SANS Internet Storm Center – API

Even as a long-time listener of the daily newscast from SANS Storm Center, I never knew they offer a free API with useful information. The downside is that the API is rather slow, but still useful for IP intelligence.

You can find a full list of their current API offerings over at

The Cloud IP’s

This endpoint ( will return a current list of subnets used by cloud providers such as Amazon and Google.

In my first analysis using this list, I already noticed that it is not complete. However, it still provides a good signal for local tagging and log file analysis., free list of IPv4 ranges of cloud providers (2024-04-30)


In my testing, this endpoint did not work as of the end of April 2024, not even with the example from the website. The return was always empty., (2024-04-30)

Other API

SANS also offers a wide variety of other API endpoints, which I have not yet had the chance to try out.