OpenDBL Umbrella

Open Dynamic Block Lists

Free threat intelligence blocklists compatible with all firewalls and security devices supporting the following formats:

Standalone IPs: x.x.x.x CIDR Subnets: x.x.x.x/yy
Total Unique IPs: 71,544 Multi-Source Verified: 16,327 Polling Interval: ≥ 15 min
10+ Years Operational Continuous, high-uptime threat intelligence service for enterprise firewalls since 2014.
Automated Feed Sanitization Real-time filtering ensuring core Internet services & public DNS never show up in published lists.
Zero-Touch FP Safeguards Multi-feed validation & automated surge anomaly detection protect production traffic.

OpenDBL CIDR-Optimized Feeds

List name Entries Last update Direction False Positive Risk Description
Entries:
13,020 CIDRs (16,327 IPs)
Updated: 2026-09-16 04:51 Direction: Incoming Risk: Very Low Risk Ultra-strict threat feed requiring multi-sensor correlation (2+ independent feeds) or a hit on an externally-vetted threat-intelligence feed (ThreatFox, Feodo Tracker, Spamhaus DROP) (13,020 CIDR blocks blocking 16,327 verified IPs). Engineered for zero-touch automated blocking with very low false positive risk.
Entries:
52,172 CIDRs (69,111 IPs)
Updated: 2026-09-16 04:51 Direction: Incoming Risk: Low Risk Wide-spectrum threat feed combining active web scanners, brute-force bots, and malware hosts (52,172 CIDR blocks blocking 69,111 unique IPs). Darknet-sensor-only sightings must be corroborated by another feed or persist across 2+ distinct days; TOR exit nodes are excluded. Suited for production firewalls.
Entries:
52,896 CIDRs (71,544 IPs)
Updated: 2026-09-16 04:52 Direction: Incoming Risk: High Risk Complete union of all active external threat feeds (52,896 CIDR blocks blocking 71,544 unique IPs), including TOR exit nodes and single-report scanners with no corroboration or scoring threshold - except single-day-only sightings from our own darknet sensor pending corroboration. High false-positive risk — best suited for SIEM correlation and honeypots, not direct inbound blocking.

Individual Block Lists & Threat Feeds

List name Entries Last update Direction False Positive Risk Description
Entries: 35,431 IPs Updated: 2026-09-16 04:51 Direction: Incoming Risk: Medium Risk Real-time threat feed generated directly from OpenDBL's passive darknet sensor network. Read more →
Entries: 588 IPs Updated: 2026-09-16 04:49 Direction: Incoming Risk: Medium Risk Compiled from multiple sources containing active, severely infected, and hostile hosts. Read more →
Entries: 1,343 IPs Updated: 2026-09-16 04:49 Direction: Incoming Risk: High Risk Real-time updated list of known TOR network exit nodes. Read more →
Entries: 598 IPs Updated: 2026-09-16 04:49 Direction: Incoming Risk: High Risk IP addresses reporting high volumes of SSH/service brute-force attack attempts. Read more →
Entries: 24,986 IPs Updated: 2026-09-16 04:49 Direction: Incoming Risk: Medium Risk Attacking IP addresses detected across customer systems within the last 48 hours. Read more →
Entries: 5,120 IPs Updated: 2026-09-16 04:51 Direction: Incoming Risk: Low Risk Top recommended attack sources from SANS Internet Storm Center DShield. Read more →
Entries: 16,764 IPs Updated: 2026-09-16 04:50 Direction: Both Risk: Low Risk Aggregated threat list consisting of malicious IPs present in 3 or more blocklists. Read more →
Entries: 1 IPs Updated: 2026-09-16 04:50 Direction: Outgoing Risk: Low Risk Active Command & Control (C2) servers for botnets, ransomware, and banking trojans (Dridex, TrickBot, QakBot). Read more →
Entries: 5,386 IPs Updated: 2026-09-16 04:50 Direction: Incoming Risk: Medium Risk Real-time list of IP addresses carrying out brute-force attacks, port scans, and web exploits. Read more →
Entries: 2,912 IPs Updated: 2026-09-16 04:50 Direction: Outgoing Risk: Medium Risk Real-time Indicators of Compromise (IOCs) for malware C2 and payload delivery infrastructure from abuse.ch. Read more →
Entries: 1,722 IPs Updated: 2026-09-16 04:50 Direction: Both Risk: Low Risk Advisory list of hijacked or leased IP netblocks controlled entirely by cybercriminals. Read more →