SSHwatch IP threat API's
SSHwatch's Threat API provides valuable real-time data about threats, optionally aggregated from our users to enhance security for everyone. By collecting and analyzing anonymized data from participating users, our platform identifies emerging threats, tracks malicious IPs, and uncovers attack patterns across the globe. This collective intelligence ensures you stay ahead of potential risks, enabling faster detection and more accurate threat mitigation.
IP threat rating lookup
https://api.sshwatch.com/ip/{ip_address}Our IP Threat Rating Lookup API allows you to query information about specific IP addresses in our threat database. By making a simple request to /ip/{ip_address}, you'll receive detailed JSON data including the threat score, submission count, and last update time for the requested IP. This endpoint makes it easy to integrate threat intelligence into your security tools, firewall rules, or monitoring systems, enabling real-time validation of suspicious connections before they can impact your infrastructure.
IP threat feed
https://api.sshwatch.com/feed/Access our comprehensive list of known malicious IPs through our Threat Feed API. With a single request to /feed, you'll receive a plaintext list of all threat IPs in our database, perfect for bulk importing into firewalls, security appliances, and other defensive systems. Each feed includes helpful comments detailing the last update time and purpose of the list, while being formatted for maximum compatibility with security tools. This API enables you to leverage SSHwatch's collective threat intelligence to strengthen your perimeter defenses and block known malicious actors before they attempt to breach your systems.
Secure Your Infrastructure Today!
Sign up now to gain comprehensive insights into your SSH access logs. Start monitoring, alerting, and analyzing your entire infrastructure effortlessly.
Get started for free