Research

Choosing Open IP Threat Intelligence—The Best Stack for July 2026 and Its Measured Cut Line

SOSEC's public baseline uses Spamhaus DROP/DROPv6 for perimeter ranges, three days of ThreatFox botnet_cc for 72-hour outbound IP:port and domain controls, Feodo on standby with valid-empty support, and DataPlane, DShield, and GreyNoise for observation, throttling, and analysis; aggregate mega-lists receive no default deny authority, and a frozen-snapshot replay verifies compilation, quarantine, expiry, and rollback.

On a black-and-gold warm-paper investigation desk, many observation streams pass through mirrors, clocks, a magnifier, and a policy gate before reaching a blocking shield, an observation queue, or quarantine
In this article

Research basisAs of 2026-07-25, this census covers threat, attack, abuse, malicious-infrastructure, scanner, anonymity, routing-risk, and aggregate IP/CIDR products obtainable without an individual commercial contract. It consolidates 503 catalog records into 332 endpoints or files, including 318 HTTP URLs. The fixed measurement selects 130 distinct network URLs, makes 133 network attempts across initial retrieval, URL corrections, and retries, and reads six commit-pinned local repository files. Among 139 analyzed records, 105 yield parseable IP data. Domain-, URL-, and hash-only sources remain in the boundary census; registration and free-key sources, dead endpoints, and historical products remain in governance review; commercial institutions are studied without adding paid data to the public-IP union. The pre-deployment replay separately pins eight product artifacts, ten official public-network controls, and one commit-pinned scanner control for hash verification, action compilation, collision measurement, six deterministic input-fault injections, and four clock-advance and rollback checks. Control collisions measure policy risk and cannot replace traffic replay and adjudicated events inside each consuming organization.

SourceOfficial Spamhaus, abuse.ch, SANS ISC, DataPlane, GreyNoise, and MISP material / NIST, CISA, OASIS, FIRST, USENIX, and academic measurements / four public catalogs and commit-pinned project sources / SOSEC 2026-07-25 market census, set analysis, freshness, policy collisions, policy compilation, and fault-injection replay

1 What to connect now: SOSEC's default public-intelligence stack

The answer: a new IP-intelligence program should start with Spamhaus DROP/DROPv6 and the last three days of ThreatFox botnet_cc. DROP owns malicious network ranges at the perimeter. ThreatFox owns precise outbound C2 decisions by IP:port and domain. Keep Feodo recommended connected while treating its current effective-rule count as zero. Add DataPlane only for protocols actually exposed on an Internet-facing service, use DShield Top 20 for observation and throttling, and reserve GreyNoise Community for analyst lookups. MISP can manage the evidence. Aggregate mega-lists receive no default blocking authority. The offline replay compiled 1,760 DROP prefix objects and 3,204 high-confidence recent ThreatFox objects; the old Feodo row, DataPlane, DShield, FireHOL, and IPsum received zero unconditional deny rules.

The stack is intentionally thin. Each source performs the job supported by its strongest evidence. DROP covers network space under malicious operational control. ThreatFox carries malware family, IOC type, confidence, and time into an outbound rule. Feodo waits for a valid protocol response from a C2 before a rule becomes active. DataPlane and DShield describe inbound activity. GreyNoise helps an analyst identify broad scanning and known business services. Clear ownership gives every address a clock, a decision maker, and a removal path.

The required layer has two active data lines. DROP/DROPv6 is the strongest freely obtainable network-range product for direct router and firewall enforcement in this market. ThreatFox is the most useful broad public-community source for current malicious infrastructure. Production use should narrow its official API or export to recent botnet_cc records while preserving port, domain, confidence, first_seen, last_seen, and is_compromised. Flattening the six-month export into a permanent IP list discards the structure that makes the product useful.

Feodo is the third line: connected and currently issuing no rules. Its design is unusually strong. An address enters the recommended list only after it returns a valid botnet C2 response; files are generated every five minutes; the data is CC0. The official FAQ currently says law-enforcement takedowns have left the datasets empty. SOSEC's July 25 07:00 UTC pin of the recommended text still contained one address last updated on March 4. A production system should accept a format-valid empty set, quarantine that stale state-conflicting record, and resume automatically when the official status and endpoint agree again.

Inbound attack-source feeds get lighter actions. A raw DataPlane file describes itself as “informational” and “not a block list,” then warns about NAT, source spoofing, and research measurement. It fits alerting, connection throttling, or challenges on a matching exposed service such as SSH or SIP. DShield block.txt contains the 20 most active /24 networks over three days. Fourteen of the 20 in our snapshot intersected the scanner control set, and the list directly included Google Cloud, Internet-measurement, and security-scanning organizations. The feed quickly shows where volume is coming from. An Internet-wide, all-protocol hard block assigns far more force than the observation supports.

1.1 Endpoints, actions, clocks, and failure handling for the engineering change

This is the production configuration behind the recommendation. The parameters reflect SOSEC's 2026-07-25 pinned snapshot, the publishers' product definitions, and the control-collision experiment. Each organization still needs negative controls for its own address space, essential SaaS, partners, authorized scanners, and egress. Every rule should retain source, version, retrieval time, object type, direction, port, validity, and removal record.

Spamhaus DROP / DROPv6: hard blocking at the perimeter

Official endpoint
drop_v4.json and drop_v6.json; networks that operate BGP policy can also consume ASN-DROP. Use the official JSON. The legacy text formats are on a deprecation path.
Action
Reject matching prefixes bidirectionally at the Internet edge and preserve DNS, proxy, and firewall hit logs. The pinned snapshot contains 1,669 distinct IPv4 prefixes and 91 IPv6 prefixes. SBL, XBL, PBL, and ZEN have different semantics and should have separate policies.
Update and removal
Use conditional retrieval daily, verify metadata, count, and hash, then atomically replace the set. Remove an address when its official SBL record leaves DROP. A failed retrieval may keep the last known-good version for up to 48 hours; expiry then raises an alert and requires an explicit operator decision.
Release control
Collide the candidate set with owned prefixes, partners, CDNs, and critical SaaS before activation. This experiment found two DROP /23 prefixes inside Cloudflare's published broad range. Organizations that depend on Cloudflare should replay their real service paths before the change.

