<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking Tor with Toro in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/241116#M468</link>
    <description>&lt;P&gt;The domain was going to cost too much for a free project. Added it as a sub domain. Still the same service with the same aggregated IP addresses in the database &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://toro.threathound.com" target="_self"&gt;https://toro.threathound.com&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Nov 2018 03:42:15 GMT</pubDate>
    <dc:creator>jfolkins</dc:creator>
    <dc:date>2018-11-26T03:42:15Z</dc:date>
    <item>
      <title>Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/188868#M113</link>
      <description>&lt;P&gt;I&amp;nbsp;recently had to work with local and federal law enforcement to resolve the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.ktvz.com/news/mtn-view-hs-bomb-threat-traced-to-eugene-14-year-old/653184885" target="_self"&gt;http://www.ktvz.com/news/mtn-view-hs-bomb-threat-traced-to-eugene-14-year-old/653184885&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because of this,&amp;nbsp;I've&amp;nbsp;created a small piece of software (MIT Licensed) that caches the ip addresses of Tor exit nodes, and creates configuration files for different services (PaloAlto, Apache, Nginx, Iptables) in order to block Tor.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRIKE&gt;&lt;A href="https://www.toro.tech" target="_blank"&gt;https://www.toro.tech&lt;/A&gt;&lt;/STRIKE&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://toro.threathound.com" target="_self"&gt;https://toro.threathound.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Toro was built with&amp;nbsp;the Go programming language, so consuming the Tor exit node ip addresses, updating the local database, and serving the configuration files over http all happen within a single process served by a single binary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I realize that&amp;nbsp;a truly motivated attacker won't be stopped by this but I think it will help weed out&amp;nbsp;certain types of offenders and potentially lead to less wasted resources for certain threat models.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feel free to ask questions.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 03:40:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/188868#M113</guid>
      <dc:creator>jfolkins</dc:creator>
      <dc:date>2018-11-26T03:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201427#M243</link>
      <description>&lt;P&gt;Okay to point a External Dynamic List entry to your directory for Palo Alto?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 19:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201427#M243</guid>
      <dc:creator>remerson</dc:creator>
      <dc:date>2018-02-20T19:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201453#M246</link>
      <description>&lt;P&gt;It is a performant application, so if your threat model allows, feel free to consume the list directly. If things get crazy, I'll rate limit it to once every thirty minutes. Though I do not antipicate this.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 21:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201453#M246</guid>
      <dc:creator>jfolkins</dc:creator>
      <dc:date>2018-02-20T21:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201481#M248</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;It looks like the EDL for Palo Alto Networks currently available at:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.toro.tech/paloalto/minutes/1440" target="_blank"&gt;https://www.toro.tech/paloalto/minutes/1440&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would also look like the 1440 value in the URL is a value for 'last-n-minutes'. What does this refer to? Would an user benefit in any way by modifying this default value?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 23:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201481#M248</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-02-20T23:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201491#M249</link>
      <description>&lt;P&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;It would also look like the 1440 value in the URL is a value for 'last-n-minutes'. What does this refer to?&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;In plain english.&lt;BR /&gt;&lt;BR /&gt;"Give me all the exit node IP addresses that were part of the network in the last day (1440 minutes)."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp; Would an user benefit in any way by modifying this default value?&lt;BR /&gt;&lt;BR /&gt;If you only want the freshest data then append&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://toro.threathound.com/paloalto/minutes/15" target="_blank"&gt;https://toro.threathound.com/paloalto/minutes/15&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;minutes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are paranoid and do not want any known associated node in the last year, append&amp;nbsp;&lt;A href="https://toro.threathound.com/paloalto/minutes/15" target="_blank"&gt;https://toro.threathound.com/paloalto/minutes/15&lt;/A&gt; minutes.&lt;BR /&gt;&lt;BR /&gt;The default of 1440 is simply the last day and seemed reasonable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 03:44:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201491#M249</guid>
      <dc:creator>jfolkins</dc:creator>
      <dc:date>2018-11-26T03:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201508#M250</link>
      <description>&lt;P&gt;Thank you for sharing!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 01:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201508#M250</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-02-21T01:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201685#M251</link>
      <description>&lt;P&gt;You are welcome.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 22:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/201685#M251</guid>
      <dc:creator>jfolkins</dc:creator>
      <dc:date>2018-02-21T22:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/221000#M359</link>
      <description>&lt;P&gt;By popular demand, a powershell .ps1 script is now an option.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 02:29:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/221000#M359</guid>
      <dc:creator>jfolkins</dc:creator>
      <dc:date>2018-07-07T02:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Tor with Toro</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/241116#M468</link>
      <description>&lt;P&gt;The domain was going to cost too much for a free project. Added it as a sub domain. Still the same service with the same aggregated IP addresses in the database &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://toro.threathound.com" target="_self"&gt;https://toro.threathound.com&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 03:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-tor-with-toro/m-p/241116#M468</guid>
      <dc:creator>jfolkins</dc:creator>
      <dc:date>2018-11-26T03:42:15Z</dc:date>
    </item>
  </channel>
</rss>

