Consolidate to single lean README, remove feeds/README.md
This commit is contained in:
@@ -1,298 +1,104 @@
|
|||||||
# Threat Intelligence RSS Telegram Bot
|
# telegram-rss-bot
|
||||||
|
|
||||||
A sophisticated Telegram bot that monitors cybersecurity RSS feeds and delivers real-time alerts to Telegram chats or topics. Automatically classifies content by severity (critical/high/medium/low), quality, and category (News, Malware, Threat Intel, OSINT, Research).
|
Telegram bot that monitors cybersecurity RSS feeds and delivers real-time alerts. Articles are classified by severity and quality before delivery.
|
||||||
|
|
||||||
**Perfect for:** Security teams, SOC analysts, threat hunters, and cybersecurity enthusiasts who want curated threat intelligence delivered directly to Telegram.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Features
|
|
||||||
|
|
||||||
- **Multi-Category Feeds:** News, Malware, Threat Intel, OSINT, Research
|
|
||||||
- **Telegram Topics Support:** Different categories post to different topics in the same group
|
|
||||||
- **Intelligent Classification:** Auto-classifies articles by severity and quality
|
|
||||||
- **Duplicate Prevention:** Deduplicates articles across feeds and sources
|
|
||||||
- **Quality Filtering:** Filter by minimum quality score and severity levels
|
|
||||||
- **SQLite Tracking:** Persistent tracking of seen articles
|
|
||||||
- **Async Architecture:** High-performance async/await design
|
|
||||||
- **Feed Health Monitoring:** `/stats` command shows feed status
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Quick Start
|
|
||||||
|
|
||||||
### 1. Prerequisites
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Python 3.9+
|
|
||||||
python3 --version
|
|
||||||
|
|
||||||
# Install dependencies
|
|
||||||
pip install python-telegram-bot feedparser aiohttp beautifulsoup4
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2. Get a Telegram Bot Token
|
|
||||||
|
|
||||||
1. Open Telegram and message [@BotFather](https://t.me/BotFather)
|
|
||||||
2. Send `/newbot`
|
|
||||||
3. Follow prompts to create your bot
|
|
||||||
4. Copy the token (looks like `123456789:ABCdefGHIjklMNOpqrsTUVwxyz`)
|
|
||||||
|
|
||||||
### 3. Configure Your Bot
|
|
||||||
|
|
||||||
**Option 1: Environment Variable**
|
|
||||||
```bash
|
|
||||||
export BOT_TOKEN="your_bot_token_here"
|
|
||||||
```
|
|
||||||
|
|
||||||
**Option 2: Create `.env` File**
|
|
||||||
```bash
|
|
||||||
# Create .env file in project directory
|
|
||||||
echo 'BOT_TOKEN=your_bot_token_here' > .env
|
|
||||||
```
|
|
||||||
|
|
||||||
### 4. Run the Bot
|
|
||||||
|
|
||||||
```bash
|
|
||||||
python3 threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
You should see:
|
|
||||||
```
|
|
||||||
🚀 Threat Intel Bot is running!
