Sophos Firewall
Add third‑party threat feeds in Active Threat Response.
Cybora delivers continuously updated, curated threat feeds directly to your firewall. Automatically block malicious infrastructure, botnets, and scanners before they even touch your internal network.
Natively integrates with leading firewalls
Local rate-limits and IPS rules are easily bypassed by botnets rotating thousands of IPs. Cybora identifies and drops these coordinated attackers at the edge before they can even test your defenses.
Achieve a massive security upgrade without the project overhead. Cybora feeds plug directly into the native external blocklist features of modern firewalls.
Attackers rotate their infrastructure daily. Depending on your plan, Cybora syncs new indicators to your firewall automatically—as frequently as every 15 minutes.
We don't just pass on raw open-source lists. Cybora aggregates OSINT, commercial feeds, global honeypots, and real firewall telemetry—filtering out false positives to deliver only verified active threats.
No heavy JSON parsing or complex API integrations. Just a secure HTTPS endpoint returning a flat TXT file—one indicator per line. Perfect for native External Dynamic Lists (EDL).
Append your unique license key and specify the indicator type you want your firewall to pull (ipv4, domain, or url).
Stop treating threat intelligence like a massive IT project. Get your key, configure your firewall, and let your perimeter defend itself automatically.
Pick Standard (IPv4) or upgrade to Premium/Ultimate for full domain and URL coverage.
Secure self-serve purchase. Annual auto-renewing subscription.
Instantly receive your unique license key. 1 key protects 1 firewall edge/device.
Add the URL into your firewall settings. It fetches the blocklist on your chosen schedule.
Why not just use free open-source lists? Because threat intelligence requires constant curation. Free lists are often outdated, untested, or extremely noisy. In a firewall context, noise is expensive: false positives create support tickets, and admins quickly stop trusting the feed.
Cybora focuses on one job: delivering a curated, firewall-friendly feed you can deploy and trust without babysitting.
We blend OSINT, commercial feeds, and global honeypots to ensure broad coverage.
Aggressive deduplication and false-positive filtering specifically for firewall deployment.
Paid plans include dedicated technical support to help investigate and whitelist blocked traffic.
SELECT PROTECTION LEVEL
Solid baseline. Fewer false positives through curation. Solid IPv4 coverage.
Professional protection. Includes domains & URLs. Hourly updates.
15-minute updates for critical infrastructure & high-risk perimeters.
Fair use
1 key = 1 device. Rate limits depend on plan to prevent abuse.
Renewals
Annual subscription that renews automatically unless cancelled.
Flexible Plans
Volume discounts and longer commitments (beyond 12 months) are available on request. Same base pricing applies regardless of company size.
Step-by-step instructions showing exactly where to paste the feed URL in your specific hardware.
Add third‑party threat feeds in Active Threat Response.
Configure external threat feeds and apply policies.
Register External Dynamic Lists (EDL) and enforce.
Import URL feeds and apply to access control.
Configure external feeds and tune enforcement.
Fetch remote blocklists and apply in firewall rules.
License keys are plan-scoped and protected with fair-use rate limits. One key is strictly intended for one firewall edge.
Delivery is served over HTTPS and designed for predictable, automated polling 24/7/365.
View System Status →We don't collect your network traffic. Review our strict security and privacy pages for current data handling practices.
We don't offer refunds, because we want you to be 100% sure Cybora works with your specific hardware setup before you spend a dime. Use our Basic feed to validate the URL delivery and TXT format.
Self‑serve purchase. Setup in minutes. Works flawlessly with any firewall that supports URL-based external threat feeds.