Who uses it?
Linked malware families, labels, tags, source evidence, and a clear history of where the indicator came from.
Updated daily, human reviewed, and built for people who need threat intelligence without having to second-guess it.
The figures below come from the latest DNS telemetry snapshot. They are refreshed as the telemetry rollups are generated.
Placeholder figures — live telemetry will replace them when available.
See which families are driving activity, which domains are associated with them, and where infections are being observed.
Each domain is more than a line in a text file. It is reviewed and enriched before it reaches the feed.
Linked malware families, labels, tags, source evidence, and a clear history of where the indicator came from.
Infection volume from DNS blocks, observed IP record sets, and the passive-DNS context around the domain.
Geolocation for infected hosts and for the domain’s location, when the available evidence supports it.
We can provide the feed as plain text, CSV, JSON, or STIX. Need a portal, an API, or RPZ? We support those too.
Get in touch and we will talk through the feed, the data behind it, and the delivery option that suits your setup.
Contact us