CapeLabs Logo
ThreatMesh

Open Threat Intelligence Feed providing daily lists of verified attacker IP addresses detected worldwide

Daily Updates
7 Days Freshness
Global Coverage

Ready to Enhance Your Threat Intelligence?

Get access to our daily updated threat feed and strengthen your security posture.

What is ThreatMesh?

ThreatMesh provides a curated feed of attacker IP addresses detected through our globally distributed network of attack detection sensors. Each IP address in our feed has been involved in verified attacks or scanning activity within the last 7 days, ensuring high relevance and up-to-date threat intelligence.

🕛

12:30 AM UTC

Daily automated updates with the latest threat data

🌐

Global Sensors

Distributed network capturing real-world malicious activities

7-Day Fresh

Only IPs with recent attack or scanning activity

Use Cases

🛡️

Firewall Automation

Automatically update firewall blocklists with the latest threat intelligence to prevent known malicious IPs from accessing your infrastructure.

🔍

SIEM/EDR Enhancement

Enrich your SIEM and EDR threat detection rules with fresh IOCs to improve detection accuracy and reduce false positives.

📊

IOC Analysis

Perform Indicator of Compromise analysis using verified threat intelligence to understand attack patterns and origins.

⚠️ Important Disclaimer

While ThreatMesh provides IPs with a high likelihood of malicious behavior, we do not guarantee 100% accuracy for every environment. Please evaluate and test before deploying in production to avoid false positives or disruption. The IPs listed are limited to those seen actively scanning or attacking within the last 7 days.