Emerging Threats compromised hosts
Attack-source lists. What Emerging Threats compromised hosts is, on what terms it is used, which fields of the IP answer it feeds, how big it is today and when it was last synced.
| Kind | Attack-source lists |
|---|---|
| Publisher | https://rules.emergingthreats.net/blockrules/ |
| Terms | The Emerging Threats open ruleset it belongs to is BSD-licensed; credit is kept. |
| Refresh | hourly |
| Size today | 610 IPv4 ranges compiled from the feed. |
| Last synced | 2026-09-13 |
| Answers | is_attack_source, attack_source |
What it is
The compromised-hosts list behind the Emerging Threats open ruleset: single addresses seen attacking, a few hundred at a time, refreshed daily by the publisher. It sits apart from the netblock-level blocklists because it names hosts rather than operators and churns daily, and it weighs 50 rather than 80.
What it answers
In the IP response this source feeds is_attack_source, attack_source. Every answer names the datasets it read in its sources block with the date each was synced, so the figure on this page and the one in an answer are the same figure.
curl https://spaw.co/api/v1/ip \
-H "Authorization: Bearer $SPAW_KEY" \
-H "Content-Type: application/json" \
-d '{"ip": "203.0.113.9"}'How to read this page
A source names a network or an operator, never a person. An address inside one of these ranges tells you what the connection is — a cloud instance, a VPN exit, a gateway, a listed host — and nothing about who is behind it.
More sources in attack-source lists
counts and dates read from the installed feed · checked 2026-09-13
More free tools
All free toolsNeed this at scale?
The Spaw API runs the same checks plus mailbox-level SMTP verification, batch and bulk endpoints, and list monitoring — 10 free lookups a month, no card required.