IOC Feeds and YARA rules

Download all IOCs as CSV, JSON lines or in the Elastic Common Schema format (ECS). Note: IOCs likely to cause false positives, such as filenames or port numbers, have been removed. Please limit downloads to once per hour, as updates are infrequent. You can also subscribe to a MISP feed of all reports and download all collected YARA rules in a single rule file.

Domain Feeds

These feeds contain the domains from the past 180 days which have the IDS flag set .

Should be used for
Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, AdBlock, Adblock Plus, Opera, Vivaldi, Brave, AdNauseam, Little Snitch Mini, TechnitiumDNS
DNSMasq (v2.86 or newer), adblock-lean, Diversion (v5 or newer)
Blocky (older than v0.23), Diversion (older than v5), OpenSnitch, PersonalBlocklist, pfBlockerNG
AdAway, uMatrix, DNS66, GasMask, NetGuard
Hostfile, Linux, Windows
Proxy Auto Configuration
Response Policy Zone, Bind, Knot, PowerDNS, Unbound
Blocky (v0.23 or newer), Nebulo, NetDuma, OPNsense, YogaDNS
DNSCloak, DNSCrypt, TechnitiumDNS, PersonalDNSfilter, InviZible Pro

Product-Specific Feeds

Checkpoint

These Checkpoint feeds contain IOCs from the past 180 days which have the IDS flag set.

Fortinet

These Fortinet feeds contain IOCs from the past 180 days which have the IDS flag set .

Microsoft Defender for Endpoint

These MDE feeds contain IOCs from the past 30 days which have the IDS flag set .

You can view the list of IOCs here and the list of reports here .

Last updated: 20 January 2025 at 14:42:40