Attacker Dataset

Active attack infrastructure: sources of exploitation attempts, scanners and malicious campaigns.

The Attacker dataset is a tighter, higher-severity list than Abuser: addresses actively launching attacks such as vulnerability exploitation, aggressive scanning and malware distribution, curated from security intelligence feeds.

Its small size makes it cheap to deploy everywhere, including in-line at the edge where every microsecond counts.

8K Records
Daily Updates
CSV · MMDB Formats
IPv4 + IPv6 Coverage

Available formats

Format Description Size
CSV Plain text, one range per line. Import into any database or data warehouse. 219 KB
CSV (zipped) Same file compressed for faster downloads and cheaper storage. 50.9 KB
MMDB Binary format for instant lookups with standard MMDB readers. 479 KB

Latest build: 7,568 records. Files are regenerated every day and published with MD5, SHA-1, SHA-256 and SHA-512 checksums so you can verify every download.

What's inside

The CSV file starts with a header line and contains one record per row, with the following fields:

Column Description
ip_end Last IP address of the range, inclusive.
ip_start First IP address of the range, IPv4 or IPv6.

The MMDB variant carries the same data in a memory-mapped binary tree, compatible with the standard MMDB reader libraries available for every major programming language.

What you can build

Related use case: Cyber security

Datasets are available with an Ipregistry subscription and download from your dashboard, or over a stable URL for automated syncs. Prefer live data? The same intelligence is served by the Ipregistry API.