Available Open Source Feeds

The table below contains the active open source feeds aggregated by ThreatStream.

Tip: Use the Circle ID to search for intelligence provided by the feed. For example, to search for intelligence provided by the Emerging Threats - Compromised feed, enter the following advanced search query:

(trusted_circle_id = 371)

See Performing Advanced Observable Searches for more information.

 

Feed Name Circle ID Circle Name Circle Description
Emerging Threats - Compromised 371 Emerging Threats - Compromised Rules to block known hostile or compromised hosts.
CI Army 193 CI Army List CI Army is a open source IP reputation list driven by collective intelligence of Sentinel IPS's MSSP customer base.
Project Honeypot 194 Project Honeypot Project Honeypot, created by Unspam, is a community sponsored Honey Network and reports malicious IP's worldwide.
Bot Scout IP 203 BotScout BotScout tracks the names, IPs, and email addresses of bots involved in forum spam.
Blocklist Bots 205 Blocklist.de - Bots Blocklist.de is provided by a fraud specialist, whose servers are often attacked via SSH, Mail-Login, FTP, Webserver and other services. This feed contains Bot IPs which have been associated with Cybercrime.
Blocklist Apache Attacks 206 Blocklist.de - Brute Force Blocklist.de is provided by a fraud specialist, whose servers are often attacked via SSH, mail login, FTP, web server and other services. This feed contains IP addresses related to brute forcing Apache auth.
TOR Exit Nodes 207 Dan.me.uk - TOR Exit Nodes List of TOR Exit nodes provided by Dan.me.uk.
Botscout BOT IPs 211 Botscout - Bot IPs BotScout tracks the names, IPs, and email addresses of bots involved in forum spam.
Haley's Brute Force IPs 212 Haley's Brute Force IPs IP addresses launching SSH dictionary attacks. Provided by charles.the-haleys.org
VoIP Blacklist by ScopServ 217 VoIPBL.org - VoIP Blacklist VoIPBL is a distributed VoIP blacklist that is aimed to protect against VoIP Fraud and minimizing abuse for network that have publicly accessible PBX's.
Maxmind Proxy List 218 Maxmind - Anonymous Proxy List Maxmind Anonymous Proxy IPs.
Emerging Threats C&C Server 369 Emerging Threats C&C Server Emerging Threats fwrules rules.
ISC SANS Source IPs 221 Internet Storm Center - Daily Sources Internet Storm Center offers an open source feed of the most suspicious domain names.
SSL Malware Blacklist 222 Abuse.ch - SSL Blacklist - C&C IPs The SSL Blacklist (SSLBL) is a project of abuse.ch with the goal of detecting malicious SSL connections, by identifying and blacklisting SSL certificates used by botnet C&C servers.
Spamhaus Drop List 223 The Spamhaus Project - Drop List spamhaus.org - The Spamhaus Project is an international nonprofit organization that tracks spam and related cyber threats.
Spamhaus Extended Drop List 224 The Spamhaus Project - Extended Drop List spamhaus.org - The Spamhaus Project is an international nonprofit organization that tracks spam and related cyber threats.
VoIP Blacklist 227 VoIPBL.org by ScopServ VoIPBL is a distributed VoIP blacklist that is aimed to protect against VoIP Fraud and minimizing abuse for network that have publicly accessible PBX's.
vxvault URLs 231 VXVault - URLs VXVault is run by a security researcher who publishes malicious URLs, IPs, and file hashes found in malware samples.
SANS Top IPs 233 Internet Storm Center - Top IPs Internet Storm Center offers an open source feed of the top Attacking IPs.
DShield Scanning IPs 368 Internet Storm Center - DShield Scanning IPs Internet Storm Center offers an open source feed for scanning IPs.
PhishTank 238 PhishTank - Phishing URLs PhishTank is a free community site where anyone can submit, verify, track and share phishing data. PhishTank is operated by OpenDNS, a company founded in 2005 to improve the Internet through safer, faster, and smarter DNS.
BruteForcer IP Blocklist 367 BruteForcer IP Blocklist Abusive IPs reported via BruteForceBlocker from rulez.sk
Emerging Threats- Compromised IPS 301 Emerging Threats - Compromised IPs Compromised IPs from Proofpoint Emerging Threats
IAT-Blocklist 252 Blocklist.de - Apache Blocklist.de is provided by a fraud specialist, whose servers are often attacked via SSH, Mail-Login, FTP, Webserver and other services.
Nuug Pop3 Groper - Web 253 bsdly.net - POP3 Groper Provided by Peter N. M. Hansteen - These hosts have tried and failed to log on to the pop3 service at bsdly.net.
URLHaus 259 Abuse.ch - URLHaus - URLs URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.
blocklist - greensnow OSINT 289 GreenSnow.co - Blocklist GreenSnow is a team consisting of the best specialists in computer security, we harvest a large number of IPs from different computers located around the world. GreenSnow is comparable with SpamHaus.org for attacks of any kind except for spam.
