Skip to content
Latest
Langflow RCE Shows Why AI Workflow Tools Need Cloud-Grade IsolationBINDCLOAK Shows Why C2 Detection Needs Message-Level VisibilityPasskey Attacks Show Why Passwordless Still Needs Endpoint DefenseDPRK npm Compromises Show Why Dependency Trust Is Now Identity RiskN-able N-central Exploitation Shows Why MSP Tools Are Control-Plane RiskHOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 BattlefieldFuyao Android TV Botnet Shows Why Cheap Streaming Sticks Are Business Network RiskSonicWall SMA Exploit Chain Shows Why VPN Appliances Need Incident Response, Not Just PatchingAdform Script Compromise Shows Why Third-Party Tags Need Supply-Chain ControlsCaptiveCrunch Shows Why Travel Wi-Fi Is Now an Identity Attack SurfaceXCSSET v40 Shows Why Developer Macs Are Supply-Chain Infrastructure84 4G/5G Core Flaws Show Why Telecom Trust Zones Need Zero TrustAstaroth WhatsApp Web Spambot Shows Browser Sessions Are Distribution InfrastructureTA488 Turns Outlook Web Access Into a Stealthy Persistence Layer

Threat Intelligence

Threat Feeds

Free, machine-readable indicators auto-extracted from our threat reporting. Plain-text blocklists for your firewall or DNS, plus CSV and JSON for your own tooling. Every feed regenerates automatically when we publish a new report, so the link stays the same and the data stays current.

3584 live indicators · 251 reports · updated on every report

Values are live and functional. They are auto-extracted and can include false positives, so test against your environment before you block.

Blocklists (plain text)

One indicator per line. Wire these straight into a firewall, DNS sink, Pi-hole, or SIEM.

Domains 1046

Malicious and suspicious domains. Point DNS filtering, a web proxy, or Pi-hole at it.

https://bulwarkblack.com/feeds/domains.txt

IPv4 addresses and CIDR ranges. Drop or alert on them at the firewall.

https://bulwarkblack.com/feeds/ips.txt
URLs 399

Full malicious URLs for web proxy and gateway blocklists.

https://bulwarkblack.com/feeds/urls.txt

MD5, SHA-1, SHA-256, SHA-512 and import hashes. Hunt across your endpoints.

https://bulwarkblack.com/feeds/hashes.txt

Structured exports

indicators.csv

Every indicator with its type, how many reports it appears in, first and last seen, and an example report.

https://bulwarkblack.com/feeds/indicators.csv
indicators.json

The same data as JSON, including the full list of reports each indicator came from.

https://bulwarkblack.com/feeds/indicators.json
rules.yar

YARA rules grouped by report: network-indicator strings plus known file hashes. Drop into your scanner to hunt across files and memory.

https://bulwarkblack.com/feeds/rules.yar

Look up a single indicator

Paste a domain, IP, hash, or CVE to check whether we have seen it and which reports it came from. Matched instantly against all 3584 indicators, right in your browser.

Prefer the API? Same data, one indicator at a time:

curl "https://bulwarkblack.com/api/ioc/lookup?value=1.2.3.4"

How to use them

Pull a feed

curl https://bulwarkblack.com/feeds/domains.txt

Refresh hourly (cron)

0 * * * * curl -s \
  https://bulwarkblack.com/feeds/ips.txt \
  -o /etc/blocklists/bulwark-ips.txt

Pi-hole / DNS sink

Add https://bulwarkblack.com/feeds/domains.txt as an adlist, then update gravity.

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.