<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:atom="http://www.w3.org/2005/Atom"
>
  <channel>
    <title>ELLIO Blog</title>
    <link>https://ellio.tech/en/blog/</link>
    <description>Threat research on reconnaissance and mass exploitation activity from ELLIO. Read the latest threat news and defense analysis.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 29 May 2026 08:30:24 GMT</lastBuildDate>
    <atom:link href="https://ellio.tech/en/blog/feed.xml" rel="self" type="application/rss+xml" />
    <image>
      <url>https://ellio.tech/logo/ELLIO_logo_white_selection.svg</url>
      <title>ELLIO Blog</title>
      <link>https://ellio.tech/en/blog/</link>
    </image>
    <item>
      <title>Sanctioned, Seized, Still Scanning: Inside a Russian Bulletproof Hosting Network Targeting the EU</title>
      <link>https://ellio.tech/en/blog/sanctioned-seized-still-scanning-inside-a-russian-bulletproof-hosting-network-targeting-the-eu/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/sanctioned-seized-still-scanning-inside-a-russian-bulletproof-hosting-network-targeting-the-eu/</guid>
      <description>On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure, the scanning did not stop.</description>
      <pubDate>Wed, 27 May 2026 10:22:37 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/Bulletproof Hosting Hero.png" type="image/png" />
      <content:encoded><![CDATA[
On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure, the scanning did not stop.
<p><img src="https://cms-images.ellio.tech/media/Bulletproof Hosting Hero.png" alt="Digital network visualization with glowing blue and red connections overlaid with text &quot;Sanctioned, Seized, Still Scanning - Inside a Russian Bulletproof Hosting Network Targeting the EU&quot;" /></p>
<p><a href="https://ellio.tech/en/blog/sanctioned-seized-still-scanning-inside-a-russian-bulletproof-hosting-network-targeting-the-eu/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>New Integrations for Microsoft Sentinel and MISP</title>
      <link>https://ellio.tech/en/blog/new-integrations-for-microsoft-sentinel-and-misp/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/new-integrations-for-microsoft-sentinel-and-misp/</guid>
      <description>ELLIO is expanding its threat intelligence ecosystem with two new integrations designed for SOC, detection engineering, and threat intelligence workflows: Microsoft Sentinel via TAXII 2.1 and a native MISP integration.</description>
      <pubDate>Thu, 14 May 2026 07:57:55 GMT</pubDate>
      <author>ELLIO Product Team</author>
      <enclosure url="https://cms-images.ellio.tech/media/New integrations Microsoft Sentonel MIST-16x9.png" type="image/png" />
      <content:encoded><![CDATA[
ELLIO is expanding its threat intelligence ecosystem with two new integrations designed for SOC, detection engineering, and threat intelligence workflows: Microsoft Sentinel via TAXII 2.1 and a native MISP integration.
<p><img src="https://cms-images.ellio.tech/media/New integrations Microsoft Sentonel MIST-16x9.png" alt="ELLIO new integrations announcement featuring Microsoft Sentinel and MISP Threat Sharing logos on blue gradient background" /></p>
<p><a href="https://ellio.tech/en/blog/new-integrations-for-microsoft-sentinel-and-misp/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>ELLIO expands with 10 new recon and scanner IP feeds</title>
      <link>https://ellio.tech/en/blog/ellio-expands-with-10-new-recon-and-scanner-ip-feeds/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/ellio-expands-with-10-new-recon-and-scanner-ip-feeds/</guid>
      <description>ELLIO Threat Intelligence &amp; Blocklist Automation has been updated with 10 new scanner and recon IP address feeds. This improves detection and control of scanning activity at the network perimeter, enabling more accurate allow and block rules without manual IP range management.</description>
      <pubDate>Wed, 06 May 2026 08:51:26 GMT</pubDate>
      <author>ELLIO Product Team</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO Scanner IP Threat Intelligence Feeds-16x9.png" type="image/png" />
      <content:encoded><![CDATA[
ELLIO Threat Intelligence &amp; Blocklist Automation has been updated with 10 new scanner and recon IP address feeds. This improves detection and control of scanning activity at the network perimeter, enabling more accurate allow and block rules without manual IP range management.
