Threat modeling becomes significantly more complex when attackers utilize distributed proxy pools originating from specific regional subnets across Oceania and neighboring territories. Our security operations center recently intercepted several coordinated credential stuffing attempts disguised as legitimate local traffic from overseas sources. Having access to comprehensive network lists allows our firewall administrators to update IP reputation tables proactively before major incidents occur. I will incorporate those routing metrics into our automated threat detection pipelines before the end of the current work week