```html ```
top of page

If the Indicator Was in the Feed and Your Firewall Pulled the Feed, the Attack Chain Broke by Itself. Nobody Wrote an Article About It. That Is the Entire Product.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 1 hour ago
  • 7 min read

Earlier today we published every CVE CISA cataloged in the last month — all thirty — with our own hit rate attached. Early on seven, nothing at all on seventeen.


The number that matters in that table is not the lead time. It is what happens during the lead time without anybody doing anything.


If an indicator is in the feed, and your firewall or SIEM pulls the feed on a schedule, the block is already in place before you have heard of the CVE. No analyzt reads an advisory. No ticket gets raised. No one decides. The attack chain breaks against a rule that arrived automatically, and the outcome is nothing at all — no incident, no forensics, no write-up, no headline.


That is a terrible thing to market and the best thing to own.



The blast radius, honestly measured




Five of this month's KEV entries, with internet-exposed host counts and the days our own receipt preceded CISA:



Product

Exposed hosts

Our lead

Citrix NetScaler

630,826

+12 days

Apache Tomcat

357,426

+85 days

Oracle WebLogic

20,923

+16 days

Gitea

8,986

+27 days

Microsoft SharePoint

not countable this way

+7 days


Read the empty row first, because it is the honest part. Exposure counts measure hosts that announce themselves in a banner. SharePoint does not — it lives behind authentication inside Microsoft 365, government tenants included. Our query returned zero. That is not a small blast radius, it is the wrong instrument, and it is the row with the largest number of humans behind it.


The same distortion runs the other way on the big bars. NetScaler tops the chart partly because a load balancer is the easiest thing on this list to fingerprint. Tomcat's true footprint is larger than 357,426 because it ships inside other vendors' products where nothing announces it — third-party estimates for Tomcat range from 0.02% of websites to 104,177 companies, a spread wide enough to be useless.


Anyone publishing a clean blast-radius number is measuring what is easy. We are publishing ours with the hole in it.



Host count is the smaller half


The number a scanner cannot give you is what the host is trusted to do.


NetScaler is the workforce. Citrix reports more than 400,000 customers and that over 90% of the Fortune 500 rely on NetScaler. One compromised appliance is not one host — it is every remote employee of that organization, at the exact point where their session is terminated and their credentials are handled.


SharePoint is the filing cabinet. The document and collaboration layer for Microsoft 365. When it is an agency's tenant, the blast radius is that agency's working papers. Microsoft does not publish per-tenant seat counts, so nobody outside can size it honestly — which is why you will see confident numbers about it from people who should not have them.


Gitea is everything downstream. The smallest number on the chart, 8,986, and arguably the worst outcome, because remote code execution as the service account means every repository, deploy key and CI secret on that box — and then whatever that forge builds, for everyone who installs it.


Blast radius is host count multiplied by what the host is trusted to do, and one of those two numbers is not in any scanner.



What "automatic" actually means


Here is the part that does not require you to be clever, awake, or staffed.


Our feed publishes IP, domain and hash blocklists in CSV, plus OPNsense and Suricata formats and a Splunk-friendly output. A firewall pointed at the CSV re-pulls it on whatever schedule you set. When our harvester extracts a target endpoint from freshly published exploit code and writes it to the index, that record is in the next pull.


There is no step where a person has to notice. That is the whole design. The defender we built this for does not have a threat-intel analyzt — they have a rack of things they inherited and a day job. Asking them to read advisories is asking for the one resource they do not have.


We can show that the automatic path outperforms the human one on our own edge. Running the blocklist as a static list stopped 55 hosts. Running it as a live behavioral shield stopped 1,638 — roughly thirty times more — and our block_events index now holds 2,915,962 records. Same intelligence, and the difference is entirely whether it was applied automatically or looked up by somebody.


And here is the part that sounds like failure and is not: around 97.5% of what is on the list never arrives at our edge at all. That is not waste. A blocklist is a reserve. You do not get to know in advance which of the entries is the one that saves you, which is exactly why "hit rate" is the wrong measure of a feed and why we refuse to quote one as efficiency.



