Ingest GreyNoise.io malicious feed for CVE-2021-44228 and apply null routes# log4j-nullroute
Quick script to ingest IP feed from greynoise.io for log4j (CVE-2021-44228) and null route bad addresses. Works w/Cisco IOS-XE and Arista EOS.
Use the exceptions file to omit any IPs you find in the list that you do not want to null route.
Required fill-ins for vars:
secrets.py
------------
username, password, api_key
nullroute.py
-------------
edge_routers
[4.0K] /data/pocs/3f1bf70c83b38b8d80c38c53e452c6b5ce57abb3
├── [ 15] log4j_malicious-ips-exceptions.txt
├── [3.7K] nullroute.py
├── [ 381] README.md
├── [ 16] requirements.txt
└── [ 314] secrets.py
0 directories, 5 files