Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

v21 Third Party Feeds

Hey all

With v21 accepting third party feeds I was hoping toi ingest the CTIS data from the ACSC but its in STIX format and the v21 only supports IoC one per line format.

I have found a couple of IP Lists to pull threat data from to add.

TorNodes for all Tor related IPs and also TALOS have a feed (both have about 1200-1500 IPS) - I can share the URL if needed but the forum blocks me if I post thgem :-0

What other feeds do you have or are looking to add?



Edited TAGs
[edited by: Erick Jan at 12:24 AM (GMT -7) on 23 Oct 2024]
Parents
  • After testing TF a while I think this is a good feature, focusing on the needs of the user.

    Right now we're having some trouble with DNS requests made by browsers to random IPs from AWS, Google, Cloudflare on a threat list.This is more False positive but impossible to exclude because of ever changing IPs.

    This will not be an issue for regular web surfing clients.

    But most of the computers here have Intercept-X heartbeat and as soon as they hit such a Threat Feed, it is synced to Central which then flags the Computer with red health, requiring an admin to "fix" this in Central.

    As this were all false positives (much more than on the screenshot below) , we needed to change the Feed from block to monitor only.

    So my questions here are:

    are there plans from Sophos to enable exclusions for a detection like "DNS"? Currently you can only exclude IPs.

    are there plans to be able to make exclusions based on feed? Right now an exclusion is for all feeds, including the Sophos managed feeds.
    That way we could block all IPs from the Feed list inbound facing only the firewall WAN for bruteforce (User, SSL, VPN Portal etc) while allowing outbound user traffic.

  • We have some plans to improve this, i would still recommend customers to be careful with those lists. The lists and databases are most of the time full of false positives or not very well maintained entries leading to F-P disasters. 

    __________________________________________________________________________________________________________________

  • I've turned it off for the moment, but as you say you have to be careful re the lists.

Reply Children
No Data