<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where do you get additional threat feeds from in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319843#M81955</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132841"&gt;@johnde&lt;/a&gt;You can simply webpage using IIS under windows server. You can refer below link to do the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=abqTcXeyst0" target="_blank"&gt;https://www.youtube.com/watch?v=abqTcXeyst0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once your webpage is ready, configure feed url under EDL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2020 06:25:58 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-04-01T06:25:58Z</dc:date>
    <item>
      <title>Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319592#M81946</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Just curious as to what additional threat feeds you use to ingest into your PAN. Here are some of the ones we use:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Threat intelligence blocklists&lt;BR /&gt;&lt;A href="https://talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;https://talosintelligence.com/documents/ip-blacklist&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/" target="_blank"&gt;http://panwdbl.appspot.com/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.spamhaus.org/drop/drop.txt" target="_blank"&gt;http://www.spamhaus.org/drop/drop.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.spamhaus.org/drop/edrop.txt" target="_blank"&gt;http://www.spamhaus.org/drop/edrop.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/bruteforceblocker.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/bruteforceblocker.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/mdl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/mdl.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/ettor.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/ettor.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/etcompromised.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/etcompromised.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/dshieldbl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/dshieldbl.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/sslabuseiplist.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/sslabuseiplist.txt&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://panwdbl.appspot.com/lists/zeustrackerbadips.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/zeustrackerbadips.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would love to hear all of your thoughts whether its into the PAN or SIEM or something else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 15:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319592#M81946</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-03-31T15:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319604#M81949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured our own feed url on windows based server and added it under EDL. Whenever we find any of malicious/suspicious IP/domain, we add it under site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We haven't configured any of publically available URLs as given below. The reason being we do not have any control on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 15:45:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319604#M81949</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-31T15:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319620#M81950</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;How to configure own feed url on windows server?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 16:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319620#M81950</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2020-03-31T16:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319843#M81955</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132841"&gt;@johnde&lt;/a&gt;You can simply webpage using IIS under windows server. You can refer below link to do the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=abqTcXeyst0" target="_blank"&gt;https://www.youtube.com/watch?v=abqTcXeyst0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once your webpage is ready, configure feed url under EDL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 06:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319843#M81955</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-01T06:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319988#M81981</link>
      <description>&lt;P&gt;Great, thanks Mayur.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/319988#M81981</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2020-04-01T13:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/320642#M82105</link>
      <description>&lt;P&gt;I love firehol&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://iplists.firehol.org/" target="_blank"&gt;http://iplists.firehol.org/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 19:39:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/320642#M82105</guid>
      <dc:creator>jasonwald</dc:creator>
      <dc:date>2020-04-03T19:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/359912#M88027</link>
      <description>&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/mdl.txt" target="_blank" rel="nofollow noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer"&gt;http://panwdbl.appspot.com/lists &lt;/A&gt;&lt;/P&gt;&lt;P&gt;Appears to be down. Not sure if the author removed it permanently or not? If so that is a real bummer.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 14:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/359912#M88027</guid>
      <dc:creator>jasonwald</dc:creator>
      <dc:date>2020-10-30T14:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/359925#M88036</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Just a reminder that Palo Alto has a lot of back end feeds and bots that continuously update their stack. I think that a properly configured system with regular updates and dynamic inspection is a good part of an overall security strategy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 16:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/359925#M88036</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-30T16:46:08Z</dc:date>
    </item>
    <item>
      <title>same here :(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/360045#M88050</link>
      <description>&lt;P&gt;same here &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 12:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/360045#M88050</guid>
      <dc:creator>Isaaczarb</dc:creator>
      <dc:date>2020-10-31T12:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/475021#M103413</link>
      <description>&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank" rel="nofollow noopener noreferrer"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&amp;nbsp;and other panwdbl.appspot.com URLs are now retired.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for an SSL abuse list, anyone know of a vetted one?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 18:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/475021#M103413</guid>
      <dc:creator>j04nMan</dc:creator>
      <dc:date>2022-03-22T18:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Where do you get additional threat feeds from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/475023#M103414</link>
      <description>&lt;P&gt;Here's a live TOR Exit Node block list - for ingress&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dan.me.uk/torlist/" target="_blank"&gt;https://www.dan.me.uk/torlist/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 18:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-do-you-get-additional-threat-feeds-from/m-p/475023#M103414</guid>
      <dc:creator>j04nMan</dc:creator>
      <dc:date>2022-03-22T18:32:43Z</dc:date>
    </item>
  </channel>
</rss>

