Free threat intelligence feeds
27 public sources that are actually maintained, grouped by the job they do. ThreatCluster's own free feeds are in the list next to everyone else's; the point of the page is to save you the afternoon of finding out which links still work.
Formats and cadence checked September 2026. Every source sets its own terms of use.
Indicators of compromise
Blocklists and IOC feeds you can load into a firewall, proxy or SIEM.
| Feed | What it gives you | Format | Updates |
|---|---|---|---|
| ThreatCluster public IOC feed | Malicious domains, IPs and hashes from the last 30 days, extracted from incident reporting and validated on ingest | txt, JSON, CSV | Hourly |
| abuse.ch URLhaus | Malware distribution URLs with payload and tags | CSV, JSON, API | Continuous |
| abuse.ch ThreatFox | Community-submitted IOCs tied to malware families | CSV, JSON, API, MISP | Continuous |
| abuse.ch Feodo Tracker | Botnet command-and-control IPs (Dridex, Emotet, QakBot lineage) | CSV, JSON, Suricata | Continuous |
| abuse.ch SSL Blacklist | Certificate fingerprints and IPs used by malware C2 | CSV | Continuous |
| Botvrij.eu | OSINT indicators in MISP format, ready to import | MISP | Daily |
Malware and phishing
Samples, hashes and phishing URLs.
| Feed | What it gives you | Format | Updates |
|---|---|---|---|
| abuse.ch MalwareBazaar | Malware samples and hashes, tagged, with download for vetted users | API, CSV | Continuous |
| PhishTank | Community-verified phishing URLs | JSON, CSV, API | Continuous, free key |
| OpenPhish | Phishing URLs from automated detection; the community feed is free | txt | Every 12 hours (community) |
Vulnerabilities and exploitation
Which CVEs exist, how severe they are, and which are being used.
| Feed | What it gives you | Format | Updates |
|---|---|---|---|
| CISA Known Exploited Vulnerabilities | The official list of CVEs with confirmed exploitation, with due dates | CSV, JSON | As added |
| FIRST EPSS | Probability that a CVE is exploited in the next 30 days | CSV, API | Daily |
| NVD | CVE records with CVSS and affected products | JSON API | Continuous, rate-limited without a key |
| Exploit-DB | Public exploit code indexed by CVE | CSV, git | Continuous |
| ThreatCluster exploits hub | CVEs ranked by reporting of exploitation, joined with EPSS and KEV | HTML, API | Continuous |
Ransomware and leak sites
Who ransomware groups are listing, from their own sites.
| Feed | What it gives you | Format | Updates |
|---|---|---|---|
| ThreatCluster ransomware feed | Leak-site victim listings from ThreatCluster's first-party collection: group, organisation, date, sector, country | RSS; JSON and CSV on GitHub | Continuous |
| ransomware.live | Leak-site victim posts aggregated across groups | JSON API | Continuous |
| ransomwatch | Open-source leak-site scraper with published post history | JSON on GitHub | Continuous |
Network blocklists
IP and netblock lists for perimeter blocking. Aggressive by design; test before enforcing.
| Feed | What it gives you | Format | Updates |
|---|---|---|---|
| Spamhaus DROP and EDROP | Hijacked and criminal-controlled netblocks that should never route | txt | Regular |
| FireHOL IP lists | Aggregation of hundreds of public IP blocklists with overlap analysis | txt, ipset | Continuous |
| blocklist.de | IPs reported for attacks on fail2ban-protected services | txt | Every 30 minutes |
| CINS Army list | IPs with poor reputation across CINS sensors | txt | Continuous |
| Emerging Threats Open | Suricata and Snort rules plus compromised-IP lists, free tier | rules, txt | Daily |
| Tor exit node list | Current Tor exit addresses, for policy rather than blocking | txt | Continuous |
Reporting and context
Feeds that carry the story, not just the indicator.
| Feed | What it gives you | Format | Updates |
|---|---|---|---|
| ThreatCluster threat feed | One scored record per incident from 20,000 sources, deduplicated, with entities and links to sources | RSS, API | Continuous |
| AlienVault OTX | Community pulses with indicators and context | API, STIX | Continuous, free key |
| MISP default feed list | The curated list of OSINT feeds a MISP instance can enable | MISP | Varies |
| MITRE ATT&CK | Techniques, groups and software as STIX bundles | STIX 2.1 on GitHub | Per release |
Questions
Which feed should a small team start with?
CISA KEV for patching, one IOC feed for blocking (URLhaus or the ThreatCluster public feed), and one reporting feed so you know why an indicator matters. Add more only when the first three are wired into something.
Can I use these commercially?
Each source sets its own terms. abuse.ch feeds are CC0, CISA data is public domain, ThreatCluster's public feeds are TLP:CLEAR with attribution. Check the licence before redistributing.
How do I load a feed into a SIEM or firewall?
Most tools take a plain text list or CSV by URL on a schedule. The ThreatCluster format matrix shows which formats Splunk, Sentinel, Elastic, MISP and OpenCTI accept.
Are free feeds good enough?
For blocking known-bad infrastructure and tracking exploited CVEs, yes. What they lack is deduplication across sources, scoring, and the record of why an indicator was added, which is what a paid API or platform sells.
When a list of feeds stops being enough
Feeds tell you an indicator is bad. They do not tell you which of the twelve sources that mention it agree, how severe the incident behind it is, or whether it matters to your sector. That is the job of the threat intelligence API: one scored record per incident, with the sources attached, and a free key on every account.