|
|
||||||
📊 0 subscribers loaded
|
|
||||||
```
|
|
||||||
|
|
||||||
### 5. Start Receiving Alerts
|
|
||||||
|
|
||||||
In Telegram:
|
|
||||||
1. Find your bot (search by the name you gave it)
|
|
||||||
2. Send `/start` to see available commands
|
|
||||||
3. Enable categories you want:
|
|
||||||
- `/on_news` - News feeds
|
|
||||||
- `/on_threat_intel` - Threat intelligence
|
|
||||||
- `/on_malware` - Malware analysis
|
|
||||||
- `/on_osint` - OSINT feeds
|
|
||||||
- `/on_research` - Security research
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Project Structure
|
## Project Structure
|
||||||
|
|
||||||
```
|
```
|
||||||
rss/
|
rss_telegram_bot/
|
||||||
├── threat_intel_bot.py # Main bot (commands, subscriptions, alerts)
|
├── threat_intel_bot.py # Main bot — commands, subscriptions, alert dispatch
|
||||||
├── rss_manager.py # RSS feed parsing and article extraction
|
├── rss_manager.py # Feed fetching, dedup, message formatting
|
||||||
├── content_classifier.py # Article classification (severity/quality)
|
├── content_classifier.py # Severity/quality scoring, CVE/actor extraction
|
||||||
├── check_feeds.py # Utility to check feed health
|
├── check_feeds.py # CLI utility to check feed health
|
||||||
│
|
├── feeds/
|
||||||
├── feeds/ # RSS feed configurations
|
│ ├── news_feeds.json
|
||||||
│ ├── news_feeds.json # News sources
|
│ ├── malware_feeds.json
|
||||||
│ ├── malware_feeds.json # Malware analysis blogs
|
│ ├── threat_intel_feeds.json
|
||||||
│ ├── threat_intel_feeds.json # Threat intelligence feeds
|
│ ├── osint_feeds.json
|
||||||
│ ├── osint_feeds.json # OSINT resources
|
│ └── research_feeds.json
|
||||||
│ └── research_feeds.json # Security research
|
├── .env # Not committed — BOT_TOKEN + optional filters
|
||||||
│
|
├── subscribers.json # Auto-managed — chat/topic subscriptions
|
||||||
├── subscribers.json # Subscriber data (auto-created)
|
└── seen_articles.db # SQLite — tracks sent articles (7-day retention)
|
||||||
└── seen_articles.db # SQLite DB tracking seen articles
|
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
## Setup
|
||||||
|
|
||||||
## File Reference: What to Edit
|
```bash
|
||||||
|
pip install python-telegram-bot feedparser aiohttp beautifulsoup4
|
||||||
|
```
|
||||||
|
|
||||||
| What You Want to Do | File to Edit | Section |
|
Create `.env`:
|
||||||
|---------------------|--------------|---------|
|
|
||||||
| **Add/remove news feeds** | `feeds/news_feeds.json` | Add URL under category |
|
|
||||||
| **Add/remove threat intel feeds** | `feeds/threat_intel_feeds.json` | Add URL under category |
|
|
||||||
| **Add/remove malware feeds** | `feeds/malware_feeds.json` | Add URL under category |
|
|
||||||
| **Add/remove OSINT feeds** | `feeds/osint_feeds.json` | Add URL under category |
|
|
||||||
| **Add/remove research feeds** | `feeds/research_feeds.json` | Add URL under category |
|
|
||||||
| **Change quality threshold** | `.env` or environment | Set `MIN_QUALITY_SCORE=50` |
|
|
||||||
| **Filter by severity** | `.env` or environment | Set `ALLOWED_SEVERITIES=critical,high` |
|
|
||||||
| **Change polling interval** | `threat_intel_bot.py` | Line 475 (default: 300 seconds) |
|
|
||||||
| **Customize classification rules** | `content_classifier.py` | Keyword dictionaries |
