<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proofpoint and other inbound blocklists in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101137#M99637</link>
    <description>&lt;P&gt;Hi networkadmin,&lt;/P&gt;
&lt;P&gt;currently (0.9.18) there are 2 feeds provided by ProofPoint ET:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ET Domains, providing a list of domain indicators&lt;/LI&gt;
&lt;LI&gt;ET IPs, providing a list of IP indicators&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each of them is covered by a prototype, &lt;STRONG&gt;proofpoint.EmergingThreatsDomains&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;proofpoint.EmergingThreatsIPs&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Inside the feeds, each indicator (IP or domain) has associated a list of categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you create a Miner based on one of the ProofPoint prototypes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-192.168.55.159 2016-08-03 21-45-28.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5055iF729B7BD1BE522D5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="screenshot-192.168.55.159 2016-08-03 21-45-28.png" alt="screenshot-192.168.55.159 2016-08-03 21-45-28.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can specify the Auth Code provided by ProofPoint and the list of categories you are interested in:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-192.168.55.159 2016-08-03 21-45-51.png" style="width: 556px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5056iA789B15DBF25FD96/image-dimensions/556x196/is-moderation-mode/true?v=v2" width="556" height="196" role="button" title="screenshot-192.168.55.159 2016-08-03 21-45-51.png" alt="screenshot-192.168.55.159 2016-08-03 21-45-51.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-192.168.55.159 2016-08-03 21-46-21.png" style="width: 561px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5057i1F75F3CC1D740F13/image-dimensions/561x295/is-moderation-mode/true?v=v2" width="561" height="295" role="button" title="screenshot-192.168.55.159 2016-08-03 21-46-21.png" alt="screenshot-192.168.55.159 2016-08-03 21-46-21.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create multiple Miners, and each of them can have different categories. This way you can have different feeds for inbound and outbound IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ProofPoint can easily provide best practices about using their feeds for blocking or preventing attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please, let me know if you need additional details.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Aug 2016 19:55:18 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2016-08-03T19:55:18Z</dc:date>
    <item>
      <title>Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101132#M99635</link>
      <description>&lt;P&gt;I've been experimenting with MineMeld and have to say I love it so far.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was browsing the list of feeds and looked at the ProofPoint ET Pro feed and I wondered if anyone knows how this feed works?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got pricing and it's quite reasonable, but I'm not 100% clear how it integrates and can be integrated with Palo Alto, does anyone know?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be interested in any views on the most effective inbound blocklists?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 19:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101132#M99635</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-08-03T19:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101133#M99636</link>
      <description>&lt;P&gt;I have added a couple of custom Proofpoint feeds that are free and keep forgetting to send them to Luigi to integrate into the product. I can't speak for what might be different between the free and paid versions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;url: &lt;A href="http://rules.emergingthreats.net/blockrules/compromised-ips.txt" target="_blank"&gt;http://rules.emergingthreats.net/blockrules/compromised-ips.txt&lt;/A&gt;&lt;BR /&gt;description: &amp;gt;&amp;nbsp;Emerging Threats Compromised List&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;url: &lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;BR /&gt;description: &amp;gt;&amp;nbsp;Emerging Threats FW Block List&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 19:50:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101133#M99636</guid>
      <dc:creator>Greg_R</dc:creator>
      <dc:date>2016-08-03T19:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101137#M99637</link>
      <description>&lt;P&gt;Hi networkadmin,&lt;/P&gt;
&lt;P&gt;currently (0.9.18) there are 2 feeds provided by ProofPoint ET:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ET Domains, providing a list of domain indicators&lt;/LI&gt;