ThreatFox recent botnet_cc: short-lived outbound control

Official endpoint
POST {"query":"get_iocs","days":3} to the Community API at https://threatfox-api.abuse.ch/api/v1/, or use an official export. The days parameter filters on first_seen; the API requires a free Auth-Key, while the pinned public recent CSV was retrievable without one. The community service has fair-use limits, and commercial use may require the enhanced API. A third-party GitHub mirror is useful for availability research only.
Filter
Take the latest three days and retain threat_type=botnet_cc. Send IP:port and domains to separate network and DNS/proxy policies. Automated enforcement requires confidence_level >= 75. The pinned recent CSV had 4,302 rows: 3,332 botnet C2 records comprising 2,400 IP:port values, 818 domains, and 114 URLs. Applying max(first_seen,last_seen), the 72-hour clock, and the confidence gate compiles 3,204 objects: 2,317 IP:port values, 777 domains, and 110 URLs.
Action
Block only the matching outbound destination and port, reject domains at enterprise DNS or the proxy, and leave URLs to Web controls. A device that accepts only bare IPs should alert first. Promote to full-IP blocking after an independent signal or local C2 behavior confirms the decision.
Refresh and expiry
Retrieve every 15 to 30 minutes and retain each record for 72 hours from max(first_seen,last_seen). Publisher removal triggers immediate withdrawal. An expired update removes records from enforcement while keeping the source-health alert active, which prevents a short-lived cloud instance from becoming a permanent bad address.

Feodo recommended: high-confidence C2 on standby

Official endpoint
ipblocklist_recommended.txt or JSON, with no key, under CC0, generated every five minutes. The publisher recommends retrieval every 5 to 15 minutes.
Action
Use active records only for outbound destination blocking. Send the official 30-day and aggressive historical products to SIEM hunting. The aggressive version carries an explicit high-false-positive warning.
Current state
The FAQ currently describes the datasets as empty; the pinned endpoint still carried one March record. Quarantine that row and publish zero effective rules. A valid empty set creates a successful update receipt and a zero-rule release.
Failure handling
HTML, truncation, a backward-moving time, or a conflict between service status and content triggers quarantine. Existing rules leave enforcement when their short validity expires, traffic returns to the ordinary path, and the SOC retains a source-failure alert.

DataPlane / DShield / GreyNoise: inbound and analyst support

DataPlane
Retrieve only official files that match protocols genuinely exposed by the organization, such as sshpwauth.txt for SSH password authentication, at most hourly, and keep records for no more than seven days from lastseen. Default to alerting or throttling. Raw signals are free for noncommercial use; commercial use requires permission, and redistribution is restricted.
DShield
Update block.txt at most hourly, retain its three-day window, apply it to inbound connections, and begin in shadow or throttle mode. The general feed documentation permits commercial use with attribution and no resale, while the current file header points to CC BY-NC-SA 2.5; obtain written clarification before a commercial deployment. Source-attribution uncertainty and scanner collisions prevent automatic promotion to an all-protocol /24 block.
GreyNoise
Use https://api.greynoise.io/v3/community/{ip} for human review of high-value hits. It returns noise, riot, classification, and last_seen. Anonymous access allows 10 lookups per day; a free business-email account provides 50 searches per week. That capacity serves analyst triage.
Shared exit test
Remove a source from production when 30 consecutive days produce no unique correct event, alerts merely duplicate another source, the license stops covering the use, removal latency exceeds the validity window, or business exceptions keep growing.

HTML, a zero-byte body, field drift, an abnormal count, or a backward timestamp places the new download in quarantine. Publishing keeps two known-good versions, replaces a ruleset atomically, and exposes a kill switch for each source. DROP can use a failure grace measured in days. ThreatFox and Feodo require one measured in hours because their objects age faster.

1.2 Three deployment profiles

A small team's minimum stack is DROP/DROPv6, ThreatFox recent botnet C2, and Feodo recommended on standby. Connect the official ThreatFox interface when its terms cover the present use. If commercial use requires the enhanced API, buy the appropriate access or benchmark a commercial C2 product. Relabeling a community mirror as a permanent free substitute loses license clarity, structured fields, and service accountability.

An Internet-service operator adds one DataPlane or blocklist.de signal that matches an exposed service, runs it in shadow for seven days, and then decides whether throttling or challenge is justified. DShield Top 20 highlights large scanning concentrations; GreyNoise samples the identities behind them. Web registration, forum, and account abuse may also use StopForumSpam, AbuseIPDB, or HTTP:BL as application-level scores and challenge inputs.

A mature SOC uses MISP to preserve events, attributes, tags, source, decay, and sharing scope. Enforcement devices still subscribe only to narrow sets that passed the action gate. FireHOL, IPsum, Bitwire, Data-Shield, malicious-ip, and historical C2 products stay in hunting and source-research collections. MISP is this study's preferred open-source management platform; feed quality remains an editorial and operational decision.

Four address situations enter a black-and-gold policy gate and split by evidence and business impact into blocking, throttling or challenge, alert and enrichment, context only, and quarantine, with feedback returning to the decision desk
Figure 1. The winning stack depends on division of labor. Malicious network ranges, current C2, inbound scanners, shared cloud, and research scanning enter different actions; stronger actions require narrower objects, newer evidence, and faster removal.

2 Why this stack wins: match products to actions before comparing coverage

“Best” needs an assigned job. Spamhaus DROP/DROPv6 wins for network-range enforcement at the edge. ThreatFox recent is the first choice for current, broad public-community malicious infrastructure. Feodo recommended wins among free C2 products that validate protocol response, with zero current coverage. DataPlane is the clearest protocol-specific Internet-edge observation product. GreyNoise wins for scanner-context lookup. MISP is the open-source intelligence-management choice. FireHOL is the strongest public aggregate catalog. A single league table would erase the uses that make each winner valuable.

DROP wins on action semantics and removal. Spamhaus defines the objects as network space controlled by professional spam or cybercrime operations, advises dropping all traffic, and ties records to removable SBL entries. The pinned snapshot's 1,669 distinct IPv4 prefixes cover about 14.9 million addresses, a manageable footprint, and the publisher reviews the product daily. This is an edited network-range decision with a clear operational owner.

ThreatFox wins on breadth and structure for current public C2. Among 3,332 botnet C2 records in the pinned recent CSV, 2,400 preserve IP and port and 3,032 carry last_seen. Consolidation before the confidence gate yields 1,741 distinct IPv4 addresses, including 169 inside DROP ranges. The production compiler then applies confidence_level >= 75 and the 72-hour clock, yielding 1,686 distinct IPv4 addresses: 167 inside DROP and 1,519 outside it. Roughly nine out of ten extend coverage beyond DROP's host population. The low overlap follows the jobs: one line assesses whole-network control; the other describes a specific malware communication endpoint.

Feodo wins on validation design and currently provides no active coverage. It tracks a defined group of botnet families and requires a valid C2 response from an address. Successful takedowns should therefore produce an empty list. Organizations that need broad, verified live C2 still have a procurement gap. Feodo's FAQ points readers to Spamhaus BCL, a commercial or partner-distributed product. Today's public free market has no single C2 IP file combining broad coverage, active validation, unrestricted commercial consumption, complete removal, and anonymous access.

