Feed Categories
Every feed is sourced from a trusted open-source or government threat intelligence provider and refreshed every hour.
C2 & Active Malware Infrastructure
Feodo Tracker botnet C2s, Abuse.ch MalwareBazaar, Emerging Threats compromised IPs. Blocks active command-and-control servers used by malware families including Emotet, QakBot and IcedID.
Phishing & Malware URLs
URLhaus malware distribution URLs, PhishTank phishing sites, OpenPhish live phishing feeds. Updated continuously from community submissions and automated analysis.
Scanners & Brute-Force Sources
IP addresses actively conducting port scans, vulnerability scans and brute-force attacks. Sources include GreyNoise, Blocklist.de and the Emerging Threats scanner list.
Anonymisation Networks
Tor exit node list (Dan.me.uk), VPN provider ranges, proxy networks and hosting ASNs commonly used to evade geo-blocking and attribution. Updated every hour.
SaaS Provider Allow-Lists (EDL)
19 SaaS provider IP ranges for Cloudflare, AWS, Microsoft 365, Google Workspace, GitHub, Zoom, Salesforce and more โ in EDL format for firewall allow-list policies.
Government & ISAC Sources
CISA Known Exploited Vulnerabilities (KEV) associated infrastructure, NCSC UK threat feeds, Spamhaus DROP and EDROP hijacked IP blocks used by criminal networks.
EDL Format โ Drop Into Any Firewall
Every feed is served as a plain-text External Dynamic List (EDL) compatible with Palo Alto, FortiGate, Cisco, pfSense and any firewall that supports URL-based IP lists.
Palo Alto PAN-OS
Add as External Dynamic List object. Type: IP List or URL List. Refresh every 5 minutes. Apply to Security Policy as address group.
FortiGate FortiOS
Use as External Connector with IP/Domain category. Set refresh interval to 1 hour. Apply as address object in firewall policies.
Cisco Firepower / ASA
Add as Network Feed object in FMC. Apply to access control policy as network object. Supports both IP and URL list types.
Free Feeds โ No Account Needed
Four feeds are always free, no login required. Start protecting your network right now.
Feodo Tracker C2 IPs
Active botnet command-and-control servers. Updated multiple times per day. One of the most important single feeds for blocking active malware. Free, no account.
Spamhaus DROP
Hijacked IP blocks used exclusively by criminals. Block before any other list โ near-zero false positives, extremely high signal. Free, no account.
URLhaus Malware URLs
Live malware distribution URLs from Abuse.ch community submissions. Updated continuously. Blocks malware downloads at the firewall layer. Free, no account.
Tor Exit Nodes
All current Tor exit nodes. Essential for detecting anonymised traffic and policy enforcement on networks that prohibit Tor use. Free, no account.
Get All 24 Feeds with Pro
From $19.99/month ยท 14-day free trial ยท Cancel anytime
๐ Start Free TrialSee how feeds integrate into a firewall audit โ download sample FortiGate audit report