Skip to content
Latest
AI Infrastructure Is Becoming a Control Plane Attack SurfaceQScan and QTRouter Show Why Proxy Infrastructure Is an Espionage Force MultipliervCenter Exploitation Shows Patching Alone Is Not Incident ResponseEdge Infrastructure Convergence Shows Why Perimeter Devices Need Their Own Patch SLAsSigned ClickOnce Lures Show Why Hiring Workflows Need Endpoint GuardrailsShieldBreak Shows Why Endpoint Protection Needs Compensating ControlsAI-Enabled Malware Still Behaves Like MalwarePrivate APNs Are Becoming OT Attack PathsvCenter Exploitation Shows Why Control Planes Need ContainmentApollo Breach Shows Why Helpdesk Vishing Is a Cloud-Control ProblemBTR.sys Shows Why Trusted Security Drivers Need Behavioral MonitoringWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime Controls

Threat Intelligence

Threat Feeds

Free, machine-readable indicators enriched from our threat reporting. Only values that meet the current exact, fresh malicious-evidence policy enter these feeds; clean, unknown, pending, and unsupported values stay out.

92 live indicators·30 reports·checking live guard

Values are live and functional. Provider matches are evidence rather than universal ground truth, and fast-moving network indicators expire automatically. Stage the feeds in monitoring and review impact before enforcement.

Blocklists (plain text)

One indicator per line. Import into a review or monitoring workflow before enforcing blocks.

Domains admitted by fresh exact-match malicious evidence for DNS and web-proxy monitoring.

https://bulwarkblack.com/feeds/domains.txt

IPv4 addresses admitted by fresh exact-match malicious evidence for firewall monitoring.

https://bulwarkblack.com/feeds/ips.txt

Exact URLs admitted by fresh malicious-list evidence for web proxies and gateways.

https://bulwarkblack.com/feeds/urls.txt

MD5, SHA-1, and SHA-256 hashes admitted by fresh exact-match malicious evidence for endpoint hunting.

https://bulwarkblack.com/feeds/hashes.txt

Structured exports

indicators.csv

Every verified feed indicator with its type, report count, first and last seen dates, and an example report.

https://bulwarkblack.com/feeds/indicators.csv
indicators.json

The same verified data as JSON, including the reports each indicator came from.

https://bulwarkblack.com/feeds/indicators.json
rules.yar

YARA rules grouped by report and generated only from verified feed indicators. Tune before deployment.

https://bulwarkblack.com/feeds/rules.yar

Look up a single indicator

Paste a domain, IP, URL, or supported file hash to check whether it is in the current verified feed and which reports it came from. Context-only observables remain available in the Indicator Database.

Prefer the API? Same data, one indicator at a time:

curl "https://bulwarkblack.com/api/ioc/lookup?value=1.2.3.4"

How to use them

Pull a feed

curl https://bulwarkblack.com/feeds/domains.txt

Refresh hourly (cron)

0 * * * * curl -s \
  https://bulwarkblack.com/feeds/ips.txt \
  -o /etc/blocklists/bulwark-ips.txt

Pi-hole / DNS sink

Add https://bulwarkblack.com/feeds/domains.txt as an adlist, then update gravity.

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.