Good suggestion. To be honest, Cgo was the easiest for me to implement, as I originally wrote the tool in a different language. Also, most of the documentation for Netfilter and SO_ORIGINAL_DST is in C.
As for results: I’m seeing about one 'hit' per second on a standard VPS. It's a constant stream of bots looking for exploitable systems and probes from scanners like Shodan and Censys. It’s actually surprising how quickly a new IP gets picked up by these crawlers.
Am a fan of your work! Would it be useful if I throw these domains directly to URLScan? For retrieving the results I'll probably have to setup a proper DB and a workflow around parsing the Twitter content. Now, it's just a simple script.
Sure, I don't see why not, the worst thing that could happen is that the domain doesn't resolve or the webserver doesn't respond, but at least there will be a record of the domain having been scanned! Thanks for the kind words ;)
In the meantime, I'm using a modified command like so: `curl https://twitter.threatintel.rocks/ --silent | jq -r '.malicious_urls | .[]' | sort -u | grep -v …`
As for results: I’m seeing about one 'hit' per second on a standard VPS. It's a constant stream of bots looking for exploitable systems and probes from scanners like Shodan and Censys. It’s actually surprising how quickly a new IP gets picked up by these crawlers.