Inbound attack data wins an observation and traffic-management role. DataPlane spans more than 300 nodes, 65 metropolitan areas, and six continents, with separate files for SSH, SIP, DNS, and other behavior; it also warns consumers about the interpretation boundary. DShield compresses worldwide reports into an operational Top 20 /24. That convenience can carry cloud, research scanning, and hostile traffic together. Both products help defend the services that generated the observation. Cross-protocol permanent blocking exceeds their evidence.

2.1 Five admission questions turn reputation into executable evidence

A source earns a place in the default stack by answering five questions in order: what behavior did it see; where did it see it; when was the record last valid; who removes an error; and what action will a hit trigger? DROP, ThreatFox, and Feodo answer most of these within their narrow scopes. DataPlane and DShield perform well on behavior and time, so their action stops at observation, throttling, or challenge. GreyNoise Community provides per-IP query capacity and belongs at the analyst desk.

License and redistribution rights are admission criteria. Spamhaus DROP is free across organization sizes and business types under attribution and product-marketing restrictions. Feodo uses CC0. DShield's general feed documentation permits commercial use with attribution and no resale, while the current block.txt header cites CC BY-NC-SA 2.5; commercial deployment requires written clarification. ThreatFox Community is free under fair-use conditions, while commercial use may require a paid API. DataPlane raw signals are free only for noncommercial use. “Publicly downloadable” describes access; the current terms determine production rights.

2.2 Four hits on the same day should produce four different decisions

Start with a high-confidence ThreatFox record. An employee endpoint is connecting to a botnet_cc IP:port that was still active forty minutes ago. The network control rejects only that outbound destination and port, EDR isolates the originating endpoint, and the SOC follows the domain, process, DNS, and related traffic. The rule expires automatically after 72 hours and leaves immediately if the publisher withdraws it sooner. The hit connects directly to malware communication, with direction, port, time, and affected asset all known, so it can support a strong action.

At the same time, an Internet-facing service receives probes from a DShield Top 20 /24, and DataPlane has observed that source against the matching protocol. The service raises the cost only where the scanning occurs: throttle SSH, challenge a login, or temporarily block the individual source IP while preserving the session. If the /24 collides with a known research scanner, the analyst checks GreyNoise, the scanner's official identity, and the local request. Agreement between two feeds strengthens the finding of scanning activity; it leaves the rest of the /24, other protocols, and outbound traffic outside the action.

A third hit falls inside a DROP prefix. The edge rejects the network range bidirectionally and records the product version plus the SBL-linked withdrawal path. If pre-deployment negative controls show that a real customer path traverses the range, the change pauses while the network team confirms CDN, proxy, or partner routing. DROP's editorial semantics support the strong action, and the negative control exposes this organization's exceptional cost. Hit count has no role in that decision.

The fourth update comes from Feodo: identity, format, and time checks pass, and the product delivers an empty set. The system publishes zero rules, records a successful update, and declines to restore the old March address. Operations can see that takedown feedback has reached the control plane. All four decisions use the same rule: identify the object and behavior carried by the evidence, then assign a proportionate action. Source count adds confidence only when behavior, direction, and time also agree.

2.3 From frozen snapshot to deployable policy: offline compilation and fault replay

This experiment answers an engineering question: what reaches the enforcement plane after a frozen delivery passes identity, format, clock, action, and control-set gates? The inputs are eight product artifacts, ten official public-network controls, and one commit-pinned scanner control. Each artifact first passes byte-count and SHA-256 verification, then compiles into the direction, protocol, action, and TTL proposed by this report. Public-cloud, service-range, crawler, and scanner collisions indicate deployment risk. Threat-detection precision, recall, and business false-positive rate require independent local traffic and adjudicated labels, so this replay leaves those measures open.

The replay anchor is the timestamp published in the ThreatFox artifact: . DROP validation checks every JSON object, cidr, sblid, and the metadata record count. ThreatFox requires 15 fields per row before the botnet_cc, confidence 75, and max(first_seen,last_seen) 72-hour gates. Feodo, DataPlane, DShield, FireHOL, and IPsum are normalized through their pinned formats. “Compiled output” in the table records the objects granted policy authority; raw list size remains in the input column.

Source and frozen inputPolicy compiler outputControl collision and fault checkOperational decision
Spamhaus DROP/DROPv6
1,669 IPv4 prefixes and 91 IPv6 prefixes. IPv4 metadata declares 1,670 records; normalization removes one duplicate.
1,760 bidirectional edge-deny objects scoped to the listed prefixes. Other SBL, XBL, PBL, and ZEN products inherit no authority.Two prefixes intersect published Cloudflare ranges across 1,024 addresses; five intersect the scanner control across 217 addresses. Metadata count and hashes pass.Admit to hard blocking after replaying owned, partner, CDN, and critical-SaaS paths. A known-good version may be retained automatically for at most 48 hours.
ThreatFox recent botnet_cc
4,302 raw rows, including 3,332 botnet C2 records.
The 72-hour and confidence gates pass 3,204 objects: 2,317 IP:port, 777 domains, and 110 URLs. IP:port consolidation yields 1,686 distinct IPv4 addresses, including 1,519 outside DROP.Among distinct IPv4 addresses, 35 fall in published AWS ranges, 16 in GitHub service ranges, and 14 in published Google ranges. Field count, clocks, and hash pass.Send IP:port only to outbound destination-and-port policy, domains to DNS, and URLs to the proxy. Every object expires in 72 hours; collided addresses require asset and session context.
Feodo recommended
The body contains one syntactically valid IPv4 row. Its file timestamp is 2026-03-04, 3,425.04 hours old at replay.
Zero outbound deny rules. The old row enters quarantine, while a valid empty set may publish zero rules.The old row falls in a published AWS range. The state machine accepts an empty current generation and keeps the March row out of enforcement.Keep a standby subscription. Short-lived rules resume after time, format, and publisher active state agree again.
DataPlane SSH
11,450 distinct IPv4 addresses.
Zero hard-block rules and 11,450 SSH observation keys, scoped to services that actually expose SSH.152 addresses fall in published Google ranges, 114 in GitHub service ranges, 13 in AWS, and four in the scanner control.Shadow, alert, throttle, or challenge. Commercial use first resolves licensing; other protocols receive no inherited signal.
DShield Top 20
Twenty /24s covering 5,120 IPv4 addresses.
Zero all-protocol hard blocks and twenty inbound shadow or throttle scopes.Fourteen /24s intersect the scanner control across 3,401 addresses, 66.43% of listed coverage.Observe or raise friction on matching inbound services. Whole-prefix, all-protocol, bidirectional deny fails the action gate.
FireHOL Level 1 baseline
4,588 objects covering 611,303,425 IPv4 addresses.
Zero unconditional default-deny rules. Upstream lineage, object meaning, action, and TTL require separate treatment.Two prefixes intersect Cloudflare ranges across 1,024 addresses; sixteen intersect the scanner control across 3,023 addresses.Retain as a strong catalog and upstream discovery surface. Aggregate size grants no enforcement authority.
IPsum Level 1 baseline
110,687 distinct IPv4 addresses.
Zero unconditional default-deny rules. Records enter hunting, consensus, and source study.13,061 addresses fall in the scanner control, 2,961 in AWS, 2,489 in GitHub service ranges, 3,198 in published Google ranges, and 43 in Google crawler ranges.List count describes capacity. Each upstream's behavior and clock determine any action.

