World Crime Feeds - OneFirewall WCF
World Crime Feeds (WCF) contains real time data for cyber-attacks across the globe. WCF is powered using the following four main sources:
- Cyber-attacks feeds from alliance members submissions
- Open Source Threat Feeds (Emerging threats, AlienVault, etc…)
- Security Partners and Paid services ( Labs, etc…)
- OneEye Forecast (offered only to enterprise alliance members)
WCF indexes are currently: 1.5 million IPv4 Networks 600 million single IPv4 address (~7% of the total internet)
As the IP/s are fluid during the span of the time and cyber actors constantly change network and location, OneFirewall developed a propriety algorithm to decline the importance of these events during the time. From the current Data Base the total IPs that are blocked from OneFirewall Alliance members are ~511k (~0.6% of the total internet is blocked).
List of Cyber Threat Intelligence Connectors with OneFirewall
- 29 OneFirewall Alliance Members
- Cyber Threat Alliance - (https://cyberthreatalliance.org/)
- Machine Learning in parternship with Polytechnic University of Turin (https://www.polito.it/index.php?lang=en)
- Europe based Telecommunication Company (Security Partner)
- [confidential] Russian multinational cybersecurity and anti-virus provider (Security Partner)
- Alienvault/AT&T Cybersecurity - (https://cybersecurity.att.com/)
- CIArmy/CINS Score - (http://www.ciarmy.com/)
- Emerging Threats, Compromised IPs - (https://www.proofpoint.com/us)
- Rutgers Department of Computer Science - (https://resources.cs.rutgers.edu/)
- Botnet C2 IP Ruleset & SSL BlackList - (https://sslbl.abuse.ch/)
- GreenSnow - (https://greensnow.co/)
- FireHOL - (http://iplists.firehol.org/)
- BAD IPs - (https://www.badips.com/)
- SANS Internet Storm Center - (https://www.dshield.org/)
- Blocklist - (http://www.blocklist.de/)
- Phishtank - (https://phishtank.com/)
- IP Blacklist - (http://www.darklist.de/)
- Norwegian UNIX User Group
- Cybercrime Tracker - (https://cybercrime-tracker.net)
- Artists Against 419 - (https://db.aa419.org/)
- ADBlockPlus - (https://adblockplus.org/)
- Joewein.de LLC (Tokyo, Japan)
- VX Vault - (http://vxvault.net/)
- IP Quality Score - (https://www.ipqualityscore.com/)
- Project HoneyPot - (https://www.projecthoneypot.org)
- Honey DB - (https://honeydb.io)
- Abuse IPDB - (https://www.abuseipdb.com/)
- MalwareDomainList - (http://www.malwaredomainlist.com/)
- Prof. Charles B. Haley personal feeds
- StopForumSpam (https://stopforumspam.com/)
- Malc0de - (http://malc0de.com/)
- BlockList - (http://www.blocklist.de/en/index.html)
The total connectors are accountable for 790 CTI Feeds sources
The service is offered via online subscription and is consumable via HTTP API, API documentation is available, however most of our alliance members are expected to use WCF-Agent to interact with WCF. For enterprise-subscribed alliance members OneFirewall offers the free of charge development of new or custom plugins of WCF Agent. More details about the cyber-crime sources are described below.