<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOC feeds in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/235443#M45643</link>
    <description>&lt;P&gt;Thats cool. Thanks.&lt;/P&gt;&lt;P&gt;Do we need to manually install new HCP takes ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 09:15:24 GMT</pubDate>
    <dc:creator>majkel</dc:creator>
    <dc:date>2024-12-12T09:15:24Z</dc:date>
    <item>
      <title>IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211186#M40007</link>
      <description>&lt;P&gt;Hey boys and girls,&lt;/P&gt;
&lt;P&gt;Happy Friday and weekend &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Just figured would share some IOC feeds I put together in my lab, I counted and there is about 2000 known bad IPs that are blocked via all of them together, so hopefully it can help others.&lt;/P&gt;
&lt;P&gt;If anyone has any others to share, please do so. FYI, you do need either AV or AB blades enabled to use IOC feeds and for best results, I recommend R81.20 version, as it also lets you test the feeds from smart console.&lt;/P&gt;
&lt;P&gt;I truly believe everyone should do this method, as lets be honest, with ever evolving threats from the Internet, who has the time to manually keep updating bad IPs to be blocked? I will take a wild guess and say probably no one lol&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@azurefw:0]# ioc_feeds show&lt;BR /&gt;Feed Name: talos_1&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.talosintelligence.com/" target="_blank" rel="noopener"&gt;https://www.talosintelligence.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: sans&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://isc.sans.edu/" target="_blank" rel="noopener"&gt;https://isc.sans.edu/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: isacs&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.nationalisacs.org/" target="_blank" rel="noopener"&gt;https://www.nationalisacs.org/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: Imfraguard&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.infragard.org/" target="_blank" rel="noopener"&gt;https://www.infragard.org/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: virustotal&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.virustotal.com/" target="_blank" rel="noopener"&gt;https://www.virustotal.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: Cisa&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais" target="_blank" rel="noopener"&gt;https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: googlesafebrowsing&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://safebrowsing.google.com/" target="_blank" rel="noopener"&gt;https://safebrowsing.google.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: spamhaus&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.spamhaus.org/" target="_blank" rel="noopener"&gt;https://www.spamhaus.org/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: abuse.ch&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://abuse.ch/" target="_blank" rel="noopener"&gt;https://abuse.ch/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: virusshare&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://virusshare.com/" target="_blank" rel="noopener"&gt;https://virusshare.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: talos&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://www.talosintelligence.com/documents/ip-blacklist" target="_blank" rel="noopener"&gt;http://www.talosintelligence.com/documents/ip-blacklist&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: sslbl&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://sslbl.abuse.ch/blacklist/sslipblacklist.csv" target="_blank" rel="noopener"&gt;https://sslbl.abuse.ch/blacklist/sslipblacklist.csv&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: cybercrime&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://cybercrime-tracker.net/ccamlist.php" target="_blank" rel="noopener"&gt;https://cybercrime-tracker.net/ccamlist.php&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: reputation&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://reputation.alienvault.com/reputation.data" target="_blank" rel="noopener"&gt;http://reputation.alienvault.com/reputation.data&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: ipspamlist&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://www.ipspamlist.com/public_feeds.csv" target="_blank" rel="noopener"&gt;http://www.ipspamlist.com/public_feeds.csv&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: botvrij&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.botvrij.eu/data/ioclist.hostname.raw" target="_blank" rel="noopener"&gt;https://www.botvrij.eu/data/ioclist.hostname.raw&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: Known_bad_IPs&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.misp-project.org/feeds/" target="_blank" rel="noopener"&gt;https://www.misp-project.org/feeds/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: github-blocklist&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://github.com/firehol/blocklist-ipsets" target="_blank" rel="noopener"&gt;https://github.com/firehol/blocklist-ipsets&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: feodo_tracker&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt" target="_blank" rel="noopener"&gt;https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: emerging_threats&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: test-feed&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://csp.infoblox.com/" target="_blank" rel="noopener"&gt;https://csp.infoblox.com/&lt;/A&gt;&lt;BR /&gt;Action: Detect&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Total number of feeds: 21&lt;BR /&gt;Active feeds: 21&lt;BR /&gt;[Expert@azurefw:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 20:18:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211186#M40007</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T20:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211187#M40008</link>
      <description>&lt;P&gt;Apologies, forgot to add 2 files I also used. This gives good example of what CSV file would look like.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 20:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211187#M40008</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T20:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211188#M40009</link>
      <description>&lt;P&gt;Thank you for sharing! I have been looking for more of these to add to our current roster.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 20:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211188#M40009</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-04-12T20:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211189#M40010</link>
      <description>&lt;P&gt;Very welcome, happy to help. Unlike Ed Sheeran's song "Perfect", this is far from it, but its something lol&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 20:50:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211189#M40010</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T20:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211190#M40011</link>
