Last 24 hours
26223events503addresses307blocked
Last 7 days
152441events2204addresses307blocked
Last All time
174533events3402addresses307blocked
Time since last attack: 12m
Is my IP here?
example: 203.0.113.7, or an IPv6 address
Live feed
| Time | Address | What happened | Outcome |
|---|---|---|---|
| 2026-10-04T22:53:56Z–2026-10-04T22:53:56Z | 213.209.159.133 | 32 requests on 32 distinct paths — requested a .env file, hoping to find API keys or database credentials (×18); fuzzed a short, random filename looking for a forgotten script that responds (×5); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×3); +5 more kinds | — |
| 2026-10-04T22:52:53Z–2026-10-04T22:52:54Z | 185.95.156.182 | 4 requests on 2 distinct paths — requested wp-login.php to check whether this site runs WordPress (×2); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×2) | — |
| 2026-10-04T22:52:41Z–2026-10-04T22:52:41Z | 94.154.43.31 | requested an absolute URL instead of a path, testing whether this server behaves as an open forward proxy | — |
| 2026-10-04T22:52:18Z–2026-10-04T22:52:27Z | 35.201.174.126 | 92 requests on 85 distinct paths — requested a .env file, hoping to find API keys or database credentials (×37); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×27); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×13); +6 more kinds | — |
| 2026-10-04T22:20:00Z–2026-10-04T22:52:24Z | 195.178.110.159 | 4 requests on 4 distinct paths — probed for an exposed .svn directory to read the site's version-control metadata (×2); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1) | — |
| 2026-10-04T22:51:54Z–2026-10-04T22:52:06Z | 104.208.73.227 | 50 requests on 50 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds | — |
| 2026-10-04T22:45:13Z–2026-10-04T22:45:16Z | 74.161.160.33 | 3 requests on 3 distinct paths — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×1); requested wp-login.php to check whether this site runs WordPress (×1) | — |
| 2026-10-04T22:44:53Z–2026-10-04T22:44:53Z | 161.118.226.254 | read a WordPress plugin's readme.txt to fingerprint its exact version for a known vulnerability | — |
| 2026-10-04T22:41:29Z–2026-10-04T22:41:30Z | 203.159.90.90 | 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1) | — |
| 2026-10-04T22:40:33Z–2026-10-04T22:40:36Z | 192.227.203.228 | 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1) | — |
| 2026-10-04T22:38:26Z–2026-10-04T22:38:26Z | 93.123.109.167 | 16 requests on 8 distinct paths — requested wp-login.php to check whether this site runs WordPress | — |
| 2026-10-04T22:35:19Z–2026-10-04T22:36:32Z | 20.214.109.68 | 11 requests on 11 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×3); probed wp-includes/PHPMailer/, a WordPress core library directory commonly used to drop a webshell after a prior compromise (×3); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×3); +2 more kinds | — |
| 2026-10-04T22:31:16Z–2026-10-04T22:31:34Z | 20.210.186.186 | 36 requests on 36 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×31); requested wp-login.php to check whether this site runs WordPress (×3); fuzzed a common filename under /cgi-bin/, looking for a forgotten legacy CGI script (×2) | — |