The collisions explain why repeated appearance across lists cannot automatically strengthen an action. ThreatFox contributes 1,519 enforcement-layer IPv4 addresses outside DROP, while 167 are already inside it, giving the source a clear marginal role. IPsum's 13,061 scanner-control collisions and DShield's 66.43% coverage collision show that both products carry substantial scanner semantics suited to inbound context and traffic management. Addresses in Cloudflare, AWS, Google, or GitHub ranges may host a malicious tenant or legitimate service. Session, port, asset, and adjudicated outcome determine the final label.

The fault replay executed six input cases and passed all six. A changed pinned hash, an HTTP 200 HTML body, truncated DROP NDJSON, ThreatFox field drift, and timestamp regression were rejected; none of those five candidates changed the active generation. A current, valid empty set was accepted and compiled to zero rules. Four lifecycle checks then passed: a DROP candidate that cleared format and hash gates became active before an injected deployment-health failure restored the previous generation; one hour after a ThreatFox refresh failure, 3,204 rules remained active, and advancing beyond every object's 72-hour deadline reduced the set to zero; DROP switched from automatic retention to operator decision at hour 48; and the March Feodo row could not replace the accepted empty generation. Retrieval, parsing, compilation, expiry, and rollback now form an executed closed path.

This extension establishes a reproducible cross-sectional measurement and deployment-gate replay. Blocklist Babel used six months of repeated collection to study record survival, overlap evolution, and propagation, showing why a one-day union cannot carry those longitudinal claims. A publishable effectiveness study still needs a preregistered 90-to-180-day experiment: fixed collection cadence and missing-sample handling; the same candidates at an ISP, an ordinary enterprise, and a cloud-hosting operator; event labels stratified by asset class and action; time to first correct hit, unique correct incidents per million connections, legitimate impact, removal survival, and analyst labor; and paired bootstrap confidence intervals over shared events. Longitudinal truth would support conditional precision, recall, and operating-cost comparisons. The current table supplies the frozen inputs, compilation rules, negative controls, failure model, and evidence boundary required to run that study.

3 What the census covered: 503 catalog records narrowed to 105 parseable datasets

The census began by merging MISP default feeds, the FireHOL catalog, Maltrail configuration, the Bert-JanP catalog, and manual additions, producing 503 candidate records. Consolidating aliases of the same file, format copies, and explicit mirrors left a delivery surface of 332 endpoints or files, including 318 HTTP URLs. Candidates cover routing governance, current C2, attack sources, honeypots, community reports, anonymity networks, scanners, cloud and service ranges, aggregators, legacy projects, and adjacent products centered on domains, URLs, certificates, or samples.

Five groups of black-and-gold archive drawers send public intelligence records into a sieve, which separates exact IP, network range, mixed indicators, authentication-required, dead endpoint, and excluded outputs
Figure 2. Endpoint consolidation, object identification, and access boundaries narrow the market entrance. Domain, URL, and hash products remain in the institutional and governance review; only pinned products that deliver IP/CIDR enter the set experiment.

The fixed measurement selected 130 distinct network URLs, made 133 requests across initial retrieval, URL correction, and retries, and read six commit-pinned local repository files. Network requests returned HTTP 200 on 109 attempts; authentication, 404, rate limit, transport, or other failures ended 24. Three successful responses delivered a login page, terms page, or redirect HTML. The 99 parseable network IP datasets plus six local files produced 105 experimental datasets.

The cohort intentionally includes direct products, format mirrors, aggregators, control sets, dead endpoints, and the long tail, so it can answer how market data is copied, ages, and collides with policy. It is a purposive sample of the 318 URLs. Retrieval success describes this queue on this date. Selection rules, request receipts, hashes, and research time bind the result.

3.1 Eight address classes carry eight meanings

Routing-level malicious ranges describe network control. Current C2 describes destinations used by infected hosts. Service attack sources describe time-bounded behavior against a protocol. Community reports describe submissions and scoring. Aggregators describe a composition of upstreams. Tor, VPN, and proxies describe anonymity. Scanners and crawlers describe identity and measurement behavior. Cloud, CDN, public DNS, and bogon data describe infrastructure or routing context. The class determines direction, port, TTL, and action.

Mirrors, format conversions, and time-window files retain delivery value, while evidence votes are counted at the root observer. Feodo CSV, JSON, and text are one product. Official ThreatFox data and a GitHub mirror share a root. FireHOL levels combine several lists. An IPsum threshold may consume aggregated upstreams again. Preserving lineage tells the consumer whether five hits represent five observers or one observation copied five times.

4 The real structure of mega-lists: one-third duplicated membership and four-fifths single-source addresses

After per-source deduplication, 99 datasets containing exact IPv4 produced 8,433,954 membership observations and a union of 5,702,621 addresses. The 2,731,333 memberships beyond the union create a 32.38 percent duplicate rate. Within the union, 4,695,398 addresses appear in one dataset, or 82.34 percent, while the maximum frequency is 37. Concatenation spends rules and analyst time on copies; a two-list vote discards most unique observations.

On warm paper, three black-and-gold horizontal bars have different lengths, a matrix contains many gold dots and a smaller number of blue and red hollow dots, and a three-color bar tail descends at right
Figure 3. Some 8,433,954 memberships converge into 5,702,621 addresses. High duplication and high singleton share coexist, so quality has to return to purpose, root source, and time.

Purpose-specific cohorts tell more. Nineteen current aggregate datasets contain 1,286,587 memberships and an 806,156-address union, for 37.34 percent duplicates. Eight current C2 datasets show only 12.53 percent duplicates and 88.59 percent singletons. The attack-source cohort has a 38.44 percent duplicate rate; current outbound aggregates reach 50.89 percent. A rare C2 address may be new or may come from one weak source. High consensus in an aggregate cohort often reflects shared upstreams.

Three independent black-and-gold observation sources expand through mirrors, format conversion, and aggregation into many lists; one scale piles up every file while another regroups the files into three root lineages
Figure 4. Mirror, format conversion, and re-aggregation inflate file count. Lineage consolidation restores root observers before measuring independent coverage.

IPInsights' 651,035 exact addresses completely contain IPsum L1, L2, and L3; IPsum L3 and OpenDBL IPsum are identical in the snapshot. Of 173,859 exact IPv4 addresses in Bitwire outbound, 158,817 also occur in inbound, a 91.35 percent containment. Product names, direction labels, and download URLs can make the independent information look much larger than it is.

