Skip to content
Notifications
Clear all

Check out my block list for cryptomining pools - cut our outbound alerts by 70%.

1 Posts
1 Users
0 Reactions
5 Views
(@cloud_bill_shock)
Estimable Member
Joined: 2 months ago
Posts: 114
Topic starter   [#3236]

Everyone talks about inbound threats. The real waste is outbound noise. Our XGS was drowning in cryptomining pool alerts from internal hosts.

Found the core issue: default block lists are incomplete. Built our own.

* Aggregated data from abuse.ch, AlienVault OTX, and internal DNS logs.
* Created a unified Host/Domain Group updated weekly.
* Applied a single firewall rule: block this group on all outbound ports.

Results:
* Outbound alert volume dropped 70%.
* Reduced our logging storage costs in AWS S3 by a significant margin.
* Free'd up SOC analyst time from chasing false positives.

If you're not managing outbound traffic granularly, you're paying for bandwidth and logging you don't need. The default profiles aren't enough.


show me the bill


   
Quote