Threat feed
FireHOL WebClient
Last fetched
General Blacklists · refreshed hourly · last verified
FireHOL WebClient is a General Blacklists threat-intelligence feed, refreshed hourly, indexed by WhisperGraph. WhisperGraph currently records 134 indicators listed by it.
What is FireHOL WebClient
FireHOL WebClient is the web-client-targeting view from the FireHOL IP lists project. It enumerates IP addresses observed performing web-application brute force, credential stuffing, and other client-side abuse against participating sources. Inclusion is targeted: an IP appears here when it has been reported across multiple upstream feeds for HTTP-layer abuse rather than generic scanning, which keeps the feed useful for application-layer rate-limiting and WAF deployments without the false-positive noise of a broader reputation list. It is indexed here as a record for web-application abuse research and for tuning WAF rule sets.
- Refresh cadence
- hourly
Category drift. The curated category for this feed is General Blacklists, while WhisperGraph currently files it under blacklists.
Indicators currently listed
134 indicators across 1 node type.
Related pages
Pivot from FireHOL WebClient into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.