Automated IPv4 threat intelligence: combined blacklist from 100+ feeds with confidence scoring. Updated every 3h.
-
Updated
Sep 26, 2026 - Python
Automated IPv4 threat intelligence: combined blacklist from 100+ feeds with confidence scoring. Updated every 3h.
Collection of Azure Sentinel - Playbook | Logic App (Template)
Your daily summary of tracked changes for Webamon campaigns and emerging clusters seen across the web.
Security intelligence pipeline for aggregating hostile IP infrastructure, abuse feeds, anonymizers, and attack telemetry into runtime lookup databases.
Hourly plain-text mirror of the T.C. Siber Güvenlik Başkanlığı malicious address lists, split by type and category.
Unofficial, automatically updated threat-intelligence blocklists sourced from Türkiye’s public cybersecurity API. Firewall-ready domain, URL, IPv4 and IPv6 feeds.
SOC enrichment feeds: daily IPv4/IPv6 External Dynamic Lists (EDL) of public NTP pool servers and commercial VPN infrastructure. Plain text, one entry per line, ready for firewall lists, IDS datasets and SIEM lookups.
Free real-time phishing-domains threat feed (CC0 1.0), mirrored from phishunt.io. TXT/JSON/CSV + API + MCP.
Free, no-auth threat intelligence feeds: validated IOC blocklists (domains, IPs, hashes), threat clusters and CVE data, snapshotted daily. TLP:CLEAR — git history shows when an indicator first appeared. From ThreatCluster.
Scrolling threat feed
GreyNoise Project Swarm — Sensor Data Collector to Threat Feed
ThreatCull downloads public blocklists, drops duplicates, private ranges and your own infrastructure, scores each indicator by how many independent sources list it, and serves the result to your firewalls, DNS servers and SIEM.
Web interface for managing Lookout Mobile Endpoint Security threat feed blocklists
Daily and weekly threat intelligence briefs — CVEs, KEV, campaign intel, supply-chain attacks, IOC families. Fully automated.
Daily-curated blocklist feed for the ScamShield extension (OpenPhish + URLhaus, Tranco FP guard)
Automated CTI aggregator producing validated, deduplicated and firewall-ready IP, hash and URL threat feeds every hour.
To associate your repository with the threat-feed topic, visit your repo's landing page and select "manage topics."