Noisy Scanners and Tor Protection for Network Firewall by VisionHeight
VisionHeight · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Scanners and Tor Networks Protection for Network Firewall bundles operational threat feeds for AWS Network Firewall, including currently-active Tor exit nodes and IP sources generating high-volume noise traffic against public-facing workloads.
The Tor exit node feed reflects the live state of the Tor network. Every IP currently capable of routing exit traffic from Tor is included, with entries removed as nodes leave the network. Block these to enforce policy against anonymized network access and to remove a common source of attribution-resistant attack traffic.
Show the rest of the publisher’s description (2 more lines)
The noisy scanner feed identifies IP sources currently generating opportunistic scan traffic against the public internet, looking for exposed services, vulnerabilities, and credential-stuffing targets. These IPs are responsible for the bulk of unsolicited probe traffic against AWS workloads. Block them at the network firewall to dramatically reduce SOC alert volume and downstream SIEM ingestion costs, without losing visibility into targeted reconnaissance from sophisticated actors.
Both feeds refresh daily, with entries added and removed based on VisionHeight's live telemetry of global attack infrastructure. Delivered as Network Firewall rule groups, the feeds attach directly to your firewall policy.
Highlights
Highlighted by the publisher on AWS Marketplace.
Live Tor exit node coverage: every IP currently capable of routing Tor exit traffic is included, with entries removed as nodes leave the network. Block these to satisfy compliance requirements for anonymizing network traffic and to cut a common source of attribution-resistant attacks.
Noisy scanner suppression: blocks IP sources generating high-volume opportunistic scan traffic. Cuts SOC alert volume and SIEM ingestion costs at packet 1, while preserving visibility into targeted reconnaissance.
One subscription, bundled coverage: includes Tor exit nodes and active scanner sources at a flat per-GB rate. Add the rule group to your Network Firewall policy and all protections are active immediately.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
17 listed- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
Non-refundable.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

