Available Open Source Feeds
The table below contains the active open source feeds aggregated by ThreatStream.
Tip: Use the Circle ID to search for intelligence provided by the feed. For example, to search for intelligence provided by the Emerging Threats - Compromised feed, enter the following advanced search query:
(trusted_circle_id = 371)
See Performing Advanced Observable Searches for more information.
| Feed Name | Circle ID | Circle Name | Circle Description |
|---|---|---|---|
| Emerging Threats - Compromised | 371 | Emerging Threats - Compromised | Rules to block known hostile or compromised hosts. |
| CI Army | 193 | CI Army List | CI Army is a open source IP reputation list driven by collective intelligence of Sentinel IPS's MSSP customer base. |
| Project Honeypot | 194 | Project Honeypot | Project Honeypot, created by Unspam, is a community sponsored Honey Network and reports malicious IP's worldwide. |
| Bot Scout IP | 203 | BotScout | BotScout tracks the names, IPs, and email addresses of bots involved in forum spam. |
| Blocklist Bots | 205 | Blocklist.de - Bots | Blocklist.de is provided by a fraud specialist, whose servers are often attacked via SSH, Mail-Login, FTP, Webserver and other services. This feed contains Bot IPs which have been associated with Cybercrime. |
| Blocklist Apache Attacks | 206 | Blocklist.de - Brute Force | Blocklist.de is provided by a fraud specialist, whose servers are often attacked via SSH, mail login, FTP, web server and other services. This feed contains IP addresses related to brute forcing Apache auth. |
| TOR Exit Nodes | 207 | Dan.me.uk - TOR Exit Nodes | List of TOR Exit nodes provided by Dan.me.uk. |
| Botscout BOT IPs | 211 | Botscout - Bot IPs | BotScout tracks the names, IPs, and email addresses of bots involved in forum spam. |
| Haley's Brute Force IPs | 212 | Haley's Brute Force IPs | IP addresses launching SSH dictionary attacks. Provided by charles.the-haleys.org |
| VoIP Blacklist by ScopServ | 217 | VoIPBL.org - VoIP Blacklist | VoIPBL is a distributed VoIP blacklist that is aimed to protect against VoIP Fraud and minimizing abuse for network that have publicly accessible PBX's. |
| Maxmind Proxy List | 218 | Maxmind - Anonymous Proxy List | Maxmind Anonymous Proxy IPs. |
| Emerging Threats C&C Server | 369 | Emerging Threats C&C Server | Emerging Threats fwrules rules. |
| ISC SANS Source IPs | 221 | Internet Storm Center - Daily Sources | Internet Storm Center offers an open source feed of the most suspicious domain names. |
| SSL Malware Blacklist | 222 | Abuse.ch - SSL Blacklist - C&C IPs | The SSL Blacklist (SSLBL) is a project of abuse.ch with the goal of detecting malicious SSL connections, by identifying and blacklisting SSL certificates used by botnet C&C servers. |
| Spamhaus Drop List | 223 | The Spamhaus Project - Drop List | spamhaus.org - The Spamhaus Project is an international nonprofit organization that tracks spam and related cyber threats. |
| Spamhaus Extended Drop List | 224 | The Spamhaus Project - Extended Drop List | spamhaus.org - The Spamhaus Project is an international nonprofit organization that tracks spam and related cyber threats. |
| VoIP Blacklist | 227 | VoIPBL.org by ScopServ | VoIPBL is a distributed VoIP blacklist that is aimed to protect against VoIP Fraud and minimizing abuse for network that have publicly accessible PBX's. |
| vxvault URLs | 231 | VXVault - URLs | VXVault is run by a security researcher who publishes malicious URLs, IPs, and file hashes found in malware samples. |
| SANS Top IPs | 233 | Internet Storm Center - Top IPs | Internet Storm Center offers an open source feed of the top Attacking IPs. |
| DShield Scanning IPs | 368 | Internet Storm Center - DShield Scanning IPs | Internet Storm Center offers an open source feed for scanning IPs. |
| PhishTank | 238 | PhishTank - Phishing URLs | PhishTank is a free community site where anyone can submit, verify, track and share phishing data. PhishTank is operated by OpenDNS, a company founded in 2005 to improve the Internet through safer, faster, and smarter DNS. |
| BruteForcer IP Blocklist | 367 | BruteForcer IP Blocklist | Abusive IPs reported via BruteForceBlocker from rulez.sk |
| Emerging Threats- Compromised IPS | 301 | Emerging Threats - Compromised IPs | Compromised IPs from Proofpoint Emerging Threats |
| IAT-Blocklist | 252 | Blocklist.de - Apache | Blocklist.de is provided by a fraud specialist, whose servers are often attacked via SSH, Mail-Login, FTP, Webserver and other services. |
| Nuug Pop3 Groper - Web | 253 | bsdly.net - POP3 Groper | Provided by Peter N. M. Hansteen - These hosts have tried and failed to log on to the pop3 service at bsdly.net. |
| URLHaus | 259 | Abuse.ch - URLHaus - URLs | URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution. |
