MSSP, such as Orange, are selling to their customers Threat Intelligence feeds. Those feeds can provide with up to 100 000 IP addresses classified as malicious for several use cases (mail, web, bot ...). This feature will bring us new opps for our MSSP.
They will upsell their TI services on top of F5XC to their customer base.
In a nutshell, expectations are:
- 128 000 entries
- IP only (no header)
- Authentication to feeds URL with HTTPS Basic Auth
- Pull is preferred with a scheduler
- Ability to add several and isolated feeds to get more granularity