Skip to main content

What is Badfellas in Trisul?

Badfellas is the Trisul threat-intelligence plugin. It checks your network traffic against indicators of compromise (IOCs) from threat-intelligence feeds. When traffic matches a known malicious indicator, Trisul flags it.


How it works​

  • Badfellas ships in the trisul-badfellas package.
  • It comes with more than a dozen selected intel feeds.
  • Indicators include IPv4 and IPv6 addresses, domain names, URLs, file hashes, and information in SSL certificates.
  • You can add your own feeds. Put each feed in a TAB-separated file on the Hub node, and Badfellas distributes it to the Probe nodes.

In Trisul​

In dashboards, activity that matches a threat-intelligence indicator counts toward the Blacklist value. See Blacklist.



Frequently asked questions​

What does Badfellas do in Trisul?​

Badfellas is the Trisul threat-intelligence plugin. It checks network traffic against indicators of compromise from threat-intelligence feeds and flags traffic that matches a known malicious indicator.

Which indicators does Badfellas check?​

Indicators include IPv4 and IPv6 addresses, domain names, URLs, file hashes, and information in SSL certificates.

Can I add my own threat-intelligence feeds?​

Yes. You put your feed in a TAB-separated file on the Hub node and point the Badfellas plugin at it. Badfellas distributes the feed to the Probe nodes.