| 2026-10-04T22:24:53Z–2026-10-04T22:30:26Z | 213.209.159.223 | 156 requests on 154 distinct paths — requested a .env file, hoping to find API keys or database credentials (×118); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×12); requested a database dump or site archive by its common backup filename (×6); +10 more kinds | — |
| 2026-10-04T22:29:36Z–2026-10-04T22:29:53Z | 20.204.16.113 | 69 requests on 69 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×63); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×4); requested a filename commonly used by web shells left behind by a previous compromise (×1); +1 more kind | — |
| 2026-10-04T22:28:13Z–2026-10-04T22:28:34Z | 20.210.128.125 | 37 requests on 37 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×33); requested a WordPress core file used to fingerprint the installed version and active plugins (×1); requested wp-config.php or a backup copy of it, hoping to read the database password in clear text (×1); +2 more kinds | — |
| 2026-10-04T22:27:08Z–2026-10-04T22:27:18Z | 20.194.30.107 | 20 requests on 20 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×19); checked for a known-vulnerable or backdoored WordPress plugin path (×1) | — |
| 2026-10-04T22:17:03Z–2026-10-04T22:17:40Z | 20.194.96.114 | 83 requests on 83 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×61); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×13); requested a filename commonly used by web shells left behind by a previous compromise (×2); +6 more kinds | — |
| 2026-10-04T22:15:32Z–2026-10-04T22:15:32Z | 54.202.51.12 | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | — |
| 2026-10-04T22:05:32Z–2026-10-04T22:14:17Z | 136.110.31.111 | 437 requests across 2 sites, 160 distinct paths — requested a .env file, hoping to find API keys or database credentials (×169); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×88); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×52); +21 more kinds | block |
| 2026-10-04T22:11:46Z–2026-10-04T22:11:47Z | 185.19.40.202 | 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1) | — |
| 2026-10-04T22:07:13Z–2026-10-04T22:10:50Z | 45.194.37.6 | 6 requests — probed a list of common site paths looking for an unprotected admin panel or staging copy | — |
| 2026-10-04T22:08:19Z–2026-10-04T22:08:57Z | 130.12.180.117 | 56 requests on 19 distinct paths — requested a .env file, hoping to find API keys or database credentials (×50); requested the .git directory itself, hoping it is exposed and browsable (×3); probed for an exposed .git directory to download the site's source history and config (×3) | — |
| 2026-10-04T22:08:20Z–2026-10-04T22:08:45Z | 20.58.177.98 | 75 requests on 75 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×74); checked for a known-vulnerable or backdoored WordPress plugin path (×1) | — |
| 2026-10-04T22:08:32Z–2026-10-04T22:08:36Z | 45.138.12.16 | 3 requests on 3 distinct paths — requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×1); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1) | — |
Top 5 right now
- 1.144.172.97.20293.3
- 2.45.138.12.2892.0
- 3.213.209.159.22389.9
- 4.207.175.220.5989.6
- 5.45.148.10.12089.0
Events / hour (7 days)
| Hour | Events |
|---|---|
| 2026-09-27T23:00:00Z | 93 |
| 2026-09-28T00:00:00Z | 56 |
| 2026-09-28T01:00:00Z | 27 |
| 2026-09-28T02:00:00Z | 131 |
| 2026-09-28T03:00:00Z | 278 |
| 2026-09-28T04:00:00Z | 29 |
