Submenu – Threat Intelligence

This page contains the general settings for the threat intelligence feed provided by Webroot.

Prerequisites

To enable the threat intelligence feed provided by Webroot, the following prerequisites must be met:

  • A valid license for the Threat Intelligence Feed must be installed.
  • DNS resolution must be available for the BrightCloud service endpoints.
  • Airlock Gateway must be able to establish outbound HTTPS connections to the following currently used endpoints:
  • Hostname

    IP version

    Protocol

    Port

    Purpose

    api-dualstack.bcti.brightcloud.com

    IPv4/IPv6

    TCP

    443

    BrightCloud API endpoint

    localdb-ip-daily.brightcloud.com

    IPv4

    TCP

    443

    Database update endpoint

    localdb-ip-rtu.brightcloud.com

    IPv4

    TCP

    443

    Real-time database update endpoint

    localdb-ipv6-daily.brightcloud.com

    IPv6

    TCP

    443

    IPv6 database update endpoint

The database update hostnames are provided dynamically by api-dualstack.bcti.brightcloud.com and may change over time. Therefore, additional BrightCloud database update hostnames may be returned by the service.

Connectivity must be possible through a back-end interface or through the management interface. Airlock Gateway does not use the external interface to connect to the threat intelligence feed service.

Further information