01 · hero
Sensible defaults for your MikroTik firewall.
Battle-tested RouterOS firewall rules and community-curated address lists. Paste, schedule, done. No agent, no telemetry, no account required.
Pick your path
door A
I want firewall rules.
A walkthrough that hardens a fresh router in about 10 minutes. Input chain, forward chain, IPv6, Winbox/SSH access.
door B
I want blocklists.
Subscribe to community-curated address lists. RouterOS pulls them with/tool fetch. Updates daily; signed.
- SCANNER
scannersRecon traffic from public scanners — masscan, zmap, shodan. - BOTNET
botnet-c2Known C2 endpoints from public threat-intel feeds. - BRUTE
ssh-bruteforceRepeat SSH offenders observed in the last 7 days. - TOR
tor-exitsPublic Tor exit nodes — informational, log don’t drop.
Live entry counts and update cadence appear here once the list engine ships.
02 · trust strip
Why this is trustworthy
Independent
solo dev · no investorsVerifiable lists
sha512 manifest · off-routerNo telemetry
fetch from your routerCommunity-funded
no ads, no tracking
03 · how it works
How it works.
STEP 01Pick a list
Browse curated lists or paste our firewall script.
STEP 02Paste the URL into RouterOS
/tool fetch url=… on a daily schedule.
STEP 03Drop reaches your router
Lists update; your firewall stays current.