Skip to content
Latest
Q3 Attack Trends Show Trusted Paths Are Becoming the Real TargetFortiBleed Shows Why VPN Credential Compromise Needs Full Incident ResponseGitHub Enterprise SSRF Shows Why Secret Scanning Needs Network GuardrailsBlinder Tunnel Shows How Developer Trust Becomes Critical Infrastructure RiskBrowser Detection and Response Shows Why the Browser Is Now a Security Blind SpotApache Struts REST Plugin Flaws Show Why Legacy Java Apps Need Exposure ReviewClingSTUN Shows Why IoT Edge Devices Need Real Egress MonitoringApache Thrift 61-CVE Patch Shows Why RPC Frameworks Need InventoryNIST OT Zero Trust Guidance Shows Segmentation Must Reach Below Level 3Milk Dragon Shows Social Commerce Phishing Needs Identity and Payment ControlsCisco SD-WAN Auth Bypass Shows Edge Control Planes Need Emergency ReviewRansomware Data Theft Surge Shows Why Exfiltration Defense Comes FirstLive Exposed Credentials Show Why Secret Scanning Must End in RevocationAntino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware Detection

Threat Intelligence

Threat Feeds

Free, machine-readable indicators enriched from our threat reporting. Only values that meet the current exact, fresh malicious-evidence policy enter these feeds; clean, unknown, pending, and unsupported values stay out.

13 live indicators·6 reports·checking live guard

Values are live and functional. Provider matches are evidence rather than universal ground truth, and fast-moving network indicators expire automatically. Stage the feeds in monitoring and review impact before enforcement.

Blocklists (plain text)

One indicator per line. Import into a review or monitoring workflow before enforcing blocks.

Domains admitted by fresh exact-match malicious evidence for DNS and web-proxy monitoring.

https://bulwarkblack.com/feeds/domains.txt

IPv4 addresses admitted by fresh exact-match malicious evidence for firewall monitoring.

https://bulwarkblack.com/feeds/ips.txt

Exact URLs admitted by fresh malicious-list evidence for web proxies and gateways.

https://bulwarkblack.com/feeds/urls.txt

MD5, SHA-1, and SHA-256 hashes admitted by fresh exact-match malicious evidence for endpoint hunting.

https://bulwarkblack.com/feeds/hashes.txt

Structured exports

indicators.csv

Every verified feed indicator with its type, report count, first and last seen dates, and an example report.

https://bulwarkblack.com/feeds/indicators.csv
indicators.json

The same verified data as JSON, including the reports each indicator came from.

https://bulwarkblack.com/feeds/indicators.json
rules.yar

YARA rules grouped by report and generated only from verified feed indicators. Tune before deployment.

https://bulwarkblack.com/feeds/rules.yar

Look up a single indicator

Paste a domain, IP, URL, or supported file hash to check whether it is in the current verified feed and which reports it came from. Context-only observables remain available in the Indicator Database.

Prefer the API? Same data, one indicator at a time:

curl "https://bulwarkblack.com/api/ioc/lookup?value=1.2.3.4"

How to use them

Pull a feed

curl https://bulwarkblack.com/feeds/domains.txt

Refresh hourly (cron)

0 * * * * curl -s \
  https://bulwarkblack.com/feeds/ips.txt \
  -o /etc/blocklists/bulwark-ips.txt

Pi-hole / DNS sink

Add https://bulwarkblack.com/feeds/domains.txt as an adlist, then update gravity.

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.