4.1 Popular projects that leave the default blocking path

FireHOL is the best public list catalog and aggregate-research entrance. Level 1 combines fullbogons, Spamhaus DROP, DShield, Feodo, and other sets with different meanings, which makes a useful lab starting point. Among 149 pinned child lists, 50 source files were more than a year old and 14 declared that the upstream could no longer be retrieved. Production work should recover the child sources. The FireHOL composite belongs in research and compatibility.

IPsum is useful for investigation ranking. It turns the number of input appearances into L1 through L7 thresholds and is transparent, active, and easy to automate. Counts grow when the same root data travels through multiple aggregators. In this snapshot, 32.24 percent of L2 and 37.79 percent of L3 intersected the scanner control set. A higher level frequently means “many lists saw scanning,” which remains separate from all-protocol maliciousness.

Bitwire, Data-Shield, and large malicious-ip collections are shadow-evaluation material. Bitwire inbound contains 3.82 million exact addresses; 12.59 percent fall inside published AWS ranges, and 99.986 percent of the scanner control set is touched. Data-Shield's critical/full containment direction runs against the intuitive names. malicious-ip preserves source mapping, which improves engineering transparency. These products can generate hunting clues and throttle candidates. Their complete output stays disconnected from default deny.

Recent C2, PacketsDatabase, and cumulative historical sets move to quarantine or hunting. Of Recent C2's 15,355 addresses, 42.54 percent fall in AWS ranges, and its thirty-day Git difference showed additions without removals. PacketsDatabase claims half-hourly updates while the pinned data file had gone about 158.6 days without a change and still contained public DNS. Feodo aggressive, Fox-IT historical Cobalt Strike, permanent append-only sets, and 90/365-day abuse collections retain retrospective value. A product name containing “recent” or “C2” cannot supply missing lifecycle evidence.

5 Freshness has four clocks: observation, last seen, publication, and local activation

An IP's risk changes across four clocks. Event time records when behavior occurred. last_seen records when the publisher most recently confirmed it. Publication time records when the file or API delivered it. Local activation records when the rule actually began enforcement. A new Git commit advances the third clock and leaves an old observation old.

Four black-and-gold clocks represent sensor observation, last seen, list publication, and local activation, while an address card is reassigned to a different host at the end of the chain
Figure 5. Four clocks determine which action a record can still support. Address reassignment can make an old judgment harm a new user, so removal speed matters as much as discovery speed.

Eight projects with readable Git history show the difference. At 2026-07-25 07:39:33 UTC, the most recent data change in ShadowWhisperer Threats was about 0.66 hours old, Data-Shield 1.56 hours, the ThreatFox mirror 1.81, Bitwire 2.68, ReportedIP 3.01, ziyad 3.18, and Recent C2 18.65. PacketsDatabase reached 3,806.52 hours. Commit cadence finds abandonment; content additions and removals show whether the list still breathes.

On warm paper, rows of cells at left are grouped in gold, blue, gray, red, and crossed-out black, while eight horizontal bars at right have unequal lengths and one red bar runs nearly the full width
Figure 6. FireHOL child-list age appears at left; the latest data-file change for eight repositories appears at right. An active aggregator can still contain upstreams that have been quiet for years.

Churn exposes lifecycle quality. In one day the ThreatFox mirror added 56 and removed 248; over 90 days it added 6,739 and removed 15,639. Data-Shield added 1,860 and removed 1,766 in one day. Recent C2 added 334 and removed zero over thirty days. Regular removal shows that remediation, takedown, and reassignment can reach the published product. A set that only grows naturally becomes history.

5.1 TTL follows the object, and a valid empty set is a successful delivery

DROP prefixes follow the publisher's daily review and leave local policy with the official record. ThreatFox IP:port and domain records stay for 72 hours after recent activity. Feodo recommended consumes current active objects. DataPlane inbound observations live for one to seven days. Community reports and registration abuse begin with a seven-to-thirty-day shadow window. Historical samples remain available in the hunting store. A single 30-day TTL would keep short-lived cloud addresses too long and delete routing-governance records too early.

An empty list, a failed retrieval, and a failed parse have different outcomes. An identity-, format-, time-, and count-valid empty list publishes zero rules. A 404, login HTML, truncation, or a parser that suddenly accepts zero rows enters quarantine. Feodo's current state adds a status/content conflict: retain the receipt, quarantine the old address, and wait for agreement between the service status and endpoint.

6 False positives happen at the action: the same observation can carry radically different cost

“This address scanned SSH” can be accurate. Turning that observation into a permanent bidirectional all-protocol block creates a policy error. DShield narrowed its snapshot to the 20 most active /24 networks, yet 14 intersected the third-party scanner control set. Before threat-type, confidence, and time filtering, ThreatFox official recent contained 1,924 exact IPv4 addresses; 38 fell in AWS ranges, 18 in GitHub service ranges, and 14 in Google Cloud ranges. The production compiler reduces those figures to 1,686, 35, 16, and 14. These addresses can host a real malicious tenant or a compromised machine. Exact ports and short TTLs reduce the blast radius.

Large aggregators amplify these collisions. Across all exact-address datasets, the experiment counted 738,407 cloud-range memberships, 173,403 known-service memberships, 89,223 shared-service memberships, 242,090 scanner-control memberships, and 810 crawler memberships. IPInsights and the stale PacketsDatabase exactly included 1.1.1.1, 1.0.0.1, 8.8.8.8, and 8.8.4.4; a yearly TweetFeed range covered 9.9.9.9. A public-DNS hit vetoes default blocking. Cloud and scanner hits require tenant, port, and local-session context.

6.1 Five action tiers turn a list hit into a business decision

Direct block accepts governed ranges such as DROP and validated outbound C2 still inside its validity, with direction, port, and asset group narrowed wherever possible. Throttle or challenge accepts inbound attack sources, registration abuse, anonymity exits, and high-risk community signals. Alert or enrich accepts historical C2, shared-cloud addresses, new single-source observations, and aggregates. Context only retains Tor, VPN, scanner, crawler, cloud, ASN, and geography identity. Quarantine catches unclear licenses, HTML masquerading as data, abandoned sources, format breaks, unknown lineage, and abnormal control collisions.

Run every new source in shadow for seven to thirty days. Record hits per million connections, asset and port, session result, confirmed incident, legitimate subject, analyst minutes, removal latency, and rule cost. A source leaves production after thirty days without a unique correct event, with only duplicate alerts, or with continuously rising exceptions. Blocking value is measured against resolved events and net business harm.

7 Choosing institutions and platforms: assign responsibility for observation, validation, removal, and delivery

An institution's value begins with visibility and is realized by the work that follows. Direct observers operate honeypots, sinkholes, scanners, sandboxes, mail traps, or endpoint telemetry. Specialists validate malware family and infrastructure. Distributors maintain APIs, formats, and withdrawal. Coordinators send findings to network owners. Platforms preserve relationships, access, and decay. Commercial services add private telemetry, SLAs, and support. Procurement should confirm each responsibility explicitly; brand size provides context only.