&lt;LI&gt;ET IPs, providing a list of IP indicators&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each of them is covered by a prototype, &lt;STRONG&gt;proofpoint.EmergingThreatsDomains&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;proofpoint.EmergingThreatsIPs&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Inside the feeds, each indicator (IP or domain) has associated a list of categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you create a Miner based on one of the ProofPoint prototypes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-192.168.55.159 2016-08-03 21-45-28.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5055iF729B7BD1BE522D5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="screenshot-192.168.55.159 2016-08-03 21-45-28.png" alt="screenshot-192.168.55.159 2016-08-03 21-45-28.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can specify the Auth Code provided by ProofPoint and the list of categories you are interested in:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-192.168.55.159 2016-08-03 21-45-51.png" style="width: 556px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5056iA789B15DBF25FD96/image-dimensions/556x196/is-moderation-mode/true?v=v2" width="556" height="196" role="button" title="screenshot-192.168.55.159 2016-08-03 21-45-51.png" alt="screenshot-192.168.55.159 2016-08-03 21-45-51.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-192.168.55.159 2016-08-03 21-46-21.png" style="width: 561px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5057i1F75F3CC1D740F13/image-dimensions/561x295/is-moderation-mode/true?v=v2" width="561" height="295" role="button" title="screenshot-192.168.55.159 2016-08-03 21-46-21.png" alt="screenshot-192.168.55.159 2016-08-03 21-46-21.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create multiple Miners, and each of them can have different categories. This way you can have different feeds for inbound and outbound IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ProofPoint can easily provide best practices about using their feeds for blocking or preventing attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please, let me know if you need additional details.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 19:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101137#M99637</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-03T19:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101138#M99638</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;
&lt;P&gt;I will make sure to add them in the next release.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 19:57:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101138#M99638</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-03T19:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101160#M99639</link>
      <description>&lt;P&gt;Thanks, one concern/query I do have is how people are using minemeld given there seems to be total of 50,000 entries maximum across &lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;EBLs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know the count on the ProofPoint feed for example but I could imagine things being quite large.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also (and I'm hoping to speak to ProofPoint) does anyone know if there is masses more on their commercial feed than the open source one?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ask as I believe the ET Pro subscription inclues a ton of suricata/snort rules which we cannot use with our PAN, so essentially the only piece we'd be using is the EBL content via minemeld.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 06:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101160#M99639</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-08-04T06:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101222#M99640</link>
      <description>&lt;P&gt;Hi networkadmin,&lt;/P&gt;
&lt;P&gt;the ProofPoint ET Intelligence delivers feeds with much more context than what available in the Open Source. Let me know if you need a contact in PP, I'd be happy to help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are 2 things you can do to cope with the EDL max number of entries:&lt;/P&gt;
&lt;P&gt;- you can limit the number of entries download from the MM feed attaching the 'n' parameter in&amp;nbsp;the URL. Example, if the feed is published as https://&amp;lt;minemeld&amp;gt;/feeds/IPfeed, you can download only 10000 elements by using https://&amp;lt;minemeld&amp;gt;/feeds/IPFeed?n=10000&lt;/P&gt;
&lt;P&gt;- by default MineMeld output feed are sorted using the "most recent" criteria. This means that when you download the first 10000 elements, you are downloading the 10000 most recent elements added to the feed. Sorting attribute can be changed by changing the prototype of the feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note that starting from 7.1, you have a max of 50000 (150000 on PA5K and PA7K) IPs in EDL &lt;STRONG&gt;and&lt;/STRONG&gt; a max 50000 for URLs+Domains. Ref:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Videos/PAN-OS-7-1-URL-Filtering-Dynamic-Block-List-External-Block-List/ta-p/74098" target="_blank"&gt;https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Videos/PAN-OS-7-1-URL-Filtering-Dynamic-Block-List-External-Block-List/ta-p/74098&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Luigi&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 14:24:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/101222#M99640</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-08-04T14:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint and other inbound blocklists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/552109#M112366</link>
      <description>&lt;P&gt;Hi Lmori,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has there been any change to being able to use ET Pro? Improvements?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are switching over to PaloAlto Firewalls and am trying to find out if we can use ET Pro with them since we have valid license currently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Jacob&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 18:01:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proofpoint-and-other-inbound-blocklists/m-p/552109#M112366</guid>
      <dc:creator>jacobcavaness</dc:creator>
      <dc:date>2023-08-01T18:01:47Z</dc:date>
    </item>
  </channel>
</rss>

