<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower DNS Policy - Would like a known bad name to use as a check its working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337846#M924569</link>
    <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;just saw this post as I ended up using, which at the time of posting triggers a dns policy block&lt;/P&gt;
&lt;P&gt;(got it from&amp;nbsp;&lt;A href="http://mirror1.malwaredomains.com/files/domains.txt" target="_blank"&gt;http://mirror1.malwaredomains.com/files/domains.txt&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;acasadibarbara.it.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Feb 2018 14:05:26 GMT</pubDate>
    <dc:creator>evan.chadwick1</dc:creator>
    <dc:date>2018-02-26T14:05:26Z</dc:date>
    <item>
      <title>Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337512#M924567</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd love to some known bad names that should trigger a blacklist event for DNS policy within Security Intelligence.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone provide this? I just need a couple for testing post roll out.&lt;/P&gt;
&lt;P&gt;(i know i can source some on the internet reports, but would like some Cisco provided ones.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337512#M924567</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2020-02-21T15:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337794#M924568</link>
      <description>&lt;P&gt;Hello Evan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To you can try some of the following sites from the DNS Malware object.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bollyrulez.tv&lt;BR /&gt;static.tvlive32.com&lt;BR /&gt;&lt;A href="http://www.desirulez.net" target="_blank"&gt;www.desirulez.net&lt;/A&gt;&lt;BR /&gt;provalist.info&lt;BR /&gt;xn--80acvhc3abphaf7h.xn--p1ai&lt;BR /&gt;iqoption.ink&lt;BR /&gt;redirect.libertex.tech&lt;BR /&gt;thumbsnap.com&lt;BR /&gt;ressandy-actorsion.com&lt;BR /&gt;cowledges.com&lt;BR /&gt;acaraapa.com&lt;BR /&gt;referencebrain.com&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 13:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337794#M924568</guid>
      <dc:creator>argrullo</dc:creator>
      <dc:date>2018-02-26T13:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337846#M924569</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;just saw this post as I ended up using, which at the time of posting triggers a dns policy block&lt;/P&gt;
&lt;P&gt;(got it from&amp;nbsp;&lt;A href="http://mirror1.malwaredomains.com/files/domains.txt" target="_blank"&gt;http://mirror1.malwaredomains.com/files/domains.txt&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;acasadibarbara.it.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 14:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337846#M924569</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2018-02-26T14:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337912#M924570</link>
      <description>&lt;P&gt;for teh record i tried a couple from your post and they did't trigger my dns policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this site was 100% with 3 tests of different names.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist" target="_blank"&gt;https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 15:09:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337912#M924570</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2018-02-26T15:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337978#M924571</link>
      <description>&lt;P&gt;Which ones did not work for you?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 16:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3337978#M924571</guid>
      <dc:creator>argrullo</dc:creator>
      <dc:date>2018-02-26T16:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3338283#M924572</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it was 2am, so I have to recall, i think i tried these two&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;bollyrulez.tv&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;static.tvlive32.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I had all blacklist options selected in my Dns policy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I tried 2 from the link i posted and both worked.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It would be great if Cisco created a couple of names that were just for testing certain categories, ie&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ciscofakemalwarename.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ciscofakephishingname.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;etc&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 01:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3338283#M924572</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2018-02-27T01:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3338754#M924573</link>
      <description>&lt;P&gt;Hello Evan,&lt;/P&gt;
&lt;P&gt;I tried the ones you mentioned and they worked on my environment. Please see the attached files for screenshots.&lt;/P&gt;
&lt;P&gt;I know it can be frustrating when something does not seem to work. Realistically the DNS names you are seeing, are part of a Security Intelligence feed.&lt;/P&gt;
&lt;P&gt;You are able to create your own DNS list and put any DNS request in it, then add that object to the DNS Policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can go to Objects &amp;gt; Security Intelligence &amp;gt; DNS Lists and Feeds &amp;gt; Add DNS Lists and Feeds.&lt;/P&gt;
&lt;P&gt;Here you can upload a file with dns request you would like to block.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Then add that newly created object to your DNS Policy.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 14:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3338754#M924573</guid>
      <dc:creator>argrullo</dc:creator>
      <dc:date>2018-02-27T14:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower DNS Policy - Would like a known bad name to use as a check its working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3339053#M924574</link>
      <description>&lt;P&gt;Thanks for persisting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll try the names again, as it was late, and confirm if they get caught or not.&lt;/P&gt;
&lt;P&gt;I have uploaded my own list, and I suppose this is a good idea to confirm if things are working, the ultimate would be if I knew it was from a dynamic Cisco feed, i'll get back to you.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Evan&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 20:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-policy-would-like-a-known-bad-name-to-use-as-a/m-p/3339053#M924574</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2018-02-27T20:30:39Z</dc:date>
    </item>
  </channel>
</rss>

