Skip to content

Threat feed

IPsum

Last fetched

General Blacklists · refreshed daily · last verified

IPsum is a General Blacklists threat-intelligence feed, refreshed daily, indexed by WhisperGraph.

What is IPsum

IPsum is the meta-aggregator IP reputation feed maintained by Miroslav Stampar. It is composed of dozens of upstream community deny-lists, scored by the number of independent lists each IP appears on. The published feed is tiered (level 1 through level 8) so operators can pick the confidence threshold appropriate for their deployment — level 1 is the union of every upstream and very noisy, level 8 is restricted to IPs flagged by eight or more independent sources and is consequently very high-confidence. The methodology is fully documented and reproducible. It is indexed here because IPsum is a canonical academic-research baseline for IP reputation work.

Refresh cadence
daily

Category drift. The curated category for this feed is General Blacklists, while WhisperGraph currently files it under blacklists.

Indicators currently listed

Indicators currently listed is temporarily unavailable.

The graph did not answer within the page budget. Refresh in a moment to retry — fresh data is fetched on the next visit.

Related pages

Pivot from IPsum into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.