|
|
||||||
|
|
||||||
---
|
```env
|
||||||
|
BOT_TOKEN=your_token_here
|
||||||
|
MIN_QUALITY_SCORE=0
|
||||||
|
ALLOWED_SEVERITIES=critical,high,medium,low
|
||||||
|
```
|
||||||
|
|
||||||
|
Run:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
python3 threat_intel_bot.py
|
||||||
|
```
|
||||||
|
|
||||||
## Bot Commands
|
## Bot Commands
|
||||||
|
|
||||||
### User Commands
|
| Command | Action |
|
||||||
|
|---|---|
|
||||||
|
| `/on_<category>` | Subscribe this chat/topic to a category |
|
||||||
|
| `/off_<category>` | Unsubscribe |
|
||||||
|
| `/stats` | Check feed health and subscriber count |
|
||||||
|
| `/help` | Show commands |
|
||||||
|
|
||||||
| Command | Description |
|
Categories: `news`, `malware`, `threat_intel`, `osint`, `research`
|
||||||
|---------|-------------|
|
|
||||||
| `/start` | Show welcome message and available commands |
|
|
||||||
| `/help` | Same as `/start` |
|
|
||||||
| `/on_news` | Subscribe to news feeds |
|
|
||||||
| `/on_malware` | Subscribe to malware analysis |
|
|
||||||
| `/on_threat_intel` | Subscribe to threat intelligence |
|
|
||||||
| `/on_osint` | Subscribe to OSINT feeds |
|
|
||||||
| `/on_research` | Subscribe to security research |
|
|
||||||
| `/off_news` | Unsubscribe from news |
|
|
||||||
| `/off_malware` | Unsubscribe from malware |
|
|
||||||
| `/off_threat_intel` | Unsubscribe from threat intel |
|
|
||||||
| `/off_osint` | Unsubscribe from OSINT |
|
|
||||||
| `/off_research` | Unsubscribe from research |
|
|
||||||
| `/stats` | Check feed health and status |
|
|
||||||
|
|
||||||
---
|
**Telegram Topics:** Run `/on_<category>` inside each topic to route categories to separate threads.
|
||||||
|
|
||||||
## Using with Telegram Topics (Forum Groups)
|
## Feed Management
|
||||||
|
|
||||||
**Setup:**
|
Each `feeds/*.json` file follows this structure:
|
||||||
1. Create a Telegram group
|
|
||||||
2. Enable "Topics" in group settings
|
|
||||||
3. Create topics: "News", "Threat Intel", "Malware", etc.
|
|
||||||
4. Add your bot to the group
|
|
||||||
|
|
||||||
**Subscribe topics to categories:**
|
|
||||||
- Open "News" topic → Send `/on_news`
|
|
||||||
- Open "Threat Intel" topic → Send `/on_threat_intel`
|
|
||||||
- Open "Malware" topic → Send `/on_malware`
|
|
||||||
- Open "OSINT" topic → Send `/on_osint`
|
|
||||||
- Open "Research" topic → Send `/on_research`
|
|
||||||
|
|
||||||
**Result:** Each category posts to its own topic automatically!
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Managing RSS Feeds
|
|
||||||
|
|
||||||
### Feed File Structure
|
|
||||||
|
|
||||||
Each feed file (`feeds/*.json`) has this format:
|
|
||||||
|
|
||||||
```json
|
```json
|
||||||
{
|
{
|
||||||
"category_name": {
|
"category_name": {
|
||||||
"Feed Name": "https://example.com/rss.xml",
|
"Feed Display Name": "https://example.com/rss.xml"
|
||||||
"Another Feed": "https://another.com/feed"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
**Example:** Add a new threat intel feed
|
Add or remove feeds by editing the JSON, then restart the bot. Run `python3 check_feeds.py` to verify feed health before deploying.
|
||||||
|
|
||||||
**File:** `feeds/threat_intel_feeds.json`
|
## Classification
|
||||||
|
|
||||||
```json
|
**Severity** is keyword-based (title + description):
|
||||||
{
|
- `critical` — zero-days, active exploitation, RCE, ransomware
|
||||||
"threat_intel": {
|
- `high` — privesc, auth bypass, code execution, kernel exploits
|
||||||
"SANS ISC": "https://isc.sans.edu/rssfeed.xml",
|
- `medium` — XSS, CSRF, DoS, memory corruption
|
||||||
"Your New Feed": "https://newfeed.com/rss.xml"
|
- `low` — everything else
|
||||||
}
|
|
||||||
}
|
**Quality score (0–100)** factors in: source reputation, content length, presence of CVEs, PoC indicators, threat actor mentions, MITRE techniques.
