4Architecture layers
<5minIntelligence propagation
STIX 2.1Native format
TLS 1.3All channels encrypted
LAYER 01 · ALLIANCE MEMBER NETWORK

Collective telemetry from 290+ organisations

A trusted network spanning finance, telecommunications, critical national infrastructure, cloud providers, and MSSPs. Each member contributes threat observations — malicious IPs, domains, URLs, file hashes — validated through a shared trust framework aligned with Cyber Threat Alliance (CTA) standards.

  • Crowd-sourced indicators from diverse sectors provide cross-industry attack visibility
  • Multi-member validation reduces false positives and increases confidence scoring
  • Members earn OFA Tokens for quality submissions, incentivising timely reporting
  • CTA membership (since 2020) extends telemetry reach to global threat-sharing ecosystems
LAYER 02 · INTELLIGENCE PLATFORM

Enrichment & scoring

Raw telemetry enters the OneFirewall Intelligence Platform where it's validated, deduplicated, enriched, and scored. The platform outputs structured STIX 2.1 objects and assigns a Crime Score (0–1000) to each indicator, making intelligence immediately actionable without manual transformation.

  • STIX 2.1 enrichment: indicator, observed-data, attack-pattern, threat-actor, relationship objects
  • MITRE ATT&CK mapping across 20+ techniques (T1595, T1566, T1110, T1046, T1071, T1498)
  • ASN and geolocation enrichment for network-level context
  • Crime Score decay modelling — indicators age and reflect infrastructure churn
  • Sector telemetry tagging identifies which industries are being targeted
LAYER 03 · WCF AGENT

World Crime Feeds distribution

The WCF Agent is a lightweight, platform-agnostic distribution component deployed at the customer site. It continuously synchronises enforcement-ready intelligence from the OneFirewall API to connected security devices. Updates are delta-based — only changed indicators are transferred, minimising bandwidth and processing overhead.

  • Containerised deployment (Docker / VM) — minimal footprint, no agent sprawl
  • Supports pull and push synchronisation modes, configurable update intervals
  • All traffic encrypted over TLS 1.3 with mutual authentication
  • Translates intelligence into native formats: ACL, IP-reputation lists, TAXII 2.1, JSON, CSV
  • OneDevice series: purpose-built hardware appliance with integrated WCF Agent
LAYER 04 · ENFORCEMENT

Automated blocking at the edge

The final layer is where intelligence becomes action. Connected security controls — firewalls, IPS, WAF, SIEM, XDR, cloud policy engines — receive updated rule sets and block or alert on indicators matching the configured Crime Score threshold (alliance baseline: score ≥ 190).

Enterprise firewalls: Check Point, FortiGate, Palo Alto, Sophos, SonicWall, Forcepoint, pfSense — see the full integrations list.

Layer 02, Visualised

One indicator, every relationship mapped

A single malicious IP enters the platform and is immediately linked to the attack patterns it indicates and the courses of action that mitigate them — structured STIX 2.1 objects and MITRE ATT&CK techniques, not a flat list.

Graph showing a malicious IP linked to MITRE ATT&CK attack patterns and mitigations
Logical Architecture

From customer site to central scoring, in one diagram

Security products and intrusion prevention systems at the customer site feed events to the OneFirewall Agent, which exchanges STIX/TAXII objects with the central Score Engine, Threats Analysis Engine, and Business Intelligence Engine — enriched continuously by external feeds including Cyber Threat Alliance and Proofpoint.

Logical architecture diagram showing the customer site, OneFirewall Agent, central systems and external feeds
API Access

One API, GET or POST, every feed

Alliance members and security partners authenticate once against the OneFirewall API and can pull enforcement-ready IOC feeds (IPs, STIX 2.1, file hashes) or push their own validated observations back into the shared pool — the same endpoint structure across every integration.

Diagram of the OneFirewall API structure for GET and POST IOC feeds

Want the full technical walkthrough?

Book a briefing with the engineering team that built it.

Request Architecture Briefing