# # KahfGuard router IP blocklist sources. # # The machine-readable copy of this list lives in scripts/ip_feed_sources.py, # which is what the pipeline actually reads. This file is the human-facing # index, published to S3 alongside sources/block.txt so downstream consumers # can see where the router IP lists come from. # # Format: [category] [key] url # Category is the router list the feed is merged into; key is the filename # stem used in s3://kahfguard/sources/ip-feeds/v1/. # # Entry counts are as measured on 2026-08-21 and are what the guard # thresholds in scripts/ip_guards.py were calibrated against. # --- tor ----------------------------------------------------------------- [tor] [tor-exits] https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/tor_exits.ipset [tor] [tor-relays] https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/dm_tor.ipset [tor] [tor-bulk-exit] https://check.torproject.org/torbulkexitlist # --- vpn ----------------------------------------------------------------- [vpn] [x4bnet-vpn-v4] https://raw.githubusercontent.com/X4BNet/lists_vpn/main/output/vpn/ipv4.txt [vpn] [x4bnet-vpn-v6] https://raw.githubusercontent.com/X4BNet/lists_vpn/main/output/vpn/ipv6.txt [vpn] [nazgul-vpn-v4] https://raw.githubusercontent.com/NazgulCoder/IPLists/main/output/vpn-ipv4.txt [vpn] [nazgul-vpn-v6] https://raw.githubusercontent.com/NazgulCoder/IPLists/main/output/vpn-ipv6.txt [vpn] [cloudflare-warp] https://raw.githubusercontent.com/NazgulCoder/IPLists/main/resources/cloudflare-warp.txt # --- proxy --------------------------------------------------------------- [proxy] [ssl-proxies] https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/sslproxies.ipset [proxy] [socks-proxies] https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/socks_proxy.ipset # --- bad ----------------------------------------------------------------- [bad] [firehol-level1] https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset [bad] [firehol-abusers-1d] https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_abusers_1d.netset [bad] [blocklist-de] https://lists.blocklist.de/lists/all.txt # --- evaluated and deliberately excluded --------------------------------- # Do not add these back without reading docs/ip-blocklist-pipeline.md first. # # firehol_anonymous.netset 2,668,920 lines — 62x the entire viable set. # firehol_proxies.netset 2,663,082 lines — same. # sefinek main.txt 218,938 bare IPs, no CIDR aggregation. # dan.me.uk/torlist/exit one fetch per 30 min; 403s shared runner IPs. # X4BNet output/datacenter/ 33% is AS212238 CDNEXT, a CDN. Also contains # 8.8.8.0/24 and the range holding # gitlab.kahf.co.uk.