| 2026-09-28T05:00:00Z | 70 |
| 2026-09-28T06:00:00Z | 296 |
| 2026-09-28T07:00:00Z | 190 |
| 2026-09-28T08:00:00Z | 37 |
| 2026-09-28T09:00:00Z | 33 |
| 2026-09-28T10:00:00Z | 24 |
| 2026-09-28T11:00:00Z | 379 |
| 2026-09-28T12:00:00Z | 33 |
| 2026-09-28T13:00:00Z | 5 |
| 2026-09-28T14:00:00Z | 175 |
| 2026-09-28T15:00:00Z | 8 |
| 2026-09-28T16:00:00Z | 51 |
| 2026-09-28T17:00:00Z | 18 |
| 2026-09-28T18:00:00Z | 50 |
| 2026-09-28T19:00:00Z | 48 |
| 2026-09-28T20:00:00Z | 41 |
| 2026-09-28T21:00:00Z | 13 |
| 2026-09-28T22:00:00Z | 563 |
| 2026-09-28T23:00:00Z | 775 |
| 2026-09-29T00:00:00Z | 756 |
| 2026-09-29T01:00:00Z | 461 |
| 2026-09-29T02:00:00Z | 285 |
| 2026-09-29T03:00:00Z | 1088 |
| 2026-09-29T04:00:00Z | 1141 |
| 2026-09-29T05:00:00Z | 1544 |
| 2026-09-29T06:00:00Z | 4244 |
| 2026-09-29T07:00:00Z | 1363 |
| 2026-09-29T08:00:00Z | 1784 |
| 2026-09-29T09:00:00Z | 1514 |
| 2026-09-29T10:00:00Z | 1749 |
| 2026-09-29T11:00:00Z | 968 |
| 2026-09-29T12:00:00Z | 1746 |
| 2026-09-29T13:00:00Z | 1285 |
| 2026-09-29T14:00:00Z | 1442 |
| 2026-09-29T15:00:00Z | 1116 |
| 2026-09-29T16:00:00Z | 760 |
| 2026-09-29T17:00:00Z | 1308 |
| 2026-09-29T18:00:00Z | 838 |
| 2026-09-29T19:00:00Z | 3473 |
| 2026-09-29T20:00:00Z | 1526 |
| 2026-09-29T21:00:00Z | 1185 |
| 2026-09-29T22:00:00Z | 860 |
| 2026-09-29T23:00:00Z | 332 |
| 2026-09-30T00:00:00Z | 798 |
| 2026-09-30T01:00:00Z | 1579 |
| 2026-09-30T02:00:00Z | 753 |
| 2026-09-30T03:00:00Z | 2499 |
| 2026-09-30T04:00:00Z | 2550 |
| 2026-09-30T05:00:00Z | 2663 |
| 2026-09-30T06:00:00Z | 1024 |
| 2026-09-30T07:00:00Z | 1537 |
| 2026-09-30T08:00:00Z | 914 |
| 2026-09-30T09:00:00Z | 1091 |
| 2026-09-30T10:00:00Z | 1307 |
| 2026-09-30T11:00:00Z | 378 |
| 2026-09-30T12:00:00Z | 2011 |
| 2026-09-30T13:00:00Z | 1417 |
| 2026-09-30T14:00:00Z | 918 |
| 2026-09-30T15:00:00Z | 761 |
| 2026-09-30T16:00:00Z | 1324 |
| 2026-09-30T17:00:00Z | 1012 |
| 2026-09-30T18:00:00Z | 861 |
| 2026-09-30T19:00:00Z | 1149 |
| 2026-09-30T20:00:00Z | 1179 |
| 2026-09-30T21:00:00Z | 944 |
| 2026-09-30T22:00:00Z | 388 |
| 2026-09-30T23:00:00Z | 142 |
| 2026-10-01T00:00:00Z | 518 |
| 2026-10-01T01:00:00Z | 639 |
| 2026-10-01T02:00:00Z | 220 |
| 2026-10-01T03:00:00Z | 414 |
| 2026-10-01T04:00:00Z | 441 |
| 2026-10-01T05:00:00Z | 771 |
| 2026-10-01T06:00:00Z | 607 |
| 2026-10-01T07:00:00Z | 967 |
| 2026-10-01T08:00:00Z | 187 |
| 2026-10-01T09:00:00Z | 1141 |
| 2026-10-01T10:00:00Z | 652 |
| 2026-10-01T11:00:00Z | 378 |
| 2026-10-01T12:00:00Z | 317 |
| 2026-10-01T13:00:00Z | 871 |
| 2026-10-01T14:00:00Z | 1247 |
| 2026-10-01T15:00:00Z | 787 |
| 2026-10-01T16:00:00Z | 899 |
| 2026-10-01T17:00:00Z | 373 |
| 2026-10-01T18:00:00Z | 2206 |
| 2026-10-01T19:00:00Z | 913 |
| 2026-10-01T20:00:00Z | 570 |
| 2026-10-01T21:00:00Z | 416 |
| 2026-10-01T22:00:00Z | 846 |
| 2026-10-01T23:00:00Z | 480 |
| 2026-10-02T00:00:00Z | 527 |
| 2026-10-02T01:00:00Z | 1095 |
| 2026-10-02T02:00:00Z | 224 |
| 2026-10-02T03:00:00Z | 1250 |
| 2026-10-02T04:00:00Z | 1706 |
| 2026-10-02T05:00:00Z | 697 |
| 2026-10-02T06:00:00Z | 3338 |
| 2026-10-02T07:00:00Z | 1596 |
| 2026-10-02T08:00:00Z | 1918 |
| 2026-10-02T09:00:00Z | 613 |
| 2026-10-02T10:00:00Z | 1428 |
| 2026-10-02T11:00:00Z | 796 |
| 2026-10-02T12:00:00Z | 567 |
| 2026-10-02T13:00:00Z | 1669 |
