Hi netmaster_UC3M,
I am glad you are liking MM !
IPv4 Aggregator and URL/domains aggregator are different:
- IPv4 Aggregator understand the semantic of the IPv4 indicators and can be used to whitelist ranges, CIDR or unicast IPs. This means that if you send it an indicator like "10.0.0.0/8" as whitelist, the range 10.0.0.0-10.255.255.255 will be whitelisted. If a malicious indicator is partially overlapping that range, like 10.255.255.255-11.0.0.0, the overlapping part will be whitelisted and only the non-overlapping part will be send downstream - in this case 11.0.0.0.
- URL/domains aggregators are simpler and currently support only perfect match for whitelist and aggregation. I have plans to support wildcard or better regexs, but this is still in planning.
Hope this helps.
luigi
... View more