Seven black-and-gold observation sources enter five institutional workshops for validation, correlation, distribution, coordination, and standardization, then supply perimeter defense, SOC, incident response, and management decisions with remediation feedback
Figure 7. Intelligence institutions connect sensors, samples, routing, community reports, and incident response to validation, distribution, and remediation. Timely address removal usually shows that the feedback chain works.

The preferred public professional-infrastructure pairing is Spamhaus plus abuse.ch. Spamhaus takes editorial responsibility for network ownership, routing-level malicious ranges, and removal. abuse.ch connects community submissions, samples, C2, and takedown state through ThreatFox, Feodo, URLhaus, and MalwareBazaar. They cover different vantage points with relatively clear interfaces, terms, and product boundaries. SANS ISC/DShield and DataPlane contribute Internet-edge observation. Shadowserver's distinguishing value is large-scale measurement, reporting to network owners, and remediation feedback.

MISP is this study's preferred open-source TIP. It stores events, attributes, tags, root source, sharing scope, warninglists, and decay models, and it can carry the action and TTL fields used here. A small team with two or three enforcement lines can use a lightweight database and versioned sets. Multi-community sharing, analyst collaboration, event relationships, and access control justify MISP. Its default-feed catalog is a discovery entrance, with upstream quality decided separately.

GreyNoise is the preferred scanner-context analysis service. The Community API can review individual high-value hits; its free quota is too small for bulk enrichment. Shodan, Censys, Rapid7 Sonar, and other measurement organizations should enter the control set through their official scanner identities, reverse DNS, and opt-out material. A scanner address may also host a compromised instance, so the current behavior still governs the action.

7.1 Commercial procurement fills the gaps the public market actually leaves

The public stack leaves three clear gaps: broad and continuously validated live C2, private DNS/endpoint/email telemetry across regions, and dependable bulk delivery with support. A commercial product is sensible when the program needs these capabilities. Feodo's official FAQ recommends Spamhaus BCL for broader active C2. Other commercial providers can enter the candidate pool and face the same blind benchmark.

Give every candidate the same historical traffic and adjudicated incidents, hide the brand, and compare time to first correct hit, unique correct events, duplicate noise, shared-infrastructure harm, publication latency, removal time, analyst labor, and cost per useful incident. Then review data rights, regional coverage, privacy, SLA, exit export, and incident notification. Address count and claims of global visibility describe capacity; the benchmark decides value.

8 A thirty-day release: let each source earn stronger action

The production chain can stay short: quarantined retrieval, schema checks, lineage consolidation, clock calculation, control collision, shadow operation, action-specific publication, and continuous withdrawal. Every stage emits a version, count, and reason code. An operator can trace a hit to its root observation and download artifact, or disable every downstream rule from one source.

A black-and-gold production line moves public lists through quarantined download, schema validation, lineage consolidation, four clocks, context collisions, and shadow mode before five action tiers, with evidence retention and rollback alongside
Figure 8. A minimum rollback-capable supply chain. Retrieval begins the process; lineage, time, control collisions, and shadow results grant enforcement authority.
  1. Days 1–3: register official DROP, ThreatFox, and Feodo endpoints, terms, formats, cadence, and owners. Build negative controls for owned addresses, critical SaaS, partners, cloud, authorized scanning, and public DNS. Prepare two known-good versions and a per-source circuit breaker.
  2. Days 4–10: verify DROP prefix additions, removals, and rollback on a pre-production gateway. Send ThreatFox, Feodo, DShield, and one service-specific signal to logs only. Confirm that valid C2 test traffic hits and that essential business paths, health checks, and authorized scanners remain available.
  3. Days 11–20: activate DROP at the edge; issue 72-hour rules for high-confidence ThreatFox IP:port and domain records; promote inbound signals only to throttling or challenge. Review new rules, withdrawals, business exceptions, update failures, and unique source contribution each day.
  4. Days 21–30: use resolved incidents and real traffic to calculate hits per million connections, correct and unique incidents, legitimate impact, analyst minutes, and withdrawal latency. Remove sources with no contribution or growing harm, then schedule the next quarterly retest.

8.1 A one-page decision ledger beats a decorative total score

Keep three layers of evidence for each source. Observation records sensor, behavior, direction, port, validation, first_seen, and last_seen. Distribution records root source, mirror, conversion, license, format, publication delay, and removal. Decision records local asset, action, hit, exception, rollback, and owner. License, action semantics, and time integrity are hard gates; a missing gate holds the source in enrichment or quarantine.

After the gates, score evidence strength from zero through four: missing, publisher assertion, pinned sample, historical measurement, and sustained local result. Compare scores only among candidates for the same job. Control collision, rights, and the business owner retain veto power. Dashboards should lead with unique correct incidents, publication delay, removal delay, legitimate impact, and investigation cost. Address count is a capacity measure.

9 Evidence boundary and final answer

The intersection and union analysis covers 99 datasets with exact IPv4; CIDR coverage is measured separately, and IPv6 lacks a comparable experiment. Control collisions reveal policy risk and can include a truly malicious cloud tenant, a compromised service, legitimate measurement, or copied upstream data. Each organization needs session evidence, asset context, adjudicated incidents, and remediation outcomes for a real false-positive rate. Git measurements pin file-publication history and cannot reconstruct every record's sensor time.

The public research ledger (JSON) pins the census boundary, retrieval result, set analysis, control collisions, freshness observations, product choices, policy compilation, fault injection, and exit logic. Its SHA-256 is ACDC5CDA52D55101F50075C572C28AED3BB387BC2362A74A12B17BC389D03D29. The ledger publishes sanitized aggregate evidence only; potentially malicious addresses, downloaded bodies, credentials, raw responses, and private traffic remain in ignored research storage.

The highest-value next study is a 90-to-180-day repeated pull of the same endpoints with local truth from an Internet service provider, an ordinary enterprise, and a cloud-hosting operator. It should extend IPv6, DNS resolution chains, and certificate relationships. A source that consistently discovers more unique correct incidents sooner, removes records faster, and produces less legitimate impact can challenge the category winners named here.

9.1 Closing: the current best stack is ready for a change ticket

As of 2026-07-25, SOSEC's recommendation is explicit: Spamhaus DROP/DROPv6 blocks malicious network ranges at the perimeter; high-confidence botnet_cc from ThreatFox recent controls outbound IP:port and domain for 72 hours; Feodo recommended stays connected and currently publishes zero rules; DataPlane and DShield drive alert, throttle, and challenge on matching inbound services; GreyNoise Community supports selected analyst lookups; MISP becomes the open-source management platform when collaboration requires it.

