40+Validated sources
1.5M+IPs from a single source alone
0.1–0.9Confidence scoring range
4Threat data types
What the Intelligence Covers

Four data types, continuously updated from diverse global sources

Malicious IP Addresses

IPv4 & IPv6 addresses and CIDR ranges confirmed as attack sources — C2 servers, Tor exit nodes, botnet infrastructure, and brute-force origins. Over 1.5M unique IPs from a single validated source alone.

Domain Blocklists

Malicious domains used for phishing, malware distribution, DNS tunnelling, and command-and-control, with source-calibrated confidence scoring (0.1–0.9).

Malicious URLs

Precise URL-level threat intelligence — not just domains — enabling web proxies, WAFs, and secure web gateways to block specific malicious endpoints while allowing legitimate traffic.

File Hashes

Known malware file signatures from sandbox analysis and alliance member submissions. Supports MD5, SHA1, SHA256, and filename indicators.

Database Growth & Source Quality

Every new source is proven before it's trusted

The Alliance continually evaluates and adds new intelligence sources through a rigorous process: broad research, targeted evaluation, cross-referencing with existing feeds, and consistency validation over time. New sources are assigned initial confidence scores of approximately 0.2 and recalibrated as accuracy is demonstrated.

+168%

Critical-risk entries growth

+61%

Medium-risk entries growth

+46%

High-risk entries growth

+17%

Low-risk entries growth

See the Database in Action

Real views from the platform

MITRE ATT&CK Graph

Indicators automatically linked to attack patterns, courses of action, and source reports.

Threat-Actor Pivoting

Trace a single malicious IP across every alliance member and sighting.

Geolocated Attack Routing

Built from the live intelligence database, updated continuously.

Put 40+ sources behind your firewall.

Enforcement-ready feeds, not another dashboard to watch.

Start a Proof of Value