A four-layer architecture built for collective defence.
From 290+ alliance member telemetry to automated firewall enforcement — how OneFirewall ingests, validates, enriches and distributes actionable threat intelligence in near real time.
Collective telemetry from 290+ organisations
A trusted network spanning finance, telecommunications, critical national infrastructure, cloud providers, and MSSPs. Each member contributes threat observations — malicious IPs, domains, URLs, file hashes — validated through a shared trust framework aligned with Cyber Threat Alliance (CTA) standards.
- Crowd-sourced indicators from diverse sectors provide cross-industry attack visibility
- Multi-member validation reduces false positives and increases confidence scoring
- Members earn OFA Tokens for quality submissions, incentivising timely reporting
- CTA membership (since 2020) extends telemetry reach to global threat-sharing ecosystems
Enrichment & scoring
Raw telemetry enters the OneFirewall Intelligence Platform where it's validated, deduplicated, enriched, and scored. The platform outputs structured STIX 2.1 objects and assigns a Crime Score (0–1000) to each indicator, making intelligence immediately actionable without manual transformation.
- STIX 2.1 enrichment: indicator, observed-data, attack-pattern, threat-actor, relationship objects
- MITRE ATT&CK mapping across 20+ techniques (T1595, T1566, T1110, T1046, T1071, T1498)
- ASN and geolocation enrichment for network-level context
- Crime Score decay modelling — indicators age and reflect infrastructure churn
- Sector telemetry tagging identifies which industries are being targeted
World Crime Feeds distribution
The WCF Agent is a lightweight, platform-agnostic distribution component deployed at the customer site. It continuously synchronises enforcement-ready intelligence from the OneFirewall API to connected security devices. Updates are delta-based — only changed indicators are transferred, minimising bandwidth and processing overhead.
- Containerised deployment (Docker / VM) — minimal footprint, no agent sprawl
- Supports pull and push synchronisation modes, configurable update intervals
- All traffic encrypted over TLS 1.3 with mutual authentication
- Translates intelligence into native formats: ACL, IP-reputation lists, TAXII 2.1, JSON, CSV
- OneDevice series: purpose-built hardware appliance with integrated WCF Agent
Automated blocking at the edge
The final layer is where intelligence becomes action. Connected security controls — firewalls, IPS, WAF, SIEM, XDR, cloud policy engines — receive updated rule sets and block or alert on indicators matching the configured Crime Score threshold (alliance baseline: score ≥ 190).
Enterprise firewalls: Check Point, FortiGate, Palo Alto, Sophos, SonicWall, Forcepoint, pfSense — see the full integrations list.
One indicator, every relationship mapped
A single malicious IP enters the platform and is immediately linked to the attack patterns it indicates and the courses of action that mitigate them — structured STIX 2.1 objects and MITRE ATT&CK techniques, not a flat list.
From customer site to central scoring, in one diagram
Security products and intrusion prevention systems at the customer site feed events to the OneFirewall Agent, which exchanges STIX/TAXII objects with the central Score Engine, Threats Analysis Engine, and Business Intelligence Engine — enriched continuously by external feeds including Cyber Threat Alliance and Proofpoint.
One API, GET or POST, every feed
Alliance members and security partners authenticate once against the OneFirewall API and can pull enforcement-ready IOC feeds (IPs, STIX 2.1, file hashes) or push their own validated observations back into the shared pool — the same endpoint structure across every integration.
