Report an attack
POST https://reports.provider.tools/api/v1/abuse/report
Content-Type: application/json
X-Report-Token: ar_YOURTOKEN (optional)
{ "ip": "203.0.113.7", "service": "ssh", "port": 22, "count": 5 }
Supported services (100+): server access (ssh, rdp, vpn...), mail (imap, smtp-auth...), databases (mysql, postgresql...), web attacks (http, sqli, xss...), DDoS, malware/botnet, game servers and more. Full machine-readable list: GET /api/v1/abuse/report
Report tokens
Tokens are created in the Reporting page (free account, one per server) or via API:
POST https://reports.provider.tools/api/v1/abuse/tokens (account auth required)
{ "label": "mail-01" }
GET https://reports.provider.tools/api/v1/abuse/tokens/{token} (your token's statistics)
Send the token as X-Report-Token header with every report. Anonymous reports (no token) count exactly the same for listing.
Rules
- Only public IP addresses are accepted (private/reserved ranges are rejected).
- Rate limit: 120 reports per 5 minutes per source IP.
- Deduplication: identical (IP, service) reports within 10 minutes are not counted twice.
- Whitelisted IPs are ignored.
Other endpoints
| Method | Endpoint | Description |
|---|---|---|
GET | /api/v1/abuse/check?ip=.. | Check an IP with anonymized evidence (JSON) |
GET | /api/v1/abuse/export | Plain-text list of all listed IPs, optional ?service= / ?format=json |
GET | /api/v1/abuse/stats | Public aggregate network statistics |
GET | /api/v1/abuse/fail2ban-install | Installer script (?block=0, ?token=, ?block_service=) |
GET | /api/v1/abuse/fail2ban-config | fail2ban action file / jail examples download |
Related articles
Attack Defense - What it is & how it works
The product explained from zero: report attacks from your servers to a global list - and automatically block reported attackers on your own systems. Free, anonymous, GDPR compliant.
ReadOn your server: fail2ban (reporting & auto-blocking)
One command installs reporting AND automatic blocking of reported attackers on your server - with block consumer, 5-minute sync, whitelist and per-service filtering.
ReadIn your firewall: block reported attackers
Block the Attack Defense list directly on routers and border firewalls without fail2ban - iptables, nftables, ufw, pf (BSD) and Windows Firewall, synced every 5 minutes.
Read