Threat-intelligence feed
General BlacklistsLast verified Page fetched
FireHOL Level 3 is a general blacklists threat-intelligence feed tracked by WhisperGraph as a FEED_SOURCE node. The Whisper Internet Directory publishes this page so security analysts and LLM agents can link to it as a stable record for FireHOL Level 3.
FireHOL Level 3 is the broadest tier of the FireHOL IP lists project. It extends Level 2 with additional feeds covering recently-observed abuse, mass-scanning sources, and reputation-based deny-lists with looser inclusion criteria. The trade-off is a noticeably higher false-positive rate than Level 1 or Level 2; Level 3 is best used as a SIEM enrichment overlay or alert-triage signal rather than as a default-block. Operators who deploy it at the perimeter typically pair it with a documented allow-list workflow to handle the false positives. It is indexed here because Level 3 is a frequent citation in DDoS post-mortems.
FEED_SOURCE node not currently in WhisperGraph. The editorial entry for FireHOL Level 3is committed to the directory but the corresponding graph node is missing — typically a transient state during the threat-feed import pipeline's between-runs window. The page will reconcile on the next revalidation.
WhisperGraph has observed 3 distinct IPv4 addresses listed in FireHOL Level 3across the directory's curated host corpus. This is a sampled lower bound — the feed's full membership is larger — surfaced because LISTED_IN cannot be enumerated from the feed side directly (see the Cypher panel below).
A sample of IPv4 addresses currently listed in FireHOL Level 3. Each links to its full infrastructure profile.
Look up which threat feeds list a given IP — the indicator-anchored query that powers the threat card:
MATCH (ip:IPV4 {name: $ip})-[:LISTED_IN]->(f:FEED_SOURCE)
WHERE f.name = "FireHOL Level 3"
WITH f
MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
RETURN f.name AS feed, c.name AS categoryVerify the feed's graph-side identity directly:
MATCH (f:FEED_SOURCE {name: "FireHOL Level 3"})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
RETURN f.id AS id, f.name AS name, c.name AS categoryOr query Whisper from your own LLM workflow via the Whisper MCP server.
Pivot from FireHOL Level 3 into adjacent entities.