Stop Defending Alone - IoCs Validated Beyond Your Perimeter

Aggregate, validate, and consume CTI identified by 290+ alliance members and CTA partners. Convert distributed detection into centralized, automated blocking across firewalls, IPS, WAF, SIEM, and cloud controls!

OneFirewall Intelligence

Premium & Actionable Threat Intelligence (CTI)

0
IP Addresses
0
Domains
0
URLs
0
Malware Signatures
OneFirewall IoC Sources

Intelligence Overview

  • Aggregated and enriched intelligence feeds Crime Score
  • Real-time updates
  • Designed for direct firewall enforcement
  • Reduces need for multiple security vendors
  • Built for SOC teams and MSSPs
Start a Proof of Value

Intelligence Capabilities

IP Reputation Feeds

Botnet Tracking

Malicious ASN Detection

Threat Actor Monitoring

IOC & CTI Automation

Real-time Distribution

Intelligence in Action

A closer look at the live views your team works from — from raw IOC lookups to Alliance-wide attack telemetry.

Live threat map showing 561 attacks in the last 30 minutes, submission counts by country, and the top offending IP, ASN, and reporting sources
Live Threat Map Real-time attack volume by country, with the top offending IP, ASN, and reporting sources surfaced instantly.
IP reputation lookup panel showing a Crime Score of 546 rated Critical, protected status across three firewalls, and 13,287 community reports from 19 members
IP Reputation Lookup A single IPv4 cross-referenced against thousands of community reports, with its Crime Score and protection status across every connected firewall.
Panel showing attack destinations across partner and member organizations alongside a MITRE ATT&CK attack-pattern and course-of-action mapping
Alliance Network & ATT&CK Mapping Attack destinations across Alliance members and partners, cross-mapped to MITRE ATT&CK techniques and recommended mitigations.
STIX 2.1 relationship graph linking a malicious IP indicator to Network Service Discovery, Vulnerability Scanning, and Active Scanning attack patterns
STIX 2.1 Relationship Graph Every indicator is delivered as a linked STIX 2.1 graph — connecting a malicious IP straight to the attack patterns it indicates.
Donut chart titled Malicious by Criticality, breaking down permitted malicious traffic into Low, Medium, High, and Critical severity counts
Severity Breakdown Every permitted request is scored and bucketed by severity, so you always know how much risk actually got through.
Dashboard showing High and Critical threat counts by age bucket, a world map of attack origins, and a bar chart of events by connected firewall device
Attack Age & Origin How long threats have been active, where they originate on the map, and which of your connected devices intercepted them.
Crime Score history chart trending upward over time, alongside a log of allow and deny decisions across SSH, RDP, and HTTPS connections
Crime Score History & Connections Watch an indicator's Crime Score evolve over time, alongside the live allow/deny log of every connection tied to it.

What We Do

Threat Intelligence Alliance

Crowd-sourced threat intelligence covering IPs, domains, URLs, and malware. Over 210 alliance members sharing vetted intelligence.

Automated Prevention

Real-time synchronization with IPS, XDR, firewalls, WAFs, and routers for automated threat blocking.

Mobile & Endpoint Protection

Self-routing local VPN application protecting devices from malicious inbound and outbound traffic.

Enterprise VPN & DNS

Workplace-dedicated VPN and secure DNS services powered by alliance threat intelligence.

AI Gateway Security

Specialized firewall for AI public services preventing data leakage while enabling safe AI usage.

Offensive Security

Comprehensive DAST, dark web scanning, and penetration testing to validate defensive posture.

Why OneFirewall

Real-time threat, IoC and CTI blocking
Unified intelligence layer
Seamless IPS integration (WCF Agent)
Device-based pricing (not traffic-based)
Centralized management
Reduced security tool sprawl
Faster incident response
Enterprise-grade scalability

Proud Member of the Cyber Threat Alliance since 2020

Sharing vetted intelligence globally to strengthen collective cyber defence.

Learn More About Our Membership → Cyber Threat Alliance Integration

Standards-Based Sharing: STIX 2.1 & TAXII 2.1

If you already run MISP, OpenCTI, or another CTI platform, you don't need a custom connector for us — we speak the same protocol they do.

STIX 2.1 logo TAXII 2.1 logo

What we shipped in the 2 Aug 2026 release

  • A TAXII 2.1 server — discovery, collections, objects, manifest, all standard
  • STIX 2.1 Indicators across our IP, domain, and URL collections
  • Push support: submit up to 50 STIX 2.1 Indicators per request
  • The older STIX 2.0 REST lookup is still there, untouched
How the Integration Works

Why it's worth using

We built this after enough members asked to pull our feeds straight into their existing TAXII-speaking tooling instead of writing a one-off parser for our REST API. Same underlying Crime Score data, just delivered the way your platform already expects it.

Architecture Overview

01

Intelligence Ingestion

02

Threat Validation

03

Enrichment Layer

04

Distribution Engine

05

IPS Synchronization

06

Real-Time Prevention

Honeynet

DeceptionGrid is OneFirewall’s global honeynet: geographically distributed, high-fidelity honeypots designed to attract attackers and turn their activity into actionable threat intelligence.

Each node simulates believable environments (services, banners, and behaviors) to lure scans and targeted probing, record sessions and traffic, and extract IOCs, TTPs, and attacker fingerprints that enrich the OneFirewall Threat Intelligence Data Lake.

🛰️ Distributed Honeypot Network

Strategically deployed nodes across regions to maximize visibility into real-world adversary activity and emerging threat patterns.

🎭 High-Fidelity Decoy Services

Nodes expose realistic services (remote access, web/API, IoT/OT, databases, cloud/DevOps) to attract different attacker profiles.

📼 Full Telemetry

Session recording, packet capture, and real-time logging to observe intent, tooling, and tradecraft—then correlate at scale.

⚡ Intelligence → Defense

Findings are converted into IOCs/TTPs and fed back into OneFirewall’s platform to strengthen prevention and reduce attack surface.

What’s simulated on each node

🔐 Network & Remote Access

  • SSH (22), Telnet (23)
  • RDP (3389)
  • VPN Gateways (e.g., OpenVPN/IPsec)

🌐 Web & API

  • HTTP/HTTPS (80/443)
  • REST APIs (custom ports)
  • WebSockets endpoints

🏭 IoT & OT Protocols

  • Modbus (502), MQTT (1883)
  • UPnP/SSDP
  • BACnet (47808), Zigbee (simulated)

🧱 Data, File & Databases

  • FTP/SFTP, SMB/CIFS (445), NFS (2049)
  • ElasticSearch (9200)
  • MySQL, PostgreSQL, MongoDB, Redis, Cassandra

☁️ DevOps & Cloud

  • Docker API (2375)
  • Kubernetes API/Kubelet (10250)
  • Jenkins (8080), GitLab (8929)

📨 Auth, Email & Messaging

  • SMTP (25), IMAP (143), POP3 (110)
  • LDAP/LDAPS (389/636), Kerberos (88)
  • OAuth/OIDC endpoints

How it works

Lure & Engage

  • Nodes respond to scans and probing with realistic service banners and behaviors.

Record & Analyze

  • Activity is logged, enriched, and correlated in real time.

Extract Intelligence

  • Behavior is converted into IOCs, TTPs, and attacker fingerprints.

Feed Defense

  • Threat data is shared into OneFirewall’s platform to strengthen prevention.
Read DeceptionGrid Docs →