Threat intelligence shouldn't be a Fortune 500 luxury.

Block botnets, scanners, and malicious proxies with firewall-ready intelligence any team can deploy today. Powered by a global sensor network, and free to start.

No credit card Free blocklists API included
The problem

The best threat intel is locked behind a sales call.

Most platforms are built, and priced, for big security teams.

You shouldn't sit through a sales demo just to find out the price.

You shouldn't need an analyst team to act on a threat.

Staying protected shouldn't depend on the size of your budget.

So we built it the other way around. Sign up, pull the data, and start blocking in minutes. Start free, no sales call →

Who it's for

Built for every security team

From a one-person ops shop to a global NOC, teams across every discipline put Whatoblock to work

SOC Analysts Rapid, actionable insight into external threats.
Security Researchers Deep data and malware payloads for analysis.
Enterprise Security Teams Comprehensive external threat context at scale.
MSPs and MSSPs Protect every client with shared intelligence.
Developers and Integrators Build tools and automation on our API.
Academic and Data Analysts Real-world data for long-term research.
How it works

From sensors to intelligence

01

Collection

A global fleet of HoneyBot sensors mimics commonly exploited software and services, capturing every packet that interacts with them.

HTTP/S SMB SSH RDP Telnet
02

Analysis

Traffic is streamed to our engine in real time, which fingerprints each source and classifies its intent: scanner, C2, proxy or DDoS.

03

Intelligence

Proof, not promises. Live feeds you can act on, served as firewall ready blocklists, a live API, bulk open data, or piped straight into your security stack. Hover any tile.

Investigate

Heartbeat

--
Proxy, Tor & DDoS IPs, ready to block
Open ProxyTorDatacenterDDoS
Top ASN--
Top Country--
  • Proxy, Tor & datacenter classification
  • Geo & ASN enrichment
  • Prefix search: ip: org: asn:
Explore Heartbeat
Monitor

Scanners

--
See who is probing your ports, worldwide
By portBy protocolBy ASNBy country
Top ASN--
Top Protocol--
  • TCP / UDP scanner data
  • Protocol & ASN filtering
  • Live threat map
Explore scanners
Track

Botnet C2

--
Live C2 infrastructure & malware samples
C2 IPsMalware samplesMD5
Downloadable--
Top Country--
  • Live C2 tracking
  • Threat scoring
  • Payload downloads
Explore C2s
Access

Open Data

--
Total records
Total Size--
Top Service--
IPs Detected--
  • DNS / NTP / SSDP datasets
  • Bulk downloads
  • Multiple formats
Browse datasets
Index

Threat Level

--
Composite global index
LowMediumHighCritical
Block

Blocklists

Firewall ready feeds of malicious IPs (botnet C2, scanners and abusive proxies), exported for your firewall, SIEM, or scripts.

  • Category & confidence filters
  • JSON / CSV / XML / text exports
  • Free tier included
Build a feed
Last 31 days

Unique threats seen this month

Distinct source IPs our sensors classified in each category over the last 31 days.

Who we protect

Built to protect critical infrastructure

Our sensors emulate the systems attackers hunt, capture every attack against them, and turn it into protection for the operators who run:

Artificial intelligence infrastructure

Expanding attack surface exposes models, data, and pipelines

  • Prompt injection
  • Data poisoning
  • Model and data leakage
  • Supply chain compromise
  • Model denial of service
  • Credential theft
  • Excessive agency exploitation
  • Model theft
  • Insecure output handling
  • Adversarial input evasion
FAQ

Frequently Asked Questions

How do you detect scans or botnet activity?

We use proprietary detection software deployed on a global network of servers to ensure high accuracy.

Is the service free to use?

Our platform operates on a subscription based system. New users can start for free to explore our services before subscribing. We reserve the right to disable accounts involved in suspicious or harmful activity.

Why is my IP listed if I didn't initiate any activity?

If your IP is listed, it means it triggered detection mechanisms. Our system logs activity based on observed behavior, not intent.

Do you have an API?

Yes. We offer a comprehensive API across all of our threat intelligence products, with firewall-ready exports in JSON, CSV, XML, and plain text.

Can I request data for a specific region or country?

Absolutely. Let us know what you need and we'll do our best to accommodate your request.

Pricing

Start free, no sales call required

Create an account to explore the platform and pull from our free blocklists today. Upgrade only when you need more.

PRO
CTI Unlimited
flat subscription

Full feeds, API access, and historical data on one flat subscription, not per seat.

See pricing
ENTERPRISE
Custom
let's talk

Higher volumes, custom feeds, and dedicated support for larger teams.

Contact us