Harnessing Public Sources for IP and Domain Maliciousness Detection
Learn how public sources like IP sets and blocklists can enhance your cybersecurity defenses by providing specific findings into IP and domain maliciousness. Discover how to integrate these resources into WAF solutions like Fortinet and Imperva.

Threat actors use IP addresses and domains for phishing, malware distribution, and other attacks. Public IP sets and blocklists can supplement internal telemetry and can be imported into web application firewalls such as Fortinet and Imperva.
Why Use Public Sources for Threat Intelligence?
Public sources of threat intelligence offer a cost-effective and community-driven way to identify malicious entities. These include:
- IP Sets: Collections of IP addresses flagged for malicious activity, such as spamming or DDoS attacks.
- Public Blocklists: Curated lists of IPs and domains associated with cyber threats, maintained by security researchers and organizations.
Advantages:
- Cost Efficiency: Free access to valuable data.
- Collaborative Defense: Benefit from community contributions and collective vigilance.
- Ease of Integration: Compatible with most modern security tools and WAFs.
Popular Public Sources for Malicious IPs and Domains
Here are some well-known resources:
1. Spamhaus
A leading provider of IP and domain blocklists, Spamhaus specializes in identifying spamming sources and related threats.
2. AbuseIPDB
This platform allows users to report and search for abusive IP addresses, providing a global perspective on malicious activities.
3. Emerging Threats Ruleset
Focused on real-time threat intelligence, this source provides blocklists and signatures for intrusion detection systems.
4. Open Threat Exchange (OTX)
A collaborative platform by AlienVault where users share threat indicators, including IPs and domains.
5. Project Honeypot
A community project that collects information on spammers and malicious bots, offering blocklists to protect networks.
Integrating Public Sources into WAFs
Web Application Firewalls (WAFs) like Fortinet and Imperva can be configured to use public blocklists for enhanced threat mitigation. Here’s how:
1. Fortinet WAF
- Import Blocklists: Use the FortiGate interface to upload custom IP or domain blocklists.
- Regular Updates: Automate the update process to ensure the latest threats are blocked.
- Traffic Analysis: Fortinet’s deep packet inspection can complement blocklists with protocol-aware inspection.
2. Imperva WAF
- Custom Policies: Define rules based on public blocklists.
- Data Integration: Utilize Imperva’s API to pull threat intelligence directly into your policies.
- Anomaly Detection: Combine blocklists with Imperva’s behavior analytics for comprehensive defense.
3. Other WAFs
Many modern WAF solutions support importing blocklists in formats like CSV or JSON, making them versatile for integration with public sources.
Best Practices for Using Public Sources
- Validate Sources: Ensure the blocklists you use are maintained by reputable organizations.
- Automate Updates: Use scripts or APIs to fetch and update blocklists regularly.
- Combine with Internal Threat Intelligence: Augment public data with insights from your own environment.
- Monitor Performance: Track the impact of blocklists on network performance and false positives.
Enhancing Public Sources with isMalicious
While public sources are invaluable, combining them with advanced tools like isMalicious elevates your cybersecurity posture:
- Comprehensive Insights: Analyze IPs and domains with detailed historical data and risk scores.
- Customizable APIs: Directly integrate public sources with tailored intelligence into your existing systems.
- Real-Time Alerts: Get notified of emerging threats faster than relying on static blocklists.
Stay Ahead of Cyber Threats
Public IP sets and blocklists can supplement a layered security strategy. When integrated into WAF controls, they give analysts another source of evidence for blocking or challenging traffic.
Take the next step in securing your network. Explore isMalicious and discover how to combine public intelligence with current tools for maximum protection.
Related articles
- 12 juil. 2026Mobile Smishing Defense: URL Scanners And Domain Reputation For July 2026
Mobile phishing keeps gaining operational relevance. Security teams need URL scanning, domain reputation checks, DNS pivots, and employee reporting workflows built for SMS and chat.
2 mai 2026Brand Impersonation and Lookalike Domains: A Practical Monitoring Playbook for Security, Legal, and Fraud TeamsTyposquats and homoglyphs are cheap to register and expensive to ignore. Learn how to discover, prioritize, and remove lookalike infrastructure before it harvests credentials or poisons your customers’ trust in search and email.
11 avr. 2026IP and Domain Intelligence: Building a Proactive Cyber Threat DefenseReactive security leaves organizations perpetually one step behind attackers. Learn how combining IP and domain intelligence transforms your security posture from reactive incident response to proactive threat prevention that stops attacks before they start.
Protect Your Infrastructure
Check any IP or domain against our threat intelligence database with indexed records.
Try the IP / Domain Checker