Skip to main content

OneFirewall Intelligence

Visit the OneFirewall Intelligence Page OneFirewall provides threat intelligence feeds built from data shared across the OneFirewall Alliance.

Threat Intelligence Feeds

OneFirewall provides several Indicator of Attack (IoA) feeds:
  • IPv4: Malicious IP addresses identified through suspicious traffic patterns, known malware sources, and blacklists.
  • Files: File hash analysis (MD5, SHA1, SHA-256) to detect malicious files.
  • URLs: Web addresses flagged for malicious activity using reputation scores and behavioral patterns.
  • Domains: Fully qualified domain names (FQDNs) identified as malicious through pattern analysis, historical data, and reputation scoring.

Threat Intelligence Sources

The OneFirewall World Crime Feeds (WCF) Platform aggregates threat intelligence from multiple sources:
  • Cyber Threat Alliance: Cybersecurity organizations sharing threat intelligence.
  • OneEye Forecast: OneFirewall’s private honeynet, providing insights into emerging threats.
  • Additional Sources: Contributions from over 135 entities, including Checkpoint, Fortigate, AlienVault, Juniper Networks, SonicWall, and more.

Source Breakdown

OneFirewall’s DataLake draws from over 135 unique sources:
  1. Cyber Threat Alliance (30+ member organizations) – 1 source
  2. DeceptionGrid (OneFirewall’s Honeynet) – 1 source
  3. AI/ML-Based Inspection (OneFirewall’s proprietary models) – 1 source
  4. OneFirewall Security Operations Center (SOC) – 1 source
  5. Publicly Available Threat Feeds – 49 sources
  6. Private Intelligence from Security Partners – 7 sources
  7. Extended Alliance Members (Active contributing customers) – 75 sources
Note: The number and distribution of feeds may vary over time based on real-time activity and partner contributions.

Data Quality

As a member of the Cyber Threat Alliance, OneFirewall validates submitted data and has access to threat intelligence shared by all CTA members.

Impact of the OneFirewall Alliance Platform

The OneFirewall Alliance Platform (WCF) shares threat intelligence in real time, pooling data from multiple sources. This enables:
  • Faster responses to attacks.
  • Broader perspectives on emerging threats.
  • Reduced security costs.