A website or IP address can be blocked by ThreatDown in multiple ways. This article explains how to identify which feature performed the block, how to respond to the detection, and how to customize the block page in Nebula.
ThreatDown has three real-time features that can block a website: Web Protection, Browser Phishing Protection (BPP), and DNS Filtering. Because they log differently and behave differently, the fastest way to help an end user who reported a blocked website is to identify which feature caused the block, then follow that feature's specific steps below.
Identify which feature blocked the website
Check Nebula to verify how the block is recorded:
| Feature | Where it's logged | Type | Outcome |
|---|---|---|---|
| Web Protection | Monitor > Detection Center > Detection Log | Outbound Connection or Inbound Connection | N/A |
| BPP | Monitor > Detection Center > Detection Log | Browser | N/A |
| DNS Filtering | Monitor > DNS Filtering > Activity | N/A | Block |
Block pages
You can also use a screenshot of the block page to determine which feature blocked the website. The block page of both BPP and DNS Filtering can be customized to help with identifying the blocking feature. We recommend updating the block pages to include the feature name and an email address end-users can use to report a block.
- Customize BPP block page: Protection policy settings in Nebula.
- Customize DNS Filtering block page: Customize DNS Filtering block page in Nebula.
Below are the default block pages for each feature.
Web Protection block page
BPP block page
DNS Filtering block page
Once you've identified which feature blocked the site, go to the matching section below.
Respond to the detection
Follow the steps below to investigate the detection of the corresponding feature.
Web Protection and BPP
- Copy the value in the Location column of the Detection Log.
- Look it up against a trusted online URL scanner, such as www.virustotal.com or www.abuseipdb.com.
- If you believe the detection is a false positive, report it to ThreatDown.
- If you need to unblock the site immediately and can't wait for our research team, use an exclusion. Website exclusions affect both Web Protection and BPP. It's generally recommended to wait for research than to use an exclusion.
Note: Some Web Protection detections include both a domain and an IP address, for example, ransomwaretest.threatdown.com(34.233.211.129). To identify which specific value triggered the block, contact Support.
DNS Filtering
Review the DNS Filtering Activity table for the domain and categories that triggered the rule.
Click on the rule name from the table to edit the rule.
Decide whether to adjust the blocked categories or add the domain to the rule's allow list.
For more information, see Configure DNS Filtering rules in Nebula.