Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

For information on best practices when configuring feed precedence order, see Best Practices for Setting Configuring Feed Precedence.


Feed NameDefault ActionDefault Precedence
Default Allow ListAllow - No log1
Default Block ListBlock  – No Redirect2
Base HostnamesBlock  – No Redirect3
AntiMalwareBlock  – No Redirect4
Malware DGA HostnamesBlock  – No Redirect5
RansomwareBlock  – No Redirect6
Threat Insight - Rapid Domain TriageBlock  – No Redirect7
SuspiciousBlock  – No Redirect8
Suspicious LookalikesBlock  – No Redirect9
Suspicious NOEDBlock  – No Redirect10
DOH Public Hostnames Block  – No Redirect11
DOH Public IPsBlock  – No Redirect12
Newly Observed Emergent DomainsAllow – With Log13
Threat Insight - DGAAllow – With Log14
Threat Insight-Data ExfiltrationAllow – With Log15
Threat Insight-Fast FluxAllow – With Log16
Threat Insight-DNS MessengerAllow – With Log17
AntiMalware_IPAllow – With Log18
Threat Insight - Notional Data ExfiltrationAllow – With Log19
Extended Base and Anti-malware HostnamesAllow – With Log20
Extended Ransomware IPsAllow – With Log21
Extended AntiMalware IPsAllow – With Log22
DHS_AIS_ HostnameAllow – With Log23
Cryptocurrency hostnames and domainsAllow – With Log24
TOR Exit Node IPsAllow – With Log25

...