Yes I know but there is some key elements missing for my needs. My script dues subnet consolidation /24, /64 and /128, check aging, duplicates and coverage. Also my script has native CSF integration, works 100% offline and it is focused on local firewall optimization based on observed log patterns. Also one major key difference is real time subnet control without any outdated confidence score. Botnets are changing subnet all the time and in my opinion any kind of scoring is more or less useless, sorry. I catch them very fast and block whole subnet for next 2 months after it get dropped from the list. By that time they will use another subnet range anyway...
Like you mention everyone has different needs. I could not find anything close I had on my mind so I build it my self. Simple and convenient. It needs 2 seconds to burst true my deny list. It is just a little addition to the already existing excellent firewall and deny list.
I choose to share it with others. That is all. Plain and simple.
BTW this options in csf.conf file are there to fine tune your server for your needs. Again, changing some of these option will help a lot to catch these slow botnet attacks. That is why I mention it. You have to know that we are not all IT geeks. Like my self I have to study all of it before I say ahhhh
