Filter list from the public FilterLists directory. Format: CIDRs (IPv6). See the project homepage for details and inclusion criteria.
Blocklists for Suricata / IDS
Intrusion detection systems can read IP reputation lists as datasets.
Adding a blocklist to Suricata / IDS
curl -fsSL "https://www.team-cymru.org/Services/Bogons/fullbogons-ipv6.txt" -o /var/lib/suricata/data/blocklist.txt Reference the file from a rule using a dataset:
alert ip [!$HOME_NET] any -> $HOME_NET any (msg:"Team Cymru Fullbogons (IPv6) match";
ip.src; dataset:isset,blocklist, type string, load blocklist.txt; sid:1000001;)The address shown above is an example. Every list in the directory has its own URL, which you can copy with one click.
Recommended lists for Suricata / IDS
By topic
All 135 lists for Suricata / IDS
CPBL IP Filter (P2P-format, IPv4)
Filter list covering privacy. Format: IPs (Start-end-range). Maintained by Chon Bongo. See the project homepage for details and inclusion criteria.
Dandelion Sprout’s and other adblocker lists’ IPs
Filter list covering ads, phishing. Format: IPs (IPv4). Maintained by Imre Kristoffer Eilertsen. See the project homepage for details and […]
Dandelion Sprout’s Disallowed Clients for AdGuard Home in Particular
Filter list from the public FilterLists directory. Format: IPs (IPv4). Maintained by Imre Kristoffer Eilertsen. See the project homepage for […]
Dandelion Sprout’s Nordic Filters for Tidier Websites (for Shadowsocks)
Filter list covering ads, malware. Format: Socks5. Maintained by Imre Kristoffer Eilertsen. See the project homepage for details and inclusion […]
Dandelion Sprout’s Official DNS Server
Filter list covering ads, malware, phishing, cookies, push-notes. Format: DNS servers. Maintained by Imre Kristoffer Eilertsen. See the project homepage […]
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Address ranges belonging to data centres and hosting providers.
Filter list covering proxy. Format: DNS servers. See the project homepage for details and inclusion criteria.
The networks attacking most right now, a very short list.
DShield.org Recommended Block List
Filter list covering malware. Format: IPs (Start-end-range). Maintained by DShield. See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Energized IP Extension
Filter list covering malware. Format: IPs (IPv4). Maintained by Team Boltz. See the project homepage for details and inclusion criteria.
Live command servers of banking malware.
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
gnX Threat Intelligence
Filter list covering malware. Format: IPs (IPv4). Maintained by gnxsecurity. See the project homepage for details and inclusion criteria.
Filter list covering proxy. Format: Socks5. See the project homepage for details and inclusion criteria.
Filter list covering malware. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Filter list from the public FilterLists directory. Format: IPs (IPv4). See the project homepage for details and inclusion criteria.
Filter list covering ads. Format: DNS servers. See the project homepage for details and inclusion criteria.
Filter list covering ads, privacy. Format: DNS servers. See the project homepage for details and inclusion criteria.
Filter list covering ads, privacy. Format: IPs (IPv4).
