OpenDBL Umbrella

Open Dynamic Block Lists

Threat intelligence blocklists compatible with all enterprise firewalls and security devices.

Standalone IPs: x.x.x.x CIDR Subnets: x.x.x.x/yy

Keep polling interval at 15 minutes or higher and use HTTPS if possible.

Active Lists: 10 Total Blocked Entries: 62,875 Polling Interval: ≥ 15 min

Recommended Block Lists

List name Entries Last update Direction False Positive Risk Description
5120 2026-07-23 20:49 Incoming Low Risk Top recommended attack sources from SANS Internet Storm Center DShield. Read more →
18586 2026-07-23 20:49 Both Low Risk Aggregated threat list consisting of malicious IPs present in 3 or more blocklists. Read more →
1 2026-07-23 20:49 Outgoing Low Risk Active Command & Control (C2) servers for botnets, ransomware, and banking trojans (Dridex, TrickBot, QakBot). Read more →
1669 2026-07-23 20:49 Both Low Risk Advisory list of hijacked or leased IP netblocks controlled entirely by cybercriminals. Read more →

Additional Threat Intelligence Feeds

List name Entries Last update Direction False Positive Risk Description
575 2026-07-23 20:49 Incoming Medium Risk Compiled from multiple sources containing active, severely infected, and hostile hosts. Read more →
1397 2026-07-23 20:49 Incoming High Risk Real-time updated list of known TOR network exit nodes. Read more →
581 2026-07-23 20:49 Incoming High Risk IP addresses reporting high volumes of SSH/service brute-force attack attempts. Read more →
29767 2026-07-23 20:49 Incoming Medium Risk Attacking IP addresses detected across customer systems within the last 48 hours. Read more →
3235 2026-07-23 20:49 Incoming Medium Risk Real-time list of IP addresses carrying out brute-force attacks, port scans, and web exploits. Read more →
1944 2026-07-23 20:49 Outgoing Medium Risk Real-time Indicators of Compromise (IOCs) for malware C2 and payload delivery infrastructure from abuse.ch. Read more →