Skip to content

zenfokus/blacklists

Repository files navigation

IP Threat Intelligence Lists

A collection of freely available, regularly updated IP blacklists for use in firewalls, bunkerweb, apache waf, fail2ban, IDS/IPS, network security solutions, or threat hunting.

Overview of sources

File Description Source
blocklist_net_ua.list Malicious IPs according to blocklist.net.ua Link
dm_tor.list Active TOR exit and relay nodes Link
et_block.list Known malicious IPs from Emerging Threats Link
firehol-level4.list General malicious IPs – low risk Link
firehol_webserver.list Compromised or dangerous web servers Link
greensnow.list Attackers with suspicious behavior Link
iblocklist_ciarmy_malicious.list IPs with confirmed malicious behavior Link
spamhaus_drop.list Spamhaus DROP – known cybercrime networks Link
spamhaus_edrop.list Spamhaus eDROP – extended cybercrime IP list Link
stopforumspam.list IPs that have been flagged for forum spam Link

All-in-One List (AIO)

For easy integration into firewalls or network analyses, a consolidated blacklist is available that combines all of the above sources:

AIO blacklist:
https://raw.githubusercontent.com/zenfokus/blacklists/refs/heads/main/aio/aio_blacklist.list

This list is updated regularly and is ideal for productive use if only one central file is to be used.


License / Use

All lists come from publicly available sources. Please note the respective terms of use of the original sources. This collection is intended solely for research and security analysis.

About

A collection of curated IP and domain blacklists to block known threats, trackers, and malicious actors.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors