Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Q-Feeds

#1
Sorry we picked up this problem via our support system where this problem was logged as well. Glad the fix worked!
#2
We've implemented some changes regarding this, please let us know if you're still experiencing alert fatigue ;-)
#3
Dear community,

It's been a while since we've posted an update, but we've got a pretty big one in the pipeline. Right now, our setup is limited to three distinct feeds which don't leave much room for granular choice:

  • Malware IP list
  • Malware DNS list
  • Phishing URL list (on request / requires proxy capabilities)
(Don't worry, these aren't going anywhere!)

The Custom Feed Hurdle: Initially, we wanted to build a custom feed generator allowing users to filter by threat scores, MITRE mappings, etc. However to be completely honest, it takes a massive toll on our infrastructure if 4,000+ users/companies are constantly compiling and pulling entirely unique feeds. We aren't quite there yet. It is still on our to do list though.

Our Plan B (Pre-Defined Feeds): Instead, we are rolling out a wider variety of curated, pre-defined feeds. Given that we pull from a 15M+ IOC database (You can browser it in our TIP / IOC browser), what distinguished feeds would actually add value to your OPNSense firewalls?

Some ideas we're tossing around:

  • Risk tier splits (e.g., separating by High, Medium, and Low risk thresholds)
  • Specific MITRE ATT&CK techniques or vectors
  • Threat actor focused feeds

Drop your ideas or use cases below.
#4
Sorry for the late reaction and thank you for this feedback. Granular controls like you describe might become difficult and feels risky. We don't like whitelisting very much ;-) Will have a look on what we can do.
#5
Obviously sorry for the inconvenience. But the only way to get this solved in the future within an hour (and often sooner) is indeed to let us know via our false positive reporting in the TIP.
#7
Dear community,

Last weekend we launched our new website, including the subscription management portal that was already available before.

As part of this update, we've worked on integrating the TIP more closely with the website and introduced Single Sign-On (SSO) to make the experience smoother. We're planning to add more integrations and improvements in the future.

We'd love to hear your feedback. If you notice anything that could be improved, something that doesn't work as expected, or simply have suggestions, please let us know.

Thanks in advance for taking the time to test it and share your thoughts!
#8
can someone with these problems share the output of this command?

/usr/local/opnsense/scripts/qfeeds/qfeedsctl.py logs
#10
hmm that's not the way it's intended.. We'll create a Github Issue for it.
#11
Quote from: wirehire on May 29, 2026, 06:31:21 PMThere are still a lot of Vodafone numbers on the list. can you share why?

Well, can you specific 'a lot' for us? Obviously we're unable to whitelist everything residing from Vodafone and it's also hard to identify the specific ones since Vodafone does not communicate about it.
#12
With the help of your feedback we can indeed improve our services and minimize false positives. Best way to report them though is via our TIP (tip.qfeeds.com) This way we process them on average within 30~40 minutes Max.
#13
We found a solution (for the majority) and it will be done within the next couple of hours. The IP you listed has been removed from the list already. thank you for letting us know!
#14
Thank you for reporting! This was an issue on our end and we solved it. You might need to re-apply the settings in the plugin. (no need to rotate the api-key)

For those interested. Community licenses don't have an expiry date but the plugin checks against a license check which returned 'null'. as an expiry date This caused the issue. the expiry date now shows the date 9999-12-31
#15
Quote from: Patrick M. Hausen on April 30, 2026, 01:49:17 PMBTW ... 🙂



Haha, oops... let's just say it's our Dutch accent ;)