Threat Intelligence

Curated threat intelligence, working inside the security controls you already run.

Overview

Threat intelligence is only as good as the controls it reaches. Fenrir's threat intelligence service delivers curated, high-confidence indicators into the next generation firewalls and Microsoft security tooling you already run, so malicious IP addresses, URLs and domains are enforced where your traffic flows. As a Malware Free Networks® (MFN®) partner, we combine the National Cyber Security Centre's near real-time intelligence on malware, remote scanning and exploitation, and phishing with our own curation, then manage the indicator lifecycle so your blocklists stay current. You decide whether an indicator blocks traffic or raises an alert, and you can start in alert-only mode until you trust it.

This service suits organisations that want curated threat intelligence without full managed detection and response: teams running their own security operations, IT functions maintaining their own controls, and organisations already invested in Microsoft security tooling. It is also included as standard for our Managed Services clients.

Services include

  • Curated indicators of compromise (IP, URL and domain) from Malware Free Networks® and Fenrir's own analysis
  • Delivery as an external dynamic list your firewall consumes directly, with documented onboarding for Palo Alto and Fortinet
  • Integration into Microsoft Defender for Endpoint and Microsoft Sentinel
  • Indicator lifecycle managed for you: additions, expiries and revocations flow through automatically
  • Onboarding and integration support to get the feed live in your controls
  • Included as standard for Fenrir Managed Services clients

Why use this service?

Our Threat Intelligence service focuses on curated indicators specific to New Zealand, enforcement in the controls you already own, and lifecycle management handled for you.

Curated, high-confidence indicators

Intelligence from Malware Free Networks® and Fenrir's own analysis, filtered so what reaches your controls is worth enforcing.

Enforcement in tools you already own

Indicators are delivered into your existing firewalls and Microsoft security tooling, with no new platform to buy or deploy.

Indicator lifecycle managed for you

Additions, expiries and revocations are handled continuously, keeping your blocklists accurate without manual upkeep.

Frequently asked questions

What is Malware Free Networks®?
MFN® is a threat disruption service operated by New Zealand's National Cyber Security Centre. It collects threat intelligence from high confidence sources and provides it to partner organisations, who deliver it into their customers' security controls. Fenrir is an MFN partner.
The NCSC does not charge partners for MFN. What are we paying Fenrir for?
Correct, and we would rather say so than have you find out later. The NCSC supplies the feed to partners at no cost. You are paying for what happens next: our curation on top of the MFN indicators, integration into your specific environmental controls, and lifecycle management so indicators are added, expired and revoked without your team touching them. You also get someone to call when something looks wrong. If you would rather run all of that in house, the NCSC can refer you to the full partner list.
Do we need to be a Managed Services customer to get this?
No. Threat Intelligence is sold on its own for organisations that run their own security operations. It is also included as standard in our Managed Services.
What do we need in place to consume the feed?
A firewall able to consume an external dynamic list. We have documented onboarding for Palo Alto and Fortinet. If you run Microsoft Defender for Endpoint or Microsoft Sentinel, we integrate the indicators there as well. Tell us what you run and we will say whether we can support it.
Will this give us all the protection we need?
No. MFN defends against current threats targeting New Zealand organisations and is built to run alongside your other security controls rather than replace them. Its strength is the advanced activity the NCSC sees first, and we help you pair it with the rest of your security stack.
Is any information about our environment shared?
We deploy nothing inside your network. MFN reaches you as a threat feed. The NCSC does receive analytical feedback that keeps the feed effective, and it contains no personal information: which indicator was triggered, the date and time of the event, and our name as the partner. Where your organisation has consented, the NCSC can also receive information about when an indicator has been seen and disrupted on your network. That choice is yours. We walk you through it at onboarding and record what you choose in your service schedule.
Can we check it is working?
Yes. The NCSC publishes test links that let you confirm for yourself whether you are protected against malicious URLs, domains and IP addresses. We run them with you at onboarding, and you can re-run them any time without asking us.

Want to learn more?

Ready for a chat about your cyber security needs? Get in touch and we can set up a call, coffee, or a meeting.

Get in touch