|
||||||
|
|
||||||
|
Filter via env vars:
|
||||||
|
```env
|
||||||
|
MIN_QUALITY_SCORE=50
|
||||||
|
ALLOWED_SEVERITIES=critical,high
|
||||||
```
|
```
|
||||||
|
|
||||||
**After editing:** Restart the bot
|
## Systemd Service (VPS)
|
||||||
|
|
||||||
```bash
|
`/etc/systemd/system/rss-bot.service`:
|
||||||
# Stop: Ctrl+C
|
|
||||||
# Start:
|
|
||||||
python3 threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Content Classification
|
|
||||||
|
|
||||||
### How Articles Are Classified
|
|
||||||
|
|
||||||
**Quality Score (0-100):**
|
|
||||||
- High-quality sources (Project Zero, Mandiant): +30 points
|
|
||||||
- Deep dive/technical analysis: +25 points
|
|
||||||
- Proof-of-concept/exploit: +20 points
|
|
||||||
- Research papers: +15 points
|
|
||||||
- Vulnerability advisory: +10 points
|
|
||||||
|
|
||||||
**Severity Levels:**
|
|
||||||
- **Critical:** Zero-days, active exploitation, RCE, ransomware
|
|
||||||
- **High:** Privilege escalation, auth bypass, code execution
|
|
||||||
- **Medium:** XSS, CSRF, information disclosure, DoS
|
|
||||||
- **Low:** Everything else
|
|
||||||
|
|
||||||
### Filtering Articles
|
|
||||||
|
|
||||||
**By Quality Score:**
|
|
||||||
```bash
|
|
||||||
# Only show high-quality articles (score 50+)
|
|
||||||
export MIN_QUALITY_SCORE=50
|
|
||||||
python3 threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
**By Severity:**
|
|
||||||
```bash
|
|
||||||
# Only critical and high severity
|
|
||||||
export ALLOWED_SEVERITIES="critical,high"
|
|
||||||
python3 threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
**Both:**
|
|
||||||
```bash
|
|
||||||
export MIN_QUALITY_SCORE=40
|
|
||||||
export ALLOWED_SEVERITIES="critical,high,medium"
|
|
||||||
python3 threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Advanced Configuration
|
|
||||||
|
|
||||||
### Environment Variables
|
|
||||||
|
|
||||||
Create `.env` file:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Required
|
|
||||||
BOT_TOKEN=123456789:ABCdefGHIjklMNOpqrsTUVwxyz
|
|
||||||
|
|
||||||
# Optional filters
|
|
||||||
MIN_QUALITY_SCORE=0 # 0-100 (default: 0 = no filtering)
|
|
||||||
ALLOWED_SEVERITIES=critical,high,medium,low # Comma-separated
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Checking Feed Health
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Check if all feeds are working
|
|
||||||
python3 check_feeds.py
|
|
||||||
|
|
||||||
# Or use the bot command
|
|
||||||
# In Telegram: /stats
|
|
||||||
```
|
|
||||||
|
|
||||||
**Output shows:**
|
|
||||||
- ✅ Online feeds (with article count)
|
|
||||||
- ❌ Offline/broken feeds (with error)
|
|
||||||
- Last update time
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Running as a Service (Linux)
|
|
||||||
|
|
||||||
### Systemd Service
|
|
||||||
|
|
||||||
**1. Create service file:**
|
|
||||||
|
|
||||||
```bash
|
|
||||||
sudo nano /etc/systemd/system/threat-intel-bot.service
|
|
||||||
```
|
|
||||||
|
|
||||||
**2. Add this content:**
|
|
||||||
|
|
||||||
```ini
|
```ini
|
||||||
[Unit]
|
[Unit]
|
||||||
Description=Threat Intelligence RSS Telegram Bot
|
Description=Threat Intel RSS Telegram Bot
|
||||||
After=network.target
|
After=network.target
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
Type=simple
|
Type=simple
|
||||||
User=your_username
|
User=your_user
|
||||||
