TweetFeed
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes.
TweetFeed collects indicators of compromise from social posts
A community fed repository of malicious URLs, domains, IP addresses, and file hashes drawn from security posts on X.
What it aggregates
TweetFeed collects indicators of compromise shared by the information security community on X, formerly Twitter. The repository publishes malicious URLs, domains, IP addresses, and SHA256 and MD5 file hashes, refreshed on a schedule so that defenders can pull current data. The premise is that many threat researchers post fresh indicators publicly, and consolidating them in one place makes them easier to consume.
Access formats
The data is offered as CSV feeds for today, the last week, month, and year, plus an RSS feed of the day's indicators. Machine readable formats include MISP manifests and STIX 2.1 bundles for today, week, and month, and a MISP hash cache for correlation. An API at api.tweetfeed.live provides programmatic access, and the README documents how to add the feeds as a source in a MISP instance.
Context and licensing
The project is intended for defensive security use and includes a disclaimer about the source and reliability of crowd sourced indicators. It is released under the CC0-1.0 license, meaning the data is placed in the public domain, and the August 2026 snapshot shows 676 stars and 69 forks. Counters in the README are regenerated by the pipeline every fifteen minutes while the written sections stay stable.
Editorial conclusion
TweetFeed is CC0-1.0 licensed and records 676 stars with 69 forks as of August 2026. It consolidates community reported malicious indicators into CSV, RSS, MISP, and STIX formats for defensive use.
Community notes