Skip to main content

Data Sources

Sentinel draws on several publicly available, regularly updated data sources for threat intelligence — keeping it self-hosting friendly rather than depending on a proprietary feed.

Data sourceUsed forEnv var
FireHOL IP ListsMalicious IP identification, feeding Threat Intelligence.
PhishTank (phishtank.org)URLs for Phishing Detection.PHISHING_LIST_URL
disposable-email-domains projectDetecting throwaway email addresses.EMAIL_LIST_DISPOSABLE
intoli/user-agents datasetIdentifying suspicious/uncommon user agents.USER_AGENT_LIST_URL
High-risk countries20+ countries flagged for stricter default handling.HIGH_RISK_COUNTRIES

Automatic updates

Each source refreshes on its own cron-style schedule — override the relevant *_SCHEDULE variable to change the frequency. See ENV Variables for the full list of source URLs and schedule variables.

Start typing to search...

Navigate Select