154.230.76",
90+
"34.154.243.11",
91+
"34.155.110.169",
92+
"34.155.197.131",
93+
"34.155.222.152",
94+
"34.155.41.247",
95+
"34.155.5.100",
96+
"34.155.5.117",
97+
"34.155.90.61",
98+
"34.159.53.97",
99+
"34.160.28.41",
100+
"34.163.125.167",
101+
"34.163.155.105",
102+
"34.163.57.57",
103+
"34.165.120.206",
104+
"34.165.131.171",
105+
"34.165.156.139",
106+
"34.165.17.246",
107+
"34.165.2.110",
108+
"34.165.24.222",
109+
"34.165.27.131",
110+
"34.165.33.165",
111+
"34.165.43.106",
112+
"34.165.46.47",
113+
"34.166.53.160",
114+
"34.166.53.242",
115+
"34.166.54.238",
116+
"34.166.54.6",
117+
"34.166.55.153",
118+
"34.166.58.213",
119+
"34.166.58.243",
120+
"34.166.58.79",
121+
"34.166.59.20",
122+
"34.166.61.81",
123+
"34.175.18.78",
124+
"34.175.182.55",
125+
"34.175.198.50",
126+
"34.175.205.166",
127+
"34.175.230.35",
128+
"34.175.255.99",
129+
"34.175.27.251",
130+
"34.175.30.176",
131+
"34.175.46.46",
132+
"34.175.80.182",
133+
"34.18.30.132",
134+
"34.18.32.96",
135+
"34.18.34.118",
136+
"34.18.34.73",
137+
"34.18.37.73",
138+
"34.18.39.0",
139+
"34.18.39.155",
140+
"34.18.44.71",
141+
"34.18.46.240",
142+
"34.18.53.229",
143+
"34.22.66.91",
144+
"34.35.13.198",
145+
"34.35.42.196",
146+
"34.35.45.251",
147+
"34.35.56.170",
148+
"34.35.60.86",
149+
"34.35.64.191",
150+
"34.35.69.156",
151+
"34.35.70.193",
152+
"34.35.79.219",
153+
"34.35.80.189",
154+
"34.36.155.211",
155+
"34.39.136.78",
156+
"34.39.140.36",
157+
"34.39.161.254",
158+
"34.39.177.125",
159+
"34.39.195.104",
160+
"34.54.155.245",
161+
"34.54.5.247",
162+
"34.64.107.163",
163+
"34.64.189.205",
164+
"34.64.228.117",
165+
"34.64.237.45",
166+
"34.64.45.118",
167+
"34.64.46.249",
168+
"34.64.54.175",
169+
"34.64.84.25",
170+
"34.64.93.168",
171+
"34.65.108.153",
172+
"34.65.137.215",
173+
"34.65.155.169",
174+
"34.65.213.226",
175+
"34.65.222.25",
176+
"34.65.225.124",
177+
"34.65.233.60",
178+
"34.65.248.119",
179+
"34.65.51.103",
180+
"34.65.89.6",
181+
"34.66.69.154",
182+
"34.69.63.16",
183+
"34.69.88.119",
184+
"34.8.224.70",
185+
"34.8.234.58",
186+
"34.8.67.192",
187+
"34.80.133.68",
188+
"34.80.230.166",
189+
"34.80.34.30",
190+
"34.81.38.132",
191+
"34.84.125.129",
192+
"34.84.201.32",
193+
"34.84.225.105",
194+
"34.84.93.160",
195+
"34.84.99.239",
196+
"34.85.68.167",
197+
"34.87.167.125",
198+
"34.87.61.186",
199+
"34.87.83.144",
200+
"34.89.183.45",
201+
"34.89.197.46",
202+
"34.89.42.214",
203+
"34.89.56.78",
204+
"34.90.16.31",
205+
"34.90.67.58",
206+
"34.90.70.107",
207+
"34.90.71.103",
208+
"34.91.128.226",
209+
"34.91.26.125",
210+
"34.93.118.113",
211+
"34.93.175.218",
212+
"34.93.3.196",
213+
"34.93.9.198",
214+
"34.95.33.72",
215+
"34.95.62.136",
216+
"34.95.66.187",
217+
"34.95.8.232",
218+
"34.96.120.25",
219+
"34.96.83.202",
220+
"34.98.68.183",
221+
"34.98.77.231",
222+
"35.186.207.80",
