<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: predefined IP address feeds are too small in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274276#M608</link>
    <description>&lt;P&gt;yes, I understand that I cannot rely on them since paloalto doesn't maintain it.&amp;nbsp; But the question is what to use instead to block traffic from well-known malicious IP addresses. Ok, I mean well-known to other companies, not to paloalto, since their feeds are empty &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 10:54:33 GMT</pubDate>
    <dc:creator>vladimir.stepanov</dc:creator>
    <dc:date>2019-07-02T10:54:33Z</dc:date>
    <item>
      <title>predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274271#M604</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am checking the content of two predefined dynamic IP lists for high risky IP addresses and known malicious IP addresses and they are too small, just 613 addresses in total.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;There is a document&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/content-inspection-features/palo-alto-networks-malicious-ip-address-feeds" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/content-inspection-features/palo-alto-networks-malicious-ip-address-feeds&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and there we can find that at the time of writing there were 2969 IP addresses only in high risky list.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;So the question, if it can be some problem with feed updates on our appliances or it is the actual size of these lists.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 10:01:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274271#M604</guid>
      <dc:creator>vladimir.stepanov</dc:creator>
      <dc:date>2019-07-02T10:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274272#M605</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69451"&gt;@vladimir.stepanov&lt;/a&gt;&amp;nbsp;There is nothing wrong with your appliance, they are around 600 now. The list is updated regularly with the anti-virus updates and the numbers can change when new IPs are added or removed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 10:15:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274272#M605</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-07-02T10:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274274#M606</link>
      <description>&lt;P&gt;But why it is like this, was there any announce or answer from paloalto? It is clear that 600 Ip addresses are nothing, also, before they had 10 times bigger list. So what, have paloalto failed with this feature and cannot support it anymore?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 10:27:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274274#M606</guid>
      <dc:creator>vladimir.stepanov</dc:creator>
      <dc:date>2019-07-02T10:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274275#M607</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69451"&gt;@vladimir.stepanov&lt;/a&gt;&amp;nbsp;You should not rely too much on the pre-defined lists. They have never been a comprehensive security feed, but just a small addition to all the other firewall security features and profiles. &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 10:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274275#M607</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-07-02T10:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274276#M608</link>
      <description>&lt;P&gt;yes, I understand that I cannot rely on them since paloalto doesn't maintain it.&amp;nbsp; But the question is what to use instead to block traffic from well-known malicious IP addresses. Ok, I mean well-known to other companies, not to paloalto, since their feeds are empty &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 10:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274276#M608</guid>
      <dc:creator>vladimir.stepanov</dc:creator>
      <dc:date>2019-07-02T10:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274455#M609</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you want to have other EBL's check these out:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source on PAN support:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/54183#54183" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/message/54183#54183&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sans notes on this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/" target="_blank" rel="noopener"&gt;https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Others listed on this site:&lt;/P&gt;&lt;P&gt;&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://malc0de.com/bl/IP_Blacklist.txt" target="_blank" rel="noopener"&gt;http://malc0de.com/bl/IP_Blacklist.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank" rel="noopener"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However remember that IP's change frequently and a proper security poster also takes DNS and URL filtering into consideration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 19:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/274455#M609</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-02T19:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/277034#M613</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69451"&gt;@vladimir.stepanov&lt;/a&gt;: If you need more customized feeds, you can buy a subscription for Autofocus and generate a dynamic feed for your invididual needs. Blocking too many targets is dangerous - you have to keep in mind, that these lists are valid for all global PAN customers.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 13:11:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/277034#M613</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-07-17T13:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/353256#M961</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;wrote:&amp;nbsp;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;A title="MyAARPMedicare" href="https://www.myaarpmedicare.vip/" target="_blank" rel="noopener"&gt;&lt;FONT color="#00FFFF"&gt;MyAARPMedicare&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69451"&gt;@vladimir.stepanov&lt;/a&gt;: If you need more customized feeds, you can buy a subscription for Autofocus and generate a dynamic feed for your invididual needs. Blocking too many targets is dangerous - you have to keep in mind, that these lists are valid for all global PAN customers.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;I understand that I cannot rely on them since paloalto doesn't maintain it.&amp;nbsp; But the question is what to use instead to block traffic from well-known malicious IP addresses.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 10:21:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/353256#M961</guid>
      <dc:creator>CrashDog</dc:creator>
      <dc:date>2020-10-08T10:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: predefined IP address feeds are too small</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/355372#M966</link>
      <description>&lt;P&gt;You can also setup a minemeld server and import preexisting feeds from other malware intelligence.&lt;/P&gt;&lt;P&gt;e.g. urlhaus, spamhouse and so on got public feeds for known spammers and so on.&lt;/P&gt;&lt;P&gt;There is a own area in the live-community for all minemeld related topics&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 06:54:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/predefined-ip-address-feeds-are-too-small/m-p/355372#M966</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-10-09T06:54:32Z</dc:date>
    </item>
  </channel>
</rss>

