Skip to main content
DFIR
back

Blocklist Export

Daily-generated blocklists from cross-source IOC consensus. IPs appearing in 2+ independent feeds. Download for pfSense, iptables, or Suricata. Updated every 24 hours.

Loading…

pfSense

Newline-separated IPs for pfSense URL alias (Alias) import

iptables

Shell script with INPUT/FORWARD DROP rules

Suricata

Suricata drop rules with auto-incrementing SID

Usage

pfSense: Add the URL as an Alias of type URL (URL Alias) in Firewall → Aliases.

iptables: Run chmod +x blocklist-iptables.sh && sudo ./blocklist-iptables.sh

Suricata: Place the rules file in /etc/suricata/rules/ and add it to your suricata.yaml.

API endpoints: /api/v1/blocklists/pfsense, /api/v1/blocklists/iptables, /api/v1/blocklists/suricata

edge·
github·portfolio