223+
"35.189.176.163",
224+
"35.189.18.208",
225+
"35.190.0.180",
226+
"35.190.13.237",
227+
"35.190.79.68",
228+
"35.190.88.43",
229+
"35.197.175.44",
230+
"35.197.181.108",
231+
"35.197.219.110",
232+
"35.198.112.13",
233+
"35.198.38.182",
234+
"35.199.96.109",
235+
"35.200.146.253",
236+
"35.200.158.164",
237+
"35.200.175.78",
238+
"35.200.234.99",
239+
"35.200.3.131",
240+
"35.201.142.86",
241+
"35.201.22.63",
242+
"35.201.23.188",
243+
"35.202.21.123",
244+
"35.203.101.162",
245+
"35.203.108.13",
246+
"35.203.35.23",
247+
"35.203.57.162",
248+
"35.203.82.121",
249+
"35.203.90.79",
250+
"35.203.99.74",
251+
"35.204.129.196",
252+
"35.222.81.194",
253+
"35.223.6.69",
254+
"35.224.140.142",
255+
"35.225.156.101",
256+
"35.227.237.180",
257+
"35.229.186.216",
258+
"35.234.118.195",
259+
"35.234.18.10",
260+
"35.234.8.249",
261+
"35.240.144.192",
262+
"35.240.243.57",
263+
"35.240.255.15",
264+
"35.241.28.254",
265+
"35.242.159.176",
266+
"35.242.180.163",
267+
"35.242.201.199",
268+
"35.244.133.254",
269+
"35.244.157.127",
270+
"35.244.250.18",
271+
"35.244.251.25",
272+
"35.244.5.205",
273+
"35.244.57.196",
274+
"35.244.66.177",
275+
"35.244.73.76",
276+
"35.244.93.0",
277+
"35.247.148.38",
278+
"35.247.161.94",
279+
"35.247.173.40"
280+
],
281+
"matching_attributes": [
282+
"ip-src",
283+
"ip-dst",
284+
"domain|ip",
285+
"ip-src|port",
286+
"ip-dst|port"
287+
],
288+
"name": "List of known Palo Alto Cortex Cloud IP ranges",
289+
"type": "cidr",
290+
"version": 20260819
291+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
#!/usr/bin/env python3
2+
# -*- coding: utf-8 -*-
3+
4+
import re
5+
from generator import download_to_file, get_version, write_to_file, get_abspath_source_file
6+
7+
# Rough IPv4 and IPv6 extraction regex taken from `generate-ovh.py`
8+
ip_regex = re.compile(r'[" ](\d{1,3}(?:\.\d{1,3}){3})[\\:]')
9+
10+
def process(file, dst):
11+
warninglist = {
12+
'name': "List of known Palo Alto Cortex Cloud IP ranges",
13+
'version': get_version(),
14+
'description': "Palo Alto Cortex Cloud IP address ranges (https://docs.ovhcloud.com/en/guides/web-cloud/web-hosting/clusters-and-shared-hosting-ip)",
15+
'type': "cidr",
16+
'list': [],
17+
'matching_attributes': [
18+
"ip-src",
19+
"ip-dst",
20+
"domain|ip",
21+
"ip-src|port",
22+
"ip-dst|port"
23+
]
24+
}
25+
26+
with open(get_abspath_source_file(file), 'r') as f:
27+
file_contents = f.read()
28+
warninglist['list'].extend(list(map(lambda x: ''.join(x), ip_regex.findall(file_contents))))
29+
30+
write_to_file(warninglist, dst)
31+
32+
33+
if __name__ == '__main__':
34+
source = "https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources"
35+
file = "palo-alto-networks-cortex-cloud.html"
36+
download_to_file(source, file)
37+
process(file, "palo-alto-networks-cortex-cloud")

0 commit comments

Comments
 (0)