Skip to content

Threat intelligence API / integrations

AdGuard Home

AdGuard Home reads the same plain list of domains that Pi-hole does. Add the ThreatCluster domain feed as a custom blocklist and it is in use straight away. The feed is a public text file, so this needs no API key.

Prerequisites

  1. An AdGuard Home you can sign in to. The screenshots are from version 0.107.79, run in Docker on 29 September 2026.
  2. The feed address: https://threatcluster.io/api/iocs/public/domains.txt

Setup

  1. Open Filters, then DNS blocklists. Select Add blocklist, then Add a custom list. Give it a name, paste the feed address and select Save.

    The AdGuard Home New blocklist dialog with a name and the ThreatCluster feed address filled in, above Cancel and Save buttons
    The name is yours to choose. It appears in the query log beside every lookup the list blocks.
  2. AdGuard Home downloads the list when you save. There is no separate update step.

    The DNS blocklists table with three lists, the third being the ThreatCluster feed, enabled, with a rules count of 387
    387 rules read from the feed.
  3. Test it. Ask AdGuard Home for a domain from the feed and for one that is not on it. Replace the address and port with your own.

    dig +short @192.168.1.2 fonts.tarotfree101.top
    dig +short @192.168.1.2 example.org
    A terminal asking AdGuard Home for a domain from the feed, which returns 0.0.0.0, and for example.org, which returns two real addresses
    The blocked domain comes back as 0.0.0.0. The test ran against a local AdGuard Home on port 8054.
  4. Open Query Log. A blocked lookup is shown in red with the name of the list that blocked it.

    The AdGuard Home query log with a lookup for the feed domain marked Blocked by the ThreatCluster list and a lookup for example.org marked Processed
    The lookups before the list was added are further down, marked Processed.

Keeping it current

Under Settings, then General settings, set Filters update interval. The feed changes daily, so 24 hours or less is worth having.

Worth knowing

  1. What is in the feed. Domains confirmed as attacker infrastructure in the last 30 days. Every one has passed validation.
  2. If a block is wrong. Tell us at /corrections so it comes off the feed for everyone.
  3. Pi-hole uses the same address. See the Pi-hole guide.