Skip to content
  • There are no suggestions because the search field is empty.

Discontinued Threat Intelligence Feeds

As discussed in the following article https://community.rsa.com/t5/netwitness-platform-threat/discontinued-content/ta-p/629239 , as of September 1, 2021 we have deprecated the following threat intel feeds.  Most of the content in them is no longer relevant or has been replaced with other sources of information. 

For any questions or concerns, please reach out to support.

RSA Feeds

The following feeds are being discontinued:

  • Name: Arin Net Destination ASNs
  • Description:

    Identifies the country in which a specific destination ASN resides, as identified by Arin Net.

  • Notes:

    MaxMind is no longer supporting this content.


  • Name: Arin Net Source ASNs
  • Description:

    Identifies the country in which a specific source ASN resides, as identified by Arin Net.

  • Notes:

    MaxMind is no longer supporting this content.


  • Name: ASN Info Pack
  • Description:

    Provides additional meta information for AS Networks, Organization names, Country codes, and country names as sourced from MaxMind and ArinNet.

  • Notes:

    MaxMind is no longer supporting this content.


  • Name: File Upload Sites
  • Description:

    Creates meta when hits to known online file storage sites are detected.

  • Notes:

    Due to the distributed and constantly evolving infrastructure of cloud services, it is not beneficial to track all systems by their FQDNs.


  • Name: High Risk File
  • Description:

    Detects high-risk file types by extension.

  • Notes:

    Prone to false positives due to attackers mimicking legitimate download behaviors.


  • Name: Hijacked
  • Description:

    Hijacked IP list source from www.bluetack.co.uk.

  • Notes:

    Outdated list of IP addresses that is are longer publicly updated and provided to the community.


  • Name:

    hunting

  • Description:

    The Hunting feed can be deployed to provide a baseline response framework that allows analysts to investigate collections with a modular approach to response.

  • Notes:

    Replaced by the Investigation Feed.


  • Name:

    IDefense Threat Indicators Domains

  • Description:

    Verisign idefense security intelligence services gives information security executives access to accurate and actionable cyber-intelligence related to vulnerabilities, malicious code, and global threats 24 hours a day, 7 days a week.

  • Notes:

    This feed is no longer available nor updated, due to an expired partnership with IDefense.


  • Name:

    Malware Domains

  • Description:

    List of domains commonly associated with malware sourced from www.malwaredomains.com.

  • Notes:

    RSA no longer licenses this feed.


  • Name:

    MaxMind ASN

  • Description:

    List of AS Networks associated with IP address ranges regularly updated and sourced from MaxMind.

  • Notes:

    MaxMind is no longer supporting this content.


  • Name:

    NetWitness Fraud Intelligence powered by Verisign

  • Description:

    Verisign idefense security intelligence services gives information security executives access to accurate and actionable cyber-intelligence related to vulnerabilities, malicious code, and global threats 24 hours a day, 7 days a week.

  • Notes:

    This feed has been incorporated into the existing RSA Research feed.


  • Name: Palevo Tracker Domains
  • Description:

    Palevo Tracker offers three different blocklists, used to block the access to well known Palevo botnet Command & Control botnets.

  • Notes:

    The Palevo tracker feeds are no longer being updated by the community; the threat has diminished, and this content provides no operational security value.


  • Name: Palevo Tracker IPs

  • Name: RSA FirstWatch APT Attachments
  • Description:

    Contains attachments that are known to be associated with APTs.

  • Notes: Due to rapid evolution of attacker TTP, these indicators were too varied to provide much operational value.

  • Name: RSA FirstWatch Criminal Socks User IPs
  • Description:

    Contains IPs that have been observed using criminal anonymization services.

  • Notes:

    The malware that this project leveraged has since gone dormant, and the data it provided has outlived its usefulness.


  • Name: RSA FirstWatch Criminal VPN Entry Domains
  • Description:

    Contains domains that represent known VPN entry nodes for criminal anonymization services.

  • Notes:

    The feeds associated with VPN IPs (RSA FirstWatch Criminal VPN Entry/Exit IPs) provide more value than the domain related ones. The only time the domain feeds would fire are on DNS lookup vs. the actual VPN traffic.


  • Name: RSA FirstWatch Criminal VPN Exit Domains
  • Description:

    Contains domains that represent known VPN exit nodes for criminal anonymization services.


  • Name: RSA FirstWatch Exploit Domains
  • Description:

    Contains Domains that are known to be associated with malware delivery.

  • Notes:

    Duplication of effort and value of the RSA Fraud Action Domain feed.


  • Name: RSA FirstWatch Exploit IPs
  • Description:

    Contains IPs that are known to be associated with malware delivery.


  • Name: RSA FirstWatch IP Reputation
  • Description:

    Contains IP that are known to be compromised.


  • Name: RSA FirstWatch Insider Threat Domains
  • Description:

    Contains domains known to be associated with insider threats.

  • Notes:

    Due to the distributed nature of cloud services and the number of new file sharing services that continue to appear this feed provided more noise than analytical value.


  • Name: RSA FirstWatch Insider Threat IPs
  • Description:

    Contains IPs known to be associated with insider threats.


  • Name: SpyEye Domain Tracker
  • Description:

    SpyEye domain tracker is a list of spyeye (also known as zbot, prg, wsnpoem, gorhax and kneber) command & control domain names. SpyEye tracker has tracked more than 2,800 malicious spyeye c&c servers. SpyEye is spread mainly through drive-by downloads and phishing schemes.

  • Notes:

    The SpyEye tracker feeds are no longer being updated by the community; the threat has diminished, and this content provides no operational security value.


  • Name: SpyEye Tracker

  • Name: SRI Attackers
  • Description:

    Contains malicious ip addresses sourced from www.sri.com.

  • Notes:

    A change in licensing prevents RSA from redistributing the data feed


  • Name: SSH IP Blacklist
  • Description:

    The SSH blacklist, contains IP addresses of hosts which tried to bruteforce into any of currently 10 hosts (all running OpenBSD, FreeBSD or Linux) using the SSH protocol. The hosts are located in Germany, the United States, and Australia, and are setup to report and log those attempts to a central database.

  • Notes:

    The website that hosts this material has posted a notice that they will no longer be providing updates.


  • Name: Tor Nodes
  • Description:

    Contains IPs that are listed as active nodes in the Tor network.

  • Notes:

    This list contains all Tor nodes, and because other services are often hosted on the same IP address as the Tor node, this leads to false positives.


  • Name: url-shortening-services.zip
  • Description:

    Detects hits to known URL-shortening services.

  • Notes:

    Due to their adoption across social media and within organizations, this feed has limited analytic value due to increased noise.


  • Name: WikiLeaks Domains
  • Description:

    Wikileaks domain mirrors.

  • Notes:

    Wikileaks has adopted a TOR as a method of distribution instead of a wide network of WWW mirrors.


  • Name: Zeus Domain Tracker
  • Description:

    Zeus domain tracker is a list of zeus (also known as zbotprgwsnpoemgorhax and kneber) command & control domain names. Zeus tracker has tracked more than 2,800 malicious zeus C&C servers. Zeus is spread mainly through drive-by downloads and phishing schemes.

  • Notes:

    The ZeuS feed is sporadically updated by the community, and the updates are prone to false positives because updates have shifted towards compromised sites rather than core ZeuS infrastructure.


  • Name: Zeus Tracker
  • Description:

    Zeus tracker is a list of IP addresses of zeus servers (hosts) around the world.