<p><img src="https://cms-images.ellio.tech/media/ELLIO Scanner IP Threat Intelligence Feeds-16x9.png" alt="ELLIO RECON IP Lists dashboard showing scanner IP counts from various security tools including Censys (600,784), Cortex Xpanse (4,611), BinaryEdge (2,279), and others with trend visualizations" /></p>
<p><a href="https://ellio.tech/en/blog/ellio-expands-with-10-new-recon-and-scanner-ip-feeds/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>[watchdog]: Inside a Mirai variant with six-layer persistence</title>
      <link>https://ellio.tech/en/blog/watchdog-inside-a-mirai-variant-with-six-layer-persistence/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/watchdog-inside-a-mirai-variant-with-six-layer-persistence/</guid>
      <description>An open directory is serving a Mirai variant across 14 CPU architectures - all updated yesterday. It kills competitors by SHA256 hash, persists through six layers, and hides as a kernel thread. Here&apos;s what&apos;s inside.
</description>
      <pubDate>Tue, 31 Mar 2026 11:00:00 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/Mirai Botnet with 6 layers of persistence Hero" type="image/jpeg" />
      <content:encoded><![CDATA[
An open directory is serving a Mirai variant across 14 CPU architectures - all updated yesterday. It kills competitors by SHA256 hash, persists through six layers, and hides as a kernel thread. Here&apos;s what&apos;s inside.

<p><img src="https://cms-images.ellio.tech/media/Mirai Botnet with 6 layers of persistence Hero" alt="ELLIO threat intelligence dashboard showing IP 178.16.53.51 flagged as malicious Mirai botnet from Amsterdam, with timeline of exploit attempts and port scanning activity detected between March 22-24, 2026." /></p>
<p><a href="https://ellio.tech/en/blog/watchdog-inside-a-mirai-variant-with-six-layer-persistence/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>What Gets Deployed via Exposed Docker APIs</title>
      <link>https://ellio.tech/en/blog/what-gets-deployed-on-exposed-docker-apis/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/what-gets-deployed-on-exposed-docker-apis/</guid>
      <description>Over 1,000 unique IPs scan for exposed Docker APIs every day. A fraction go further. We captured every container creation payload  and classified them by monetization strategy.</description>
      <pubDate>Thu, 26 Mar 2026 11:09:38 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/What gets deployed on exposed Docker APIs Hero-1.What gets deployed on exposed Docker APIs Hero" type="image/jpeg" />
      <content:encoded><![CDATA[
Over 1,000 unique IPs scan for exposed Docker APIs every day. A fraction go further. We captured every container creation payload  and classified them by monetization strategy.
<p><img src="https://cms-images.ellio.tech/media/What gets deployed on exposed Docker APIs Hero-1.What gets deployed on exposed Docker APIs Hero" alt="Screenshot of ELLIO threat intelligence interface showing malicious Docker API exploits from IPs 45.156.87.4 and 187.86.243.141, with security indicators and threat classification tags" /></p>
<p><a href="https://ellio.tech/en/blog/what-gets-deployed-on-exposed-docker-apis/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>React2Shell Update: Custom Go L7 DDoS Botnet</title>
      <link>https://ellio.tech/en/blog/react2shell-update-custom-go-l7-ddos-botnet/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/react2shell-update-custom-go-l7-ddos-botnet/</guid>
      <description>A single delivery IP has been exploiting React2Shell to distribute malware from an open directory. 31 binaries including a custom Go L7 DDoS botnet with Cloudflare token forgery, two Mirai variants across 13 CPU architectures, and a C2 server.</description>
      <pubDate>Thu, 19 Mar 2026 13:18:56 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/React2Shell L7 DDoS Botnet Hero" type="image/jpeg" />
      <content:encoded><![CDATA[
A single delivery IP has been exploiting React2Shell to distribute malware from an open directory. 31 binaries including a custom Go L7 DDoS botnet with Cloudflare token forgery, two Mirai variants across 13 CPU architectures, and a C2 server.
<p><img src="https://cms-images.ellio.tech/media/React2Shell L7 DDoS Botnet Hero" alt="ELLIO threat intelligence dashboard showing React2Shell activity across ports, countries, and time from Dec 2025 to Mar 2026 with color-coded heatmap visualization" /></p>
<p><a href="https://ellio.tech/en/blog/react2shell-update-custom-go-l7-ddos-botnet/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Analyze everything or move straight to network-level blocking?</title>
      <link>https://ellio.tech/en/blog/analyze-everything-or-move-straight-to-network-level-blocking/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/analyze-everything-or-move-straight-to-network-level-blocking/</guid>
      <description>One IP. Four days. Nearly 900 user agents. Over 3,000 probes. Sometimes a single IP address tells you everything you need to know about how industrialized internet scanning has become.</description>
      <pubDate>Mon, 16 Mar 2026 18:53:24 GMT</pubDate>
      <author>ELLIO Community Team</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO Threat Intelligence Real-Time Cyber Attack Prevention -16x9.png" type="image/png" />
      <content:encoded><![CDATA[
One IP. Four days. Nearly 900 user agents. Over 3,000 probes. Sometimes a single IP address tells you everything you need to know about how industrialized internet scanning has become.
