Free defensive intelligence

A practical IOC feed for URL investigations.

Turn the last 24 hours of public URL Radar scans into a compact hostname watchlist for triage, hunting and authorised security operations.

Included

Useful context, not a blind blocklist

  • Sanitised hostname and report reference
  • Risk score, classification and detection tags
  • First and last observed timestamps
  • Scan count, confidence basis and cautious action

Safety boundary

Know what the feed means

Only provider-confirmed rows are direct block recommendations. Heuristic rows are leads for review, not proof of malicious ownership. Paths, query values, submitter details, raw commands and payloads are excluded.

SOC workflow

Use it where defenders work

Import the CSV into a case, search the JSON from an authorised automation, or pivot from a row to its explainable public report. Data reflects a point-in-time observation and expires from the dashboard after 24 hours.

Need more?

Help shape a team feed

Longer retention, authenticated delivery, stable schemas, enrichment and commercial redistribution are potential licensed capabilities—not active promises.

Discuss a security-team pilot →