Legal Notice
Terms of use, disclaimers, and limitations of liability.
Last updated: March 2026
Nature of this project
TarPit-Lab is a personal, non-commercial, open threat intelligence project operated by a private individual. It has no legal entity, no commercial registration, no employees, and generates no revenue. It is provided as a public resource for the security research community, free of charge and without any warranty.
Contact: [email protected]
Nature of the data
All data published on this site — including IP addresses, request paths, attack classifications, and associated metadata — reflects inbound, unsolicited probes directed at a honeypot server. This server is deliberately exposed to the internet for the sole purpose of capturing this activity.
The data does not represent vulnerabilities, breaches, or compromises of any real production system. Paths, payloads, and request details visible in exports and feeds are attacker-supplied inputs received by our honeypot — they are not indicative of weaknesses in any third-party infrastructure.
No warranty
All data, feeds, blocklists, and information provided through this site are offered as-is, without warranty of any kind, express or implied. TarPit-Lab makes no representations or warranties regarding the completeness, accuracy, reliability, timeliness, or fitness for a particular purpose of any data published here.
Threat intelligence data is inherently incomplete — it represents activity observed by a single sensor at a single point on the internet and should not be treated as a comprehensive view of global threat activity.
Limitation of liability
To the maximum extent permitted by applicable law, TarPit-Lab and its operator shall not be liable for any direct, indirect, incidental, special, or consequential damages arising from the use of, or inability to use, any data, feed, or information published on this site.
In particular, TarPit-Lab shall not be liable for any damages resulting from blocking decisions made on the basis of IP blocklists or other exports provided here. IP blocklists should never be used as the sole basis for blocking decisions. False positives are possible — shared infrastructure, VPN exit nodes, and legitimate scanners may appear in the data.
Acceptable use
Data published by TarPit-Lab may be used freely for defensive, research, and educational purposes. You may integrate the IP blocklist and JSON feed into your own tools and infrastructure. Attribution is appreciated but not required.
You may not use data from TarPit-Lab to harass, target, or take offensive action against any IP address or organisation listed in our exports. The data is provided for defensive purposes only.
Third-party data sources
Geographic and network attribution data is provided by MaxMind GeoLite2, subject to the GeoLite2 End User License Agreement. Scanner identification data is sourced from MISP Project warning lists, used under their respective open licenses.
Intellectual property
The TarPit-Lab software, design, and original content are the work of the project operator. The raw threat data collected by the honeypot is factual in nature and not subject to copyright. Feeds and exports may be used freely as described above.
Governing law
This project is operated from within the European Union. To the extent any legal dispute arises, it shall be governed by the laws of the European Union and the member state of the operator's residence, without regard to conflict of law provisions.
Data license
The threat intelligence data published by TarPit-Lab — including the public JSON feed, IP blocklists, ASN blocklists, Threat Pulse reports, and the Intel page — is made available under the Creative Commons Attribution 4.0 International (CC-BY 4.0) license.
You are free to share and adapt this data for any purpose, including commercial use, provided you give appropriate credit to TarPit-Lab (tarpit-lab.xyz) and indicate if changes were made.
The software source code of this project is independent of the data license and is not covered by CC-BY 4.0.