Customers of Palo Alto Networks NGFW who purchase a VulnCheck IP Intelligence license are able to leverage Palo Alto Networks' Dynamic Block List (DBL) functionality to block attacker Command & Control (C2) infrastructure detected by VulnCheck.
Palo Alto Networks NGFW provides an easy to use Dynamic Block List (DBL) feature, which may be used with third-party intelligence providers like VulnCheck.
For more information on these features from Palo Alto Networks see: How to Configure Dynamic Block List (DBL) or External Block List (EBL)
On your Palo Alto Networks device:
Objects > Dynamic Block List
Add
Name
field, type the name of the VulnCheck Tag, such as vulncheck-c2
Source
field, enter "https://api.vulncheck.com/v3/tags/vulncheck-c2?token=INSERT_VULNCHECK_TOKEN"