Documentation/Threat Feeds

Threat Intelligence Feeds

91+ community threat intelligence sources powering SOC Defenders

Feed Architecture

Our threat intelligence is sourced from 91+ community feeds organized into 3 tiers based on update frequency and criticality:

TIER 1Critical

Updated every 15 minutes. Active C2 servers, live phishing, abuse.ch feeds.

17 feeds

TIER 2Standard

Updated every 1 hour. Community blocklists, hash feeds, emerging threats.

37 feeds

TIER 3Background

Updated every 6 hours. Historical aggregates, reputation lists, large datasets.

37 feeds

Enterprise-Grade Reliability

Circuit Breaker

Auto-disabled feeds that fail repeatedly to prevent cascading failures.

Exponential Backoff

Smart retry logic with jitter to prevent thundering herd.

TLP Classification

Traffic Light Protocol tagging for proper information sharing.

Confidence Scoring

Source reputation-based scoring for IOC prioritization.

Tier 1 Feeds

Updated every 15 minutes

17 feeds
Feed NameCategoryDescription
URLhausMalwareMalicious URLs distributing malware
Feodo TrackerC2/RATBotnet C2 IPs (Emotet, TrickBot, QakBot, Dridex)
ThreatFoxMixedMixed IOCs from community submissions
C2 Tracker - Cobalt StrikeC2/RATActive Cobalt Strike C2 servers
C2 Tracker - MetasploitC2/RATActive Metasploit Framework C2 servers
C2 Tracker - SliverC2/RATActive Sliver C2 servers
C2 Tracker - Brute RatelC2/RATActive Brute Ratel C4 servers
C2 Tracker - HavocC2/RATActive Havoc C2 servers
C2 Tracker - AsyncRATC2/RATActive AsyncRAT C2 servers
C2 Tracker - DcRATC2/RATActive DcRAT C2 servers
C2 Tracker - PoshC2/RATActive Posh C2 servers
OpenPhishPhishingActive phishing URLs
C2 Tracker - MythicC2/RATActive Mythic C2 servers
C2 Tracker - DeimosC2/RATActive Deimos C2 servers
C2 Tracker - NightHawkC2/RATActive NightHawk C2 servers
SSL Blacklist IPsC2/RATIPs associated with malicious SSL certificates
VXVault URLsMalwareLive malware download URLs

Tier 2 Feeds

Updated every 1 hour

37 feeds
Feed NameCategoryDescription
MalwareBazaar MD5MalwareRecent malware MD5 hashes
MalwareBazaar SHA256MalwareRecent malware SHA256 hashes
SSL Blacklist JA3C2/RATMalicious JA3 fingerprints
DigitalSide IPsBlocklistLatest malicious IPs
DigitalSide DomainsBlocklistLatest malicious domains
DigitalSide URLsMalwareLatest malicious URLs
Phishing ArmyPhishingPhishing domain blocklist
TweetFeedMixedIOCs shared by security researchers on Twitter/X
Botvrij Destination IPsC2/RATDestination IPs from malware traffic
Botvrij DomainsMalwareMalicious domains from threat analysis
Blocklist.de SSHBlocklistSSH brute force attackers
Blocklist.de ApacheBlocklistApache web attack IPs
Blocklist.de BruteforceBlocklistBrute force login attackers
Binary DefenseBlocklistAttacker IPs from honeypot network
GreenSnowBlocklistActive attacking IPs
CI Army Bad IPsBlocklistKnown bad actors from Collective Intelligence
ET Compromised IPsBlocklistKnown compromised hosts
Botvrij URLsMalwareMalicious URLs from threat analysis
Blocklist.de MailBlocklistMail spam IPs
Blocklist.de BotsBlocklistBot IPs
Blocklist.de Strong IPsBlocklistPersistent attackers (multiple attacks)
Blocklist.de AllBlocklistAll reported attacking IPs
Bambenek DGA DomainsC2/RATHigh-confidence DGA domains
Bambenek C2 IPsC2/RATHigh-confidence C2 IPs
Bambenek C2 DomainsC2/RATHigh-confidence C2 domains
DShield Top 20BlocklistTop 20 attacking IPs
DShield Suspicious Domains HighBlocklistHigh-confidence malicious domains
InterServerBlocklistAttack IPs from hosting provider honeypots
Talos IP BlacklistBlocklistTalos known malicious IPs
MyIP Full BlacklistBlocklistComprehensive IP blacklist
Bruteforce BlockerBlocklistBrute force attackers
NoThink SSHBlocklistSSH attacking IPs
NoThink TelnetBlocklistTelnet attacking IPs
Rutgers Malware DomainsMalwareMalicious domains list
Cybercrime TrackerC2/RATActive C2 panel URLs
Disposable Email DomainsBlocklistTemporary/disposable email domains
Cryptominer DomainsMalwareCryptojacking domains

Tier 3 Feeds

Updated every 6 hours

37 feeds
Feed NameCategoryDescription
IPsum Level 3+BlocklistIPs on 3+ threat intel lists
IPsum Level 4+BlocklistIPs on 4+ threat intel lists
IPsum Level 5+BlocklistIPs on 5+ threat intel lists (highest confidence)
Tor Exit NodesBlocklistCurrent Tor exit node IPs
Spamhaus DROPBlocklistDont Route Or Peer - hijacked/leased ranges
Spamhaus EDROPBlocklistExtended DROP - additional bad ranges
CISA KEVMixedCISA Known Exploited Vulnerabilities catalog
FireHOL Level 1BlocklistCritically dangerous IPs
DarklistBlocklistSSH brute force and spam IPs
CyberCure IPsBlocklistActive threat IPs from CyberCure honeypots
IPsum Level 2+BlocklistIPs on 2+ threat intel lists
IPsum Level 6+BlocklistIPs on 6+ threat intel lists (very high confidence)
IPsum Level 7+BlocklistIPs on 7+ threat intel lists (extremely high confidence)
FireHOL Level 2BlocklistConfirmed dangerous IPs
FireHOL Level 3BlocklistSuspected dangerous IPs
FireHOL Abusers 1dBlocklistRecent (24h) active abusers
FireHOL WebclientBlocklistIPs attacking web clients
AlienVault ReputationBlocklistAlienVault IP reputation data
ET Tor NodesBlocklistTor exit and relay nodes
ET DShieldBlocklistCombined block list
ET BotCCC2/RATKnown Bot C&C IPs
Malware Domain ListMalwareHistorical malware domains
URLhaus FullMalwareFull URLhaus database (text)
Spam404PhishingScam/spam domains
Disconnect MalvertisingMalwareMalvertising domains
SANS ISC Top IPsBlocklistTop attacking source IPs
StopForumSpamBlocklistToxic IPs (forum spam/abuse)
CryptoLocker DomainsRansomwareCryptoLocker DGA domains
Locky DGA DomainsRansomwareLocky ransomware DGA domains
Mirai Scanner IPsC2/RATMirai-infected scanner IPs
BotScout IPsBlocklistRecently caught bot IPs
MyIP WebSecBlocklistLatest attackers (CSF format)
SSL Blacklist SHA1C2/RATMalicious SSL certificate SHA1 hashes
NoCoin BlocklistMalwareCryptominer domain blocklist
Dan.me.uk TorBlocklistTor exit nodes (alternative)
PhishStats URLsPhishingPhishing URLs with confidence scores
PhishTank VerifiedPhishingVerified phishing URLs

Data Sources & Attribution

All threat intelligence is sourced from free, community-driven projects. We gratefully acknowledge:

Access via API

All IOCs are available through our REST API and TAXII 2.1 server for SIEM/SOAR integration.