I am having difficulty writing a detection rule to identify VPN IPs, specifically for services like Mullvad VPN and other similar VPN providers, using only built-in threat feeds (no external data sources). I do not want to hardcode ASN numbers.
Question
Detection rule tto flag VPN IPs
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
