Omega Point Threat ID
Trust & transparency

Registry methodology & appeals

A threat registry is only as good as its false-positive rate. This page documents exactly how the Omega Point Threat ID registry decides what is listed, how listings expire, and how anyone can request removal.

What we list — and what we never list

The public feed contains IP addresses only, and only those meeting a strict, corroborated bar (see below). We never publish personal identities, account handles, case data, or any investigative information — that data is internal-only by policy and is technically walled off from the public feed.

How an IP gets listed

Every listing is an observation, not an accusation. An IP is published only when all of the following hold:

Sources include our own $1 honeypot sensor network, GreyNoise scanner intelligence, Shodan infrastructure data, and community reporting. Verdicts are computed deterministically and each listing records its sources, threat types, first-seen, last-seen, and sighting count.

Aging & expiry

IP reputation is perishable — addresses on cloud and shared hosting get reassigned to innocent parties. Listings therefore age out: entries that stop being observed decay in confidence and drop below the publication bar, removing them from the public feed automatically. A listing reflects recent, repeated malicious behavior — not a permanent brand.

Appeals & de-listing

If your IP is listed and you believe it is a false positive — or you have remediated the issue (e.g. patched a compromised host) — request removal. We review de-listing requests promptly and remove any listing we cannot re-corroborate.

Request removal two ways:

Request de-listing

Using the data responsibly

Threat data is corroborating evidence, not proof. Use the feed to inform defensive controls (firewall/WAF blocklists, alerting, triage) — not as the sole basis for an accusation or an adverse action against a person. Consumable formats: .txt, .csv, STIX 2.1, JSON.