OpenDBL Umbrella

Open Dynamic Block Lists

Free threat intelligence blocklists compatible with all firewalls and security devices supporting the following formats:

Standalone IPs: x.x.x.x CIDR Subnets: x.x.x.x/yy
Total Unique IPs: 53,863 Multi-Source Verified: 5,278 Polling Interval: ≥ 15 min
10+ Years Operational Continuous, high-uptime threat intelligence service for enterprise firewalls since 2014.
Automated Feed Sanitization Real-time filtering ensuring core Internet services & public DNS never show up in published lists.
Zero-Touch FP Safeguards Multi-feed validation & automated surge anomaly detection protect production traffic.

OpenDBL Tiered Threat Lists

List name Entries Last update Direction False Positive Risk Description
Entries: 4,461 Updated: 2026-07-25 22:49 Direction: Both Risk: Very Low Risk CIDR-optimized multi-source threat feed (4,461 CIDR blocks blocking 5,278 verified IPs). Designed for zero-touch automated firewall blocking.
Entries: 19,621 Updated: 2026-07-25 22:49 Direction: Both Risk: Low Risk CIDR-optimized broad threat feed (19,621 CIDR blocks blocking 52,584 unique IPs). Aggregates active attack scanners, malware C2s & persistent attack sources (high-risk single-source IPs require 3+ day persistence or multi-feed verification).
Entries: 20,317 Updated: 2026-07-25 22:49 Direction: Both Risk: Medium Risk CIDR-optimized full-spectrum threat feed (20,317 CIDR blocks blocking 53,863 unique IPs). Combines 100% of active attack scanners, TOR exit nodes, and brute-force reporters.

Individual Block Lists & Threat Feeds

List name Entries Last update Direction False Positive Risk Description
Entries: 24,627 Updated: 2026-07-25 22:49 Direction: Incoming Risk: Medium Risk Attacking IP addresses detected across customer systems within the last 48 hours. Read more →
Entries: 584 Updated: 2026-07-25 22:49 Direction: Incoming Risk: High Risk IP addresses reporting high volumes of SSH/service brute-force attack attempts. Read more →
Entries: 5,120 Updated: 2026-07-25 22:49 Direction: Incoming Risk: Low Risk Top recommended attack sources from SANS Internet Storm Center DShield. Read more →
Entries: 583 Updated: 2026-07-25 22:49 Direction: Incoming Risk: Medium Risk Compiled from multiple sources containing active, severely infected, and hostile hosts. Read more →
Entries: 1 Updated: 2026-07-25 22:49 Direction: Outgoing Risk: Low Risk Active Command & Control (C2) servers for botnets, ransomware, and banking trojans (Dridex, TrickBot, QakBot). Read more →
Entries: 3,107 Updated: 2026-07-25 22:49 Direction: Incoming Risk: Medium Risk Real-time list of IP addresses carrying out brute-force attacks, port scans, and web exploits. Read more →
Entries: 14,811 Updated: 2026-07-25 22:49 Direction: Both Risk: Low Risk Aggregated threat list consisting of malicious IPs present in 3 or more blocklists. Read more →
Entries: 1,669 Updated: 2026-07-25 22:49 Direction: Both Risk: Low Risk Advisory list of hijacked or leased IP netblocks controlled entirely by cybercriminals. Read more →
Entries: 1,855 Updated: 2026-07-25 22:49 Direction: Outgoing Risk: Medium Risk Real-time Indicators of Compromise (IOCs) for malware C2 and payload delivery infrastructure from abuse.ch. Read more →
Entries: 1,393 Updated: 2026-07-25 22:49 Direction: Incoming Risk: High Risk Real-time updated list of known TOR network exit nodes. Read more →