The platform

Every threat your team needs to block, in one platform.

Detect botnets, track scanners, and block malicious IPs before they reach your infrastructure, with real time intelligence any team can deploy today.

Real time intelligence Global sensor network Blocklist ready
Capabilities

Advanced Threat Intelligence Features

Comprehensive cybersecurity capabilities designed to protect your organization from evolving threats

24/7 Real-time Monitoring 99.9% Uptime Threats Detected Global Coverage

TCP/UDP Scanners

Monitor scanning activity across global networks with real-time insight into how systems are being probed.

  • Identify emerging threat patterns
  • Continuous infrastructure monitoring
  • Detect abnormal traffic patterns

Botnet Tracking

Detailed visibility into C2 infrastructure and active botnet operations.

  • Track botnet behavior over time
  • Intelligence on attack chains
  • Download payloads for research

Heartbeat Analysis

Real-time IP detection, category analysis, and geographic tracking to categorize threats.

  • Real-time IP threat intelligence
  • Category-based classification
  • Proxy, Tor & datacenter IPs

Open Data Access

Internet-wide survey data with insights into global exposure to common vulnerabilities.

  • Download binary files
  • Raw survey data across protocols
  • Filter by service, protocol, MD5

Platform Capabilities

RESTful API, integrations, simple subscription billing, and enterprise-grade infrastructure.

  • RESTful API with filtering
  • SIEM & security tool integrations
  • Subscription billing

Real-Time Threat Map

Visualize global cyber threats in real time on an interactive 2D map and 3D globe with stunning analytics.

  • Real-time threat visualization
  • Interactive 2D map & 3D globe
  • Filter by source type

Email Notifications

Automated email alerts keep you updated on critical threat intelligence without constant dashboard monitoring.

  • Alert when a new botnet appears
  • Daily top-five scanner summary
  • Suspicious-activity alerts

Global Search

Search across all threat intelligence in one place with powerful prefix-based query syntax for instant results.

  • Unified search across data sources
  • Prefix queries (ip:, port:, country:)
  • Filter by data type and sort

Real-Time Detection

Immediate insights into emerging threats and scanning activities as they happen across global networks.

Comprehensive Analytics

Advanced analytics and visualization to transform raw threat data into actionable security intelligence.

Proactive Defense

Identify and mitigate threats before they impact your organization with early warning systems.

Integrations & API

Plug it into the stack you already have

No new console to live in. Pull intelligence straight into your firewall, SIEM, or a cron job with a simple, documented API, and pay only for what you use.

  • REST API across every product
  • Subscription based, no per seat licensing
  • Blocklist exports for firewalls & SIEMs
Get your API key free
~/whatoblock-api
$ curl "https://whatoblock.com/apiv3/heartbeat?\
apiKey=$API_KEY&time=24h&country=US&format=json&info=true"
{
"success": true,
"ips": ["185.220.101.45", "198.51.100.23"],
"records": 2,
"tokens_charged": 0.2,
"category_breakdown": {
"ResidentialProxy": { "count": 1 },
"OpenProxy": { "count": 1 }
}
}|
Why Whatoblock

Why Choose Whatoblock

Built for security professionals who demand comprehensive threat intelligence and actionable insights

01 Sign up

Start for free

Create an account and start for free to explore. No credit card required.

02 Integrate

Point your firewall

Copy a blocklist URL into your firewall, or pull from the API. Plain text, JSON, CSV, or XML.

03 Protect

Block in real time

Malicious IPs are blocked automatically as the feeds update. Set it and forget it.

04 Scale

Grow with usage

From a single firewall to a global NOC, pay only for what you use as you scale.