Skip to main content

Feed catalog

The catalog ships fourteen curated sources with their URL, parser settings, suggested weight and licence, so you get value on day one without hunting for endpoints.

Threat Protection → Threat feed catalog → Create a feed from this source.

The feed catalog: each source with its kind, its recommended action and weight, its url and its licence

Each entry carries the action and weight it is recommended with — monitor · weight 40 for Tor exit nodes, block · weight 80 for FireHOL level 1 — and the licence line, because that is the part that decides whether you may use it.

It creates an entity, it does not become one​

A catalog entry is a template. Creating a feed copies the entry into an editable ThreatFeed and the catalog is out of the picture from then on.

That is deliberate. Providers move their endpoints, and several of these sources forbid redistribution — so the extension ships pointers and parsers, never mirrored data. When a URL changes, you fix one field instead of waiting for a release.

Sources that need credentials or a manual URL are created disabled, so nothing starts failing silently while you fill in what is missing.

What ships​

Blocklists​

SourceWeightActionNotes
Spamhaus DROP90blockNetblocks controlled by criminal operations. Very low false-positive rate
FireHOL level 180blockConservative aggregation of well-established lists. The usual starting point
Emerging Threats — compromised hosts70blockSmall, high-signal
FireHOL level 260monitorBroader, higher false-positive rate
FireHOL level 340monitorWidest. A scoring signal, not a blocking one
AbuseIPDB blacklist85blockNeeds an account and an API key

Anonymity​

SourceWeightActionNotes
Tor exit nodes40monitorA strong signal, and a legitimate one for many users

Cloud provider ranges​

Not blocklists — a hosting signal. Most scrapers leave a cloud ASN, and so does every legitimate server-to-server integration you have.

SourceWeightAction
AWS (ipv4 and ipv6)15monitor
Google Cloud15monitor
DigitalOcean20monitor
Azure15monitor

Allowlist inputs​

SourceWeightActionNotes
Cloudflare edge (ipv4, ipv6)0monitorWhen your traffic legitimately arrives through Cloudflare, these must never be scored

Entries that need work before they run​

Two entries cannot ship ready to use, and say so on their card:

AbuseIPDB needs an account. Add a Key header with your API key — as a vault reference — and an Accept: application/json header, then enable it.

Azure rotates its download URL every week, so no fixed link can be shipped. Fetch the current weekly JSON link from the Microsoft download page and paste it into the feed's url.

Verify before production​

Check the URL and the licence yourself

Providers change endpoints and terms without notice. Spamhaus has been consolidating DROP onto JSON endpoints; several sources restrict commercial use. The catalog records the licence it knew about at the time it was written — treat that as a starting point for your own check, not as legal clearance.

After creating a feed, press Refresh now and read the status panel. A non-zero Rejected lines count, or an entry count far from what you expect, usually means the provider changed format.

Adding your own sources​

Nothing about a catalog entry is privileged — it produces an ordinary ThreatFeed. Internal blocklists, a corporate threat intelligence platform, or a MISP instance are created the same way, by hand or through the admin API.