Actionable Cyber Threat Intelligence for real-time protection

Cyber criminals from around the world are grouping in associations to be more effective on their attacks, while 98% of organizations defend themselves alone!. Join OneFirewall Alliance Today for instant protection with a united CTI

OneFirewall Alliance - Global Threat Intelligence Network

Trusted by Global Organizations

A subset of our alliance members - currently surpassing 290 members worldwide.

Compatible and integrated with the following architectures and 166 more!

Alliance Members {contributors}

Real-time threat data collected from alliance members across Top 12 countries — continuously enriching the Alliance IoC feed

● LIVE — Intelligence nodes actively contributing IoCs to the Alliance feed

Product Ecosystem

An integrated suite of cybersecurity products — all powered by our Alliance Threat Intelligence

INTELLIGENCE CORE

Cyber Threat Intelligence (CTI)

Allianc-sourced threat intelligence covering IP addresses, domains, URLs, and malware. Real-time feeds for comprehensive threat coverage.

Actionable Cyber Threat Intelligence & IoC Feeds →
290+Alliance Members
Real-TimeThreat Feeds
GlobalCoverage

Network Security (IPS)

Automated Prevention

One-Click integration for automated threat blocking across IPS, XDR, firewalls, WAFs, and routers.

View Plugin Integrations →

OneDevice Firewall

IPS Appliance available in two versions: parallel with pfSense or standalone in-series.

OneDevice Appliance →

Web Firewall

Web Application Firewall (WAF) for protecting web applications against common Web attacks.

WAF Documentation →

Secure DNS

DNS service powered by Alliance Threat Intelligence to prevent resolution of malicious domains and block risky IPs.

Secure DNS Documentation →

Endpoint & Access Protection

Mobile Protection

Mobile App with local VPN self-routing to prevent malicious inbound and outbound traffic.

OFA Mobile →

Private VPN

Dedicated VPN for workplace environments, fully integrated with the threat intelligence alliance.

closedvpn.io →

AI Gateway

Firewall for AI public services, enabling safe and secure AI usage while preventing data leakage.

onefirewall.ai →

In-Depth Security

Active Scan

Offensive security platform for DAST, dark web scanning, and penetration testing.

vulnix0.com →

Secure Channel

Secure Owned Communication (SOC) platform for protecting sensitive data in transit and at rest.

SOC Documentation →

Software Security

Comprehensive security platform developed in partnership with AquilaX LTD in UK.

aquilax.ai →

What We Do

Threat Intelligence Alliance

Crowd-sourced threat intelligence covering IPs, domains, URLs, and malware. Over 210 alliance members sharing vetted intelligence.

Automated Prevention

Real-time synchronization with IPS, XDR, firewalls, WAFs, and routers for automated threat blocking.

Mobile & Endpoint Protection

Self-routing local VPN application protecting devices from malicious inbound and outbound traffic.

Enterprise VPN & DNS

Workplace-dedicated VPN and secure DNS services powered by alliance threat intelligence.

AI Gateway Security

Specialized firewall for AI public services preventing data leakage while enabling safe AI usage.

Offensive Security

Comprehensive DAST, dark web scanning, and penetration testing to validate defensive posture.

MITRE ATT&CK relationship graph linking a malicious IP indicator to attack patterns and mitigations
Alliance Intelligence, EnrichedEvery indicator is automatically mapped to MITRE ATT&CK context the moment it's shared.
OneFirewall integrations marketplace showing Checkpoint, Fortinet, Sophos, Palo Alto, pfSense, Cisco IOS, Peplink, Forcepoint and Infoblox
One Console, Every FirewallPush enforcement-ready blocklists straight into the firewalls, WAFs, and routers you already run.
Wall of Fire panel showing 44,383 attacks prevented, 1,455 threat actors blocked, and 207,317 automated firewall rules deployed
Prevention at ScaleTens of thousands of attacks stopped and hundreds of thousands of rules deployed automatically.

Why OneFirewall

Real-time threat, IoC and CTI blocking
Unified intelligence layer
Automated IPS integration (WCF Agent)
Device-based pricing (not traffic-based)
Centralized management
Reduced security tool sprawl
Faster incident response
Enterprise-grade scalability

Architecture Overview

01

Intelligence Ingestion

02

Threat Validation

03

Enrichment Layer

04

Distribution Engine

05

IPS Synchronization

06

Real-Time Prevention

Platform in Action

Real dashboards from the OneFirewall platform — the same views your team gets during a Proof of Value.

