Minotaur — HybridSOC threat feeds, natively on your firewall
Minotaur is HybridSOC's threat-intelligence feed, delivered through the native external-feed mechanism your firewall already has — no extra appliance, no bespoke integration project. Browse every currently supported platform below and jump straight to the one you run.
Attack-surface mapping and continuous exposure management
Minotaur continuously maps everything you expose to the internet — domains, hosts, certificates, leaked credentials and shadow IT — and tells you what an attacker would find first.
Coverage starts at home: Minotaur and HybridSOC already watch businesses across Lithuania's biggest cities, mapped below.

Vilnius
The capital and largest business hub — government, finance and the country's largest concentration of enterprise and public-sector infrastructure.
Kaunas
Lithuania's second city and a major industrial and logistics centre, with a fast-growing tech and manufacturing base.
Klaipėda
The country's only major seaport — critical maritime, logistics and energy infrastructure on the Baltic coast.
Šiauliai
A northern industrial and manufacturing centre, home to a regional airport and a growing logistics sector.
All cities →See every Lithuanian city HybridSOC covers.
Other countries and cities
Built to do the job, end to end
External attack-surface map
Continuous discovery of domains, subdomains, IPs, ports and services you own — including the ones you forgot.
Exposure scoring
Findings ranked by real exploitability and business impact, not raw CVSS noise.
Leaked-credential monitoring
Open and dark-web monitoring for your credentials, keys and data — surfaced early.
Shadow-IT detection
Unsanctioned assets and forgotten cloud resources flagged before attackers use them.
Change alerting
New exposures and certificate expiries pushed to your team the moment they appear.
Feeds HybridSOC
Exposure context enriches detections, so alerts arrive with the attack path already drawn.
// au-delà des pare-feu ci-dessus : nous développons aussi des plugins Minotaur pour l'ensemble plus large de l'écosystème de sécurité — certains sont déjà en service, d'autres encore en cours.
Every platform Minotaur plugs into today
One feed, delivered the way each platform already expects to receive external threat data — external dynamic lists, IoC feeds, URL table aliases, or a security-intelligence connector, depending on the vendor.
Sophos Firewall
Add Minotaur's threat feed to Sophos Firewall via Active Threat Response and third-party threat feeds, so malicious indicators are blocked automatically.
View setup guide →Fortinet FortiGate
Set up Minotaur on FortiGate through External Connectors and dynamic objects, then reference them in policies that block malicious IPs and domains.
View setup guide →Palo Alto Networks
Register Minotaur as a Palo Alto Networks External Dynamic List so indicators refresh automatically and policy enforces without a manual commit each time.
View setup guide →Cisco Secure Firewall
Connect Minotaur to Cisco Secure Firewall through Security Intelligence feeds in FMC, then apply them directly in your access control policies.
View setup guide →Check Point
Integrate Minotaur with Check Point using External IoC feeds in SmartConsole, so gateways fetch observables and enforce them under Threat Prevention.
View setup guide →OPNsense
Configure Minotaur in OPNsense as a URL Table Alias and reference it in firewall rules to block malicious IP infrastructure.
View setup guide →pfSense
Use Minotaur in pfSense via URL Table aliases, then apply the imported IP indicators directly inside your firewall rules.
View setup guide →SonicWall
Integrate Minotaur with SonicWall using Dynamic External Address Groups and Objects to apply the feed's IPs and FQDNs in policy.
View setup guide →ManageEngine
Feed Minotaur indicators into ManageEngine's threat-intelligence and firewall-management modules to correlate and act on them across your managed endpoints.
View setup guide →Bitdefender
Bring Minotaur's indicators into Bitdefender GravityZone as a custom threat-intelligence source, extending detection beyond Bitdefender's own signatures.
View setup guide →Test compatibility with the free Basic feed first
We don't offer refunds, because we want you to be certain Minotaur works with your specific hardware before you spend anything. Use the Basic feed to validate delivery and the TXT format end to end.
| Tier | Price | Update frequency | Indicator types | Coverage | Support |
|---|---|---|---|---|---|
| Basic | Free | 24 hours | IPv4 only | 20,000 IPv4 | None |
| Standard | €49/mo | 6 hours | IPv4 + Domains + URLs | Full feed | Community |
| Premium | €149/mo | 1 hour | IPv4 + Domains + URLs | Full feed | Dedicated |
| Ultimate | €399/mo | 15 minutes | IPv4 + Domains + URLs | Full feed + priority additions | Priority |
When to upgrade: if you need Domain and URL blocking, hourly (or faster) updates, or support investigating a block, move up from Basic to Standard, Premium or Ultimate.
Frequently asked questions
Is it really one key per firewall?
Yes. One licence key is meant for one firewall device, or one logical HA cluster acting as a single edge. Managing several sites or clients (MSP)? You need one key per device — this keeps pricing predictable and prevents API abuse.
Will the feed ever block legitimate traffic?
We curate the list aggressively and maintain strict allow-lists to minimise false positives, but with any threat-intelligence feed an IP can occasionally be flagged incorrectly. Paid plans include support to review a block and fast-track removing an inaccurate indicator.
How do renewals and billing work?
Choose monthly or annual billing in EUR. Subscriptions renew automatically for the selected period unless cancelled beforehand — the same billing flow as the rest of CYBORA's platform.
What polling interval should I set on my firewall?
Match your firewall's polling interval to your plan's update frequency: roughly every 24h on Basic, 6h on Standard, 1h on Premium, or 15 minutes on Ultimate.
What happens if my key leaks?
Request a rotation any time via support. Usage is monitored continuously — a key polling far outside normal patterns, or from multiple unrelated origin IPs, is automatically throttled. Keep keys out of public documentation and shared repos.
Do you offer refunds?
No, and deliberately so: the free Basic feed lets you fully validate delivery and format compatibility with your exact hardware before you spend anything. Once you're confident it works, paid plans are final.
Voyez-le sur votre propre périmètre
Tell us where you are today. A CYBORA engineer — not a salesperson — will come back with what actually applies to your situation.
- Reply within one business day
- Scoped to your regulatory frameworks
- No obligation, no sales pitch
Take control of your perimeter
Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.