| 2026-10-02T14:00:00Z | 546 |
| 2026-10-02T15:00:00Z | 340 |
| 2026-10-02T16:00:00Z | 558 |
| 2026-10-02T17:00:00Z | 489 |
| 2026-10-02T18:00:00Z | 1707 |
| 2026-10-02T19:00:00Z | 642 |
| 2026-10-02T20:00:00Z | 402 |
| 2026-10-02T21:00:00Z | 816 |
| 2026-10-02T22:00:00Z | 637 |
| 2026-10-02T23:00:00Z | 385 |
| 2026-10-03T00:00:00Z | 897 |
| 2026-10-03T01:00:00Z | 688 |
| 2026-10-03T02:00:00Z | 469 |
| 2026-10-03T03:00:00Z | 371 |
| 2026-10-03T04:00:00Z | 856 |
| 2026-10-03T05:00:00Z | 876 |
| 2026-10-03T06:00:00Z | 923 |
| 2026-10-03T07:00:00Z | 1115 |
| 2026-10-03T08:00:00Z | 1187 |
| 2026-10-03T09:00:00Z | 673 |
| 2026-10-03T10:00:00Z | 933 |
| 2026-10-03T11:00:00Z | 909 |
| 2026-10-03T12:00:00Z | 756 |
| 2026-10-03T13:00:00Z | 1043 |
| 2026-10-03T14:00:00Z | 353 |
| 2026-10-03T15:00:00Z | 1076 |
| 2026-10-03T16:00:00Z | 727 |
| 2026-10-03T17:00:00Z | 435 |
| 2026-10-03T18:00:00Z | 1590 |
| 2026-10-03T19:00:00Z | 905 |
| 2026-10-03T20:00:00Z | 1062 |
| 2026-10-03T21:00:00Z | 802 |
| 2026-10-03T22:00:00Z | 1376 |
| 2026-10-03T23:00:00Z | 832 |
| 2026-10-04T00:00:00Z | 618 |
| 2026-10-04T01:00:00Z | 661 |
| 2026-10-04T02:00:00Z | 1146 |
| 2026-10-04T03:00:00Z | 1365 |
| 2026-10-04T04:00:00Z | 507 |
| 2026-10-04T05:00:00Z | 887 |
| 2026-10-04T06:00:00Z | 890 |
| 2026-10-04T07:00:00Z | 787 |
| 2026-10-04T08:00:00Z | 723 |
| 2026-10-04T09:00:00Z | 1784 |
| 2026-10-04T10:00:00Z | 1183 |
| 2026-10-04T11:00:00Z | 949 |
| 2026-10-04T12:00:00Z | 550 |
| 2026-10-04T13:00:00Z | 567 |
| 2026-10-04T14:00:00Z | 1263 |
| 2026-10-04T15:00:00Z | 1049 |
| 2026-10-04T16:00:00Z | 745 |
| 2026-10-04T17:00:00Z | 1068 |
| 2026-10-04T18:00:00Z | 1080 |
| 2026-10-04T19:00:00Z | 1715 |
| 2026-10-04T20:00:00Z | 2199 |
| 2026-10-04T21:00:00Z | 1759 |
| 2026-10-04T22:00:00Z | 1896 |
Top attack types (7 days)
Breakdown by surface
| Surface | Attack type | Count |
|---|---|---|
| ftp | credential-brute | 17 |
| mail-smtp | credential-brute | 207 |
| mail-smtp | spam-relay-probe | 126 |
| panel | credential-brute | 12 |
| panel | injection | 8 |
| panel | open-proxy-probe | 8 |
| panel | recon | 26 |
| panel | scanner-tool | 38 |
| panel | secrets-hunt | 329 |
| ssh | recon | 5 |
| ssh | scanner-tool | 18 |
| web-app | bot-impersonation | 68 |
| web-app | credential-spray | 6583 |
| web-app | cve-exploit | 852 |
| web-app | dos-pattern | 2 |
| web-app | injection | 4662 |
| web-app | recon | 74813 |
| web-app | scanner-tool | 5905 |
| web-app | secrets-hunt | 56160 |
| web-app | unknown | 2602 |
Top ASNs
| ASN | Organisation | Addresses |
|---|---|---|
| AS396982 | Google LLC | 1201 |
| AS14061 | DigitalOcean, LLC | 353 |
| AS8075 | Microsoft Corporation | 151 |
| AS48090 | Techoff Srv Limited | 66 |
| AS206092 | F.n.s. Holdings Limited | 58 |
| AS16509 | Amazon.com, Inc. | 53 |
| AS63949 | Akamai Connected Cloud | 50 |
| AS218785 | Tc Datacenter Limited | 39 |
| AS31898 | Oracle Corporation | 38 |
| AS197170 | TechTies Inc. | 37 |
Top 10 countries
| Country | Addresses |
|---|---|
| United States | 1145 |
| Singapore | 194 |
| India | 184 |
| The Netherlands | 177 |
| Germany | 170 |
| France | 130 |
| Belgium | 123 |
| United Kingdom | 94 |
| Taiwan | 86 |
| Brazil | 82 |
Most Wanted
Hosting/cloud-ASN addresses only — a residential or mobile address never appears here, whatever its score.
