SikkerAPI Now Supports CIDR Range Alerts

SikkerAPI now supports CIDR Range Alerts, enabling structured IP range monitoring and automated subnet-level threat intelligence alerts across your network blocks.
With CIDR Range Alerts, you can monitor entire IP ranges using standard CIDR notation and receive notifications when an address inside those ranges is detected by SikkerAPI. This adds continuous network security monitoring at the subnet level, directly integrated into the SikkerAPI platform.
What Is CIDR Range Monitoring?
CIDR (Classless Inter-Domain Routing) notation allows you to define IP address blocks such as /28, /24, /20, or /16. Instead of focusing on a single IP, you can monitor an entire subnet or allocated public IP block.
With SikkerAPI CIDR Range Alerts:
- You register an IP range in CIDR format
- New detections are continuously matched against that range
- Alerts are grouped into an hourly digest
- Notifications are only sent when new IPs inside your range are detected
Each alert includes:
- IP address
- Confidence score
- Country
- Last seen timestamp
To reduce alert fatigue, each IP is only notified once per configured range.
This makes CIDR Range Alerts a practical solution for enterprise IP monitoring, public IP block monitoring, and automated IP reputation alerts across entire network segments.
Included in the Free API Plan
CIDR Range Alerts are available across all SikkerAPI plans — including the Free API tier.
The Free plan includes:
- 1 CIDR range alert (up to /28)
- 1,000 IP reputation lookups per day
- 1,000 reports per day
- 5,000 blacklist IPs
- 1,000 TAXII indicators per day
Access to CIDR-based subnet monitoring in a free plan is uncommon in the IP reputation and threat intelligence space. Higher tiers increase the number of supported CIDR ranges and allow broader network prefixes for larger infrastructure environments. Click here for more information on different pricing tiers.
Built for Real-World Network Monitoring
CIDR Range Alerts are designed for organizations that manage:
- Allocated public IP address blocks
- Cloud infrastructure
- Hosting provider networks
- Customer subnets
- Enterprise network segments
Instead of manually checking individual addresses, you can apply structured IP range security monitoring and receive automated alerts when new activity appears inside your monitored CIDR blocks.
The feature works alongside the existing SikkerAPI IP reputation API, blacklist datasets, bulk lookups, reporting endpoints, and TAXII 2.1 threat intelligence feeds.
CIDR Range Alerts are now live.
To configure your first CIDR range and enable subnet-level IP monitoring, visit the guide by clicking [/link=/docs/range-alerts]here[/link].
Comments
No comments yet. Be the first to share your thoughts!