WorkingDirectory=/home/your_username/Documents/telegram-bots/rss
|
WorkingDirectory=/home/your_user/rss_telegram_bot
|
||||||
Environment="BOT_TOKEN=your_bot_token_here"
|
EnvironmentFile=/home/your_user/rss_telegram_bot/.env
|
||||||
ExecStart=/usr/bin/python3 /home/your_username/Documents/telegram-bots/rss/threat_intel_bot.py
|
ExecStart=/usr/bin/python3 threat_intel_bot.py
|
||||||
Restart=always
|
Restart=always
|
||||||
RestartSec=10
|
RestartSec=10
|
||||||
|
|
||||||
@@ -300,403 +106,15 @@ RestartSec=10
|
|||||||
WantedBy=multi-user.target
|
WantedBy=multi-user.target
|
||||||
```
|
```
|
||||||
|
|
||||||
**3. Enable and start:**
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
sudo systemctl daemon-reload
|
sudo systemctl daemon-reload
|
||||||
sudo systemctl enable threat-intel-bot
|
sudo systemctl enable --now rss-bot
|
||||||
sudo systemctl start threat-intel-bot
|
sudo journalctl -u rss-bot -f
|
||||||
```
|
```
|
||||||
|
|
||||||
**4. Check status:**
|
## Notes
|
||||||
|
|
||||||
```bash
|
- First run marks all current articles as seen — no flood on startup
|
||||||
sudo systemctl status threat-intel-bot
|
- Polling interval: 5 minutes (`asyncio.sleep(300)` in `threat_intel_bot.py`)
|
||||||
sudo journalctl -u threat-intel-bot -f # View logs
|
- Only today's UTC articles are processed (strict date gate in `rss_manager.py`)
|
||||||
```
|
- `seen_articles.db` auto-purges entries older than 7 days
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Running with Docker (Optional)
|
|
||||||
|
|
||||||
### Dockerfile
|
|
||||||
|
|
||||||
```dockerfile
|
|
||||||
FROM python:3.11-slim
|
|
||||||
|
|
||||||
WORKDIR /app
|
|
||||||
|
|
||||||
# Install dependencies
|
|
||||||
RUN pip install python-telegram-bot feedparser aiohttp beautifulsoup4
|
|
||||||
|
|
||||||
# Copy bot files
|
|
||||||
COPY . /app
|
|
||||||
|
|
||||||
# Run bot
|
|
||||||
CMD ["python3", "threat_intel_bot.py"]
|
|
||||||
```
|
|
||||||
|
|
||||||
### Docker Compose
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
version: '3.8'
|
|
||||||
|
|
||||||
services:
|
|
||||||
threat-intel-bot:
|
|
||||||
build: .
|
|
||||||
container_name: threat-intel-bot
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- BOT_TOKEN=${BOT_TOKEN}
|
|
||||||
- MIN_QUALITY_SCORE=${MIN_QUALITY_SCORE:-0}
|
|
||||||
- ALLOWED_SEVERITIES=${ALLOWED_SEVERITIES:-critical,high,medium,low}
|
|
||||||
volumes:
|
|
||||||
- ./subscribers.json:/app/subscribers.json
|
|
||||||
- ./seen_articles.db:/app/seen_articles.db
|
|
||||||
```
|
|
||||||
|
|
||||||
**Run:**
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Create .env file first
|
|
||||||
docker compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Customization
|
|
||||||
|
|
||||||
### Add Your Own Feed Categories
|
|
||||||
|
|
||||||
**1. Edit `threat_intel_bot.py`:**
|
|
||||||
|
|
||||||
Find `CATEGORY_CONFIG` (line 37):
|
|
||||||
|
|
||||||
```python
|
|
||||||
CATEGORY_CONFIG = {
|
|
||||||
"news": {"label": "News", "emoji": "📰", "feeds_file": "feeds/news_feeds.json"},
|
|
||||||
"malware": {"label": "Malware", "emoji": "🦠", "feeds_file": "feeds/malware_feeds.json"},
|
|
||||||
# Add new category:
|
|
||||||
"your_category": {"label": "Your Category", "emoji": "🔥", "feeds_file": "feeds/your_feeds.json"},
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**2. Create feed file:**
