Abuse.ch Threat Feeds
Community threat intel family: URLhaus, MalwareBazaar, ThreatFox, and YARAify, in partnership with Spamhaus.
Technical Architecture & Overview
Abuse.ch operates widely consumed free malware and IOC feeds: URLhaus for malware-distribution URLs, MalwareBazaar for sample sharing, ThreatFox for IOC exchange, and YARAify for YARA rule matching. The project operates in partnership with Spamhaus, with unified API documentation and free accounts required for API access. MISP feed integrations are standard practice.
Targeted Technical Use Cases
Free, high-signal IOC and malware feeds for blocklists, hunting, and enrichment pipelines.
Evaluation & Trade-offs
Core Strengths
- +High-signal data maintained by a respected nonprofit project.
- +Multiple feed types covering URLs, samples, and IOCs.
- +Established MISP and SIEM integration paths.
Trade-Offs & Limitations
- -Free API access now requires an account with rate limits.
- -Feeds reflect what the community reports, not a full threat picture.
Defensive Security Application
Feeding network blocklists and detection content with current, community-verified IOCs.
Frequently Asked Questions
What is Abuse.ch Threat Feeds?→
Abuse.ch operates widely consumed free malware and IOC feeds: URLhaus for malware-distribution URLs, MalwareBazaar for sample sharing, ThreatFox for IOC exchange, and YARAify for YARA rule matching. The project operates in partnership with Spamhaus, with unified API documentation and free accounts required for API access. MISP feed integrations are standard practice.
What is Abuse.ch Threat Feeds used for?→
Free, high-signal IOC and malware feeds for blocklists, hunting, and enrichment pipelines.
What are the strengths of Abuse.ch Threat Feeds?→
- +High-signal data maintained by a respected nonprofit project.
- +Multiple feed types covering URLs, samples, and IOCs.
- +Established MISP and SIEM integration paths.
What are the limitations of Abuse.ch Threat Feeds?→
- +Free API access now requires an account with rate limits.
- +Feeds reflect what the community reports, not a full threat picture.
How is Abuse.ch Threat Feeds used defensively?→
Feeding network blocklists and detection content with current, community-verified IOCs.