Cyber threat intelligence at enterprise scale.
OneFirewall Alliance integrates 40+ reliable cyber threat intelligence sources, delivering real-time data on malicious IPs, domains, URLs, and file hashes — enriched, scored, and enforcement-ready for your firewalls, IPS, WAF, and SIEM.
Four data types, continuously updated from diverse global sources
Malicious IP Addresses
IPv4 & IPv6 addresses and CIDR ranges confirmed as attack sources — C2 servers, Tor exit nodes, botnet infrastructure, and brute-force origins. Over 1.5M unique IPs from a single validated source alone.
Domain Blocklists
Malicious domains used for phishing, malware distribution, DNS tunnelling, and command-and-control, with source-calibrated confidence scoring (0.1–0.9).
Malicious URLs
Precise URL-level threat intelligence — not just domains — enabling web proxies, WAFs, and secure web gateways to block specific malicious endpoints while allowing legitimate traffic.
File Hashes
Known malware file signatures from sandbox analysis and alliance member submissions. Supports MD5, SHA1, SHA256, and filename indicators.
Every new source is proven before it's trusted
The Alliance continually evaluates and adds new intelligence sources through a rigorous process: broad research, targeted evaluation, cross-referencing with existing feeds, and consistency validation over time. New sources are assigned initial confidence scores of approximately 0.2 and recalibrated as accuracy is demonstrated.
+168%
Critical-risk entries growth
+61%
Medium-risk entries growth
+46%
High-risk entries growth
+17%
Low-risk entries growth
Real views from the platform
MITRE ATT&CK Graph
Indicators automatically linked to attack patterns, courses of action, and source reports.
Threat-Actor Pivoting
Trace a single malicious IP across every alliance member and sighting.
Geolocated Attack Routing
Built from the live intelligence database, updated continuously.
