✗Distribution of illegal content (incl. CSAM, illegal weapons or drug trade)
✗Phishing, malware distribution & botnet C2 infrastructure
✗Fraud, scams & trading of stolen data or credentials
✗Copyright-infringing piracy / warez hosting
✗Tor exit nodes
✗Tor relay & bridge nodes
✗Any anonymisation proxy used to obscure the origin of abuse
✗Spam / unsolicited bulk email origination
✗DDoS & amplification attacks (open resolvers, NTP/memcached reflection)
✗Booter / stresser services
✗Unauthorised port/vulnerability scanning & route hijacking