---
title: "Custom Lists"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35473695/Custom%20Lists"
format: markdown
---
<span style="color: #000000">In addition to the predefined threat intelligence feeds that your subscription offers, you can create custom lists (containing domains and IP addresses) to define allow lists and block lists for additional protection. You can use a custom list to complement existing feeds or override the </span>**<span style="color: #000000">Block</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Allow</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Redirect</span>**<span style="color: #000000"> action that is currently defined for an existing feed. </span>The default custom list configurations include Default Allow ( **Allow - No Log ) ** and Default Block ( **Block - No Redirect** ). 

![image](media://757ed8dd-3927-471e-aeaf-e82900bf38fa)

**Image**: A detailed view of the Feeds and Threat Insight rule panel showing the default allow and block options.  

The default custom lists are included in the default policy and allow the editing of domains, IP addresses, and tags. You can edit or modify the default custom lists per your organization's requirements. Note: Neither the Name field nor the Description field is editable. <span style="color: #000000">For information on editing custom lists, see</span>[<span style="color: #000000">* Editing Custom Lists*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469450)<span style="color: #000000">*.*</span><span style="color: #000000"> </span>

### Default Custom Lists

- **Default Allow**: The default allow list will be added with "Allow - No Log" by default in the Default Global Policy. You can change the configuration to any Allow related actions such as "Allow - With Log" which enables only allow actions with no logging (Allow - No Log).
  **Image**: A detailed view of the Feeds and Threat Insight rule panel showing the Default Allow options.
- <span style="color: #000000">**Default Block**</span><span style="color: #000000">: The default block list will be added with "Block - No Redirect" action by default in the Default Global Policy. You can change the configuration to any Block related actions like Block - No Redirect, Block - Default Redirect or Block - Custom Redirect. </span>  
> Macro (inline-media-image)

  
**Image**: A detailed view of the Feeds and Threat Insight rule panel showing the Default Block options.

<span style="color: #000000">You can add a custom list to multiple security policies or multiple custom lists to one security policy based on your business needs. When you assign multiple custom lists that contain the same domain name(s) but with different actions to the same security policy, Infoblox Platform takes actions based on the following order:</span>

1. <span style="color: #000000">Allow (= Allow but no log)</span>
2. <span style="color: #000000">Redirect</span>
3. <span style="color: #000000">Block</span>
4. <span style="color: #000000">Log (= Allow and log)</span>

<span style="color: #000000">Infoblox</span><span style="color: #000000"> Platform automatically creates the following default global policies. If you are concerned about DNS data exfiltration through DNS tunneling, DNSMessenger, and DGA (including Dictionary DGA), you can add any or all of these policies to the security policy for a allow list or backlist. Note that you cannot modify or delete these default policies.</span>

- **<span style="color: #000000">Threat Insight – Data Exfiltration</span>**<span style="color: #000000">:  The default action for this policy is </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">. This list helps minimize the risk of DNS data exfiltration that are brought upon your networks through DNS tunneling.</span>
- **<span style="color: #000000">Threat Insight - </span>****<span style="color: #000000">Notional Data Exfiltration</span>**<span style="color: #000000">: </span>**<span style="color: #000000">Threat Insight - Notional Data Exfiltration</span>**<span style="color: #000000"> is part of the default feed and will be listed below </span>**<span style="color: #000000">Threat Insight - Data Exfiltration</span>**<span style="color: #000000">. (For existing customers to be aware and take advantage of this new Threat Insight - it will be automatically enabled and displayed below </span>**<span style="color: #000000">Threat Insight - Data Exfiltration</span>**<span style="color: #000000">, if that’s already enabled in existing policy). This list includes low confidence DNS Tunnel detections. The default action for this policy is </span>**<span style="color: #000000">Allow with Log</span>**<span style="color: #000000">. Ideally, only high confidence DNS Tunnel detections should be of interest and blocked, which are listed in the existing </span>**<span style="color: #000000">Threat Insight - Data Exfiltration </span>**<span style="color: #000000">list. However, there are cases where you may want to be informed of even lower confidence tunnels in your network. This Notional Data Exfiltration Threat Insight list addresses those cases. These are just suggestions for tunnel activity (hence, Notional) and not confident enough to be added to the original Threat Insight - Data Exfiltration list. Customers can also change the default action of this Notional list to </span>**<span style="color: #000000">Block</span>**<span style="color: #000000"> based on the organization's sensitivity to these low confidence DNS tunnels.</span>  
**<span style="color: #000000">Threat Insight - Notional Data Exfiltration</span>**<span style="color: #000000"> is part of the default feed and will be listed below </span>**<span style="color: #000000">Threat Insight - Data Exfiltration</span>**<span style="color: #000000">. (For existing customers to be aware and take advantage of this new Threat Insight - it will be automatically enabled and displayed below </span>**<span style="color: #000000">Threat Insight - Data Exfiltration</span>**<span style="color: #000000">, if that’s already enabled in existing policy).</span>

> Macro (inline-media-image)

  
**Image**: A detailed view of the Feeds and Threat Insight rule panel showing the Notional Data Exfiltration action options.

