Fortinet firewall threat intelligence
FortiGate threat feeds for faster firewall blocking
PrecisionSec supplies curated IP, domain and SHA-256 hash threat feeds that FortiGate pulls in through native External Connectors, so your firewall blocks freshly-seen malicious infrastructure without manual list maintenance.
- IP, domain and malware-hash feeds
- Native FortiGate External Connector delivery
- 15-day evaluation with setup help

Coverage that adds to FortiGuard
FortiGuard gives your FortiGate a strong baseline. PrecisionSec adds to it: thousands of curated malicious domains, IPs and file hashes a day, focused on the active malware, C2 and phishing infrastructure our researchers track directly.
You reference our indicators in the same firewall policies you already run, so the extra intelligence blocks traffic the moment it lands, with no change to how your team works.
Wired in as an external threat feed
PrecisionSec delivers as a native FortiGate external threat feed. FortiGate pulls the connector URL on the schedule you set, so new indicators refresh on your firewall automatically, with nothing to import by hand.
Each feed lands as a threat-feed object you reference in address, web filter or DNS filter policies. You choose which indicator types to pull and how aggressively to act on them, from monitor-only to hard block.

Your blocklist keeps itself current
New malware campaigns move fast. Because the feed refreshes on its own, your FortiGate starts blocking freshly-seen domains, IPs and hashes without anyone opening a ticket or editing a rule.
That means less time hand-maintaining blocklists, and fewer gaps between a threat going active and your firewall acting on it.

What you get with the FortiGate integration
Thousands of IOCs per day
Curated malicious domains, IPs and file hashes, refreshed continuously so your FortiGate acts on current threats.
Updates with no hand-holding
FortiGate pulls the feed on your schedule, so new indicators apply automatically with nothing to import.
Setup help from our team
We work with you to add the feeds as external connectors, map them into your FortiGate policies and choose the right indicator types and actions for your environment.
Each PrecisionSec external threat feed is built on the same curated data behind our Malicious Domain, Malicious IP and Malware Hash feeds, so the FortiGate connectors carry the same indicators your other tools see.
Frequently asked questions
FortiGate feed coverage, delivery and trial access
Which feed types are supported?
PrecisionSec delivers three FortiGate-compatible feed types: malicious IP addresses, malicious domains and SHA-256 malware hashes.
How does FortiGate connect to the feeds?
Each feed is added as a native FortiGate External Connector using an authenticated feed URL. FortiGate pulls updates on the schedule you set, with nothing to import by hand.
How often do the feeds refresh?
A 60-minute FortiGate refresh interval is recommended, so newly-seen indicators reach your firewall within the hour.
Does this replace FortiGuard?
No. PrecisionSec feeds add focused coverage of the active malware, C2 and phishing infrastructure our researchers track directly, alongside your existing FortiGuard subscription rather than in place of it.
What happens during the evaluation?
You get 15 days of live feed access, credentials and configuration help from our team to add the feeds as External Connectors and map them into your FortiGate policies.
Get started
Start a FortiGate evaluation
Tell us about your FortiGate deployment. We'll help you evaluate live PrecisionSec threat feeds for blocking malicious domains, IPs and hashes through FortiGate external connectors.