Threat intelligence feed
Malicious IP Feed
Real-time IP addresses tied to active malware distribution, C2 and phishing infrastructure. Every IP is attributed to a specific family and campaign, so you can block at the network perimeter with confidence.
15-day free trial · no credit card · reply within one business day
Drops straight into the tools your SOC already runs
Block at the network perimeter
Stop malicious infrastructure before it reaches the endpoint
An IP block is the broadest, fastest control you have: one rule on a firewall, router or DNS resolver stops traffic before it ever reaches an endpoint. The Malicious IP Feed gives you a current set of IPs tied to active C2, distribution and phishing infrastructure, each attributed to the family or campaign behind it, so you can push a perimeter block with confidence instead of guessing.
Attribution on every IP
Each IP is mapped to a known malware family and observed campaign. A block tells you whether you're looking at a Cobalt Strike C2 server, a ClickFix distribution host, or a Lokibot panel, not just an anonymous address.
Perimeter blocking, no waiting on endpoints
Push high-confidence IPs into your firewall, router or DNS resolver to stop traffic before it reaches a single endpoint. That's coverage for unmanaged devices and IoT that EDR can't reach.
Flexible delivery, no new tooling
Consume the feed as CSV, REST API (JSON), STIX/TAXII or MISP. Push IPs directly into FortiGate NGFW as an external threat feed, or into any SIEM, TIP or MSSP workflow without a new ingestion pipeline.
The Malicious IP Feed is a real-time list of IP addresses engaged in active malware distribution, command-and-control (C2) and phishing infrastructure. An accurate, current view of malicious IPs is one of the fastest ways to stop a threat, whether you’re a SOC analyst, security manager or data reseller blocking at the perimeter.
Every IP is attributed to a known malware family and observed campaign. A block doesn’t just stop traffic. It tells you whether you’re looking at a Cobalt Strike C2 server, a ClickFix distribution host, or a Lokibot panel, turning a blocked connection into campaign context.
You get targeted IP coverage that works alongside your domain and URL blocklists: fewer indicators, higher confidence, and a perimeter control that protects devices your endpoint tools can’t reach.
What’s in the feed
- Real-time IPs tied to active malware distribution, C2 and phishing infrastructure
- Family and campaign attribution on every indicator
- Coverage across dozens of currently tracked malware, infostealer, RAT and loader families
- CSV and REST API (JSON) delivery for bulk ingestion and automation
- Available through STIX/TAXII and MISP feeds for teams standardizing on threat-intelligence platforms
- Ready for FortiGate external threat feeds and any router, DNS or firewall blocking workflow
Evaluate before you commit
You can validate freshness, attribution quality and feed fit against your existing stack before committing. Test IP indicators against your Microsoft Sentinel incidents, populate MISP or OpenCTI events, or compare coverage overlap with your current sources to see where this feed adds signal.
Start a 15-day free trial. Access is immediate and includes the full PrecisionSec feed set: malicious IP, domain, URL and hash feeds, plus the malware domain list.
When to use this feed
- Firewall and router blocking: push high-confidence C2 and distribution IPs directly into FortiGate NGFW, or into any router, DNS or firewall control in the path of network traffic.
- SOC alert enrichment: pivot from an IP hit to campaign context and family attribution so analysts know what they’re dealing with before escalation.
- Unmanaged device and IoT coverage: block malicious infrastructure at the perimeter for devices that can’t run an EDR agent.
- Threat hunting: use attributed IP indicators to search for related campaign infrastructure across current and historical logs.
- MSSP and multi-tenant coverage: add curated C2 and distribution IP intelligence across customer environments with a predictable feed format.
- Data resellers and security products: integrate high-confidence malicious IP intelligence into your own platform without building a collection pipeline.
You get the Malicious IP Feed with every PrecisionSec intelligence subscription, alongside the malicious domain, URL and hash feeds and the malware domain list. Request evaluation access to see live data, delivery formats and integration options.
Ready to see all of our data?
Start your 15-day free trial and get the full Malicious IP Feed feed, plus every other malware and C2 feed.