PathSecurity.

Managed Threat Feed/Powered by DarkDataLabs honeypot intelligence

Your firewall is guessing. Ours has seen the attackers.

Block the IPs already hitting everyone else, before they reach you. A daily blocklist of proven-malicious IPs, sourced from a live honeypot network, refreshed nightly, and delivered straight to your firewall or SIEM.

first-party sensors, not a reseller feed. no card to start.

pathsecurity://feed/nightly
refreshed nightly
attacker ipcchitsverdict
  • 45.135.232.18RU4,213brute-force
  • 193.32.162.94NL2,881scanner
  • 104.248.55.201US1,507cred-stuffing
  • 212.70.149.71BG1,344exploit-probe
  • 89.248.165.33SC1,102botnet-c2
272,935 IPs trackeddelivered to firewall / SIEM
117M+
real attacks observed
272,935
tracked attacker IPs
23
honeypot sensors
203
countries
18 mo
continuous coverage

refreshed nightly/first-party sensors/not a reseller feed

the problem

Every network is under automated attack. Generic blocklists are already stale.

The scanning never stops

Bots, brute-force rigs, and exploit probes hit every exposed service within minutes. It is constant, automated, and indiscriminate. Your edge is being tested right now.

Free lists lag the attack

Public blocklists are crowd-sourced, slow, and full of noise. By the time an IP lands on one, it has already worked its way through a hundred networks. You are blocking yesterday's attacker.

We run the sensors those attackers hit first. When an IP shows up in tonight's feed, it has already proven itself hostile against real infrastructure. You block it before it reaches you.

how it works

We run the sensors. We score the attackers. You block them.

  1. 1step_1

    We run the sensors

    A network of 23 honeypot sensors across 203 countries absorbs real automated attacks around the clock. We own the sensors, so the signal is first-party.

  2. 2step_2

    We score the day's attackers

    Every IP that touches a sensor is proven hostile against real infrastructure, not guessed. We rank the day's worst offenders and refresh the list nightly.

  3. 3step_3

    You block them automatically

    The scored blocklist flows straight into your firewall or SIEM. The addresses hitting everyone else get dropped at your edge before they reach you.

what's included

Five deliverables, wired into where your team already works

Daily blocklist

Proven-malicious IPs, auto-delivered to your firewall or SIEM every night in a drop-in format.

Monthly threat report

A readable brief on what is hitting networks like yours, the trends behind it, and what changed.

IP reputation lookups

Check any address against 272,935 tracked attackers to triage alerts and score inbound traffic.

Emerging-threat alerts

New attack campaigns pushed to you the moment the sensor network starts seeing them.

SIEM and firewall integration

The feed lands where your team already works. Splunk, Sentinel, Palo Alto, pfSense, and the rest.

pricing

Straightforward monthly plans

Start with the daily blocklist. Add lookups, alerts, and raw data as you grow.

Starter

$99/mo

The daily blocklist and a monthly read on your threat landscape.

  • Daily blocklist to firewall or SIEM
  • Monthly threat report
  • Nightly refresh
  • Email support
Start Starter
Most popular

Professional

$249/mo

For teams that want lookups, alerts, and native SIEM delivery.

  • Everything in Starter
  • IP reputation API
  • Emerging-threat alerts
  • SIEM integration
  • Priority support
Start Professional

Enterprise

$499+/mo

Custom sensor coverage and raw data for your own tooling.

  • Everything in Professional
  • Custom sensor feeds
  • Raw dataset license
  • Dedicated support
  • Onboarding assistance
Talk to us
get started

See who is already knocking on your door

Book a free 15-minute exposure assessment. We will show you how many of tonight's tracked attackers are already probing your ranges, and how fast the feed shuts them out.

Book your 15-minute exposure assessment
Tell us where to point the feed. This goes to a human, not a bot.

No card required. A human security engineer reviews every request.