Hi all,
Our security architect would like to block any IP that is listed as bad or possibly bad by our SIEM or virustotal.
This ends up involving a lot of manual IP blocking.
I think the better approach would be to ensure our public sites are hardened, and client devices secured, but they would first like to take an IP block list approach, regardless of possible impact.
We're using a slightly modified optimized IPS profile, and import a couple indicator ip lists.
I'm wondering what others have done in this type of situation to help reduce the amount of alerts seen, and automatically block as much as possible.
Thank you