      <description>&lt;P&gt;I will keep updating as I find more&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feed Name: ipq&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.ipqualityscore.com/" target="_blank"&gt;https://www.ipqualityscore.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 21:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211190#M40011</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T21:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211192#M40012</link>
      <description>&lt;P&gt;I know this is Fortinet, but it has 107 entries&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feed Name: fortiguard&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.fortiguard.com/services/ioc" target="_blank"&gt;https://www.fortiguard.com/services/ioc&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 21:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211192#M40012</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T21:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211193#M40013</link>
      <description>&lt;P&gt;Microsoft, 269 entries, pretty good&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-ca/security/business/siem-and-xdr/microsoft-defender-threat-intelligence" target="_blank"&gt;https://www.microsoft.com/en-ca/security/business/siem-and-xdr/microsoft-defender-threat-intelligence&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 21:10:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211193#M40013</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T21:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211194#M40014</link>
      <description>&lt;P&gt;The BEST I found so far, almost 4000 entries.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/security/ngips/index.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/security/ngips/index.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 21:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211194#M40014</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T21:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211195#M40015</link>
      <description>&lt;P&gt;Most UPDATED I have so far. But, will keep adding whatever else I find.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@azurefw:0]# ioc_feeds show&lt;BR /&gt;Feed Name: cisco&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.cisco.com/c/en/us/products/security/ngips/index.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/security/ngips/index.html&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: cortex&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://xsoar.pan.dev/docs/reference/integrations/cortex-xdr---ioc" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/cortex-xdr---ioc&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: microsoft&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.microsoft.com/en-ca/security/business/siem-and-xdr/microsoft-defender-threat-intelligence" target="_blank"&gt;https://www.microsoft.com/en-ca/security/business/siem-and-xdr/microsoft-defender-threat-intelligence&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: fortiguard&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.fortiguard.com/services/ioc" target="_blank"&gt;https://www.fortiguard.com/services/ioc&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: ipq&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.ipqualityscore.com/" target="_blank"&gt;https://www.ipqualityscore.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: talos_1&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.talosintelligence.com/" target="_blank"&gt;https://www.talosintelligence.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: sans&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://isc.sans.edu/" target="_blank"&gt;https://isc.sans.edu/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: isacs&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.nationalisacs.org/" target="_blank"&gt;https://www.nationalisacs.org/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: Imfraguard&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.infragard.org/" target="_blank"&gt;https://www.infragard.org/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: virustotal&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.virustotal.com/" target="_blank"&gt;https://www.virustotal.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: Cisa&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais" target="_blank"&gt;https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: googlesafebrowsing&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://safebrowsing.google.com/" target="_blank"&gt;https://safebrowsing.google.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: spamhaus&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.spamhaus.org/" target="_blank"&gt;https://www.spamhaus.org/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: abuse.ch&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://abuse.ch/" target="_blank"&gt;https://abuse.ch/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: virusshare&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://virusshare.com/" target="_blank"&gt;https://virusshare.com/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: talos&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://www.talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;http://www.talosintelligence.com/documents/ip-blacklist&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: sslbl&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://sslbl.abuse.ch/blacklist/sslipblacklist.csv" target="_blank"&gt;https://sslbl.abuse.ch/blacklist/sslipblacklist.csv&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: cybercrime&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://cybercrime-tracker.net/ccamlist.php" target="_blank"&gt;https://cybercrime-tracker.net/ccamlist.php&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: reputation&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://reputation.alienvault.com/reputation.data" target="_blank"&gt;http://reputation.alienvault.com/reputation.data&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: ipspamlist&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://www.ipspamlist.com/public_feeds.csv" target="_blank"&gt;http://www.ipspamlist.com/public_feeds.csv&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: botvrij&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.botvrij.eu/data/ioclist.hostname.raw" target="_blank"&gt;https://www.botvrij.eu/data/ioclist.hostname.raw&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: Known_bad_IPs&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://www.misp-project.org/feeds/" target="_blank"&gt;https://www.misp-project.org/feeds/&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: github-blocklist&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://github.com/firehol/blocklist-ipsets" target="_blank"&gt;https://github.com/firehol/blocklist-ipsets&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: feodo_tracker&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt" target="_blank"&gt;https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: emerging_threats&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTP&lt;BR /&gt;Resource: &lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;BR /&gt;Action: Prevent&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feed Name: test-feed&lt;BR /&gt;Feed is Active&lt;BR /&gt;File will be fetched via HTTPS&lt;BR /&gt;Resource: &lt;A href="https://csp.infoblox.com/" target="_blank"&gt;https://csp.infoblox.com/&lt;/A&gt;&lt;BR /&gt;Action: Detect&lt;BR /&gt;User Name:&lt;BR /&gt;Feed is centrally managed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Total number of feeds: 26&lt;BR /&gt;Active feeds: 26&lt;BR /&gt;[Expert@azurefw:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 21:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211195#M40015</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-12T21:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211979#M40207</link>
