Feed Overview

AutoFocus custom feeds are URL lists and EDLs that are generated based on a user-generated query, which defines the indicator type and associated conditions for items populating a given list. Using this custom filter, AutoFocus outputs the threat data into a URL list or EDL, which can then be consumed as an EDL by the firewall or other services that use URL lists to enforce security policies. The threat intelligence data is sourced from various Palo Alto Networks customers and services to create the Palo Alto Networks Threat Feed, which includes IP addresses, domains, URLs, and hash indicators. This master list is updated daily and is the reference source for user-created custom threat feeds. You can view the new, daily additions to the list by selecting
Feed > Palo Alto Networks Daily Threat Feed

