Dear community,
It's been a while since we've posted an update, but we've got a pretty big one in the pipeline. Right now, our setup is limited to three distinct feeds which don't leave much room for granular choice:
- Malware IP list
- Malware DNS list
- Phishing URL list (on request / requires proxy capabilities)
(Don't worry, these aren't going anywhere!)
The Custom Feed Hurdle: Initially, we wanted to build a custom feed generator allowing users to filter by threat scores, MITRE mappings, etc. However to be completely honest, it takes a massive toll on our infrastructure if 4,000+ users/companies are constantly compiling and pulling entirely unique feeds. We aren't quite there yet. It is still on our to do list though.
Our Plan B (Pre-Defined Feeds): Instead, we are rolling out a wider variety of curated, pre-defined feeds. Given that we pull from a 15M+ IOC database (You can browser it in our TIP / IOC browser), what distinguished feeds would actually add value to your OPNSense firewalls?
Some ideas we're tossing around:
- Risk tier splits (e.g., separating by High, Medium, and Low risk thresholds)
- Specific MITRE ATT&CK techniques or vectors
- Threat actor focused feeds
Drop your ideas or use cases below.