- **<span style="color: #000000">Threat Insight – DNS Messenger</span>**<span style="color: #000000">: The default action for this policy is </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">. This list helps minimize the risk of malicious activities that are brought upon your networks through the DNSMessenger malware, a Remote Access Trojan (RAT), that attackers use to conduct malicious Powershell commands on compromised devices.</span><span style="color: #FF0000"> </span>
- **<span style="color: #000000">Threat Insight – DGA</span>**<span style="color: #000000">: The default action for this policy is </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">. This list helps minimize the risk of malicious activities that are brought upon your networks using the Domain Generation Algorithm (DGA). DGA is a scheme used by malwares for domain fluxing by generating variations of a given domain name. They can be used to create a large number of domain names used as rendezvous points with command and control servers, in an attempt to evade detection by signature filters, block lists, reputation systems, security gateways, intrusion prevention systems, and other security methods.</span>
- **<span style="color: #000000">Threat Insight - Zero Day DNS</span>**<span style="color: #000000">: </span><span style="color: #000000">The default action for Zero Day DNS is </span>**<span style="color: #000000">Block - No Redirect</span>**<span style="color: #000000">. </span>This list features real-time streaming detection. It is designed to identify domains implicated in threat campaigns immediately after their registration, eliminating the aging period. It effectively blocks threat indicators in the initial stage of the threat lifecycle, specifically within 1 to 2 minutes following their registration. This proactive approach ensures the protection of our users against threats even before the commencement of the threat campaign. Infoblox blocks these domains using  short duration TTL of 48 hours by which time other security system in place will have enough information to protect per the exisitng policy.

## <span style="color: #000000">Custom List Support for IPv6 Addresses</span>

<span style="color: #000000">IPv6 addresses are supported in custom lists. IPv6 addresses can be added to a custom list in a similar manner as adding an IPv4 address, a fully qualified domain name (FQDN), or a CIDR. For information on creating custom lists, see </span>*[<span style="color: #000000">Creating Custom Lists</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469424)*[<span style="color: #000000">.</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469424)<span style="color: #000000"> </span>

<span style="color: #000000">A custom list containing IPv6 addresses can be added to a security policy in the same manner as when adding other custom lists to a security policy. For information on adding a custom list to a security policy, see </span>[*<span style="color: #000000">Creating Security Policies</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469750)*<span style="color: #000000">.</span>*

<span style="color: #000000">IPv6 addresses added to a custom list and then added to a security policy can be viewed in the Device IP column of the</span><span style="color: #000000"> </span>*<span style="color: #000000">Security Event</span>*<span style="color: #000000">s sub-report of the</span><span style="color: #000000"> </span>*<span style="color: #000000">Security Activity</span>*<span style="color: #000000"> </span><span style="color: #000000">report (</span>**<span style="color: #000000">Infoblox Portal</span>**<span style="color: #000000"> </span><span style="color: #000000">></span><span style="color: #000000"> </span>**<span style="color: #000000">Monitor</span>**<span style="color: #000000"> > </span>**<span style="color: #000000">Reports</span>**<span style="color: #000000"> </span><span style="color: #000000">></span><span style="color: #000000"> </span>**<span style="color: #000000">Security Activity</span>**<span style="color: #000000"> </span><span style="color: #000000">></span><span style="color: #000000"> </span>**<span style="color: #000000">Security Events</span>**<span style="color: #000000">).</span>


<span style="color: #000000">For more information on custom lists, see the following: </span>

- [*<u>Viewing Custom Lists</u>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403751)
- [*<u>Creating Custom Lists</u>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469424)
- [*<u>Editing Custom Lists</u>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469450)
- [*<u>Removing Custom Lists</u>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35436187)
- [*<u>Importing Custom Lists</u>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403798)
- [<u>*Updating an Imported Custom List*</u>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469484)
- [<u>*Viewing Custom List Details*</u>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439901)
- [<span style="color: #000000"><u>*Customer-Defined Threat Level and Confidence Score for Custom and Threat Insight Lists*</u></span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35377222)


> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">You must add the custom list to the security policy for a allow list or block list in order for the custom list to take effect.</span>