
Open Threat Intelligence Feed providing daily lists of verified attacker IP addresses detected worldwide
Ready to Enhance Your Threat Intelligence?
Get access to our daily updated threat feed and strengthen your security posture.
What is ThreatMesh?
ThreatMesh provides a curated feed of attacker IP addresses detected through our globally distributed network of attack detection sensors. Each IP address in our feed has been involved in verified attacks or scanning activity within the last 7 days, ensuring high relevance and up-to-date threat intelligence.
12:30 AM UTC
Daily automated updates with the latest threat data
Global Sensors
Distributed network capturing real-world malicious activities
7-Day Fresh
Only IPs with recent attack or scanning activity
Use Cases
Firewall Automation
Automatically update firewall blocklists with the latest threat intelligence to prevent known malicious IPs from accessing your infrastructure.
SIEM/EDR Enhancement
Enrich your SIEM and EDR threat detection rules with fresh IOCs to improve detection accuracy and reduce false positives.
IOC Analysis
Perform Indicator of Compromise analysis using verified threat intelligence to understand attack patterns and origins.
⚠️ Important Disclaimer
While ThreatMesh provides IPs with a high likelihood of malicious behavior, we do not guarantee 100% accuracy for every environment. Please evaluate and test before deploying in production to avoid false positives or disruption. The IPs listed are limited to those seen actively scanning or attacking within the last 7 days.