<p><img src="https://cms-images.ellio.tech/media/ELLIO Threat Intelligence Real-Time Cyber Attack Prevention -16x9.png" alt="ELLIO threat intelligence dashboard showing IP 93.123.109.205 from Amsterdam marked as malicious, with MITRE ATT&amp;CK tactics, CVE vulnerabilities, and various exploit detectors including Setup.php, Jenkins, and SQL injection" /></p>
<p><a href="https://ellio.tech/en/blog/analyze-everything-or-move-straight-to-network-level-blocking/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Coordinated Credential-Stuffing Campaign Targets Palo Alto GlobalProtect Portals</title>
      <link>https://ellio.tech/en/blog/coordinated-credential-stuffing-campaign-targets-palo-alto-globalprotect-portals/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/coordinated-credential-stuffing-campaign-targets-palo-alto-globalprotect-portals/</guid>
      <description>A  coordinated credential-stuffing campaign hit GlobalProtect VPN portals with 8,575 IPs in 48 hours. Three attack waves, 78 targeted usernames, one password. Our team breaks down the timeline, infrastructure, fingerprints, and what defenders can do.</description>
      <pubDate>Thu, 26 Feb 2026 22:00:00 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/globalprotect-slide-1(3).png" type="image/png" />
      <content:encoded><![CDATA[
A  coordinated credential-stuffing campaign hit GlobalProtect VPN portals with 8,575 IPs in 48 hours. Three attack waves, 78 targeted usernames, one password. Our team breaks down the timeline, infrastructure, fingerprints, and what defenders can do.
<p><img src="https://cms-images.ellio.tech/media/globalprotect-slide-1(3).png" alt="Infographic showing February 2026 credential-stuffing attack on Palo Alto GlobalProtect: 8,575 unique IPs, 3 attack waves, 48-hour duration. ELLIO branding at bottom." /></p>
<p><a href="https://ellio.tech/en/blog/coordinated-credential-stuffing-campaign-targets-palo-alto-globalprotect-portals/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>&quot;n8n&quot; is the new &quot;admin.&quot;</title>
      <link>https://ellio.tech/en/blog/n8n-is-the-new-admin/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/n8n-is-the-new-admin/</guid>
      <description>On February 10, 2026, our deception network recorded &quot;n8n&quot; overtaking &quot;admin&quot; as the #2 most brute-forced SSH username. The campaign scaled from a handful of probing IPs to hundreds of unique  sources in under a week, with attackers rapidly iterating through password variants.</description>
      <pubDate>Wed, 11 Feb 2026 13:37:07 GMT</pubDate>
      <author>Vlad Iliushin</author>
      <enclosure url="https://cms-images.ellio.tech/media/n8n_1.png" type="image/png" />
      <content:encoded><![CDATA[
On February 10, 2026, our deception network recorded &quot;n8n&quot; overtaking &quot;admin&quot; as the #2 most brute-forced SSH username. The campaign scaled from a handful of probing IPs to hundreds of unique  sources in under a week, with attackers rapidly iterating through password variants.
<p><img src="https://cms-images.ellio.tech/media/n8n_1.png" alt="Line chart showing SSH brute force attack trends from Jan 12 - Feb 11, 2026, tracking unique attacking IPs per credential for usernames &quot;root&quot; (blue), &quot;admin&quot; (yellow), and &quot;n8n&quot; (red). Shows &quot;n8n&quot; surpassing &quot;admin&quot; as second most targeted." /></p>
<p><a href="https://ellio.tech/en/blog/n8n-is-the-new-admin/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>New Historical IP Timeline is live</title>
      <link>https://ellio.tech/en/blog/unveiling-the-new-historical-ip-timeline/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/unveiling-the-new-historical-ip-timeline/</guid>
      <description>ELLIO Threat Intelligence Platform expands its capabilities with an interactive Historical IP Timeline, giving teams deep visibility into historical IP activity with flexible filtering and report-ready exports. </description>
      <pubDate>Wed, 04 Feb 2026 08:00:00 GMT</pubDate>
      <author>ELLIO Product Team</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO Threat Intelligence Unified Timeline.png" type="image/png" />
      <content:encoded><![CDATA[
ELLIO Threat Intelligence Platform expands its capabilities with an interactive Historical IP Timeline, giving teams deep visibility into historical IP activity with flexible filtering and report-ready exports. 
