Choose the threats.
Control the list.

Shape ACE v2 intelligence around your environment. Build a policy, review its coverage, and publish a continuously maintained list or download a snapshot—all from your FraudGuard workspace.

High risk · Recent activityExample policy
Your policy
IFRisk level 4–5
ANDAttack seen in the last 24 hours
ANDAt least 5 attack events in 24 hours
EXCLUDEYour customer whitelist
Selected indicators5,124After exclusions
Risk breakdown
High4,780
Critical344
Customer whitelist appliedReview → Publish or download

Intelligence with your priorities

A feed should fit
your environment.

A high-risk source, an unexpected cloud provider, or recent activity from a country you don’t serve: each can call for a different policy. Decide what matters to your business, then see the result.

Meet the ACE v2 engine
Risk & confidence
Set minimum risk and confidence, then combine them with observed activity.
Time & repetition
Filter by first seen, last seen, recent attack activity, and supported observation-count windows.
Networks & infrastructure
Select source countries, ASNs, hosting providers, IPs/CIDRs, and infrastructure flags. Refine by observed tags, CVEs, services, protocols, and ports.
Your exceptions
Combine AND, OR, and NOT. Include your blacklist or GeoControl rules, then apply whitelist, global allowlist, and explicit IP/CIDR exclusions.

Build. Preview. Publish.

Build the policy.
Put the list to work.

A visual builder in app.fraudguard.io.
One selection for live lists and snapshot exports.

  1. 01 / BUILD

    Start with a useful template.

    Choose critical risk, recent high risk, newly observed attackers, or repeat attackers. Adjust the conditions or build your own.

    Nested AND / OR / NOT
  2. 02 / PREVIEW

    See what you’re selecting.

    Review risk and classification breakdowns, countries, ASNs, tags, and CVEs. See inclusion reasons, entry counts, address coverage, and what your capacity limit leaves out.

    Customer exclusions applied
  3. 03 / PUBLISH

    Connect your tools.

    Publish a dedicated HTTPS list, connect an authenticated TAXII collection, or download TXT, CSV, JSON, NDJSON, or STIX from the reviewed snapshot.

    One policy. Multiple destinations.

Dynamic firewall lists

One URL.
Your existing firewall.

Create a list, copy its dedicated HTTPS address, and let your firewall pull updates. Choose plain-text IPs or exact CIDRs, set your entry limit, and connect the perimeter tools you already run.

  • Stable URLs with credentials you can rotate
  • Daily or hourly intelligence updates by plan
  • Edit, download, disable, or delete your lists
  • Entry limits matched to your device’s capacity
  • Atomic updates that preserve the last successful list during a failed refresh

Use per-feed Basic credentials or a protected token URL. Choose an output profile for your device and its supported address families. Freshness safeguards apply to the last successful publication.

The managed-list workflow Automatic refresh
ACE v2
Your published policyConditions + customer exceptions
Dedicated HTTPS feedhttps://feeds.fraudguard.io/v2/{feed-token}/ips.txtExample token URL. Each feed has its own secure credentials.
Your firewall or security toolPoll the URL. Apply the current list.

HTTPS TXT returns one IP or CIDR per line, ready for external list readers. AWS WAF uses the synchronization connector to update its CIDR IP sets.

Protection that respects your business

Keep the threats in.
Keep your exceptions out.

Make the coverage and tradeoffs visible
before a policy reaches your perimeter.

Whitelist exclusions win

Your customer lists.

Apply custom blacklist entries and whitelist exclusions. Whitelist exclusion wins when an address appears in both, helping protect the exceptions your business depends on.

Inherit your GeoControl settings

Your country rules.

Bring existing FraudGuard geo-block settings into the policy. Keep “threats observed in this country” separate from “block all ranges assigned to this country.”

See coverage and omissions

Your device’s capacity.

Set entry limits, rank threats deterministically, and see what won’t fit. Exact CIDR aggregation preserves the selected addresses, including holes left by your whitelist.

Fewer entries. The same selected addresses.

Choose IPv4, IPv6, or both. An isolated IP becomes /32 or /128 when CIDRs are required; larger ranges combine only addresses already selected. Counts distinguish emitted entries from the addresses they represent.

One policy. Multiple destinations.

From the firewall
to the investigation.

Use the same policy to shape enforcement lists and intelligence exports. Keep the selection consistent as your team moves between blocking, enrichment, and analysis.

Filter by observed tags, CVE labels, attack types, target services, protocols, and ports. Each condition uses the supporting facts available in ACE v2 intelligence.

Point-in-time exports

Download

TXT for IP/CIDR lists. CSV for tabular imports. JSON or NDJSON for structured pipelines. STIX for threat intelligence. Add gzip to snapshot downloads.

TXT · CSV · JSON · NDJSON · STIX 2.1

Dynamic enforcement lists

HTTPS polling

Managed HTTPS lists with automatic refresh, secure access, and device-specific capacity and address profiles.

Firewalls · WAFs · Network controls

Threat intelligence feeds

Authenticated TAXII

Structured intelligence and authenticated collections for TIP, SIEM, and SOAR workflows, based on substantiated ACE observations.

STIX 2.1 · TAXII 2.1

A few useful details

Before you connect.

Talk through your deployment
Which plans include Threat Feeds?

Threat Feeds is included with active paid Business and Enterprise plans. Business is $299/month with daily intelligence updates; Enterprise is $599/month with hourly intelligence updates. Open Threat Feeds in your customer workspace or compare plans. Standard free trials do not include Threat Feeds.

Do I need to write queries or build an API integration?

Manage everything in the FraudGuard customer app. Start with a template, adjust conditions in the visual builder, review the result, and publish. Customer account APIs power the workspace; you do not need to write queries or build an integration to manage lists.

How do I connect a firewall or AWS WAF?

For firewalls that support external lists, use HTTPS TXT with one IP or CIDR per line. Choose Basic credentials or a protected token URL, address families, and an entry limit supported by your device. The workspace includes setup guidance. AWS WAF uses the customer-run synchronization connector and separate IPv4/IPv6 CIDR IP sets; it does not poll a feed URL itself.

How do my whitelist and geo settings work?

Include custom blacklist entries and inherit existing GeoControl countries, or choose countries for this policy. Country filtering selects observed threat indicators; whole-country blocking adds complete country ranges and requires CIDR output. Customer whitelist, global allowlist, and explicit exclusions apply to the final selection. Review the resulting address coverage and capacity before publishing.

How is this different from Attack Stream or OfflineDB?

Threat Feeds shapes ACE v2 intelligence into customer-defined selections. Attack Stream delivers live honeypot observations. OfflineDB provides ACE v1 SQLite and CSV downloads for local use. Each supports a different workflow.

How often do lists update?

Intelligence refreshes daily on Business and hourly on Enterprise. Your device polls on its own supported schedule; polling, exporting, or editing more often does not advance the intelligence cadence. Publish customer policy and exclusion changes against your current intelligence snapshot without waiting for the next intelligence window.

ACE v2 dynamic lists and exports

Make the intelligence
fit your defenses.

Start with a template, review its coverage,
and connect your first list from the FraudGuard workspace.