OneFirewall Threat Defense Center dashboard showing 421 attacks prevented, 408 threat actors blocked, and 27,473 automated firewall rules deployed
Threat Defense Center Live 24h view of attacks prevented, threat actors blocked, and automated firewall rules deployed across your connected devices.
DeceptionGrid diagram showing 1,000+ honeypots across 8 regions feeding a validation engine that enriches the Alliance threat feed
DeceptionGrid 1,000+ honeypots across 8 regions capture 7,000+ attacks per hour — validated and folded into the shared Alliance feed.
Chord chart showing traffic passed versus denied for a member organization, broken down by severity, with 491 and 256 affected-traffic counts highlighted
Passed vs. Denied Traffic A severity-weighted breakdown of every request a member's firewall passed versus denied, so you can see exactly what OneFirewall caught.
Sankey diagram tracing total parsed events through Passed and Blocked paths by severity tier, ending in counts of Low, Medium, High, and Critical threat actors
Event Flow Breakdown Every parsed event traced end-to-end — from clean traffic through blocked severity tiers to the actors behind them.

Frequently Asked Questions

Quick answers to the most common questions — view the full FAQ page for 30+ topics.

What is OneFirewall Alliance?

OneFirewall Alliance is a UK-based cybersecurity company headquartered in London. It operates a crowd-sourced Cyber Threat Intelligence (CTI) platform built on an alliance of 290+ organisations worldwide. Member organisations share vetted threat indicators — malicious IPs, domains, URLs, and malware signatures — consolidated, enriched, and distributed in real time as actionable feeds for automated firewall blocking.

How often is the threat intelligence updated?

Intelligence is updated in real time. New indicators submitted by alliance members are validated and distributed to all connected members within <200ms sync latency. The WCF Agent on your firewall pulls updated block-lists continuously — no manual intervention or scheduled batch imports needed.

What is the Crime Score?

The Crime Score is a proprietary risk value from 0 to 1000 assigned to every threat indicator. It combines alliance sighting frequency, historical behaviour, sector targeting profile, MITRE ATT&CK technique severity, and community confidence weighting. A score of 700+ is generally considered high-confidence for automated blocking — with thresholds configurable per environment.

Which firewalls and platforms does OneFirewall integrate with?

The WCF Agent supports 166+ security platforms including Check Point, Fortinet FortiGate, Forcepoint NGFW, Cisco, Palo Alto Networks, pfSense, OPNsense, Juniper SRX, Sophos, and many more — plus XDR platforms and WAF solutions. The full compatibility list is at docs.onefirewall.com.

Does the CTI feed support STIX / TAXII?

Yes. The OneFirewall CTI API returns indicators in STIX 2.1 format and is compatible with TAXII 2.1. You can connect directly to Splunk, Microsoft Sentinel, IBM QRadar, or any STIX/TAXII-capable SIEM or SOAR without writing custom parsers.

Is there a free trial or Proof of Value?

Yes. OneFirewall offers a Proof of Value (PoV) programme — connect to the live intelligence feed and measure its impact on your existing infrastructure before committing to membership. Contact the team to arrange yours.

Cyber Attack Intelligence: Latest News

Real-world cyber attack coverage from the past 24 hours — view all news →

Cybersecurity jobs available right now: September 29, 2026
Help Net Security Sep 29, 2026

Cybersecurity jobs available right now: September 29, 2026

Application Security Researcher Novee Security | Israel | Hybrid – View job details As an Application Security Researcher, you will test web applications and APIs to verify vulnerabilities found by No...

Read more →
GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch
Securityaffairs.com Sep 29, 2026

GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch

UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK’s AI Security Institute tested GPT-6 Astra before...

Read more →
The Russian invasion of Thailand: Desperate to escape conscription and protect their wealth from Putin's crumbling economy, IAN BIRRELL reveals how thousands are buying homes on the paradise island of Phuket
Dailymail.com Sep 29, 2026

The Russian invasion of Thailand: Desperate to escape conscription and protect their wealth from Putin's crumbling economy, IAN BIRRELL reveals how thousands are buying homes on the paradise island of Phuket

The golden domes of a Russian Orthodox church, topped with the traditional three-bar Slavic cross, seem incongruous as they tower over the palm trees, pineapple fields and rubber plantations of a trop...

Read more →
September 2026 Cyber Attacks Timeline
Hackmageddon.com Sep 29, 2026

September 2026 Cyber Attacks Timeline

A live, continuously updated timeline of the cyber attacks reported in September 2026 — tracking threat actors, attack techniques, targeted sectors and countries as each incident is vetted and added.

Read more →
Autonomous AI hacks Raise Thorny Questions of Legal Accountability
Insurance Journal Sep 29, 2026

Autonomous AI hacks Raise Thorny Questions of Legal Accountability

The Justice Department has a long history of investigating and prosecuting hackers who break into a private company’s network. But what happens when the hackers aren’t human? That’s the question at th...

Read more →
The Manhattan Project Mindset: How Nuclear Analogies Are Steering AI Policy Off Course
War on the Rocks Sep 29, 2026

The Manhattan Project Mindset: How Nuclear Analogies Are Steering AI Policy Off Course

Analogies for artificial intelligence abound. In recent years, analysts have likened the development of AI to the advent of electricity, the Industrial Revolution, contact with extraterrestrials, and ...

Read more →

See OneFirewall in Action

Watch OneFirewall Alliance in action – click to play