| Address | Score | Status | Organisation | Sensors | Last seen |
|---|---|---|---|---|---|
| 144.172.97.202 | 93.3 | blockedWantedRegular | RouterHosting LLC | edgesensor | 2026-10-04T17:25:56Z |
| 45.138.12.28 | 92.0 | blockedWantedRegularNight OwlToolkit | Tc Datacenter Limited | edgesensor | 2026-10-02T13:30:55Z |
| 213.209.159.223 | 90.0 | blockedWantedRegularToolkit | Feo Prest SRL | edgesensor | 2026-10-04T22:30:26Z |
| 207.175.220.59 | 89.6 | blockedWantedRegularToolkit | Google LLC | edgesensor | 2026-10-01T20:09:51Z |
| 45.148.10.120 | 89.0 | blockedWantedRegularToolkitRepeat Offender | Techoff Srv Limited | edgesensor | 2026-10-04T15:06:47Z |
| 20.204.42.136 | 84.5 | blockedRelentlessRegularToolkit | Microsoft Corporation | edgesensor | 2026-10-04T18:19:55Z |
| 45.138.12.26 | 83.0 | blockedRelentlessRegularToolkit | Tc Datacenter Limited | edgesensor | 2026-10-02T14:56:32Z |
| 35.241.202.92 | 82.7 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T12:16:32Z |
| 34.156.121.46 | 82.3 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T09:18:16Z |
| 35.240.100.200 | 82.2 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T08:21:32Z |
| 213.209.159.133 | 80.7 | blockedRelentlessRegularToolkit | Feo Prest SRL | edgesensor | 2026-10-04T22:53:56Z |
| 34.62.116.145 | 80.2 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T14:46:53Z |
| 34.140.234.80 | 80.0 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T13:12:39Z |
| 34.14.99.143 | 79.9 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T12:07:53Z |
| 34.156.206.32 | 79.4 | blockedRelentlessRegularToolkit | Google LLC | edgesensor | 2026-10-02T08:07:37Z |
| 34.62.82.165 | 79.1 | blockedRelentlessRegularNight OwlToolkit | Google LLC | edgesensor | 2026-10-02T05:46:48Z |
| 20.219.185.206 | 78.8 | blockedRelentlessRegularToolkit | Microsoft Corporation | edgesensor | 2026-10-04T20:48:58Z |
| 13.70.107.184 | 78.8 | blockedRelentlessRegularToolkit | Microsoft Corporation | edgesensor | 2026-10-04T20:37:39Z |
| 20.58.177.98 | 77.9 | blockedRelentlessRegularToolkit | Microsoft Corporation | sensor | 2026-10-04T22:08:45Z |
| 45.138.12.16 | 77.9 | blockedRelentlessRegularToolkit | Tc Datacenter Limited | edgesensor | 2026-10-04T22:08:36Z |
Campaigns
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 14 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 5 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 4 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 10 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 3 addresses
- Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, l… — 8 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 9 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 4 addresses
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36… — 24 addresses
- Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, l… — 4 addresses
Feeds
Free, signed, updated every 10 minutes. See /threats/about for the full terms.
- feed.txt — one address per line, hosting and cloud networks (CSF/Cloudflare-list compatible)
- feed-residential.txt — opt-in: residential, mobile and unknown networks (30-day windows)
- feed-listed.txt — lower confidence: listed and blocked, not enforced by us
- feed-v6.txt — blocked IPv6 as /64 prefixes
- feed.json — full detail, with
expiresper address - feed-web.txt, feed-ssh.txt, feed-mail.txt, feed-panel.txt — per-surface
- vocab-v1.json — the surface/attack-type vocabulary
- pubkey.minisig — signing public key