|
|
||||||
|
|
||||||
```bash
|
|
||||||
nano feeds/your_feeds.json
|
|
||||||
```
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"your_category": {
|
|
||||||
"Feed Name 1": "https://example.com/rss.xml",
|
|
||||||
"Feed Name 2": "https://another.com/feed"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**3. Restart bot**
|
|
||||||
|
|
||||||
Users can now use `/on_your_category` and `/off_your_category`
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Customize Classification Keywords
|
|
||||||
|
|
||||||
**File:** `content_classifier.py`
|
|
||||||
|
|
||||||
**Example:** Add new critical keywords
|
|
||||||
|
|
||||||
```python
|
|
||||||
CRITICAL_KEYWORDS = {
|
|
||||||
'zero-day', '0day', 'zero day',
|
|
||||||
# Add your keywords:
|
|
||||||
'your_critical_term',
|
|
||||||
'another_urgent_keyword',
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Example:** Add high-quality sources
|
|
||||||
|
|
||||||
```python
|
|
||||||
HIGH_QUALITY_SOURCES = {
|
|
||||||
'watchTowr Labs', 'Doyensec Blog',
|
|
||||||
# Add your sources (exact name from feed):
|
|
||||||
'Your Favorite Security Blog',
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
### Bot Not Responding
|
|
||||||
|
|
||||||
**Check if running:**
|
|
||||||
```bash
|
|
||||||
ps aux | grep threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
**View logs:**
|
|
||||||
```bash
|
|
||||||
# If running as service
|
|
||||||
sudo journalctl -u threat-intel-bot -f
|
|
||||||
|
|
||||||
# If running manually, check terminal output
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### No Alerts Received
|
|
||||||
|
|
||||||
**1. Check subscription:**
|
|
||||||
```
|
|
||||||
In Telegram: /stats
|
|
||||||
```
|
|
||||||
|
|
||||||
Should show you're subscribed.
|
|
||||||
|
|
||||||
**2. Check feeds are working:**
|
|
||||||
```bash
|
|
||||||
python3 check_feeds.py
|
|
||||||
```
|
|
||||||
|
|
||||||
**3. Check quality/severity filters:**
|
|
||||||
- If `MIN_QUALITY_SCORE=80`, only very high-quality articles pass
|
|
||||||
- If `ALLOWED_SEVERITIES=critical`, only critical alerts show
|
|
||||||
|
|
||||||
**Lower thresholds:**
|
|
||||||
```bash
|
|
||||||
export MIN_QUALITY_SCORE=0
|
|
||||||
export ALLOWED_SEVERITIES="critical,high,medium,low"
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Feed Parse Errors
|
|
||||||
|
|
||||||
**Symptom:** Logs show "Error fetching feed"
|
|
||||||
|
|
||||||
**Causes:**
|
|
||||||
- Feed URL is broken/changed
|
|
||||||
- Feed server is down
|
|
||||||
- Network connectivity issue
|
|
||||||
|
|
||||||
**Fix:**
|
|
||||||
1. Check feed URL in browser
|
|
||||||
2. Update URL in `feeds/*.json` if changed
|
|
||||||
3. Remove dead feeds
|
|
||||||
4. Restart bot
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### SQLite Database Issues
|
|
||||||
|
|
||||||
**Reset seen articles (get all articles again):**
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Stop bot
|
|
||||||
rm seen_articles.db
|
|
||||||
|
|
||||||
# Restart bot (will recreate DB)
|
|
||||||
python3 threat_intel_bot.py
|
|
||||||
```
|
|
||||||
|
|
||||||
**Note:** First run marks all existing articles as seen (no alerts). New articles after that trigger alerts.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Data Files
|
|
||||||
|
|
||||||
### subscribers.json
|
