Actionable Cyber Threat Intelligence for real-time protection

Cyber criminals from around the world are grouping in associations to be more effective on their attacks, while 98% of organizations defend themselves alone!. Join OneFirewall Alliance Today for instant protection with a united CTI

OneFirewall Alliance - Global Threat Intelligence Network

Trusted by Global Organizations

A subset of our alliance members - currently surpassing 290 members worldwide.

Compatible and integrated with the following architectures and 166 more!

Alliance Members {contributors}

Real-time threat data collected from alliance members across Top 12 countries — continuously enriching the Alliance IoC feed

● LIVE — Intelligence nodes actively contributing IoCs to the Alliance feed

Product Ecosystem

An integrated suite of cybersecurity products — all powered by our Alliance Threat Intelligence

INTELLIGENCE CORE

Cyber Threat Intelligence (CTI)

Allianc-sourced threat intelligence covering IP addresses, domains, URLs, and malware. Real-time feeds for comprehensive threat coverage.

Actionable Cyber Threat Intelligence & IoC Feeds →
290+Alliance Members
Real-TimeThreat Feeds
GlobalCoverage

Network Security (IPS)

Automated Prevention

One-Click integration for automated threat blocking across IPS, XDR, firewalls, WAFs, and routers.

View Plugin Integrations →

OneDevice Firewall

IPS Appliance available in two versions: parallel with pfSense or standalone in-series.

OneDevice Appliance →

Web Firewall

Web Application Firewall (WAF) for protecting web applications against common Web attacks.

WAF Documentation →

Secure DNS

DNS service powered by Alliance Threat Intelligence to prevent resolution of malicious domains and block risky IPs.

Secure DNS Documentation →

Endpoint & Access Protection

Mobile Protection

Mobile App with local VPN self-routing to prevent malicious inbound and outbound traffic.

OFA Mobile →

Private VPN

Dedicated VPN for workplace environments, fully integrated with the threat intelligence alliance.

closedvpn.io →

AI Gateway

Firewall for AI public services, enabling safe and secure AI usage while preventing data leakage.

onefirewall.ai →

In-Depth Security

Active Scan

Offensive security platform for DAST, dark web scanning, and penetration testing.

vulnix0.com →

Secure Channel

Secure Owned Communication (SOC) platform for protecting sensitive data in transit and at rest.

SOC Documentation →

Software Security

Comprehensive security platform developed in partnership with AquilaX LTD in UK.

aquilax.ai →

What We Do

Threat Intelligence Alliance

Crowd-sourced threat intelligence covering IPs, domains, URLs, and malware. Over 210 alliance members sharing vetted intelligence.

Automated Prevention

Real-time synchronization with IPS, XDR, firewalls, WAFs, and routers for automated threat blocking.

Mobile & Endpoint Protection

Self-routing local VPN application protecting devices from malicious inbound and outbound traffic.

Enterprise VPN & DNS

Workplace-dedicated VPN and secure DNS services powered by alliance threat intelligence.

AI Gateway Security

Specialized firewall for AI public services preventing data leakage while enabling safe AI usage.

Offensive Security

Comprehensive DAST, dark web scanning, and penetration testing to validate defensive posture.

MITRE ATT&CK relationship graph linking a malicious IP indicator to attack patterns and mitigations
Alliance Intelligence, EnrichedEvery indicator is automatically mapped to MITRE ATT&CK context the moment it's shared.
OneFirewall integrations marketplace showing Checkpoint, Fortinet, Sophos, Palo Alto, pfSense, Cisco IOS, Peplink, Forcepoint and Infoblox
One Console, Every FirewallPush enforcement-ready blocklists straight into the firewalls, WAFs, and routers you already run.
Wall of Fire panel showing 44,383 attacks prevented, 1,455 threat actors blocked, and 207,317 automated firewall rules deployed
Prevention at ScaleTens of thousands of attacks stopped and hundreds of thousands of rules deployed automatically.

