Back to home
Sophos

Sophos Firewall Integration

Add ThreatHive as a third-party threat feed via Active Threat Response.

  1. Log in to the Sophos Firewall admin console Open a browser and navigate to your Sophos Firewall web admin URL, then sign in with administrator credentials.
  2. Navigate to third-party threat feeds Go to Active Threat Response › Third-party Threat Feeds.
  3. Add a new feed Click Add to open the new feed dialog.
  4. Configure the ThreatHive feed
    • Name: ThreatHive_Blocklist
    • Action: Block (use Monitor during initial testing)
    • Position: Top
    • Indicator Type: IPv4 address
    • Feed URL: https://threathive.net/hiveblocklist.txt
    • Authorization Type: No authentication
    • Validate Server Certificate: Enabled (recommended)
    • Polling Interval: 15 minutes
  5. Test the connection and save
    • Click Test Connection — the status should return green.
    • If successful, click Save.
    • Sophos will immediately fetch the feed on first save.
  6. Monitor for matches and false positives Navigate to Logs & Reports › Threat Indicators to review matched IPs, blocked traffic, and any potential false positives. The feed refreshes automatically every 15 minutes.