FireHOL is an excellent catalog, IPsum a useful consensus signal, Bitwire and Data-Shield high-coverage research material, and Recent C2 plus cumulative history useful for hunting. They stay outside default deny. Organizations that need broad verified live C2, private telemetry, or delivery guarantees should spend budget on a commercially licensed product that wins a local blind benchmark. This gives a reader the sources to choose, actions to write, TTLs to set, shadow period to run, and popular list classes to keep away from enforcement.

Research record

10Evidence, objects, and sources

The material below preserves the identifiers and references used in this report.

10.1Research objects

Products, actors, techniques, affected objects, and control points discussed in the report.

Census date2026-07-25

Cutoff date for the public IP/CIDR market snapshot and institution study

Catalog candidate records503

Raw records from MISP, Bert-JanP, FireHOL, Maltrail, and manual supplementation

Distinct endpoints or files332

Deliverable surface after exact endpoint, format-alias, and explicit-mirror consolidation

Parseable IP datasets105

Ninety-nine network datasets from 133 attempts plus six commit-pinned local files

Exact IPv4 union5702621

Union after per-source deduplication across 99 exact-IPv4 datasets

Duplicate membership rate32.384964%

Memberships beyond the union among 8,433,954 per-feed-deduplicated observations

Single-source address share82.337543%

Share of exact-union addresses occurring in one dataset

Operational replay inputs8+10+1

Eight product artifacts, ten official public-network controls, and one commit-pinned scanner control

ThreatFox policy objects3204

IP:port, domain, and URL objects after the 72-hour, botnet_cc, and confidence-75 gates

Current Feodo enforcement rules0

The March row enters quarantine because time and publisher state conflict

Fault injections passed6/6

Hash, HTML, truncation, field drift, timestamp regression, and valid empty delivery

Lifecycle replays passed4/4

Valid-candidate rollback, ThreatFox expiry, DROP 48-hour boundary, and Feodo empty-generation retention

Public research ledger SHA-256ACDC5CDA52D55101F50075C572C28AED3BB387BC2362A74A12B17BC389D03D29

Sanitized census boundary, set analysis, control collisions, freshness, product choices, policy compilation, fault injection, exit logic, and evidence limits

10.2Event chronology

  1. SSLBL IP feed deprecated

    abuse.ch ended SSLBL IP delivery and now returns deprecation guidance; historical mirrors no longer carry current-feed semantics.

  2. PacketsDatabase data stopped changing

    The project continued to claim thirty-minute updates while pinned repository history placed the final data-file change on this date.

  3. Public-source freshness snapshot

    The study pinned last-change age, commit cadence, and content churn for eight Git-hosted data projects.

  4. Feodo current-state review

    The official FAQ describes the current datasets as empty; the recommended endpoint pinned on the same day still delivered one March 4 record, so production keeps the subscription and quarantines the stale, conflicting row.

  5. SOSEC census and experiments closed

    The 503 catalog candidates consolidated into 332 distinct endpoints or files; 133 network attempts covered 130 URLs, six commit-pinned files were read locally, and the result contained 105 parseable IP datasets and 99 exact-IPv4 datasets.

  6. Policy compilation and fault replay

    Eight frozen product artifacts entered action-scoped compilation; ten official network controls and one scanner control supplied collision checks; all six input-fault cases and four lifecycle cases reached their expected outcomes.