Why OneFirewall

Real-time threat, IoC and CTI blocking
Unified intelligence layer
Automated IPS integration (WCF Agent)
Device-based pricing (not traffic-based)
Centralized management
Reduced security tool sprawl
Faster incident response
Enterprise-grade scalability

Architecture Overview

01

Intelligence Ingestion

02

Threat Validation

03

Enrichment Layer

04

Distribution Engine

05

IPS Synchronization

06

Real-Time Prevention

Frequently Asked Questions

Quick answers to the most common questions — view the full FAQ page for 30+ topics.

What is OneFirewall Alliance?

OneFirewall Alliance is a UK-based cybersecurity company headquartered in London. It operates a crowd-sourced Cyber Threat Intelligence (CTI) platform built on an alliance of 290+ organisations worldwide. Member organisations share vetted threat indicators — malicious IPs, domains, URLs, and malware signatures — consolidated, enriched, and distributed in real time as actionable feeds for automated firewall blocking.

How often is the threat intelligence updated?

Intelligence is updated in real time. New indicators submitted by alliance members are validated and distributed to all connected members within <200ms sync latency. The WCF Agent on your firewall pulls updated block-lists continuously — no manual intervention or scheduled batch imports needed.

What is the Crime Score?

The Crime Score is a proprietary risk value from 0 to 1000 assigned to every threat indicator. It combines alliance sighting frequency, historical behaviour, sector targeting profile, MITRE ATT&CK technique severity, and community confidence weighting. A score of 700+ is generally considered high-confidence for automated blocking — with thresholds configurable per environment.

Which firewalls and platforms does OneFirewall integrate with?

The WCF Agent supports 166+ security platforms including Check Point, Fortinet FortiGate, Forcepoint NGFW, Cisco, Palo Alto Networks, pfSense, OPNsense, Juniper SRX, Sophos, and many more — plus XDR platforms and WAF solutions. The full compatibility list is at docs.onefirewall.com.

Does the CTI feed support STIX / TAXII?

Yes. The OneFirewall CTI API returns indicators in STIX 2.1 format and is compatible with TAXII 2.1. You can connect directly to Splunk, Microsoft Sentinel, IBM QRadar, or any STIX/TAXII-capable SIEM or SOAR without writing custom parsers.

Is there a free trial or Proof of Value?

Yes. OneFirewall offers a Proof of Value (PoV) programme — connect to the live intelligence feed and measure its impact on your existing infrastructure before committing to membership. Contact the team to arrange yours.

Cyber Attack Intelligence: Latest News

Real-world cyber attack coverage from the past 24 hours — view all news →

Frontier Models Engage in Unsanctioned Behavior During Testing
Infosecurity Magazine Aug 05, 2026

Frontier Models Engage in Unsanctioned Behavior During Testing

Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests

Read more →
What stops attackers wrecking industrial plants is knowing how
Help Net Security Aug 05, 2026

What stops attackers wrecking industrial plants is knowing how

Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 fl...

Read more →
AI Linked to 55% of Cybercrime Cases in Africa, Interpol Report Says
Naturalnews.com Aug 05, 2026

AI Linked to 55% of Cybercrime Cases in Africa, Interpol Report Says

Interpol said Monday that artificial intelligence featured in 55% of cybercrime cases examined across Africa in 2025, according to the African Cyberthreat Assessment Report 2026. The report, based on ...

Read more →
Europe’s AI sovereignty is under threat. Could Mistral be the answer?
Fortune Aug 05, 2026

Europe’s AI sovereignty is under threat. Could Mistral be the answer?

After Washington cut off access to a top U.S. model, Mistral’s push for sovereign AI looks more appealing than ever. But Europe’s AI champion is still chasing the frontier—and relying on American tech...

Read more →
Risky Business #847 -- Oops! Claude's accidental hacking spree
Risky.biz Aug 05, 2026

Risky Business #847 -- Oops! Claude's accidental hacking spree

On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: <ul> <li>Accidental AI agent hacking sprees ...

Read more →
PRNewswire Aug 05, 2026

AWWA statement on recent cyber attacks on water systems

Over the past two weeks, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and U.S. Environmental Protection Agency have urged water utilities to take immediate protective actions after...

Read more →

See OneFirewall in Action

Watch OneFirewall Alliance in action – click to play