01 · hero
Sensible defaults for your MikroTik firewall.
Battle-tested RouterOS firewall rules and community-curated address lists. Paste, schedule, done. No agent, no telemetry, no account required.
Pick your path
door A
I want firewall rules.
A walkthrough that hardens a fresh router in about 10 minutes. Input chain, forward chain, IPv6, Winbox/SSH access.
door B
I want blocklists.
Subscribe to community-curated address lists. RouterOS pulls them with
/tool fetch. Updates daily; signed.
- SCANNER
scannersRecon traffic from public scanners — masscan, zmap, shodan. - BOTNET
botnet-c2Known C2 endpoints from public threat-intel feeds. - BRUTE
ssh-bruteforceRepeat SSH offenders observed in the last 7 days. - TOR
tor-exitsPublic Tor exit nodes — informational, log don’t drop.
Live entry counts and update cadence appear here once the list engine ships.
02 · trust strip
Why this is trustworthy
-
Independent
solo dev · no investors -
Verifiable lists
sha256 manifest -
No telemetry
fetch from your router -
Community-funded
monthly transparency
03 · how it works
How it works.
-
STEP 01Pick a list
Browse curated lists or paste our firewall script.
-
STEP 02Paste the URL into RouterOS
/tool fetch url=… on a daily schedule.
-
STEP 03Drop reaches your router
Lists update; your firewall stays current.