REST API - Programmatischer Zugang3 min read2 sections

Attack Defense API

Report brute-force attacks, DDoS and scanner activity via fail2ban or HTTP API. Free, anonymous, no account required.

01

Submit a Report

POST /api/v1/abuse/report
Content-Type: application/json
X-Report-Token: ar_YOURTOKEN   (optional, no auth required)

{
  "ip": "203.0.113.7",
  "service": "ssh",
  "port": 22,
  "count": 5
}

Services

ssh, imap, pop3, smtp-auth, http, ddos, ftp, sip, sqli, webmin, botnet, portscan

Response

{
  "success": true,
  "deduped": false,
  "ip": "203.0.113.7",
  "service": "ssh",
  "category": "abuse",
  "score": 23,
  "listingState": "watchlist",
  "confidenceLevel": "medium"
}

Rules: public IPs only, 120 reports / 5 min per source IP, deduplication within 10 minutes, whitelist support.

02

Report Tokens & Statistics

Create a token (account required)

POST /api/v1/abuse/tokens
Content-Type: application/json

{ "label": "mail-01.example.com" }   (optional)

Response:
{ "success": true, "token": "ar_abc123...", "statsUrl": "/api/v1/abuse/tokens/ar_abc123..." }

Token statistics

GET /api/v1/abuse/tokens/{token}

Response:
{
  "success": true,
  "metrics": {
    "totalReports": 128,
    "last7d": 42,
    "currentlyListedFromMyReports": 3,
    "byService": [{ "service": "ssh", "count": 96 }]
  }
}

Public endpoints

MethodEndpointDescription
GET/api/v1/abuse/check?ip=..Check an IP with anonymized evidence
GET/api/v1/abuse/statsPublic aggregate network statistics
GET/api/v1/abuse/fail2ban-configfail2ban action file download