|
||||||
|
|
||||||
**Format:**
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"subscribers": {
|
|
||||||
"123456789": {
|
|
||||||
"topic_id": null,
|
|
||||||
"feed_types": ["news", "threat_intel"]
|
|
||||||
},
|
|
||||||
"987654321_12345": {
|
|
||||||
"topic_id": 12345,
|
|
||||||
"feed_types": ["malware"]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
**Explanation:**
|
|
||||||
- Key format: `chat_id` or `chat_id_topic_id`
|
|
||||||
- `topic_id`: null for private/group, number for forum topics
|
|
||||||
- `feed_types`: Array of subscribed categories
|
|
||||||
|
|
||||||
**Manual editing:** You can edit this file, but bot does it automatically.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### seen_articles.db
|
|
||||||
|
|
||||||
**SQLite database tracking processed articles.**
|
|
||||||
|
|
||||||
**Schema:**
|
|
||||||
```sql
|
|
||||||
CREATE TABLE seen_articles (
|
|
||||||
article_key TEXT PRIMARY KEY,
|
|
||||||
seen_at TEXT NOT NULL
|
|
||||||
);
|
|
||||||
```
|
|
||||||
|
|
||||||
**View contents:**
|
|
||||||
```bash
|
|
||||||
sqlite3 seen_articles.db "SELECT * FROM seen_articles LIMIT 10;"
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Best Practices
|
|
||||||
|
|
||||||
### 1. Start with Default Filters
|
|
||||||
Don't set quality/severity filters initially - see what you get first, then filter.
|
|
||||||
|
|
||||||
### 2. Use Topics for Organization
|
|
||||||
If using in a group, enable Topics and route each category to its topic.
|
|
||||||
|
|
||||||
### 3. Monitor Feed Health
|
|
||||||
Run `/stats` weekly to check for broken feeds.
|
|
||||||
|
|
||||||
### 4. Curate Your Feeds
|
|
||||||
Start with defaults, add/remove based on signal-to-noise ratio.
|
|
||||||
|
|
||||||
### 5. Run as a Service
|
|
||||||
Use systemd so bot survives reboots and crashes.
|
|
||||||
|
|
||||||
### 6. Backup Subscriber Data
|
|
||||||
```bash
|
|
||||||
cp subscribers.json subscribers.backup.json
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Feed Categories Explained
|
|
||||||
|
|
||||||
### News Feeds (`feeds/news_feeds.json`)
|
|
||||||
Daily cybersecurity news, breach announcements, general updates.
|
|
||||||
- **Update frequency:** Multiple times per day
|
|
||||||
- **Volume:** High
|
|
||||||
- **Use case:** Stay informed on current events
|
|
||||||
|
|
||||||
### Malware Feeds (`feeds/malware_feeds.json`)
|
|
||||||
Malware analysis, reverse engineering blogs, threat reports.
|
|
||||||
- **Update frequency:** Daily to weekly
|
|
||||||
- **Volume:** Medium
|
|
||||||
- **Use case:** Malware research, threat hunting
|
|
||||||
|
|
||||||
### Threat Intel Feeds (`feeds/threat_intel_feeds.json`)
|
|
||||||
Vendor threat intelligence, APT reports, threat actor profiles.
|
|
||||||
- **Update frequency:** Daily to weekly
|
|
||||||
- **Volume:** Medium
|
|
||||||
- **Use case:** Threat intelligence, SOC operations
|
|
||||||
|
|
||||||
### OSINT Feeds (`feeds/osint_feeds.json`)
|
|
||||||
Open-source intelligence, tools, techniques, investigations.
|
|
||||||
- **Update frequency:** Weekly
|
|
||||||
- **Volume:** Low to medium
|
|
||||||
- **Use case:** OSINT research, investigative work
|
|
||||||
|
|
||||||
### Research Feeds (`feeds/research_feeds.json`)
|
|
||||||
Deep technical research, vulnerability analysis, exploit development.
