İçeriğe geç
Tres Teknoloji
Products / Threat.live
T
Threat.live Threat intelligence

See threats across the network and block them before they reach you

Threat.live is a collective defense network that detects malicious IP addresses in real time and shares them free for the community. Connect the blacklist to your security stack via feed or API; stop them before they ever reach your network with BGP blackhole.

Free for the community Real-time malicious IPs BGP blackhole Open feed / API
Free Community access
Real-time Malicious IP feed
BGP Blocking via blackhole
curl / API Direct feed
Problem

Defense on your own is not as strong as defense across the network

An attacker tries many targets with the same malicious IPs. When a node in the Threat.live network detects such an IP, the indicator propagates to the entire community in real time; you then block that address before it reaches you — at the network layer with BGP blackhole, if you wish.

Real-time malicious IP feed

Malicious IPs used in botnet, DDoS and brute-force attempts are detected and listed instantly.

Blocking with BGP blackhole

Stop malicious IPs at the network layer with BGP blackhole routing, before they reach your applications.

Collective defense network

A threat seen by one node spreads to the whole community; everyone becomes each other's eyes.

Open feed and API

Pull the blacklist in a single line (curl) or connect it to your existing tools via API.

ASN & country statistics

Watch live the autonomous system (ASN) and country breakdowns where the threat concentrates.

Feed into your security stack

Push the list to your firewall, WAF and SIEM automatically; no manual list transfers.

Integrations

Pull the blacklist with a single-line command (curl) or get it via API; connect it to your existing security stack within minutes. For BGP announcement, we set it up together with your network team.

curl / HTTP feed REST API BGP blackhole Firewall pfSense Suricata Fortinet Logchase SIEM

Compliance

Community license The indicators are free and open for community use.
KVKK Only technical attack indicators are shared; no personal data is processed.
Responsible sharing Indicators are published together with verification and a confidence score.
ISO 27001-compliant operation The feed is operated securely on Tres infrastructure.

Packages

Community access is completely free. A scaled plan is offered for enterprise SLA, high rate limits and custom feed needs.

Get a quote for custom volume
Community
Free
Individual and community use
·Real-time IoC feed ·REST API + STIX/TAXII ·Indicator search ·Community support
Enterprise Most popular
On quote
High rate limit and SLA
·High request limit ·Custom feed and filter ·SIEM/WAF integration ·Priority support
Custom feed
On quote
Sector-specific intelligence
·Sector indicator set ·Dedicated feed ·Consultant support ·Extended history
FAQ

Threat.live — frequently asked questions

Yes. Community access is completely free and requires no credit card; you use the real-time IoC feed, the API and indicator search for free. There is a scaled plan only for enterprise needs such as a high request limit, SLA and custom feed.

The feed contains malicious IP addresses used in attacks such as botnet, DDoS and brute-force. Each IP is added to the list in real time with its first-seen time and observed activity; you also see live the ASN and country distribution where the threat concentrates.

You can pull the list with a single-line command (e.g. curl -s https://list.threat.live/) or get it via API. You can feed it into your firewall, pfSense, Suricata, Fortinet and SIEM; you can also block malicious IPs at the network layer with BGP blackhole. It also integrates directly with Logchase.

Indicators are compiled from multiple sources, normalized and published with a confidence score. You can filter out low-confidence indicators and push only those above a certain score to your defenses.

No. The feed contains only technical attack indicators; no personal data is processed or shared. This makes intelligence sharing safe under KVKK.

Yes. By sharing the indicators you have verified with the community, you can contribute to collective defense. Contributions go through a verification and scoring process before being added to the feed.

You move to the enterprise plan when you need high-volume automated queries, a guaranteed response time (SLA), a sector-specific feed or a dedicated feed. Community access remains free outside these needs.

Customer reviews

What teams using Threat.live say

“We saw the malicious IPs used in an attack campaign on Threat.live before they reached us and fed them into our firewall. What is more, community access is free.”
KA Kerem Aslan SOC Analyst · A technology company
“We connected the blacklist feed to our SIEM; malicious IPs update automatically, and manual list transfers are a thing of the past.”
DY Deniz Yıldız Security Engineer · A financial institution
“Being able to see within seconds whether a suspicious IP is on the list noticeably sped up our incident investigations.”
SK Selin Kaya Incident Response Specialist · A public institution
“We speak the same language as the technical team; when we open a ticket, someone who understands it responds — no repeating the scenario.”
DY Deniz Yılmaz DevOps Engineer · Trendhane
“Getting Threat.live up and running took minutes; the documentation is clear and the Turkish-language support made it easy.”
Ece Şahin Software Team Lead · Bulut Market
“After switching to Threat.live we measured the performance difference clearly in our application response times.”
EK Elif Korkmaz IT Coordinator · Akademi Online
“We can reach the support team even in the middle of the night; response times are genuinely as fast as promised.”
FY Furkan Yavuz Backend Team Lead · Loop Yazılım
“They gave us free consulting before the migration; together we worked out how much of each resource we needed.”
DY Deniz Yılmaz DevOps Engineer · Trendhane

Connect the free feed within minutes

Connect the Threat.live community blacklist to your defenses via curl or API; if you wish, let us set up BGP blackhole together. Community access is free.