MN Risk Threat Intelligence Feeds

Community threat intelligence provided by Minnesota Risk & Cybersecurity Advisory.

These feeds provide indicators associated with malicious or suspicious Internet activity. They are intended for use with firewalls, security monitoring systems, endpoint security products, SIEM platforms, threat hunting tools, and other security controls capable of consuming external threat intelligence.

Indicators are collected from multiple threat intelligence sources, analyzed, classified, and periodically updated as new information becomes available.

Threat intelligence is constantly changing. An indicator appearing in a feed does not guarantee that all activity associated with that indicator is malicious. Organizations should select feeds appropriate for their environment and risk tolerance.

Global Block Feeds

Block feeds contain high-confidence indicators considered appropriate for automated blocking in environments where the associated risk is acceptable.

IPv4 Block Feed
High-confidence malicious IPv4 addresses.
IPv4 Network Block Feed
High-confidence malicious IPv4 networks in CIDR notation. Verify that the receiving security control supports CIDR entries before using this feed.
IPv6 Block Feed
High-confidence malicious IPv6 addresses.
Domain Block Feed
Domains associated with malware, command-and-control infrastructure, phishing, or other malicious activity.
URL Block Feed
URLs associated with malware delivery, phishing, exploitation, or other malicious activity.
SHA-256 Block Feed
SHA-256 hashes associated with known malicious files.

Global Detection Feeds

Detection feeds contain indicators that may be malicious or suspicious but do not necessarily meet the confidence threshold for automatic blocking. These feeds are better suited for monitoring, alerting, correlation, and threat hunting.

IPv4 Detection Feed
Suspicious or malicious IPv4 addresses for monitoring and threat hunting.
Domain Detection Feed
Suspicious or malicious domains for monitoring and threat hunting.

Sector Feeds

Sector feeds are narrower subsets of the global feeds. Indicators are included only when OpenCTI connects them to malware or an intrusion set that targets the sector, or when an analyst applies an explicit sector label. Indicators without sector attribution remain global only.

A bank can start with the Finance sector feeds instead of automatically enforcing every indicator in the global block feeds. Sector relevance does not guarantee that an indicator will affect only that industry, so each organization should still review its policy and risk tolerance.

Browse Sector Feeds
View available industries, feed types, and current entry counts.
Sector Feed Directory
Machine-readable sector names, URLs, attribution details, and feed counts.

Feed Information

Feed Metadata
Machine-readable feed status and update information.

Using the Feeds

Many firewall and security platforms support external threat feeds over HTTPS, including products from Fortinet, Palo Alto Networks, Check Point, Sophos, Cisco, and other security vendors.

Integration Documentation
Step-by-step integration help for supported platforms, including Fortinet FortiGate and Pi-hole.

Feed contents may be added, removed, or reclassified as threat intelligence changes. Systems consuming these feeds should retrieve updated copies periodically rather than treating the contents as permanent indicators.

Questions or Corrections?

If you believe an indicator has been incorrectly classified or have questions about an MN Risk threat feed, contact us at consulting@mnrisk.com.