Filter out the noise.
Drop attackers at the edge.
Cybora delivers continuously updated, curated threat feeds directly to your firewall. Automatically block malicious infrastructure, botnets, and scanners before they even touch your internal network.
Natively integrates with leading firewalls
Don't fight an unwinnable battle against rotating IPs.
Block distributed attacks proactively.
Local rate-limits and IPS rules are easily bypassed by botnets rotating thousands of IPs. Cybora identifies and drops these coordinated attackers at the edge before they can even test your defenses.

Native firewall integration.
Achieve a massive security upgrade without the project overhead. Cybora feeds plug directly into the native external blocklist features of modern firewalls.

Automated, continuous synchronization.
Attackers rotate their infrastructure daily. Depending on your plan, Cybora syncs new indicators to your firewall automatically—as frequently as every 15 minutes.

Curated from global swarm intelligence.
We don't just pass on raw open-source lists. Cybora aggregates OSINT, commercial feeds, global honeypots, and real firewall telemetry—filtering out false positives to deliver only verified active threats.

A format every firewall understands.
No heavy JSON parsing or complex API integrations. Just a secure HTTPS endpoint returning a flat TXT file—one indicator per line. Perfect for native External Dynamic Lists (EDL).
1. The Endpoint URL
Append your unique license key and specify the indicator type you want your firewall to pull (ipv4, domain, or url).
2. The TXT Output
# Last updated: 2026-05-18 06:26:20 UTC
103.45.67.89
185.12.34.56
45.89.102.11
198.51.100.22
91.200.12.44
203.0.113.50
192.0.2.145
198.51.100.8
203.0.113.99
Deploy in under 5 minutes.
Stop treating threat intelligence like a massive IT project. Get your key, configure your firewall, and let your perimeter defend itself automatically.
Choose a plan
Pick Standard (IPv4) or upgrade to Premium/Ultimate for full domain and URL coverage.
Checkout
Secure self-serve purchase. Monthly or annual auto-renewing subscription.
Get your key
Instantly receive your unique license key. 1 key protects 1 firewall edge/device.
Paste URL
Add the URL into your firewall settings. It fetches the blocklist on your chosen schedule.
Built for precision, not just volume.
Why not just use free open-source lists? Because threat intelligence requires constant curation. Free lists are often outdated, untested, or extremely noisy. In a firewall context, noise is expensive: false positives create support tickets, and admins quickly stop trusting the feed.
Cybora focuses on one job: delivering a curated, firewall-friendly feed you can deploy and trust without babysitting.
What "Quality" means here
Multi-source aggregation
We blend OSINT, commercial feeds, and global honeypots to ensure broad coverage.
Curated for relevance
Aggressive deduplication and false-positive filtering specifically for firewall deployment.
Support included
Paid plans include dedicated technical support to help investigate and whitelist blocked traffic.
ACCESS PLANS
SELECT PROTECTION LEVEL
STANDARD
Billed annually
Solid baseline. Includes IPv4 and top domain coverage.
PREMIUM
Billed annually
Professional protection. Includes domains & URLs. Hourly updates.
ULTIMATE
Billed annually
15-minute updates for critical infrastructure & high-risk perimeters.
Fair use
1 key = 1 device. Rate limits depend on plan to prevent abuse.
Renewals
Monthly or annual subscription with automatic renewal unless cancelled.
Flexible Plans
Volume discounts and longer commitments (beyond 12 months) are available on request. Same base pricing applies regardless of company size.
Featured integrations
Integrations
Step-by-step instructions showing exactly where to paste the feed URL in your specific hardware.
Sophos Firewall
Use this guide to add the Cybora feed to Sophos Firewall using Active Threat Response and third-party threat feeds.
Fortinet FortiGate
Use this guide to add Cybora to FortiGate using External Connectors. FortiGate imports the feed as a dynamic external object and keeps …
Palo Alto Networks
Use this guide to register Cybora as an External Dynamic List (EDL) on Palo Alto Networks firewalls. EDLs are one of the strongest …
Cisco Secure Firewall
Use this guide to integrate Cybora with Cisco Secure Firewall through Security Intelligence feeds. The most common workflow is to …
Check Point
Use this guide to integrate Cybora with Check Point using External IoC feeds in SmartConsole. This native workflow lets the Security …
OPNsense
Use this guide to integrate Cybora with OPNsense using native firewall aliases. In OPNsense, the cleanest native workflow is to …
Key & Abuse Protection
License keys are plan-scoped and protected with fair-use rate limits. One key is strictly intended for one firewall edge.
Operations & Status
Delivery is served over HTTPS and designed for predictable, automated polling 24/7/365.
View System Status →Security & Privacy
We don't collect your network traffic. Review our strict security and privacy pages for current data handling practices.
Test compatibility with the Free Basic Feed.
We don't offer refunds, because we want you to be 100% sure Cybora works with your specific hardware setup before you spend a dime. Use our Basic feed to validate the URL delivery and TXT format.
Basic (Free) Limitations
- Indicator Type: IPv4 only
- Update Frequency: 24 hours
- Coverage: 20,000 IPv4
- Technical Support: None
Frequently asked questions
Is it really 1 key = 1 firewall/device?
Will this feed block legitimate traffic?
How do renewals work?
What polling interval should I set?
What happens if my key is leaked?
Do you offer refunds?
Make your firewall quieter today.
Self‑serve purchase. Setup in minutes. Works flawlessly with any firewall that supports URL-based external threat feeds.