Product Security Hardening

Unrelated Networks to block

These networks scan the internet and are not exactly a threat but due to the scanning, it reveals vulnerability information within the infrastructure.

Blocking Internet Measurement (DriftNet)

ASN211298

IPv4 Scanning IPs

87.236.176.0/24
193.163.125.0/24
68.183.53.77/32
104.248.203.191/32
104.248.204.195/32
142.93.191.98/32
157.245.216.203/32
165.22.39.64/32
167.99.209.184/32
188.166.26.88/32
206.189.7.178/32
209.97.152.248/32

IPv6 IPs

You may also opt out by sending your IP ranges and/or domain names to optout@driftnet.io. This process will be validated for confirmation by the Driftnet team.

Block Censys

AS398705

AS398324

AS398722

Block IONOS

AS8560

Block Internet Archive (Wayback Machine)

AS7941

Block North Korea

AS13127

Block Yandex (Russian Search Engine)

AS13238

Block M247 Europe

AS9009

Block ProtonVPN

AS209103

Block Cortex Xpanse

Cloudflare

GeoBlocking with Whitelist expression - This rule blocks incoming traffic from a specified list of countries and the Tor network while allowing traffic from any IP addresses included in a predefined whitelist (e.g., trusted clients or partners).

Bulk IP CSV uploads require a CSV in IP, DescriptionFormat. Here is a python script to use for creating the bulk upload csv:

cfbulkip.py

Last updated