Threat intelligence shouldn't be a Fortune 500 luxury.
Block botnets, scanners, and malicious proxies with firewall-ready intelligence any team can deploy today. Powered by a global sensor network, and free to start.
Block botnets, scanners, and malicious proxies with firewall-ready intelligence any team can deploy today. Powered by a global sensor network, and free to start.
Most platforms are built, and priced, for big security teams.
You shouldn't sit through a sales demo just to find out the price.
You shouldn't need an analyst team to act on a threat.
Staying protected shouldn't depend on the size of your budget.
So we built it the other way around. Sign up, pull the data, and start blocking in minutes. Start free, no sales call →
From a one-person ops shop to a global NOC, teams across every discipline put Whatoblock to work
A global fleet of HoneyBot sensors mimics commonly exploited software and services, capturing every packet that interacts with them.
Traffic is streamed to our engine in real time, which fingerprints each source and classifies its intent: scanner, C2, proxy or DDoS.
Proof, not promises. Live feeds you can act on, served as firewall ready blocklists, a live API, bulk open data, or piped straight into your security stack. Hover any tile.
Firewall ready feeds of malicious IPs (botnet C2, scanners and abusive proxies), exported for your firewall, SIEM, or scripts.
Distinct source IPs our sensors classified in each category over the last 31 days.
Our sensors emulate the systems attackers hunt, capture every attack against them, and turn it into protection for the operators who run:
Expanding attack surface exposes models, data, and pipelines
We use proprietary detection software deployed on a global network of servers to ensure high accuracy.
Our platform operates on a subscription based system. New users can start for free to explore our services before subscribing. We reserve the right to disable accounts involved in suspicious or harmful activity.
If your IP is listed, it means it triggered detection mechanisms. Our system logs activity based on observed behavior, not intent.
Yes. We offer a comprehensive API across all of our threat intelligence products, with firewall-ready exports in JSON, CSV, XML, and plain text.
Absolutely. Let us know what you need and we'll do our best to accommodate your request.
Create an account to explore the platform and pull from our free blocklists today. Upgrade only when you need more.
Explore the platform and access free blocklists. No card required.
Get startedFull feeds, API access, and historical data on one flat subscription, not per seat.
See pricingHigher volumes, custom feeds, and dedicated support for larger teams.
Contact us