| blocklist - greensnow OSINT | 289 | GreenSnow.co - Blocklist | GreenSnow is a team consisting of the best specialists in computer security, we harvest a large number of IPs from different computers located around the world. GreenSnow is comparable with SpamHaus.org for attacks of any kind except for spam. |
| cinsscore:ci-badguys OSINT | 291 | CINSscore.com - ci-badguys | CINS Army feed is harvested from Emerging Threat's CINS system. It consists of IP addresses that either have a poor Rogue Packet score factor, or tripped a designated number of trusted alerts across their Sentinels. |
| URLHaus Hashes | 295 | Abuse.ch - URLHaus - Hashes | URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution. |
| abuse.ch - SSL Blacklist | 297 | Abuse.ch - SSL Blacklist - Malware File Hashes | The SSL Blacklist (SSLBL) is a project of abuse.ch with the goal of detecting malicious SSL connections, by identifying and blacklisting SSL certificates used by botnet C&C servers. |
| Malware Bazaar Database | 366 | Abuse.ch - MalwareBazaar | MalwareBazaar is a project from abuse.ch with the goal of sharing malware samples with the infosec community, AV vendors and threat intelligence providers. |
| Threatfox OSINT | 328 | Threatfox OSINT | OSINT malware IOCs, powered by Abuse.ch. |
| Disconnect.me Malware and Malvertising | 406 | Disconnect Malware and Malvertising | This feed contains malware/malvertising domains provided by Disconnect.me. |
| SANS Top 10 IPs | 233 | Internet Storm Center - Top IPs | Internet Storm Center offers an open source feed of the top Attacking IPs. |
| ThaiCert | 610 | ThaiCERT | ThaiCert Threat intel feed from ThaiCERT's Threat Group Cards—OSINT-based actor profiles with tactics, tools, and timelines to support campaign attribution and analysis. |
| MITRE Attack | 611 | MITRE ATT&CK | Threat intelligence feed with MITRE ATT&CK group data—includes actor profiles, aliases, techniques, and tools to support threat mapping and defense. |
| Ransomware.live | 650 | Ransomware.live | The feed tracks active ransomware group activity with real-time victim disclosures, group profiles, IOCs, TTPs, and YARA rules. It also monitors leak sites globally with sector tagging and geographic mapping. |
| Phishing Army | 654 | Phishing Army | Free, community-driven blocklist of known phishing domains (including bare phishing domains without subdomains). |
| CERT.PL Malicious Domain Blocklist | 653 | CERT.PL Malicious Domain Blocklist | Malicious domains from Poland's national CERT covering phishing, malware distribution, and C2 infrastructure. Daily updates with actionable blocking intelligence from OSINT and sinkhole operations. |
| Binary Defense | 655 | Binary Defense | Auto-generated list of attacker IPs detected by Artillery honeypot sensors. Refreshes every 7 days by default, pulling from multiple threat sources every 2 hours. |
| Anomali Curated RSS OSINT | 656 | Anomali | Open source intelligence reports collected and curated by Anomali. Sourced from hundreds of vetted RSS feeds spanning threat reports, vulnerability disclosures, and OSINT news. |
| ShadowWhisperer Malware Blocklist | 657 | ShadowWhisperer | Community-maintained malware blocklist by ShadowWhisperer. Covers malicious sites, PUPs, hijackers, phishing. 98.5% unique intel with low OSINT overlap. Ideal for DNS blocking and threat hunting. |
| PhishHunt.io - Active Phishing Blocklist | 658 | PhishHunt.io | Active phishing intel from PhishHunt.io targeting brand impersonation: Amazon, Netflix, Instagram, Facebook, MetaMask, iCloud. Fresh campaign infrastructure with specific URL paths. Ideal for phishing defense. |
| PhishDestroy | 659 | PhishDestroy | Community-powered blocklist of phishing and scam domains, updated in real-time. Best used for DNS filtering and threat hunting. |
| TweetFeed | 660 | TweetFeed | IOCs shared by the infosec community on X/Twitter — URLs, domains, IPs, and file hashes. Real-time, multi-type feed curated by active security researchers. |
| RansomLook.io - Ransomware OSINT Feed | 661 | RansomLook.io | Ransomware OSINT intelligence from RansomLook.io tracking leak site posts, actor profiles with FBI/Europol/Interpol wanted notices, cryptocurrency wallets, and ransom notes. Complements ransomware.live with actor intelligence and financial tracking. |
| Anomali Dark Web Intelligence | 675 | Anomali | Threat indicators from dark web sources including infrastructure, malware, and adversary tooling. |
| Anomali Threat Briefings | 676 | Anomali | Rapid-response analyst briefings on emerging threats, zero days, and active campaigns. |
| Ransomfeed - Real-Time Ransomware Intelligence | 677 | Ransomfeed RSS | Real-time monitoring of ransomware group activities and victim disclosures from leak sites, tracking 92+ active groups across 110+ countries with threat actor attribution and stolen data volumes. |
| URLhaus Hostfile | 687 | Abuse.ch | High-fidelity hostfile feed from URLhaus (abuse.ch) identifying domains used for malware distribution. Ideal for DNS filtering, proactive threat hunting, and rapid incident response. |