<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Based EDLs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259144#M73485</link>
    <description>&lt;P&gt;They are free :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source on PAN support:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/54183#54183" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/message/54183#54183&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sans notes on this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/" target="_blank" rel="noopener"&gt;https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Others listed on this site:&lt;/P&gt;&lt;P&gt;&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://malc0de.com/bl/IP_Blacklist.txt" target="_blank" rel="noopener"&gt;http://malc0de.com/bl/IP_Blacklist.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank" rel="noopener"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/" target="_blank" rel="noopener"&gt;http://panwdbl.appspot.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://cinsscore.com/list/ci-badguys.txt" target="_blank" rel="noopener"&gt;http://cinsscore.com/list/ci-badguys.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2019 20:33:21 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-04-29T20:33:21Z</dc:date>
    <item>
      <title>Security Based EDLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/258864#M73410</link>
      <description>&lt;P&gt;I am trying out a PoC for Palo for a specific threat purpose.&amp;nbsp; The box came with some EDLs that I didn't expect and figured I'd share here.&amp;nbsp; They seem to cover a wide range of threats that would be really benefical for others to have deployed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd just caution to take extra care in your production enviornment when implementing these blocks looking out for unintended consequences.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EDLs.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19725iFFB4DAFBCD2502EE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="EDLs.PNG" alt="EDLs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 13:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/258864#M73410</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-04-26T13:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security Based EDLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/258886#M73419</link>
      <description>&lt;P&gt;Did you find these on your 5260 PoC box? If yes, then these are probably configured by the admin that was able to play with this monster prior to you &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 15:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/258886#M73419</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-26T15:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security Based EDLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/258887#M73420</link>
      <description>&lt;P&gt;Yeah, they came predefined on the PoC box I'm working with.&amp;nbsp; I'll probably end up integrating them into our prod environment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 15:45:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/258887#M73420</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-04-26T15:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Security Based EDLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259128#M73475</link>
      <description>&lt;P&gt;Here are the ones we use. The Team-Cymru is not valid and we are removing it soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19768iD01AC0C005AACF0F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 18:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259128#M73475</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-29T18:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security Based EDLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259140#M73483</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Here are the ones we use. The Team-Cymru is not valid and we are removing it soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19768iD01AC0C005AACF0F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like these are the same ones enabled on this 5260.&amp;nbsp; I just didn't have the original URL in my screenshot as I wasn't sure where they came from and didn't know if I should share them:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EDLs.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19771i837DD58B9B60F863/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="EDLs.PNG" alt="EDLs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 19:54:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259140#M73483</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-04-29T19:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security Based EDLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259144#M73485</link>
      <description>&lt;P&gt;They are free :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source on PAN support:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/54183#54183" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/message/54183#54183&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sans notes on this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/" target="_blank" rel="noopener"&gt;https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Others listed on this site:&lt;/P&gt;&lt;P&gt;&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://malc0de.com/bl/IP_Blacklist.txt" target="_blank" rel="noopener"&gt;http://malc0de.com/bl/IP_Blacklist.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank" rel="noopener"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/" target="_blank" rel="noopener"&gt;http://panwdbl.appspot.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://cinsscore.com/list/ci-badguys.txt" target="_blank" rel="noopener"&gt;http://cinsscore.com/list/ci-badguys.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 20:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-based-edls/m-p/259144#M73485</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-29T20:33:21Z</dc:date>
    </item>
  </channel>
</rss>

