#!/bin/bash cidr="$1" # If no CIDR was provided, query suricata. if [ -z "$cidr" ]; then echo Top offenders last 8 hours: journalctl --since=-8h -xeu suricata | cut -f 2 -d '}' | cut -f 1 -d : | sort -n | uniq -c | sort -n | tail -n 10 read -p Target: cidr fi whois "$cidr" | grep -iE 'inet|cidr|country|address|organization' read -p "Sanitized CIDR: " cidr set -x ssh shadownet iptables -A siem -s "$cidr" -j DROP if [ $? -ne 0 ]; then ssh shadownet iptables -N siem ssh shadownet iptables -I INPUT 3 -j siem ssh shadownet iptables -A siem -s "$cidr" -j DROP fi sudo iptables -A siem -s "$cidr" -j DROP set +x