<p><img src="https://cms-images.ellio.tech/media/ELLIO Threat Intelligence Unified Timeline.png" alt="Network security timeline dashboard showing activity patterns across countries from Oct 29 to Jan 28, with color-coded threat data by geography, fingerprints, HTTP paths and user agents" /></p>
<p><a href="https://ellio.tech/en/blog/unveiling-the-new-historical-ip-timeline/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>React2Shell in the Wild: Payload Analysis, Active Campaigns, and IoCs</title>
      <link>https://ellio.tech/en/blog/react2shell-in-the-wild/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/react2shell-in-the-wild/</guid>
      <description>The ELLIO sensor network has been tracking active exploitation of CVE-2025-55182 (React2Shell) in the wild. Here’s what we’re seeing.</description>
      <pubDate>Fri, 05 Dec 2025 14:41:24 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/react2shell.jpg" type="image/jpeg" />
      <content:encoded><![CDATA[
The ELLIO sensor network has been tracking active exploitation of CVE-2025-55182 (React2Shell) in the wild. Here’s what we’re seeing.
<p><img src="https://cms-images.ellio.tech/media/react2shell.jpg" alt="React2Shell vulnerability illustration" /></p>
<p><a href="https://ellio.tech/en/blog/react2shell-in-the-wild/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>From Scan to Exploit: Inside the Latest Cisco ASA/FTD Campaign</title>
      <link>https://ellio.tech/en/blog/from-scan-to-exploit-inside-the-latest-cisco-asa-ftd-campaign/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/from-scan-to-exploit-inside-the-latest-cisco-asa-ftd-campaign/</guid>
      <description>From reconnaissance to exploitation in just 48 hours. See how 75 IPs executed surgical, one-hit attacks on Cisco ASA/FTD devices - and how to disappear from target lists.</description>
      <pubDate>Wed, 26 Nov 2025 14:14:23 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/hero.jpg" type="image/jpeg" />
      <content:encoded><![CDATA[
From reconnaissance to exploitation in just 48 hours. See how 75 IPs executed surgical, one-hit attacks on Cisco ASA/FTD devices - and how to disappear from target lists.
<p><img src="https://cms-images.ellio.tech/media/hero.jpg" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/from-scan-to-exploit-inside-the-latest-cisco-asa-ftd-campaign/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Every packet tells a story: The evolution of fingerprinting and netsec</title>
      <link>https://ellio.tech/en/blog/every-packet-tells-a-story-the-evolution-of-fingerprinting-and-netsec/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/every-packet-tells-a-story-the-evolution-of-fingerprinting-and-netsec/</guid>
      <description>The journey began in 1969, when the very first RFC - Request for Comments - was published. Explore key milestones that shaped network security and the practice of network fingerprinting.</description>
      <pubDate>Fri, 29 Aug 2025 10:26:11 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/Network-Fingerprints-IP-CTI.png" type="image/png" />
      <content:encoded><![CDATA[
The journey began in 1969, when the very first RFC - Request for Comments - was published. Explore key milestones that shaped network security and the practice of network fingerprinting.
<p><img src="https://cms-images.ellio.tech/media/Network-Fingerprints-IP-CTI.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/every-packet-tells-a-story-the-evolution-of-fingerprinting-and-netsec/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Video: How to capture real value from network fingerprinting in practice</title>
      <link>https://ellio.tech/en/blog/video-how-to-capture-real-value-from-network-fingerprinting-in-practice/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/video-how-to-capture-real-value-from-network-fingerprinting-in-practice/</guid>
      <description>Learn practical tips for deploying JA4, JA3, and MuonFP fingerprints in your security operations. Get expert insights from Vlad Iliushin and discover how to unlock their full defensive value.</description>
      <pubDate>Mon, 16 Jun 2025 17:20:51 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/fingerprints.png" type="image/png" />
      <content:encoded><![CDATA[
Learn practical tips for deploying JA4, JA3, and MuonFP fingerprints in your security operations. Get expert insights from Vlad Iliushin and discover how to unlock their full defensive value.
