FluxMoat feeds

Threat-intelligence indicators republished as FluxMoat JSON manifest blocklists.

ThreatFox mirror

threatfox/manifest.json

Checksum: threatfox/manifest.sha256 · rebuilt every 6 hours.

Domain and IP indicators from ThreatFox, seen in the last six months, filtered down to what a packet tunnel can match on a live flow. Add it in FluxMoat under Blocklists as a JSON manifest source.

Verify

curl -O https://vrk176.github.io/fluxmoat-feeds/threatfox/manifest.json
curl -O https://vrk176.github.io/fluxmoat-feeds/threatfox/manifest.sha256
shasum -a 256 -c manifest.sha256

Attribution

Data: ThreatFox by abuse.ch, released under CC0 1.0.

This is an unofficial third-party mirror. It is not operated, endorsed, or supported by abuse.ch. Report problems with the mirror to the mirror repository, never to abuse.ch.