Block malware before it connects
Payload, callback and update, all by name.
Threat feeds ingested automatically. The Greywall catches what blocklists miss.
| Timestamp | Action | Site | Query Name | Source IP | Reason |
|---|---|---|---|---|---|
| 2026-09-15 16:10:02 | threat | corp-office | update-check.pw | 10.1.9.14 | feed: isac-indicators |
| 2026-09-15 16:10:31 | threat | build-agent | pkg-mirror-cdn.top | 10.40.8.2 | feed: supply-chain-iocs |
| 2026-09-15 16:11:05 | block | corp-office | sinkholed-c2.net | 10.1.9.14 | category: sinkhole |
| 2026-09-15 16:12:40 | threat | corp-office | exfil-data.click | 10.1.9.14 | push: SOAR-4412 |
Malware needs a name three times
Once to download the payload, once to reach the command server, and again for every update. Each is a lookup the resolver answers first. Block it there and the endpoint never opens the connection.
Endpoint tools act after execution
Detection on the host happens once the payload runs. The resolver acts before the download.
C2 rotates domains
Generated domains have no rank and no history. First-seen holds them; category blocks catch the sinkholed ones.
Devices you cannot instrument
Printers, cameras, lab equipment and contractor laptops resolve through the same resolver as everything else.
Block at the lookup
Security categories on every policy
Enable Malware, C2, Parked and Sinkhole on every policy, and block the DoH provider category.
Feeds on a schedule
Pull indicators from your vendors, your ISAC and your own research. Every entry carries the feed name as its source.
Hold the unknown
A generated domain is first-seen with rank zero. The Greywall holds it while the log tells you which host asked.
Malware controls
Security categories
Malware, C2, Porn, Parked and Sinkhole, maintained by Securd and applied per policy.
Feed ingestion
STIX, CSV, TXT and JSON, pulled on a schedule, with per-entry source and expiry.
Greywall
Domains with no history are held before the first connection completes.
Infected host identification
The client address on every threat event names the host that asked.
Verdict push
Block a domain across every policy from the SOAR through the push API.
Change log
Every list and feed change recorded with user and timestamp. Rollback to any publish.
The threat event in your SIEM
A feed hit is a threat event with the site, the name, the reason and the client address. Over syslog it arrives as CEF; as a webhook it arrives signed.
CEF:0|Securd|DNS|2.0|threat|update-check.pw|8|src=10.1.9.14 dhost=update-check.pw cat=feed reason=isac-indicators site=corp-officeQuestions teams ask
Does this replace endpoint protection?
No. It removes the connection the payload needs and covers devices that cannot run an agent.
How current are the categories?
Maintained by Securd and published to the resolvers continuously. Your own feeds pull on the schedule you set.
What about malware that uses an IP address?
Out of scope for a resolver. The egress firewall governs raw addresses and can consume Securd events.
Cut the connection the payload needs
Point one network at Securd and count the threat events by Friday.