Curated IP threat intelligence
SciScope is a curated IP-reputation feed built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up and hand you at maximum confidence.
We cross-referenced several widely-used public IP-reputation lists against our curated reference set of known-good infrastructure — search & AI crawlers, public DNS resolvers, and attributed research scanners. The bar is the false-positive rate; the figure beside it is the raw count of legitimate IPs. We don't name the lists — but the pattern is consistent.
Bars scaled to the ~10% maximum · full-list cross-reference, not sampled traffic · the two clean lists score 0% because each answers one narrow question well — and neither of them tells you anything about scanners. The lists that do are the ones carrying the false positives.
OpenAI and Google crawler IPs sat on the public lists we measured — alongside 281 Baidu and 15 Yandex crawlers on a single community blocklist. Consume those lists raw and you silently cut yourself off from four search engines and the AI answer engines being built on them. None of these ever reach the SciScope feed.
Legitimate IPs we found across those lists, by owner. Block the lists wholesale and you block these — de-indexing your site, breaking uptime checks, and blinding the research scanners that map the internet's exposure.
Counts: legitimate IPs of each owner found across the measured lists, 2026-07-06. Also protected — zero wrongly listed today: Applebot, Anthropic, DuckDuckGo, Qwant, Mojeek, public DNS resolvers, NTP & root DNS servers, cloud health-checkers, uptime monitors.
The obvious workaround is to keep only the entries a list is most sure about. It doesn't help here — the legitimate infrastructure is exactly what these lists are most certain is malicious.
The abuse-report feed doesn't hedge on the infrastructure it gets wrong. The legitimate services it lists carry a mean confidence of 97.5 — so the usual defence, "just filter to confidence ≥ 90," still blocks internet-measurement scanners, AI crawlers and major search engines. You can't threshold your way out of a curation problem.
Every false-positive class above is screened out of the SciScope feed, continuously. We re-measure public lists against our reference set and publish the results — the proof is the numbers on this page, not a promise.
Google, Bing, Baidu, Yandex, Apple, DuckDuckGo, Qwant, Mojeek, OpenAI, Anthropic, Perplexity — indexing and answer engines never end up blocked.
Public resolvers, NTP time servers and the DNS root — infrastructure your network depends on stays off the list, even when reflection attacks drag it into others' logs.
Load-balancer health checks and uptime probes look exactly like scanners to a naive sensor. They never reach the feed.
Censys, ONYPHE, BinaryEdge and the rest of the internet-measurement world — flagged as what they are, visible in your telemetry, never on the blocklist.
We run our own sensors, we curate centrally, and we show our work — every flagged IP ships with the evidence behind it. Behind the curation: a founder with a PhD in cybersecurity and 25+ peer-reviewed publications on intrusion detection and monitoring.
A distributed network of our own sensors observes real attack traffic across independent vantage points — original signal, not a resold black box.
Every candidate IP is screened against the protected categories above and scored on recent, corroborated hostile activity. Only real attackers make the cut.
A scored feed in JSON and CSV with per-IP evidence, a high-confidence blocklist.txt, and an opt-in crawler-identity list — block regional crawlers on your terms, not by accident.
Between overpriced enterprise platforms and underpowered free lists. Early-adopter pricing is open until 31 December 2026 — subscribe before then and the price stays yours for as long as your subscription stays active.
Early-adopter prices are available for subscriptions started on or before 31 December 2026 — we may extend that date, but we won't bring it forward. Once you're on one it stays with you for as long as your subscription stays active — renewals included. If it lapses (your key drops to Free), the then-current list prices apply when you come back. Headline prices are net of VAT; the figure beside each is what an individual pays at Estonia's 24% rate. EU business customers with a valid VAT ID are reverse-charged — give us the ID when you sign up and you pay the net price.
Email us with your use-case and what you'd need to evaluate SciScope. We'll set you up with a 14-day trial on the full Pro feature set — feed, history, per-IP lookups, everything — and extend it to 30 days if you tell us a bit about your plan. When the trial ends, pick the tier that fits; if you don't, your key simply drops to the Free stats level — no dead keys, no pressure. Trials are issued by hand right now, so you'll talk to a human, not a form.