What is Badfellas in Trisul?
Badfellas is the Trisul threat-intelligence plugin. It checks your network traffic against indicators of compromise (IOCs) from threat-intelligence feeds. When traffic matches a known malicious indicator, Trisul flags it.
How it works
- Badfellas ships in the
trisul-badfellaspackage. - It comes with more than a dozen selected intel feeds.
- Indicators include IPv4 and IPv6 addresses, domain names, URLs, file hashes, and information in SSL certificates.
- You can add your own feeds. Put each feed in a TAB-separated file on the Hub node, and Badfellas distributes it to the Probe nodes.
In Trisul
In dashboards, activity that matches a threat-intelligence indicator counts toward the Blacklist value. See Blacklist.
- To configure the plugin, see the BadFellas plugin reference.
- To add your own feeds, see Add custom intel feeds into Badfellas.
Related terms
Frequently asked questions
What does Badfellas do in Trisul?
Badfellas is the Trisul threat-intelligence plugin. It checks network traffic against indicators of compromise from threat-intelligence feeds and flags traffic that matches a known malicious indicator.
Which indicators does Badfellas check?
Indicators include IPv4 and IPv6 addresses, domain names, URLs, file hashes, and information in SSL certificates.
Can I add my own threat-intelligence feeds?
Yes. You put your feed in a TAB-separated file on the Hub node and point the Badfellas plugin at it. Badfellas distributes the feed to the Probe nodes.