See threats across the network and block them before they reach you
Threat.live is a collective defense network that detects malicious IP addresses in real time and shares them free for the community. Connect the blacklist to your security stack via feed or API; stop them before they ever reach your network with BGP blackhole.
Defense on your own is not as strong as defense across the network
An attacker tries many targets with the same malicious IPs. When a node in the Threat.live network detects such an IP, the indicator propagates to the entire community in real time; you then block that address before it reaches you — at the network layer with BGP blackhole, if you wish.
Malicious IPs used in botnet, DDoS and brute-force attempts are detected and listed instantly.
Stop malicious IPs at the network layer with BGP blackhole routing, before they reach your applications.
A threat seen by one node spreads to the whole community; everyone becomes each other's eyes.
Pull the blacklist in a single line (curl) or connect it to your existing tools via API.
Watch live the autonomous system (ASN) and country breakdowns where the threat concentrates.
Push the list to your firewall, WAF and SIEM automatically; no manual list transfers.
Integrations
Pull the blacklist with a single-line command (curl) or get it via API; connect it to your existing security stack within minutes. For BGP announcement, we set it up together with your network team.
Compliance
Packages
Community access is completely free. A scaled plan is offered for enterprise SLA, high rate limits and custom feed needs.
Threat.live — frequently asked questions
Yes. Community access is completely free and requires no credit card; you use the real-time IoC feed, the API and indicator search for free. There is a scaled plan only for enterprise needs such as a high request limit, SLA and custom feed.
The feed contains malicious IP addresses used in attacks such as botnet, DDoS and brute-force. Each IP is added to the list in real time with its first-seen time and observed activity; you also see live the ASN and country distribution where the threat concentrates.
You can pull the list with a single-line command (e.g. curl -s https://list.threat.live/) or get it via API. You can feed it into your firewall, pfSense, Suricata, Fortinet and SIEM; you can also block malicious IPs at the network layer with BGP blackhole. It also integrates directly with Logchase.
Indicators are compiled from multiple sources, normalized and published with a confidence score. You can filter out low-confidence indicators and push only those above a certain score to your defenses.
No. The feed contains only technical attack indicators; no personal data is processed or shared. This makes intelligence sharing safe under KVKK.
Yes. By sharing the indicators you have verified with the community, you can contribute to collective defense. Contributions go through a verification and scoring process before being added to the feed.
You move to the enterprise plan when you need high-volume automated queries, a guaranteed response time (SLA), a sector-specific feed or a dedicated feed. Community access remains free outside these needs.
What teams using Threat.live say
Connect the free feed within minutes
Connect the Threat.live community blacklist to your defenses via curl or API; if you wish, let us set up BGP blackhole together. Community access is free.