Curated IP threat intelligence

A threat feed that doesn't block the good guys.

SciScope is a curated IP-reputation feed built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up and hand you at maximum confidence.

Tired of explaining why Google is on your firewall's naughty list?

3.7% of a widely-used abuse-report feed's top 100k is legitimate infrastructure it flags at high confidence
296 search-engine crawler IPs wrongly listed on one popular community blocklist
0 of those false positives reach the SciScope feed
01 / the problem

The blocklists you already trust flag legitimate infrastructure

We cross-referenced several widely-used public IP-reputation lists against our curated reference set of known-good infrastructure — search & AI crawlers, public DNS resolvers, and attributed research scanners. The bar is the false-positive rate; the figure beside it is the raw count of legitimate IPs. We don't name the lists — but the pattern is consistent.

Tired of blocking search engines?

Bars scaled to the ~10% maximum · full-list cross-reference, not sampled traffic · the two clean lists score 0% because each answers one narrow question well — and neither of them tells you anything about scanners. The lists that do are the ones carrying the false positives.

103 + 24

OpenAI and Google crawler IPs sat on the public lists we measured — alongside 281 Baidu and 15 Yandex crawlers on a single community blocklist. Consume those lists raw and you silently cut yourself off from four search engines and the AI answer engines being built on them. None of these ever reach the SciScope feed.

02 / exposure

Exactly whose traffic you'd be dropping

Legitimate IPs we found across those lists, by owner. Block the lists wholesale and you block these — de-indexing your site, breaking uptime checks, and blinding the research scanners that map the internet's exposure.

Search & AI crawlers

indexing and answer engines — you want these reaching you

Baidu 281 OpenAI 103 Bingbot 37 Google 24 Yandex 15 Perplexity 7

Research scanners

attributed internet-measurement — noise in your logs, not a threat

Alpha Strike 1,545 ONYPHE 1,401 BinaryEdge 875 Censys 824 Modat 273 Arbor 194 Internet Measurement 92 SecurityTrails 26

Counts: legitimate IPs of each owner found across the measured lists, 2026-07-06. Also protected — zero wrongly listed today: Applebot, Anthropic, DuckDuckGo, Qwant, Mojeek, public DNS resolvers, NTP & root DNS servers, cloud health-checkers, uptime monitors.

03 / the catch

And they're not low-confidence guesses

The obvious workaround is to keep only the entries a list is most sure about. It doesn't help here — the legitimate infrastructure is exactly what these lists are most certain is malicious.

100%abuse confidence on 3,060 of the 3,725 legit IPs

The abuse-report feed doesn't hedge on the infrastructure it gets wrong. The legitimate services it lists carry a mean confidence of 97.5 — so the usual defence, "just filter to confidence ≥ 90," still blocks internet-measurement scanners, AI crawlers and major search engines. You can't threshold your way out of a curation problem.

04 / the guarantee

What never lands on your blocklist

Every false-positive class above is screened out of the SciScope feed, continuously. We re-measure public lists against our reference set and publish the results — the proof is the numbers on this page, not a promise.

Search & AI crawlers

Google, Bing, Baidu, Yandex, Apple, DuckDuckGo, Qwant, Mojeek, OpenAI, Anthropic, Perplexity — indexing and answer engines never end up blocked.

Public DNS & core infrastructure

Public resolvers, NTP time servers and the DNS root — infrastructure your network depends on stays off the list, even when reflection attacks drag it into others' logs.

Cloud health-checkers & monitors

Load-balancer health checks and uptime probes look exactly like scanners to a naive sensor. They never reach the feed.

Attributed research scanners

Censys, ONYPHE, BinaryEdge and the rest of the internet-measurement world — flagged as what they are, visible in your telemetry, never on the blocklist.

05 / how it works

First-party signal, curated centrally, delivered clean

We run our own sensors, we curate centrally, and we show our work — every flagged IP ships with the evidence behind it. Behind the curation: a founder with a PhD in cybersecurity and 25+ peer-reviewed publications on intrusion detection and monitoring.

SENSE

First-party passive sensors

A distributed network of our own sensors observes real attack traffic across independent vantage points — original signal, not a resold black box.

CURATE

Screened & scored

Every candidate IP is screened against the protected categories above and scored on recent, corroborated hostile activity. Only real attackers make the cut.

DELIVER

Evidence included

A scored feed in JSON and CSV with per-IP evidence, a high-confidence blocklist.txt, and an opt-in crawler-identity list — block regional crawlers on your terms, not by accident.

06 / pricing

Honest pricing, generous limits

Between overpriced enterprise platforms and underpowered free lists. Early-adopter pricing is open until 31 December 2026 — subscribe before then and the price stays yours for as long as your subscription stays active.

Tired of blocking the scanners on your own payroll?

Free
€0
Build against the real API before you commit — a live slice of the feed, not a demo.
  • Top 10 scored addressesGET /v1/free/top
  • Aggregate stats — GET /v1/stats
  • Totals, 30-day activity, top ports, event types, countries
  • Same schema as the paid feed — upgrading is a config change
  • 10 req/min · 500 req/day
  • The full feed — 10 rows, not thousands
  • Per-IP lookup, evidence breakdown, history
See it without a key
Early-adopter price
Entry
€5 / moor €45 / year — 3 months freeexcl. VAT · €6.20 / mo or €55.80 / year incl. 24% VAT
Today's full feed, straight into your firewall — for homelabs and solo defenders.
  • Full feed — JSON + CSV, scores, tags & evidence
  • High-confidence blocklist.txt
  • Opt-in crawler-identity list
  • Per-IP lookup API
  • 3-day feed history · 20 req/min · 2 000 req/day
Start a 14-day trial
MSSP / Enterprise
CustomQuoted excl. VAT
For MSSPs, product vendors and larger defenders — volume, integration and redistribution.
  • Everything in Pro
  • 90-day history + day-over-day diffs + per-IP timeline
  • Redistribution & rebranding — resell or embed in your product
  • Higher volume & rate limits (120 req/min · 100 000 req/day base)
  • Custom allowlists — allow/deny your own infra
  • Per-sensor context & enrichment
  • SLA & priority support
Talk to us

Early-adopter prices are available for subscriptions started on or before 31 December 2026 — we may extend that date, but we won't bring it forward. Once you're on one it stays with you for as long as your subscription stays active — renewals included. If it lapses (your key drops to Free), the then-current list prices apply when you come back. Headline prices are net of VAT; the figure beside each is what an individual pays at Estonia's 24% rate. EU business customers with a valid VAT ID are reverse-charged — give us the ID when you sign up and you pay the net price.

Try it on your own traffic. No card, no signup.

Email us with your use-case and what you'd need to evaluate SciScope. We'll set you up with a 14-day trial on the full Pro feature set — feed, history, per-IP lookups, everything — and extend it to 30 days if you tell us a bit about your plan. When the trial ends, pick the tier that fits; if you don't, your key simply drops to the Free stats level — no dead keys, no pressure. Trials are issued by hand right now, so you'll talk to a human, not a form.

Tired of blocking search engines? Tired of blocking the scanners on your own payroll? Tired of explaining why Google is on your firewall's naughty list?