What is Attack Defense?
Attack Defense is a community network in both directions:
- Report: your servers automatically report attack attempts (SSH brute-force, IMAP/POP3 logins, SMTP auth, web attacks, DDoS, port scans and 100+ more service types) to a central scoring list.
- Block: every participant automatically blocks the IPs reported by the community on their own servers and firewalls - attackers are stopped everywhere, not just where they were caught.
It works like blocklist.de, but more cautious: every report is a signal, never a verdict. An IP is only listed when at least two independent reports confirm it - or immediately for critical categories (malware, botnet).
Who is it for?
- Hosters & server admins who run fail2ban, CrowdSec or any server software.
- Firewall operators (iptables, nftables, ufw, pf/BSD, Windows) who want a free, automatically updated blocklist.
- Everyone who wants to check whether an IP is a known attacker before letting it in.
What it costs
Nothing. Reporting, blocking and IP checks are free and work without an account. A free account only adds optional report tokens for personal statistics.
How it works
Three steps, fully automated:
- Server reports: fail2ban bans an attacker and reports the IP to us automatically via HTTP API (CrowdSec and any custom system work too).
- We score: every report is a weighted signal. Category, confidence and reporter reputation determine the score. Scores decay exponentially - entries disappear automatically without new activity (7 days).
- Everyone blocks automatically: participants pull the current list every 5 minutes. On servers via the fail2ban block jail, on firewalls via the plain-text export. The responsible provider is notified anonymously (RDAP/whois, X-ARF format).
Important: blocking never runs over DNS queries. The DNS zones are check zones - you query them to look up a single IP. The actual blocking uses the HTTP export, synced every 5 minutes.
Listing states & the cautious principle
Every IP goes through four states:
| State | Meaning | DNS answer |
|---|---|---|
| Clean | No reports. | NXDOMAIN |
| Watchlist | One report - internal monitoring only, not publicly listed. | NXDOMAIN |
| Soft-listed | Two independent reports - listed with block code. | 127.0.0.8 (abuse) / 127.0.0.7 (exploit/scanner) |
| Hard-listed | Further reports or critical category - reject allowed. | 127.0.0.6 (botnet) and others |
The cautious principle:
- Every report counts equally - with token or anonymous.
- One single report only reaches the watchlist - no arbitrary listings.
- Two independent reports list the IP; further reports hard-list it.
- Critical categories (malware, botnet) list with a single report.
- Entries expire automatically without new reports (7 days).
Reporter reputation adjusts the weight of a report (0.25x–2.0x), never the listing threshold - trusted reporters keep entries listed longer and push hard-listing faster, unreliable sources are dampened.
Check zones & export
Each of the 109 services has its own check zone under attacks.provider.tools, plus a base zone for all attacks:
ssh.attacks.provider.tools imap.attacks.provider.tools smtp-auth.attacks.provider.tools
attacks.provider.tools (base zone - any attack)
Query the reversed IP under the zone label to check a single IP - see the article Check IPs.
For blocking there is the HTTP export - a plain-text list of all currently listed IPs (one per line), optionally filtered by service:
https://reports.provider.tools/api/v1/abuse/export (all)
https://reports.provider.tools/api/v1/abuse/export?service=ssh
This export is what the fail2ban block jail and the firewall examples sync every 5 minutes.
Quick start
- On a server with fail2ban: one command - see fail2ban (reporting & auto-blocking). Installs reporting AND blocking in 2 minutes.
- On a firewall / router: sync the export and block - see In your firewall. iptables, nftables, ufw, pf (BSD) and Windows examples.
- Just want to check an IP? Use the Live Check or
dig- see Check IPs.
Related articles
On your server: fail2ban (reporting & auto-blocking)
One command installs reporting AND automatic blocking of reported attackers on your server - with block consumer, 5-minute sync, whitelist and per-service filtering.
ReadIn your firewall: block reported attackers
Block the Attack Defense list directly on routers and border firewalls without fail2ban - iptables, nftables, ufw, pf (BSD) and Windows Firewall, synced every 5 minutes.
ReadCheck IPs: Live Check & DNS
Check whether an IP is listed: web Live Check or dig against the per-service check zones - with return codes, TXT details and the HTTP export.
Read