Threat feed
Suspicious IPs & domains — recent threat feed
Indicators showing suspicious but not yet confirmed behavior. Aggregated from 100+ threat intelligence sources, refreshed daily.
Downloads are point-in-time snapshots. To consume Suspicious indicators continuously, pull the STIX/TAXII threat intelligence feed into OpenCTI, MISP, or your own pipeline.