cinsscore:ci-badguys OSINT 291 CINSscore.com - ci-badguys CINS Army feed is harvested from Emerging Threat's CINS system. It consists of IP addresses that either have a poor Rogue Packet score factor, or tripped a designated number of trusted alerts across their Sentinels.
URLHaus Hashes 295 Abuse.ch - URLHaus - Hashes URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.
abuse.ch - SSL Blacklist 297 Abuse.ch - SSL Blacklist - Malware File Hashes The SSL Blacklist (SSLBL) is a project of abuse.ch with the goal of detecting malicious SSL connections, by identifying and blacklisting SSL certificates used by botnet C&C servers.
Malware Bazaar Database 366 Abuse.ch - MalwareBazaar MalwareBazaar is a project from abuse.ch with the goal of sharing malware samples with the infosec community, AV vendors and threat intelligence providers.
Threatfox OSINT 328 Threatfox OSINT OSINT malware IOCs, powered by Abuse.ch.
Disconnect.me Malware and Malvertising 406 Disconnect Malware and Malvertising This feed contains malware/malvertising domains provided by Disconnect.me.
SANS Top 10 IPs 233 Internet Storm Center - Top IPs Internet Storm Center offers an open source feed of the top Attacking IPs.
ThaiCert 610 ThaiCERT ThaiCert Threat intel feed from ThaiCERT's Threat Group Cards—OSINT-based actor profiles with tactics, tools, and timelines to support campaign attribution and analysis.
MITRE Attack 611 MITRE ATT&CK Threat intelligence feed with MITRE ATT&CK group data—includes actor profiles, aliases, techniques, and tools to support threat mapping and defense.
Ransomware.live 650 Ransomware.live The feed tracks active ransomware group activity with real-time victim disclosures, group profiles, IOCs, TTPs, and YARA rules. It also monitors leak sites globally with sector tagging and geographic mapping.
Phishing Army 654 Phishing Army Free, community-driven blocklist of known phishing domains (including bare phishing domains without subdomains).
CERT.PL Malicious Domain Blocklist 653 CERT.PL Malicious Domain Blocklist Malicious domains from Poland's national CERT covering phishing, malware distribution, and C2 infrastructure. Daily updates with actionable blocking intelligence from OSINT and sinkhole operations.
Binary Defense 655 Binary Defense Auto-generated list of attacker IPs detected by Artillery honeypot sensors. Refreshes every 7 days by default, pulling from multiple threat sources every 2 hours.
Anomali Curated RSS OSINT 656 Anomali Open source intelligence reports collected and curated by Anomali. Sourced from hundreds of vetted RSS feeds spanning threat reports, vulnerability disclosures, and OSINT news.
ShadowWhisperer Malware Blocklist 657 ShadowWhisperer Community-maintained malware blocklist by ShadowWhisperer. Covers malicious sites, PUPs, hijackers, phishing. 98.5% unique intel with low OSINT overlap. Ideal for DNS blocking and threat hunting.
PhishHunt.io - Active Phishing Blocklist 658 PhishHunt.io Active phishing intel from PhishHunt.io targeting brand impersonation: Amazon, Netflix, Instagram, Facebook, MetaMask, iCloud. Fresh campaign infrastructure with specific URL paths. Ideal for phishing defense.
PhishDestroy 659 PhishDestroy Community-powered blocklist of phishing and scam domains, updated in real-time. Best used for DNS filtering and threat hunting.
TweetFeed 660 TweetFeed IOCs shared by the infosec community on X/Twitter — URLs, domains, IPs, and file hashes. Real-time, multi-type feed curated by active security researchers.
RansomLook.io - Ransomware OSINT Feed 661 RansomLook.io Ransomware OSINT intelligence from RansomLook.io tracking leak site posts, actor profiles with FBI/Europol/Interpol wanted notices, cryptocurrency wallets, and ransom notes. Complements ransomware.live with actor intelligence and financial tracking.
Anomali Dark Web Intelligence 675 Anomali Threat indicators from dark web sources including infrastructure, malware, and adversary tooling.
Anomali Threat Briefings 676 Anomali Rapid-response analyst briefings on emerging threats, zero days, and active campaigns.
Ransomfeed - Real-Time Ransomware Intelligence 677 Ransomfeed RSS Real-time monitoring of ransomware group activities and victim disclosures from leak sites, tracking 92+ active groups across 110+ countries with threat actor attribution and stolen data volumes.
URLhaus Hostfile 687 Abuse.ch High-fidelity hostfile feed from URLhaus (abuse.ch) identifying domains used for malware distribution. Ideal for DNS filtering, proactive threat hunting, and rapid incident response.