IP Blocklist

Most active source IPs. Compatible with fail2ban, pfSense, and similar tools. Plain text (one IP per line) or CSV with full metadata.

https://tarpit-lab.xyz/export/ips
Format:
Period:
Up to 5,000 IPs · country · ASN · org · dominant attack type
ASN / Org Blocklist

Most active autonomous systems. Useful for network-level blocking when many IPs from the same provider are probing your infrastructure.

https://tarpit-lab.xyz/export/asn
Format:
Period:
Up to 500 ASNs · org · country · unique IPs · dominant attack type
Public JSON Feed

Structured JSON summary of the last 24 hours: event counts, top countries, top paths, top IPs, and recent events. Suitable for dashboards and integrations.

https://tarpit-lab.xyz/feed.json
Updated every minute · CORS enabled

Paths and payloads in this feed are attacker-supplied requests directed at the honeypot — not indicators of compromise in any real system. Data licensed under CC-BY 4.0.

Usage notes

All data is provided as-is for informational and defensive purposes. TarPit-Lab makes no guarantees about completeness or accuracy. Do not use IP or ASN blocklists as the sole basis for blocking decisions. All IPs and ASNs appear because they initiated unsolicited connections to a honeypot. See Legal Notice and Privacy Policy for more.

Database contains 4,080,412 total events.