<p><img src="https://cms-images.ellio.tech/media/fingerprints.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/video-how-to-capture-real-value-from-network-fingerprinting-in-practice/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>MITRE ATT&amp;CK® framework now integrated into ELLIO Threat Platform</title>
      <link>https://ellio.tech/en/blog/platform-update-2025-06/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/platform-update-2025-06/</guid>
      <description>Transform your threat investigations with the ELLIO Threat Intelligence Platform. Now with MITRE ATT&amp;CK threat mapping and advanced fingerprint analysis.</description>
      <pubDate>Wed, 11 Jun 2025 15:00:09 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO-Threat-Intelligence-Platform.png" type="image/png" />
      <content:encoded><![CDATA[
Transform your threat investigations with the ELLIO Threat Intelligence Platform. Now with MITRE ATT&amp;CK threat mapping and advanced fingerprint analysis.
<p><img src="https://cms-images.ellio.tech/media/ELLIO-Threat-Intelligence-Platform.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/platform-update-2025-06/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>IP Blockling on FortiGate 7.2.0/7.4.0 using ELLIO</title>
      <link>https://ellio.tech/en/blog/ip-blockling-on-fortigate-7-2-0-7-4-0-using-ellio-2/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/ip-blockling-on-fortigate-7-2-0-7-4-0-using-ellio-2/</guid>
      <description>This article gives you a simple, step-by-step guide to set up an external IP blocklist and firewall rules on FortiGate 7.2.0/7.4.0. Discover why adding advanced ELLIO Blocklists to your FortiGate v. 7.2.0/7.4.0 is a great way to boost its protection, and how easy it is to set up.</description>
      <pubDate>Wed, 04 Dec 2024 15:36:31 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/fortigate_740-scaled.jpg" type="image/jpeg" />
      <content:encoded><![CDATA[
This article gives you a simple, step-by-step guide to set up an external IP blocklist and firewall rules on FortiGate 7.2.0/7.4.0. Discover why adding advanced ELLIO Blocklists to your FortiGate v. 7.2.0/7.4.0 is a great way to boost its protection, and how easy it is to set up.
<p><img src="https://cms-images.ellio.tech/media/fortigate_740-scaled.jpg" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/ip-blockling-on-fortigate-7-2-0-7-4-0-using-ellio-2/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>IP Blocking vs TCP Fingerprint Blocking: How to Use and Combine Them</title>
      <link>https://ellio.tech/en/blog/ip-blocking-vs-tcp-fingerprint-blocking-how-to-use-and-combine-them/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/ip-blocking-vs-tcp-fingerprint-blocking-how-to-use-and-combine-them/</guid>
      <description>Learn how combining Threat Intelligence-based IP blocking and TCP fingerprinting enhances network security by disrupting attacker reconnaissance.</description>
      <pubDate>Mon, 14 Oct 2024 15:10:30 GMT</pubDate>
      <author>Vlad Iliushin</author>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/Artboard-no-logo.jpg" type="image/jpeg" />
      <content:encoded><![CDATA[
Learn how combining Threat Intelligence-based IP blocking and TCP fingerprinting enhances network security by disrupting attacker reconnaissance.
<p><img src="https://cms-images.ellio.tech/media/Artboard-no-logo.jpg" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/ip-blocking-vs-tcp-fingerprint-blocking-how-to-use-and-combine-them/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Managing blocklists using a central platform (part 3)</title>
      <link>https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-3/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-3/</guid>
      <description>Learn how SOCs, NOCs and MSSPs are leveraging centralized blocklist management to reduce false positives and simplify security management.</description>
      <pubDate>Wed, 09 Oct 2024 07:23:03 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO_Blocklist_Management_Platform_3.png" type="image/png" />
      <content:encoded><![CDATA[
Learn how SOCs, NOCs and MSSPs are leveraging centralized blocklist management to reduce false positives and simplify security management.
<p><img src="https://cms-images.ellio.tech/media/ELLIO_Blocklist_Management_Platform_3.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-3/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Managing blocklists using a central platform (part 2)</title>
      <link>https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-2/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-2/</guid>
      <description>Explore 8 essential steps for building and deploying effective IP blocklists with the Blocklist Management Platform.</description>
      <pubDate>Mon, 07 Oct 2024 06:56:56 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO_Blocklist_Management_Platform_3.png" type="image/png" />
      <content:encoded><![CDATA[
Explore 8 essential steps for building and deploying effective IP blocklists with the Blocklist Management Platform.
