Your customer lists.
Apply custom blacklist entries and whitelist exclusions. Whitelist exclusion wins when an address appears in both, helping protect the exceptions your business depends on.
Shape ACE v2 intelligence around your environment. Build a policy, review its coverage, and publish a continuously maintained list or download a snapshot—all from your FraudGuard workspace.
Intelligence with your priorities
A high-risk source, an unexpected cloud provider, or recent activity from a country you don’t serve: each can call for a different policy. Decide what matters to your business, then see the result.
Meet the ACE v2 engineBuild. Preview. Publish.
A visual builder in app.fraudguard.io.
One selection for live lists and snapshot exports.
Choose critical risk, recent high risk, newly observed attackers, or repeat attackers. Adjust the conditions or build your own.
Nested AND / OR / NOTReview risk and classification breakdowns, countries, ASNs, tags, and CVEs. See inclusion reasons, entry counts, address coverage, and what your capacity limit leaves out.
Customer exclusions appliedPublish a dedicated HTTPS list, connect an authenticated TAXII collection, or download TXT, CSV, JSON, NDJSON, or STIX from the reviewed snapshot.
One policy. Multiple destinations.Dynamic firewall lists
Create a list, copy its dedicated HTTPS address, and let your firewall pull updates. Choose plain-text IPs or exact CIDRs, set your entry limit, and connect the perimeter tools you already run.
Use per-feed Basic credentials or a protected token URL. Choose an output profile for your device and its supported address families. Freshness safeguards apply to the last successful publication.
https://feeds.fraudguard.io/v2/{feed-token}/ips.txtExample token URL. Each feed has its own secure credentials.HTTPS TXT returns one IP or CIDR per line, ready for external list readers. AWS WAF uses the synchronization connector to update its CIDR IP sets.
Protection that respects your business
Make the coverage and tradeoffs visible
before a policy reaches your perimeter.
Apply custom blacklist entries and whitelist exclusions. Whitelist exclusion wins when an address appears in both, helping protect the exceptions your business depends on.
Bring existing FraudGuard geo-block settings into the policy. Keep “threats observed in this country” separate from “block all ranges assigned to this country.”
Set entry limits, rank threats deterministically, and see what won’t fit. Exact CIDR aggregation preserves the selected addresses, including holes left by your whitelist.
Choose IPv4, IPv6, or both. An isolated IP becomes /32 or /128 when CIDRs are required; larger ranges combine only addresses already selected. Counts distinguish emitted entries from the addresses they represent.
One policy. Multiple destinations.
Use the same policy to shape enforcement lists and intelligence exports. Keep the selection consistent as your team moves between blocking, enrichment, and analysis.
Filter by observed tags, CVE labels, attack types, target services, protocols, and ports. Each condition uses the supporting facts available in ACE v2 intelligence.
TXT for IP/CIDR lists. CSV for tabular imports. JSON or NDJSON for structured pipelines. STIX for threat intelligence. Add gzip to snapshot downloads.
TXT · CSV · JSON · NDJSON · STIX 2.1Managed HTTPS lists with automatic refresh, secure access, and device-specific capacity and address profiles.
Firewalls · WAFs · Network controlsStructured intelligence and authenticated collections for TIP, SIEM, and SOAR workflows, based on substantiated ACE observations.
STIX 2.1 · TAXII 2.1Threat Feeds is included with active paid Business and Enterprise plans. Business is $299/month with daily intelligence updates; Enterprise is $599/month with hourly intelligence updates. Open Threat Feeds in your customer workspace or compare plans. Standard free trials do not include Threat Feeds.
Manage everything in the FraudGuard customer app. Start with a template, adjust conditions in the visual builder, review the result, and publish. Customer account APIs power the workspace; you do not need to write queries or build an integration to manage lists.
For firewalls that support external lists, use HTTPS TXT with one IP or CIDR per line. Choose Basic credentials or a protected token URL, address families, and an entry limit supported by your device. The workspace includes setup guidance. AWS WAF uses the customer-run synchronization connector and separate IPv4/IPv6 CIDR IP sets; it does not poll a feed URL itself.
Include custom blacklist entries and inherit existing GeoControl countries, or choose countries for this policy. Country filtering selects observed threat indicators; whole-country blocking adds complete country ranges and requires CIDR output. Customer whitelist, global allowlist, and explicit exclusions apply to the final selection. Review the resulting address coverage and capacity before publishing.
Threat Feeds shapes ACE v2 intelligence into customer-defined selections. Attack Stream delivers live honeypot observations. OfflineDB provides ACE v1 SQLite and CSV downloads for local use. Each supports a different workflow.
Intelligence refreshes daily on Business and hourly on Enterprise. Your device polls on its own supported schedule; polling, exporting, or editing more often does not advance the intelligence cadence. Publish customer policy and exclusion changes against your current intelligence snapshot without waiting for the next intelligence window.
ACE v2 dynamic lists and exports
Start with a template, review its coverage,
and connect your first list from the FraudGuard workspace.