The Attacker dataset is a tighter, higher-severity list than Abuser: addresses actively launching attacks such as vulnerability exploitation, aggressive scanning and malware distribution, curated from security intelligence feeds.
Its small size makes it cheap to deploy everywhere, including in-line at the edge where every microsecond counts.
Available formats
| Format | Description | Size |
|---|---|---|
| CSV | Plain text, one range per line. Import into any database or data warehouse. | 219 KB |
| CSV (zipped) | Same file compressed for faster downloads and cheaper storage. | 50.9 KB |
| MMDB | Binary format for instant lookups with standard MMDB readers. | 479 KB |
Latest build: 7,568 records. Files are regenerated every day and published with MD5, SHA-1, SHA-256 and SHA-512 checksums so you can verify every download.
What's inside
The CSV file starts with a header line and contains one record per row, with the following fields:
| Column | Description |
|---|---|
ip_end | Last IP address of the range, inclusive. |
ip_start | First IP address of the range, IPv4 or IPv6. |
The MMDB variant carries the same data in a memory-mapped binary tree, compatible with the standard MMDB reader libraries available for every major programming language.
What you can build
- Block active attack infrastructure at WAFs and edge proxies
- Prioritize incident response for traffic from known attackers
- Feed threat intelligence platforms with a curated, low-noise list
- Correlate intrusion attempts with known campaigns
Related use case: Cyber security
Datasets are available with an Ipregistry subscription and download from your dashboard, or over a stable URL for automated syncs. Prefer live data? The same intelligence is served by the Ipregistry API.