Skip to content
Latest
QScan and QTRouter Show Why Proxy Infrastructure Is an Espionage Force MultipliervCenter Exploitation Shows Patching Alone Is Not Incident ResponseEdge Infrastructure Convergence Shows Why Perimeter Devices Need Their Own Patch SLAsSigned ClickOnce Lures Show Why Hiring Workflows Need Endpoint GuardrailsShieldBreak Shows Why Endpoint Protection Needs Compensating ControlsAI-Enabled Malware Still Behaves Like MalwarePrivate APNs Are Becoming OT Attack PathsvCenter Exploitation Shows Why Control Planes Need ContainmentApollo Breach Shows Why Helpdesk Vishing Is a Cloud-Control ProblemBTR.sys Shows Why Trusted Security Drivers Need Behavioral MonitoringWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without Exploits

Threat Intelligence

Threat Feeds

Free, machine-readable indicators enriched from our threat reporting. Only values that meet the current confirmed-malicious policy enter these feeds; clean, unknown, pending, and unsupported values stay out.

0 live indicators · 0 reports · fail-closed validation

Values are live and functional. VirusTotal aggregates vendor opinions rather than establishing ground truth, so stage them in monitoring and review impact before automatic enforcement.

Feed validation is temporarily unavailable, so every machine-readable feed is empty by design. This avoids publishing unverified indicators while the enrichment pipeline is paused or unhealthy.

Blocklists (plain text)

One indicator per line. Import into a review or monitoring workflow before enforcing blocks.

Policy-confirmed malicious domains for DNS and web-proxy monitoring.

https://bulwarkblack.com/feeds/domains.txt

Policy-confirmed malicious IPv4 addresses for firewall monitoring.

https://bulwarkblack.com/feeds/ips.txt
URLs 0

Exact policy-confirmed malicious URLs for web proxies and gateways.

https://bulwarkblack.com/feeds/urls.txt

Policy-confirmed MD5, SHA-1, and SHA-256 file hashes for endpoint hunting.

https://bulwarkblack.com/feeds/hashes.txt

Structured exports

indicators.csv

Every verified feed indicator with its type, report count, first and last seen dates, and an example report.

https://bulwarkblack.com/feeds/indicators.csv
indicators.json

The same verified data as JSON, including the reports each indicator came from.

https://bulwarkblack.com/feeds/indicators.json
rules.yar

YARA rules grouped by report and generated only from verified feed indicators. Tune before deployment.

https://bulwarkblack.com/feeds/rules.yar

Look up a single indicator

Paste a domain, IP, URL, or supported file hash to check whether it is in the current verified feed and which reports it came from. Context-only observables remain available in the Indicator Database.

Prefer the API? Same data, one indicator at a time:

curl "https://bulwarkblack.com/api/ioc/lookup?value=1.2.3.4"

How to use them

Pull a feed

curl https://bulwarkblack.com/feeds/domains.txt

Refresh hourly (cron)

0 * * * * curl -s \
  https://bulwarkblack.com/feeds/ips.txt \
  -o /etc/blocklists/bulwark-ips.txt

Pi-hole / DNS sink

Add https://bulwarkblack.com/feeds/domains.txt as an adlist, then update gravity.

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.