Text alternative to the two-page, image-only QMasters · Stronghold IOC Service 2026 datasheet. This page follows the document’s reading order and describes its process diagram. The original PDF remains available from the PDF download. This text is in the source document’s language, English.
QMasters · Stronghold | Datasheet | IOC Service · 2026
Block before they knock.
Real visibility. Rapid response.
The QMasters IOC service is a daily-curated IP blacklist — 150,000–200,000 verified malicious addresses tied to active scanners, C2 infrastructure, phishing hosts, and hacking campaigns. Cross-referenced across 20+ direct feeds, pushed inline to FortiGate, Palo Alto, and Check Point every three hours. No appliance. No ingestion script. No analyst time.
At a glance
- 200K peak verified malicious IPs
- 3 hours refresh cadence
- 20+ direct feeds
- 0 touch manual sync
Daily IP blacklist
Live · sync. The following entries are shown in the datasheet’s table:
| Indicator | Vector | Severity |
|---|---|---|
| 185.243.115.84 | Scanner | Warning |
| 45.142.213.10 | C2 infrastructure | Critical |
| 91.218.50.122 | Phishing host | Critical |
| 162.247.74.27 | Hacking campaign | Critical |
What you get
- Inline IP blocking. Hourly sync into FortiGate, Palo Alto, Check Point.
- 20+ direct feeds. Cross-referenced before any IP commits to the list.
- Attack-attributed. Every IP linked to an active scan, campaign, or C2.
- Validated and scored. Enriched and deduplicated to keep false positives down.
- SIEM-ready format. Standardized output your playbooks consume on day one.
Intelligence, enforcement, response
Daily IP updates.
Verified malicious IPs on a tight cadence. Cross-checked against 20+ direct feeds before they hit your stack.
Seamless firewall sync.
Inline blocking on FortiGate, Palo Alto, and Check Point. Real-time mitigation, zero manual ingestion.
Playbook automation.
Standardized alerts feed your SIEM and SOAR. Faster triage. Less keyboard. Cleaner audit trail.
From feed to firewall. In three steps.
The process diagram shows sources (20+ direct feeds, live · collecting) flowing into the QMasters intel engine. The engine validates that an indicator is live, malicious, and current, then verifies that it is tied to an active attack, campaign, or scanning. Its outputs branch to three destinations: block (firewall), detect (SIEM), and automate (automation).
Measured outcomes. From the field.
Government agency · Public sector
−30% inbound malicious traffic
We run the IOC blacklist inline to block access in real time. Bad traffic dropped by about 30%, firewall performance is up, and we’re in control. More visibility. Less noise. Safer overall.
— Network operations · Gov. agency
Hightech · fintech app · Fin. services
Earlier. Recon blocked before exploit windows
AI changed the vulnerability game. We use IOC blocking to buy time — scanning and early reconnaissance get cut at the firewall. Results land live in our firewall and SIEM. Time we didn’t have before.
— App security · Fintech
No new appliance. Just sync.
Inline IP enforcement on the firewalls you already run. Standardized output your SIEM, SOAR, and TIP already speak.
Supported WAF solutions: Fortinet, Palo Alto, Check Point.
Formats: STIX / TAXII; CSV; JSON / REST.
Get the feed running in under 24 hours.
Onboarding covers firewall integration, validation against your existing ruleset, and a tuning pass with our SOC. Ask us about a trial.
Sales: [email protected]Web: qmasters.co
Office: Derech Begin 46, 4th floor, Tel Aviv, Israel