Curated IP threat intelligence
SciScope is a curated IP-reputation feed built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up and hand you at maximum confidence.
We cross-referenced several widely-used public IP-reputation lists against our curated reference set of known-good infrastructure — search & AI crawlers, public DNS resolvers, and attributed research scanners. The bar is the false-positive rate; the figure beside it is the raw count of legitimate IPs. We don't name the lists — but the pattern is consistent.
Bars scaled to the ~10% maximum · full-list cross-reference, not sampled traffic · well-curated lists score a clean 0% — the problem is the noisy ones.
Baidu and Yandex search crawlers sat on one popular community blocklist — legitimate search engines that anyone consuming the list raw would silently block, and the kind of false positive most feeds never notice. None of them reach the SciScope feed.
Legitimate IPs we found across those lists, by owner. Block the lists wholesale and you block these — de-indexing your site, breaking uptime checks, and blinding the research scanners that map the internet's exposure.
Counts: legitimate IPs of each owner found across the measured lists, 2026-07-06. Also protected — zero wrongly listed today: Applebot, Anthropic, DuckDuckGo, Qwant, Mojeek, public DNS resolvers, NTP & root DNS servers, cloud health-checkers, uptime monitors.
The abuse-report feed doesn't hedge on the infrastructure it gets wrong. The legitimate services it lists carry a mean confidence of 97.5 — so the usual defence, "just filter to confidence ≥ 90," still blocks internet-measurement scanners, AI crawlers and major search engines. You can't threshold your way out of a curation problem.
Every false-positive class above is screened out of the SciScope feed, continuously. We re-measure public lists against our reference set and publish the results — the proof is the numbers on this page, not a promise.
Google, Bing, Baidu, Yandex, Apple, DuckDuckGo, Qwant, Mojeek, OpenAI, Anthropic, Perplexity — indexing and answer engines never end up blocked.
Public resolvers, NTP time servers and the DNS root — infrastructure your network depends on stays off the list, even when reflection attacks drag it into others' logs.
Load-balancer health checks and uptime probes look exactly like scanners to a naive sensor. They never reach the feed.
Censys, ONYPHE, BinaryEdge and the rest of the internet-measurement world — flagged as what they are, visible in your telemetry, never on the blocklist.
We run our own sensors, we curate centrally, and we show our work — every flagged IP ships with the evidence behind it.
A distributed network of our own sensors observes real attack traffic across independent vantage points — original signal, not a resold black box.
Every candidate IP is screened against the protected categories above and scored on recent, corroborated hostile activity. Only real attackers make the cut.
A scored feed in JSON and CSV with per-IP evidence, a high-confidence blocklist.txt, and an opt-in crawler-identity list — block regional crawlers on your terms, not by accident.
Between overpriced enterprise platforms and underpowered free lists. Start on a founding price locked in for early adopters.
Founding price is locked in for early adopters. Prices exclude VAT where applicable.
Email us with your use-case and what you'd need to evaluate SciScope. We'll set you up with a 14-day trial — and extend it to 30 days if you tell us a bit about your plan. Trials are issued by hand right now, so you'll talk to a human, not a form.