Skip to content
DnsLister Forum

Where domain hunters compare notes

Upcoming updates to our threat feeds. What pre-defined feeds would actually be useful in OPNSense?

It’s been a while since we’ve posted an update, but we've got a pretty big one in the pipeline. Right now, our setup is limited to three distinct feeds which don't leave much room for granular choice:

  • Malware IP list
  • Malware DNS list
  • Phishing URL list (on request / requires proxy capabilities)

(Don't worry, these aren't going anywhere!)

The Custom Feed Hurdle: Initially, we wanted to build a custom feed generator allowing users to filter by threat scores, MITRE mappings, etc. However to be completely honest, it takes a massive toll on our infrastructure if 4,000+ users/companies are constantly compiling and pulling entirely unique feeds. We aren't quite there yet. It is still on our to do list though.

Our Plan B (Pre-Defined Feeds): Instead, we are rolling out a wider variety of curated, pre-defined feeds. Given that we pull from a 15M+ IOC database (You can browser it in our TIP / IOC browser), what distinguished feeds would actually add value to your OPNSense firewalls?

Some ideas we're tossing around:

  • Risk tier splits (e.g., separating by High, Medium, and Low risk thresholds)
  • Specific MITRE ATT&CK techniques or vectors
  • Threat actor focused feeds

Drop your ideas or use cases below.

submitted by /u/Q-Feeds to r/opnsense
[link] [comments]

Source: r/opnsense · by /u/Q-Feeds

Leave a Reply

Your email address will not be published. Required fields are marked *