Skip to content

Threat feed

FireHOL WebClient

Last fetched

General Blacklists · refreshed hourly · last verified

FireHOL WebClient is a General Blacklists threat-intelligence feed, refreshed hourly, indexed by WhisperGraph. WhisperGraph currently records 134 indicators listed by it.

What is FireHOL WebClient

FireHOL WebClient is the web-client-targeting view from the FireHOL IP lists project. It enumerates IP addresses observed performing web-application brute force, credential stuffing, and other client-side abuse against participating sources. Inclusion is targeted: an IP appears here when it has been reported across multiple upstream feeds for HTTP-layer abuse rather than generic scanning, which keeps the feed useful for application-layer rate-limiting and WAF deployments without the false-positive noise of a broader reputation list. It is indexed here as a record for web-application abuse research and for tuning WAF rule sets.

Refresh cadence
hourly

Category drift. The curated category for this feed is General Blacklists, while WhisperGraph currently files it under blacklists.

Indicators currently listed

134 indicators across 1 node type.

Related pages

Pivot from FireHOL WebClient into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.