The platform
Every threat your team needs to block, in one platform.
Detect botnets, track scanners, and block malicious IPs before they reach your infrastructure, with real time intelligence any team can deploy today.
Advanced Threat Intelligence Features
Comprehensive cybersecurity capabilities designed to protect your organization from evolving threats
TCP/UDP Scanners
Monitor scanning activity across global networks with real-time insight into how systems are being probed.
- Identify emerging threat patterns
- Continuous infrastructure monitoring
- Detect abnormal traffic patterns
Botnet Tracking
Detailed visibility into C2 infrastructure and active botnet operations.
- Track botnet behavior over time
- Intelligence on attack chains
- Download payloads for research
Heartbeat Analysis
Real-time IP detection, category analysis, and geographic tracking to categorize threats.
- Real-time IP threat intelligence
- Category-based classification
- Proxy, Tor & datacenter IPs
Open Data Access
Internet-wide survey data with insights into global exposure to common vulnerabilities.
- Download binary files
- Raw survey data across protocols
- Filter by service, protocol, MD5
Platform Capabilities
RESTful API, integrations, simple subscription billing, and enterprise-grade infrastructure.
- RESTful API with filtering
- SIEM & security tool integrations
- Subscription billing
Real-Time Threat Map
Visualize global cyber threats in real time on an interactive 2D map and 3D globe with stunning analytics.
- Real-time threat visualization
- Interactive 2D map & 3D globe
- Filter by source type
Email Notifications
Automated email alerts keep you updated on critical threat intelligence without constant dashboard monitoring.
- Alert when a new botnet appears
- Daily top-five scanner summary
- Suspicious-activity alerts
Global Search
Search across all threat intelligence in one place with powerful prefix-based query syntax for instant results.
- Unified search across data sources
- Prefix queries (ip:, port:, country:)
- Filter by data type and sort
Real-Time Detection
Immediate insights into emerging threats and scanning activities as they happen across global networks.
Comprehensive Analytics
Advanced analytics and visualization to transform raw threat data into actionable security intelligence.
Proactive Defense
Identify and mitigate threats before they impact your organization with early warning systems.
Plug it into the stack you already have
No new console to live in. Pull intelligence straight into your firewall, SIEM, or a cron job with a simple, documented API, and pay only for what you use.
- REST API across every product
- Subscription based, no per seat licensing
- Blocklist exports for firewalls & SIEMs
Why Choose Whatoblock
Built for security professionals who demand comprehensive threat intelligence and actionable insights
Start for free
Create an account and start for free to explore. No credit card required.
Point your firewall
Copy a blocklist URL into your firewall, or pull from the API. Plain text, JSON, CSV, or XML.
Block in real time
Malicious IPs are blocked automatically as the feeds update. Set it and forget it.
Grow with usage
From a single firewall to a global NOC, pay only for what you use as you scale.