Free threat intelligence feeds

27 public sources that are actually maintained, grouped by the job they do. ThreatCluster's own free feeds are in the list next to everyone else's; the point of the page is to save you the afternoon of finding out which links still work.

Formats and cadence checked September 2026. Every source sets its own terms of use.

Indicators of compromise

Blocklists and IOC feeds you can load into a firewall, proxy or SIEM.

FeedWhat it gives youFormatUpdates
ThreatCluster public IOC feedMalicious domains, IPs and hashes from the last 30 days, extracted from incident reporting and validated on ingesttxt, JSON, CSVHourly
abuse.ch URLhausMalware distribution URLs with payload and tagsCSV, JSON, APIContinuous
abuse.ch ThreatFoxCommunity-submitted IOCs tied to malware familiesCSV, JSON, API, MISPContinuous
abuse.ch Feodo TrackerBotnet command-and-control IPs (Dridex, Emotet, QakBot lineage)CSV, JSON, SuricataContinuous
abuse.ch SSL BlacklistCertificate fingerprints and IPs used by malware C2CSVContinuous
Botvrij.euOSINT indicators in MISP format, ready to importMISPDaily

Malware and phishing

Samples, hashes and phishing URLs.

FeedWhat it gives youFormatUpdates
abuse.ch MalwareBazaarMalware samples and hashes, tagged, with download for vetted usersAPI, CSVContinuous
PhishTankCommunity-verified phishing URLsJSON, CSV, APIContinuous, free key
OpenPhishPhishing URLs from automated detection; the community feed is freetxtEvery 12 hours (community)

Vulnerabilities and exploitation

Which CVEs exist, how severe they are, and which are being used.

FeedWhat it gives youFormatUpdates
CISA Known Exploited VulnerabilitiesThe official list of CVEs with confirmed exploitation, with due datesCSV, JSONAs added
FIRST EPSSProbability that a CVE is exploited in the next 30 daysCSV, APIDaily
NVDCVE records with CVSS and affected productsJSON APIContinuous, rate-limited without a key
Exploit-DBPublic exploit code indexed by CVECSV, gitContinuous
ThreatCluster exploits hubCVEs ranked by reporting of exploitation, joined with EPSS and KEVHTML, APIContinuous

Ransomware and leak sites

Who ransomware groups are listing, from their own sites.

FeedWhat it gives youFormatUpdates
ThreatCluster ransomware feedLeak-site victim listings from ThreatCluster's first-party collection: group, organisation, date, sector, countryRSS; JSON and CSV on GitHubContinuous
ransomware.liveLeak-site victim posts aggregated across groupsJSON APIContinuous
ransomwatchOpen-source leak-site scraper with published post historyJSON on GitHubContinuous

Network blocklists

IP and netblock lists for perimeter blocking. Aggressive by design; test before enforcing.

FeedWhat it gives youFormatUpdates
Spamhaus DROP and EDROPHijacked and criminal-controlled netblocks that should never routetxtRegular
FireHOL IP listsAggregation of hundreds of public IP blocklists with overlap analysistxt, ipsetContinuous
blocklist.deIPs reported for attacks on fail2ban-protected servicestxtEvery 30 minutes
CINS Army listIPs with poor reputation across CINS sensorstxtContinuous
Emerging Threats OpenSuricata and Snort rules plus compromised-IP lists, free tierrules, txtDaily
Tor exit node listCurrent Tor exit addresses, for policy rather than blockingtxtContinuous

Reporting and context

Feeds that carry the story, not just the indicator.

FeedWhat it gives youFormatUpdates
ThreatCluster threat feedOne scored record per incident from 20,000 sources, deduplicated, with entities and links to sourcesRSS, APIContinuous
AlienVault OTXCommunity pulses with indicators and contextAPI, STIXContinuous, free key
MISP default feed listThe curated list of OSINT feeds a MISP instance can enableMISPVaries
MITRE ATT&CKTechniques, groups and software as STIX bundlesSTIX 2.1 on GitHubPer release

Questions

Which feed should a small team start with?

CISA KEV for patching, one IOC feed for blocking (URLhaus or the ThreatCluster public feed), and one reporting feed so you know why an indicator matters. Add more only when the first three are wired into something.

Can I use these commercially?

Each source sets its own terms. abuse.ch feeds are CC0, CISA data is public domain, ThreatCluster's public feeds are TLP:CLEAR with attribution. Check the licence before redistributing.

How do I load a feed into a SIEM or firewall?

Most tools take a plain text list or CSV by URL on a schedule. The ThreatCluster format matrix shows which formats Splunk, Sentinel, Elastic, MISP and OpenCTI accept.

Are free feeds good enough?

For blocking known-bad infrastructure and tracking exploited CVEs, yes. What they lack is deduplication across sources, scoring, and the record of why an indicator was added, which is what a paid API or platform sells.

When a list of feeds stops being enough

Feeds tell you an indicator is bad. They do not tell you which of the twelve sources that mention it agree, how severe the incident behind it is, or whether it matters to your sector. That is the job of the threat intelligence API: one scored record per incident, with the sources attached, and a free key on every account.