The arithmetic nobody in this category will print




IBM's Cost of a Data Breach 2026, built on 602 breached organizations studied between March 2025 and February 2026: the US average breach costs $11.5 million. Global average $4.99 million, up 12% year on year. AI-enabled breaches add roughly a further million.


A year of our Pro tier is $948. $2.60 a day. Roughly two McDonald's dinners for a family of four, per month.


That is a ratio of 1 to 12,131. Pro pays for itself if it contributes to preventing one breach once every twelve thousand years.


That is not a clever argument, it is what happens when the downside is catastrophic and the control costs less than lunch. And the blocklists — the part that actually breaks the attack chain automatically — are free at $0 and always will be.



Where we are genuinely different


Not a swipe at anyone by name. Just the properties, and you can check every one of them yourself in about a minute.


The free tier is not a trial. No clock, no seat cap, no feature wall on the blocklists. If you never pay us a penny you still get the CSV, the OPNsense list and the Suricata rules.


We publish our denominator. Seven of thirty KEV listings early this month, median sixteen days — and nothing at all on seventeen. Go and look for a competitor's miss rate. It is not a criticism that you will struggle to find one; a selected sample simply makes a better slide, and everybody knows it.


Formats a one-person shop actually runs. OPNsense and Suricata are in there because that is what the defender we built this for has, not because they are impressive.


No call with a rep. Thirty-second registration, key in your inbox, pricing on the page. If pricing is behind "contact sales," the contact form is the qualification filter, and a small operator has already been filtered out.


Confidence capped at 95%, corrections published. There is a post on this blog correcting a lead claim we got backwards — we had cited our own ingest timestamp as though it beat a vendor who had actually published first. We wrote that up rather than quietly deleting it, because a feed you cannot audit is a feed you cannot rely on.


The trade-off, stated plainly: we are small, we miss more than half of what CISA catalogues, and you should not run only our feed. All three of those are in this post on purpose.



Why prevention has no evidence


The uncomfortable structural fact underneath all of this: a broken attack chain leaves no artifact.


A breach produces an incident report, a disclosure, a leak-site listing, a case study, a conference talk, and a vendor blog post claiming credit. A prevented breach produces a log line that says a connection was refused, which nobody reads, in a file nobody keeps.


So the entire visible record of this industry is composed of failures. Every number you have ever seen about attacker sophistication comes from the cases where the attacker won, because those are the only ones that generate documents. The successes are invisible by construction — and the better your prevention works, the less evidence exists that you needed it.


That is why we published the seventeen blanks this morning. If we only ever showed you the seven, we would be doing the same trick from the other direction — building a story out of a selected sample and asking you to trust the shape of it.



What to actually do, and it is free


Point something at the feed. https://analytics.dugganusa.com/api/v1/stix-feed/ips.csv and the domain and hash equivalents. Free key, thirty-second registration, no contract, no call with a rep. OPNsense and Suricata formats are there because that is what small operators actually run.


Set it to re-pull on a schedule and then forget about it. The value is entirely in it working while you are not thinking about it.


Do not run only ours. On seventeen of thirty KEV listings this month we had nothing, and a defender relying on a single feed has substituted one point of failure for another. Ours is free specifically so it can be one of several rather than a purchase somebody has to justify.


And accept that you will never know if it worked. That is not a limitation of our feed. It is the nature of prevention, and it is why the people doing it well get less credit than the people cleaning up afterwards.



Sources


Exposure counts are Shodan host-count totals for the product banner, queried 27 August 2026 — a floor, including patched hosts and excluding anything not banner-identifiable. KEV dates from our own cisa_kev index; lead days from our exploit-harvester records in the iocs index. Citrix customer and Fortune 500 figures are vendor-published. Edge-shield comparison figures and the 2,915,962 block_events count are our own.


Capped at 95 percent: we have no telemetry on whether any reader has ever blocked anything using this feed, and by the argument above we structurally cannot have it. The 30-of-30 KEV review this claim rests on is published separately with every blank included. The 30× edge-shield figure is one measurement on our own infrastructure, not a general claim about your network.




The honest sales pitch is a bad one: point your firewall at a free CSV, and on about a quarter of what CISA is going to tell you next month, you will already have been blocking it — and you will never find out which quarter. Rate this post below.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page