      <description>&lt;P&gt;Forgot to mention the most important one...duh : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://secureupdates.checkpoint.com/IP-list/TOR.txt" target="_blank"&gt;secureupdates.checkpoint.com/IP-list/TOR.txt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25368iFF62D951FED0AA89/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 17:18:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/211979#M40207</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-22T17:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212021#M40210</link>
      <description>&lt;P&gt;Hello mates, I usually use the following open source project:&lt;/P&gt;&lt;P&gt;&lt;A title="https://github.com/stamparm/ipsum" href="https://github.com/stamparm/ipsum" target="_blank" rel="noopener"&gt;https://github.com/stamparm/ipsum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sumarice malicious IP between different lists. It create lists based on the ocurrence of the IP and categorice en levels.&lt;/P&gt;&lt;P&gt;I have configured this IOC in my lab and it's working fine. The level 3 list has over 17K malicious IPs. From R81.20, the way of using network feeds in the access control policy, for me it is more granular.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="testing network feed" style="width: 907px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25373iBC2094BF2FE54C51/image-size/large?v=v2&amp;amp;px=999" role="button" title="IOC_4.png" alt="testing network feed" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;testing network feed&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy access rulebase" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25371i6F86ADCA68131FC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="IOC_3.png" alt="Policy access rulebase" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Policy access rulebase&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="block event Network feed" style="width: 796px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25369i8AF1DA49DAB9148C/image-size/large?v=v2&amp;amp;px=999" role="button" title="IOC_2.png" alt="block event Network feed" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;block event Network feed&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Update Event Network feed" style="width: 803px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25370i53C271905AF525D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="IOC_1.png" alt="Update Event Network feed" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Update Event Network feed&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best regards! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 08:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212021#M40210</guid>
      <dc:creator>delToro1</dc:creator>
      <dc:date>2024-04-23T08:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212045#M40221</link>
      <description>&lt;P&gt;Wow, nice one! Let me test it in the lab later and report back.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 11:08:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212045#M40221</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T11:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212057#M40227</link>
      <description>&lt;P&gt;Just installed policy, so let me give it some time to see if there any hits. Though its just a lab, but it is in Azure, so Im sure it will get some traffic : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:19:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212057#M40227</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T12:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212059#M40228</link>
      <description>&lt;P&gt;Btw, I see the same link but level 2 has almost 35K IP addresses, that is fantastic, thanks for sharing!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212059#M40228</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T12:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212084#M40243</link>
      <description>&lt;P&gt;No problem ;). I detect that lvl 1 has some false positives, IP addresses from onedrive or sharepoint service that are legit. For me, the lvl 3 is OK, because&amp;nbsp; the IP must appear at least in 3 lists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, of course, thanks for sharing a lot of materials and resources for IOC. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:06:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212084#M40243</guid>
      <dc:creator>delToro1</dc:creator>
      <dc:date>2024-04-23T14:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212086#M40244</link>
      <description>&lt;P&gt;well thank you!!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212086#M40244</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T14:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212089#M40245</link>
      <description>&lt;P&gt;The IPsum (lvl3) seems to be the most effective so far. We've dropped over 750 connections since I added it this morning. No one internally has tried to reach out though, so that's good.&lt;/P&gt;&lt;P&gt;The Emerging Threats one also has had a good amount of hits.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:26:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212089#M40245</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-04-23T14:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212115#M40253</link>
      <description>&lt;P&gt;Agree, same here!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 18:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212115#M40253</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T18:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212116#M40254</link>
      <description>&lt;P&gt;I see that when using network feeds, you dont technically need to have av or ab blades enabled, so thats definitely a plus right there and works beautifully.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 18:13:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/212116#M40254</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T18:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/226196#M43505</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75094"&gt;@delToro1&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;What could be the impact of this level 3 feed at the resource level?&lt;/P&gt;&lt;P&gt;Is this feed injected like the iocs_feeds directly into the antivirus blade or do locally loaded iocs work better in terms of performance?&lt;/P&gt;&lt;P&gt;We have a cluster that has suffered a lot from CPU issues so I would be concerned that it will affect us even more.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 19:33:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds/m-p/226196#M43505</guid>
      <dc:creator>mrflow1</dc:creator>
      <dc:date>2024-09-10T19:33:01Z</dc:date>
    </item>
  </channel>
</rss>