10.3Sources and material

  1. NIST SP 800-150: Cyber Threat Information Sharinghttps://csrc.nist.gov/pubs/sp/800/150/final
  2. NIST SP 800-150 fixed PDFhttps://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-150.pdf
  3. CISA: Assessing the Potential Value of Cyber Threat Intelligence Feedshttps://www.cisa.gov/resources-tools/resources/assessing-potential-value-cyber-threat-intelligence-feeds-white-paper
  4. OASIS STIX 2.1https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html
  5. FIRST Traffic Light Protocolhttps://www.first.org/tlp/
  6. USENIX Security 2019: Reading the Tea Leaveshttps://www.usenix.org/conference/usenixsecurity19/presentation/li
  7. Reading the Tea Leaves paper PDFhttps://www.usenix.org/system/files/sec19-li-vector_guo.pdf
  8. Blocklist Babel research recordhttps://dspace.networks.imdea.org/handle/20.500.12761/958
  9. Blocklist Babel paper PDFhttps://dspace.networks.imdea.org/bitstream/handle/20.500.12761/958/paper.pdf?isAllowed=y&sequence=1
  10. ACNS 2019: An Evaluation of Cyber Threat Intelligence Feedshttps://www.cyber-threat-intelligence.com/publications/ACNS2019-feedtimelineness.pdf
  11. Applied Sciences: Cyber Threat Intelligence Quality Assessmenthttps://www.mdpi.com/2076-3417/15/8/4327
  12. NIST: Contextualized Filtering of Shared Cyber Threat Informationhttps://www.nist.gov/publications/contextualized-filtering-shared-cyber-threat-information
  13. MISP default feedshttps://misp.github.io/misp-website/feeds/
  14. MISP Threat Intelligence Best Practiceshttps://www.misp-project.org/best-practices-in-threat-intelligence.html
  15. Bert-JanP Open-Source Threat Intelligence Feedshttps://github.com/Bert-JanP/Open-Source-Threat-Intel-Feeds
  16. Maltrail repository and feed configurationhttps://github.com/stamparm/maltrail
  17. FireHOL IP Lists cataloghttps://iplists.firehol.org/
  18. FireHOL Level 1 definitionhttps://iplists.firehol.org/firehol_level1.html
  19. Pinned FireHOL blocklist-ipsets catalog descriptionhttps://github.com/firehol/blocklist-ipsets/blob/a4bc4e54aedeeaf51eba57a46602bd99483fb4fe/README.md
  20. Spamhaus DROP producthttps://www.spamhaus.org/blocklists/do-not-route-or-peer/
  21. Spamhaus DROP FAQhttps://www.spamhaus.org/faqs/do-not-route-or-peer-drop/
  22. Spamhaus DROP fair-use policyhttps://www.spamhaus.org/blocklists/drop-fair-use-policy/
  23. Team Cymru Community Serviceshttps://www.team-cymru.com/community-network-services
  24. SANS ISC/DShield feed documentation and blocking boundaryhttps://isc.sans.edu/feeds_doc.html
  25. SANS ISC XML and data interfaceshttps://isc.sans.edu/xml.html
  26. DataPlane.org protocol-specific attack sourceshttps://dataplane.org/
  27. DataPlane SSH authentication signal and use boundaryhttps://dataplane.org/sshpwauth.txt
  28. Feodo Tracker blocklistshttps://feodotracker.abuse.ch/blocklist/
  29. Feodo Tracker FAQhttps://feodotracker.abuse.ch/faq/
  30. ThreatFox APIhttps://threatfox.abuse.ch/api/
  31. ThreatFox official exportshttps://threatfox.abuse.ch/export/
  32. ThreatFox FAQhttps://threatfox.abuse.ch/faq/
  33. URLhaus APIhttps://urlhaus.abuse.ch/api/
  34. MalwareBazaar APIhttps://bazaar.abuse.ch/api/
  35. AbuseIPDB FAQhttps://www.abuseipdb.com/faq.html
  36. AbuseIPDB API documentationhttps://docs.abuseipdb.com/
  37. StopForumSpam usage and data interfaceshttps://www.stopforumspam.com/usage
  38. Project Honey Pot HTTP:BLhttps://www.projecthoneypot.org/httpbl.php
  39. CINS Scorehttps://www.cinsscore.com/
  40. APNIC Honeynethttps://www.apnic.net/community/security/honeynet/
  41. blocklist.de exportshttps://www.blocklist.de/en/export.html
  42. blocklist.de delisthttps://www.blocklist.de/en/delist.html
  43. GreyNoise classificationshttps://docs.greynoise.io/docs/greynoise-classifications
  44. GreyNoise Community APIhttps://docs.greynoise.io/docs/using-the-greynoise-community-api
  45. Shadowserver Network Reportinghttps://www.shadowserver.org/what-we-do/network-reporting/
  46. Censys scanning and opt-outhttps://support.censys.com/hc/en-us/articles/360043177092-Opt-Out-of-Data-Collection
  47. Shodan scanning overviewhttps://help.shodan.io/the-basics/what-is-shodan
  48. Rapid7 Open Data and Project Sonarhttps://opendata.rapid7.com/about/
  49. Tor Bulk Exit Listhttps://check.torproject.org/torbulkexitlist
  50. Pinned ReportedIP data filehttps://github.com/reportedip/reportedip-blacklist/blob/1e5db2fec0496458daf0de9584136422dc139358/blacklist-all.txt
  51. Pinned ShadowWhisperer Threats data filehttps://github.com/ShadowWhisperer/IPs/blob/bc63e671280be97cff82b587f8e6a6a47a9182fa/Lists/Threats
  52. Pinned ShadowWhisperer third-party scanner-company controlhttps://github.com/ShadowWhisperer/IPs/blob/bc63e671280be97cff82b587f8e6a6a47a9182fa/Lists/Scanners
  53. Pinned ziyad hourly IPv4 data filehttps://github.com/ziyadnz/threat-intel-ip-feeds/blob/d03e4b57d41ebce29ac1d4987cf3ba63c9b2882c/output/hourlyIPv4.txt
  54. Pinned PacketsDatabase project claimhttps://github.com/BlacKSnowDot0/packetsdatabase-db/blob/5a5f53f928cd9267532a4c54cea400943e72275a/README.md
  55. PacketsDatabase data file at its last-change commithttps://github.com/BlacKSnowDot0/packetsdatabase-db/blob/d62b13adb2c35e84ed3c89ced5a3cf44261b1699/ip_list.txt
  56. Pinned IPsum Level 1 data filehttps://github.com/stamparm/ipsum/blob/691eac0a6fbbed14f3eee75b8f877ce4eea8375d/levels/1.txt
  57. Pinned malicious-ip 40k data filehttps://github.com/romainmarcoux/malicious-ip/blob/2646f6090d33f74c6de7336d75026c5c6623532b/full-40k.txt
  58. Pinned malicious-outgoing-ip first shardhttps://github.com/romainmarcoux/malicious-outgoing-ip/blob/c5dce62f73bd8355c09de083e039272e0baaebd4/full-outgoing-ip-aa.txt
  59. Pinned ThreatFox community mirror data filehttps://github.com/elliotwutingfeng/ThreatFox-IOC-IPs/blob/88fddac2ea1dd7d9c8dca6cade568cc15d5ed22e/ips.txt
  60. Pinned Bitwire inbound data filehttps://github.com/bitwire-it/ipblocklist/blob/deab27b533273295e26c2fe0c16f677ceac5bf76/inbound.txt
  61. Pinned Bitwire input and output statisticshttps://github.com/bitwire-it/ipblocklist/blob/deab27b533273295e26c2fe0c16f677ceac5bf76/stats/latest.json
  62. Pinned Bitwire project descriptionhttps://github.com/bitwire-it/ipblocklist/blob/deab27b533273295e26c2fe0c16f677ceac5bf76/README.md
  63. Pinned Data-Shield descriptionhttps://github.com/duggytuxy/Data-Shield_IPv4_Blocklist/blob/d5db5950eb03d7ee96a408cb4f7b2a6d700465bf/README.md
  64. Pinned Data-Shield full data filehttps://github.com/duggytuxy/Data-Shield_IPv4_Blocklist/blob/d5db5950eb03d7ee96a408cb4f7b2a6d700465bf/prod_data-shield_ipv4_blocklist.txt
  65. Pinned Data-Shield critical data filehttps://github.com/duggytuxy/Data-Shield_IPv4_Blocklist/blob/d5db5950eb03d7ee96a408cb4f7b2a6d700465bf/prod_critical_data-shield_ipv4_blocklist.txt
  66. Pinned Recent C2 data filehttps://github.com/joeavanzato/recent_c2_infrastructure/blob/08d40cb818e155b67590fcb5de2a89cf7792c1ea/c2_data.csv
  67. Public IPInsights-related aggregation repositoryhttps://github.com/duggytuxy/Intelligence_IPv4_Blocklists
  68. Pinned ThreatMon end-of-maintenance statehttps://github.com/ThreatMon/ThreatMon-Daily-C2-Feeds/blob/b16e3f28c651293f19ac03e597b4124b90b51982/README.md
  69. AlienVault OTX User Guidehttps://otx.alienvault.com/assets/static/external/otx-user-guide.pdf
  70. MITRE ATT&CK Resourceshttps://attack.mitre.org/resources/
  71. CISA Cybersecurity Information Sharinghttps://www.cisa.gov/topic/cybersecurity-information-sharing
  72. CISA AIS archived guidancehttps://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais/how-share-cyber-threat-information-through-ais
  73. Microsoft Defender Threat Intelligence datasetshttps://learn.microsoft.com/en-us/defender/threat-intelligence/data-sets
  74. Google Threat Intelligence lifecyclehttps://cloud.google.com/blog/topics/threat-intelligence/ai-five-phases-intelligence-lifecycle/
  75. Recorded Future Intelligence Graphhttps://www.recordedfuture.com/platform/intelligence-graph
  76. Cisco Talos data and product-protection chainhttps://blog.talosintelligence.com/how-cisco-talos-powers-the-solutions-protecting-your-organization/
  77. Unit 42 Attribution Frameworkhttps://unit42.paloaltonetworks.com/unit-42-attribution-framework/
  78. VirusTotal IP Objecthttps://docs.virustotal.com/reference/ip-object