OpenDBL CIDR-Optimized Feeds
| List name | Entries | Last update | Direction | False Positive Risk | Description |
|---|---|---|---|---|---|
|
13,472 CIDRs
(17,168 IPs)
|
2026-09-30 22:51 | Incoming | Very Low Risk | Ultra-strict threat feed requiring multi-sensor correlation (2+ independent feeds) or a hit on an externally-vetted threat-intelligence feed (ThreatFox, Feodo Tracker, Spamhaus DROP) (13,472 CIDR blocks blocking 17,168 verified IPs). Engineered for zero-touch automated blocking with very low false positive risk. | |
|
35,244 CIDRs
(52,853 IPs)
|
2026-09-30 22:51 | Incoming | Low Risk | Wide-spectrum threat feed combining active web scanners, brute-force bots, and malware hosts (35,244 CIDR blocks blocking 52,853 unique IPs). Darknet-sensor-only sightings must be corroborated by another feed or persist across 2+ distinct days; TOR exit nodes are excluded. Suited for production firewalls. | |
|
40,105 CIDRs
(61,290 IPs)
|
2026-09-30 22:51 | Incoming | High Risk | Complete union of all active external threat feeds (40,105 CIDR blocks blocking 61,290 unique IPs), including TOR exit nodes and single-report scanners with no corroboration or scoring threshold - except single-day-only sightings from our own darknet sensor pending corroboration. High false-positive risk — best suited for SIEM correlation and honeypots, not direct inbound blocking. |
Individual Block Lists & Threat Feeds
| List name | Entries | Last update | Direction | False Positive Risk | Description |
|---|---|---|---|---|---|
| 21,409 IPs | 2026-09-30 22:51 | Incoming | Medium Risk | Real-time threat feed generated directly from OpenDBL's passive darknet sensor network. Read more → | |
| 632 IPs | 2026-09-30 22:49 | Incoming | Medium Risk | Compiled from multiple sources containing active, severely infected, and hostile hosts. Read more → | |
| 1,406 IPs | 2026-09-30 22:49 | Incoming | High Risk | Real-time updated list of known TOR network exit nodes. Read more → | |
| 633 IPs | 2026-09-30 22:49 | Incoming | High Risk | IP addresses reporting high volumes of SSH/service brute-force attack attempts. Read more → | |
| 28,991 IPs | 2026-09-30 22:49 | Incoming | Medium Risk | Attacking IP addresses detected across customer systems within the last 48 hours. Read more → | |
| 5,120 IPs | 2026-09-30 22:51 | Incoming | Low Risk | Top recommended attack sources from SANS Internet Storm Center DShield. Read more → | |
| 17,743 IPs | 2026-09-30 22:50 | Both | Low Risk | Aggregated threat list consisting of malicious IPs present in 3 or more blocklists. Read more → | |
| 1 IPs | 2026-09-30 22:50 | Outgoing | Low Risk | Active Command & Control (C2) servers for botnets, ransomware, and banking trojans (Dridex, TrickBot, QakBot). Read more → | |
| 4,890 IPs | 2026-09-30 22:50 | Incoming | Medium Risk | Real-time list of IP addresses carrying out brute-force attacks, port scans, and web exploits. Read more → | |
| 2,702 IPs | 2026-09-30 22:50 | Outgoing | Medium Risk | Real-time Indicators of Compromise (IOCs) for malware C2 and payload delivery infrastructure from abuse.ch. Read more → | |
| 1,692 IPs | 2026-09-30 22:50 | Both | Low Risk | Advisory list of hijacked or leased IP netblocks controlled entirely by cybercriminals. Read more → |