Filter out the noise.
Drop attackers at the edge.
Cybora delivers continuously updated, curated threat feeds directly to your firewall. Automatically block malicious infrastructure, botnets, and scanners before they even touch your internal network.
Natively integrates with leading firewalls
Don't fight an unwinnable battle against rotating IPs.
Block distributed attacks proactively.
Local rate-limits and IPS rules are easily bypassed by botnets rotating thousands of IPs. Cybora identifies and drops these coordinated attackers at the edge before they can even test your defenses.

Native firewall integration.
Achieve a massive security upgrade without the project overhead. Cybora feeds plug directly into the native external blocklist features of modern firewalls.

Automated, continuous synchronization.
Attackers rotate their infrastructure daily. Depending on your plan, Cybora syncs new indicators to your firewall automatically—as frequently as every 15 minutes.

Curated from global swarm intelligence.
We don't just pass on raw open-source lists. Cybora aggregates OSINT, commercial feeds, global honeypots, and real firewall telemetry—filtering out false positives to deliver only verified active threats.

A format every firewall understands.
No heavy JSON parsing or complex API integrations. Just a secure HTTPS endpoint returning a flat TXT file—one indicator per line. Perfect for native External Dynamic Lists (EDL).
1. The Endpoint URL
Append your unique license key and specify the indicator type you want your firewall to pull (ipv4, domain, or url).
2. The TXT Output
# Last updated: 2026-04-08 13:01:27 UTC
103.45.67.89
185.12.34.56
45.89.102.11
198.51.100.22
91.200.12.44
203.0.113.50
192.0.2.145
198.51.100.8
203.0.113.99
Deploy in under 5 minutes.
Stop treating threat intelligence like a massive IT project. Get your key, configure your firewall, and let your perimeter defend itself automatically.
Choose a plan
Pick Standard (IPv4) or upgrade to Premium/Ultimate for full domain and URL coverage.
Checkout
Secure self-serve purchase. Monthly or annual auto-renewing subscription.
Get your key
Instantly receive your unique license key. 1 key protects 1 firewall edge/device.
Paste URL
Add the URL into your firewall settings. It fetches the blocklist on your chosen schedule.
Built for precision, not just volume.
Why not just use free open-source lists? Because threat intelligence requires constant curation. Free lists are often outdated, untested, or extremely noisy. In a firewall context, noise is expensive: false positives create support tickets, and admins quickly stop trusting the feed.
Cybora focuses on one job: delivering a curated, firewall-friendly feed you can deploy and trust without babysitting.
What "Quality" means here
Multi-source aggregation
We blend OSINT, commercial feeds, and global honeypots to ensure broad coverage.
Curated for relevance
Aggressive deduplication and false-positive filtering specifically for firewall deployment.
Support included
Paid plans include dedicated technical support to help investigate and whitelist blocked traffic.
ACCESS PLANS
SELECT PROTECTION LEVEL
STANDARD
Billed annually
Solid baseline. Fewer false positives through curation. Solid IPv4 coverage.
PREMIUM
Billed annually
Professional protection. Includes domains & URLs. Hourly updates.
ULTIMATE
Billed annually
15-minute updates for critical infrastructure & high-risk perimeters.
Fair use
1 key = 1 device. Rate limits depend on plan to prevent abuse.
Renewals
Monthly or annual subscription with automatic renewal unless cancelled.
Flexible Plans
Volume discounts and longer commitments (beyond 12 months) are available on request. Same base pricing applies regardless of company size.
Integrations
Step-by-step instructions showing exactly where to paste the feed URL in your specific hardware.
Sophos Firewall
Add third‑party threat feeds in Active Threat Response.
Fortinet FortiGate
Configure external threat feeds and apply policies.
Palo Alto Networks
Register External Dynamic Lists (EDL) and enforce.
Cisco Secure Firewall
Import URL feeds and apply to access control.
Check Point
Configure external feeds and tune enforcement.
OPNsense
Fetch remote blocklists and apply in firewall rules.
Key & Abuse Protection
License keys are plan-scoped and protected with fair-use rate limits. One key is strictly intended for one firewall edge.
Operations & Status
Delivery is served over HTTPS and designed for predictable, automated polling 24/7/365.
View System Status →Security & Privacy
We don't collect your network traffic. Review our strict security and privacy pages for current data handling practices.
Test compatibility with the Free Basic Feed.
We don't offer refunds, because we want you to be 100% sure Cybora works with your specific hardware setup before you spend a dime. Use our Basic feed to validate the URL delivery and TXT format.
Basic (Free) Limitations
- Indicator Type: IPv4 only
- Update Frequency: 24 hours
- Coverage: ~30k IPs
- Technical Support: None
Frequently asked questions
Is it really 1 key = 1 firewall/device?
Will this feed block legitimate traffic?
How do renewals work?
What polling interval should I set?
What happens if my key is leaked?
Do you offer refunds?
Make your firewall quieter today.
Self‑serve purchase. Setup in minutes. Works flawlessly with any firewall that supports URL-based external threat feeds.