Community threat intelligence provided by Minnesota Risk & Cybersecurity Advisory.
These feeds provide indicators associated with malicious or suspicious Internet activity. They are intended for use with firewalls, security monitoring systems, endpoint security products, SIEM platforms, threat hunting tools, and other security controls capable of consuming external threat intelligence.
Indicators are collected from multiple threat intelligence sources, analyzed, classified, and periodically updated as new information becomes available.
Block feeds contain high-confidence indicators considered appropriate for automated blocking in environments where the associated risk is acceptable.
Detection feeds contain indicators that may be malicious or suspicious but do not necessarily meet the confidence threshold for automatic blocking. These feeds are better suited for monitoring, alerting, correlation, and threat hunting.
Sector feeds are narrower subsets of the global feeds. Indicators are included only when OpenCTI connects them to malware or an intrusion set that targets the sector, or when an analyst applies an explicit sector label. Indicators without sector attribution remain global only.
A bank can start with the Finance sector feeds instead of automatically enforcing every indicator in the global block feeds. Sector relevance does not guarantee that an indicator will affect only that industry, so each organization should still review its policy and risk tolerance.
Many firewall and security platforms support external threat feeds over HTTPS, including products from Fortinet, Palo Alto Networks, Check Point, Sophos, Cisco, and other security vendors.
Feed contents may be added, removed, or reclassified as threat intelligence changes. Systems consuming these feeds should retrieve updated copies periodically rather than treating the contents as permanent indicators.
If you believe an indicator has been incorrectly classified or have questions about an MN Risk threat feed, contact us at consulting@mnrisk.com.