|
|
||||||
- **Update frequency:** Weekly to monthly
|
|
||||||
- **Volume:** Low (high quality)
|
|
||||||
- **Use case:** Learning, in-depth technical knowledge
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Contributing Feeds
|
|
||||||
|
|
||||||
**Want to add a good feed?** Edit the appropriate JSON file and submit a pull request or update your fork.
|
|
||||||
|
|
||||||
**Criteria for good feeds:**
|
|
||||||
- Reliable RSS/Atom feed
|
|
||||||
- Regular updates (at least monthly)
|
|
||||||
- Quality content (no spam/clickbait)
|
|
||||||
- Relevant to cybersecurity
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Performance
|
|
||||||
|
|
||||||
**Typical resource usage:**
|
|
||||||
- **CPU:** <5% (idle), 10-20% during feed fetch
|
|
||||||
- **RAM:** ~50-100MB
|
|
||||||
- **Network:** Minimal (fetches feeds every 5 minutes)
|
|
||||||
- **Disk:** ~10MB (grows slowly with seen articles DB)
|
|
||||||
|
|
||||||
**Scaling:**
|
|
||||||
- Tested with 50+ feeds
|
|
||||||
- Handles 100+ subscribers
|
|
||||||
- Processes ~500 articles/day
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Security Considerations
|
|
||||||
|
|
||||||
### Bot Token
|
|
||||||
- **Never commit** `.env` file to Git
|
|
||||||
- Treat bot token like a password
|
|
||||||
- Regenerate if leaked (via @BotFather)
|
|
||||||
|
|
||||||
### Network Access
|
|
||||||
- Bot fetches public RSS feeds (outbound HTTPS)
|
|
||||||
- Telegram API (outbound HTTPS)
|
|
||||||
- No inbound connections needed
|
|
||||||
|
|
||||||
### Data Privacy
|
|
||||||
- Subscriber data stored locally in `subscribers.json`
|
|
||||||
- No data sent to third parties
|
|
||||||
- Article URLs/metadata only (no personal data)
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## FAQ
|
|
||||||
|
|
||||||
**Q: How often does the bot check feeds?**
|
|
||||||
A: Every 5 minutes (configurable in `threat_intel_bot.py` line 475)
|
|
||||||
|
|
||||||
**Q: Can I run multiple bots from same code?**
|
|
||||||
A: Yes, just use different bot tokens and run in separate directories
|
|
||||||
|
|
||||||
**Q: Does it support private feeds?**
|
|
||||||
A: No, only public RSS feeds. For private feeds, you'd need to add authentication
|
|
||||||
|
|
||||||
**Q: Can I export articles to a database?**
|
|
||||||
A: Articles are in `seen_articles.db` (SQLite). You can query it or extend the code
|
|
||||||
|
|
||||||
**Q: Why no alerts on first run?**
|
|
||||||
A: First run marks existing articles as seen to avoid spam. Only new articles after that trigger alerts
|
|
||||||
|
|
||||||
**Q: Can I get alerts in multiple languages?**
|
|
||||||
A: Bot messages are in English. Articles are in whatever language the feed provides
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## License
|
|
||||||
|
|
||||||
This project is open source. Use it for personal or commercial purposes.
|
|
||||||
|
|
||||||
No warranty provided. Use at your own risk.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Credits
|
|
||||||
|
|
||||||
Built with:
|
|
||||||
- [python-telegram-bot](https://python-telegram-bot.org/) - Telegram Bot API wrapper
|
|
||||||
- [feedparser](https://feedparser.readthedocs.io/) - RSS/Atom feed parser
|
|
||||||
- [aiohttp](https://docs.aiohttp.org/) - Async HTTP client
|
|
||||||
- [BeautifulSoup4](https://www.crummy.com/software/BeautifulSoup/) - HTML parsing
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
**Maintained for personal use - built for the cybersecurity community.**
|
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
This repository contains JSON feed lists used by my Telegram bot.
|
|
||||||
|
|
||||||
The goal is simple: keep curated RSS sources in one place so the bot can automatically stay up to date with news, OSINT, malware, threat intel, and research updates.
|
|
||||||
Reference in New Issue
Block a user