Skip to main content

Pricing

Two products. One sensor network.

Investigate threats with CTI Unlimited, or block them with an industry blocklist. Both run on the same live honeypot network, both start free, and you can cancel whenever you like.

Free tier to start No card needed to sign up Cancel whenever you like
~/whatoblock
● 200 OK
$ curl "https://whatoblock.com/blocklists/download/perimeter-denylist?format=txt"
# Perimeter denylist
# sources: scanners,c2
# 4454 addresses
203.0.113.19
198.51.100.42
192.0.2.77|

Blocklists update continuously from live honeypot data and are included with your subscription.

Threat intelligence

Choose your level of access

Inspect every intelligence product for free. Choose Unlimited for complete results, investigation outputs, research downloads, and alerts.

Free

Evaluate the live data and understand how each product supports your workflow.

0 No card needed
Explore
Heartbeat, Scanner Recon, Botnet & C2, and OpenData
Access
The first five pages of live records in every product
Limits
No exports, research downloads, reports, or alerts

CTI Unlimited

Use the complete dataset and investigation tools without page limits.

69 per month, billed yearly
Data
Unlimited pages across all four intelligence products
Analysis
Full filtering, reports, JSON and PNG exports, and the threat map
Research
Botnet malware samples, OpenData downloads, and email alerts
Automated defense

Industry blocklists

Select one industry, up to three, or complete coverage. Each paid tier combines its coverage and included threat categories into one continuously updated feed. Firewall presets and optional /24 aggregation are included.

Free

Limited scanner sample

One sample feed in every supported format.

0
No card needed

Essential

1 industry with all threat categories

One continuously updated feed in every supported format.

89/ month
per month, billed yearly
€1.068 charged annually

Complete

Every current and future industry with all threat categories

One continuously updated feed in every supported format.

259/ month
per month, billed yearly
€3.108 charged annually

Explore industry coverage

Select an industry to see what its feed covers. All 14 active industries remain ranked by unique scanner IPs observed over the last 31 days.

Industry feed

Retail and Ecommerce

Our sensors saw probes against web, mail, database, and administration services that a store may expose. When a store runs this service mix, the mapping spans its public site and the systems used to manage it.

Why use this feed

A retailer running these services can use the feed in existing edge rules around its storefront and administration systems. This keeps scanner blocks current without collecting addresses from web, mail, and database logs by hand.

Explore this industry

Counts may overlap between industries. They do not represent the total size of paid feeds.

Product comparison

Match the product to the job

Decide what should happen next: a person investigates the activity, or your security controls block it automatically.

Investigate

Threat Intelligence

Give an analyst the context and tools to understand attacker activity and infrastructure.

Best for
SOC analysts, incident responders, and threat researchers
Workflow
Search, filter, pivot into source records, and monitor changes
Data
Heartbeat, Scanner Recon, Botnet & C2, and OpenData
Outputs
Reports, JSON and PNG exports, research downloads, threat map, and alerts
Start free
Review the first five pages in every intelligence product
Unlimited from69 / month
View intelligence plans
Block automatically

Industry Blocklists

Deliver observed malicious sources to the firewall or security stack that enforces your policy.

Best for
Network defenders, security engineers, and managed service providers
Workflow
Select coverage, choose a supported format, and pull one stable feed
Data
Selected industry protocols and all threat categories
Outputs
Continuously updated firewall feed in eleven formats, with optional /24 aggregation
Start free
Download a limited scanner sample in every supported format
Paid coverage from89 / month
View blocklist plans
Shared foundation

Both products use activity observed across the same live honeypot network. They are separate subscriptions, so you can use either workflow on its own or combine them.

Questions

Billing, answered

Can I cancel anytime?

Yes. Cancel from your billing page in a couple of clicks. Your access keeps working until the end of the period you already paid for, and your configuration is remembered if you come back.

What happens when I change tiers mid month?

Billing shows the exact charge or credit before you confirm. Industry-only changes within the same tier do not add another subscription item.

Monthly or yearly billing?

Both. Every price on this page is shown per month; the toggle at the top switches between yearly billing (about 20 percent cheaper) and month to month billing you can stop anytime.

Do I need CTI Unlimited to buy a blocklist?

No. They are separate products on the same data. Firewall teams often run blocklists alone; analyst teams often run CTI alone. You can combine them whenever you like.

Which firewalls are supported?

Paid feeds support all eleven advertised encoders: TXT, plain, CSV, JSON, MikroTik, Check Point, Wazuh, F5, Zeek, CIDR and RPZ. Optional /24 CIDR aggregation is included.

How do I pay?

Paid plans use secure card checkout through Stripe. The Free tier needs no card, and there is no setup fee.

Start free

Try both products before you pay

One account lets you investigate live threat activity and test a sample blocklist in the security tools you already run. Upgrade only when the free access no longer covers your workflow.

Your free account includes
Threat intelligence
The first five pages of live records across all four CTI products.
Blocklist
One scanner sample feed in every supported format.
Create a free account

No card required. No sales call.