<p><img src="https://cms-images.ellio.tech/media/ELLIO_Blocklist_Management_Platform_3.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-2/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>Managing blocklists using a central platform (part 1)</title>
      <link>https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-1/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-1/</guid>
      <description>Learn how blocklist management platforms empower SOCs and NOCs. Streamline processes, minimize errors, and enhance network security.</description>
      <pubDate>Thu, 03 Oct 2024 18:22:45 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO_Blocklist_Management_Platform_3.png" type="image/png" />
      <content:encoded><![CDATA[
Learn how blocklist management platforms empower SOCs and NOCs. Streamline processes, minimize errors, and enhance network security.
<p><img src="https://cms-images.ellio.tech/media/ELLIO_Blocklist_Management_Platform_3.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/managing-blocklists-using-a-central-platform-part-1/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>ELLIO IP Blocklist for Check Point NGFW: 3 million unwanted connections blocked in 45 days </title>
      <link>https://ellio.tech/en/blog/ellio-blocklist-for-check-point-ngfw-3-million-unwanted-connections-blocked-in-45-days/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/ellio-blocklist-for-check-point-ngfw-3-million-unwanted-connections-blocked-in-45-days/</guid>
      <description>Follow this step-by-step guide to set up IP blocking on Check Point firewalls using ELLIO Blocklists, enhancing your network protection. This tutorial provides a quick and easy way to get ELLIO up and running on your Check Point NGFW within minutes, including how to test it using free trial ...</description>
      <pubDate>Thu, 19 Sep 2024 13:41:34 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/ELLIO_IP_Blocking.png" type="image/png" />
      <content:encoded><![CDATA[
Follow this step-by-step guide to set up IP blocking on Check Point firewalls using ELLIO Blocklists, enhancing your network protection. This tutorial provides a quick and easy way to get ELLIO up and running on your Check Point NGFW within minutes, including how to test it using free trial ...
<p><img src="https://cms-images.ellio.tech/media/ELLIO_IP_Blocking.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/ellio-blocklist-for-check-point-ngfw-3-million-unwanted-connections-blocked-in-45-days/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>ELLIO for IP blocking on OPNsense</title>
      <link>https://ellio.tech/en/blog/ellio-for-ip-blocking-on-opnsense/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/ellio-for-ip-blocking-on-opnsense/</guid>
      <description>A practical guide how to quickly set up IP blocking on OPNsense firewall by using advanced ELLIO IP blocklists for filtering active malicious IP addresses.</description>
      <pubDate>Fri, 02 Aug 2024 13:13:36 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/OPNsense_IP_blocking_blocklist_ELLIO_threat_list.png" type="image/png" />
      <content:encoded><![CDATA[
A practical guide how to quickly set up IP blocking on OPNsense firewall by using advanced ELLIO IP blocklists for filtering active malicious IP addresses.
<p><img src="https://cms-images.ellio.tech/media/OPNsense_IP_blocking_blocklist_ELLIO_threat_list.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/ellio-for-ip-blocking-on-opnsense/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
    <item>
      <title>IP blocking on pfSense using ELLIO </title>
      <link>https://ellio.tech/en/blog/ip-blocking-on-pfsense-using-ellio/</link>
      <guid isPermaLink="true">https://ellio.tech/en/blog/ip-blocking-on-pfsense-using-ellio/</guid>
      <description>Explore how to set up IP filtering on pfSense, an open-source firewall/router solution, in just a few minutes, and discover why you should use advanced IP blocklists from ELLIO for this purpose.</description>
      <pubDate>Thu, 25 Jul 2024 14:44:30 GMT</pubDate>
      <author>ELLIO Threat Research Lab</author>
      <enclosure url="https://cms-images.ellio.tech/media/pfsense_ellio.png" type="image/png" />
      <content:encoded><![CDATA[
Explore how to set up IP filtering on pfSense, an open-source firewall/router solution, in just a few minutes, and discover why you should use advanced IP blocklists from ELLIO for this purpose.
<p><img src="https://cms-images.ellio.tech/media/pfsense_ellio.png" alt="Hero image" /></p>
<p><a href="https://ellio.tech/en/blog/ip-blocking-on-pfsense-using-ellio/">Read the full article</a></p>
      ]]></content:encoded>
    </item>
  </channel>
</rss>