OneFirewall Intelligence
Visit the OneFirewall Intelligence Page OneFirewall provides threat intelligence feeds built from data shared across the OneFirewall Alliance.Threat Intelligence Feeds
OneFirewall provides several Indicator of Attack (IoA) feeds:- IPv4: Malicious IP addresses identified through suspicious traffic patterns, known malware sources, and blacklists.
- Files: File hash analysis (MD5, SHA1, SHA-256) to detect malicious files.
- URLs: Web addresses flagged for malicious activity using reputation scores and behavioral patterns.
- Domains: Fully qualified domain names (FQDNs) identified as malicious through pattern analysis, historical data, and reputation scoring.
Threat Intelligence Sources
The OneFirewall World Crime Feeds (WCF) Platform aggregates threat intelligence from multiple sources:- Cyber Threat Alliance: Cybersecurity organizations sharing threat intelligence.
- OneEye Forecast: OneFirewall’s private honeynet, providing insights into emerging threats.
- Additional Sources: Contributions from over 135 entities, including Checkpoint, Fortigate, AlienVault, Juniper Networks, SonicWall, and more.
Source Breakdown
OneFirewall’s DataLake draws from over 135 unique sources:- Cyber Threat Alliance (30+ member organizations) – 1 source
- DeceptionGrid (OneFirewall’s Honeynet) – 1 source
- AI/ML-Based Inspection (OneFirewall’s proprietary models) – 1 source
- OneFirewall Security Operations Center (SOC) – 1 source
- Publicly Available Threat Feeds – 49 sources
- Private Intelligence from Security Partners – 7 sources
- Extended Alliance Members (Active contributing customers) – 75 sources
Note: The number and distribution of feeds may vary over time based on real-time activity and partner contributions.
Data Quality
As a member of the Cyber Threat Alliance, OneFirewall validates submitted data and has access to threat intelligence shared by all CTA members.Impact of the OneFirewall Alliance Platform
The OneFirewall Alliance Platform (WCF) shares threat intelligence in real time, pooling data from multiple sources. This enables:- Faster responses to attacks.
- Broader perspectives on emerging threats.
- Reduced security costs.

