Skip to content

01 · WHAT IT DOES

Less analyst time per IOC.
Same answer your senior would ship.

One call returns the verdict, the evidence behind it, and the recommended action. Tier 1 ships decisions in seconds, no investigation queue, no senior-analyst escalation per IOC.

Allsignals
6signal groups
3endpoints
Deterministic verdictsNo agent, no SDKFree tier
02 · VERDICTIQ AI

Add a senior-analyst read, in seconds.

VerdictIQ AI reads each verdict and its signals, then ships a write-up your most senior analyst would defend. Opt-in inside the VerdictIQ portal, per verdict. The verdict path stays deterministic; AI only narrates what already fired. The AI layer uses an internally-managed model; sub-processor list at /trust#ai-subprocessors.

Grounded on your own response

The narrative cites the same signals[] and evidence[] that produced the verdict. No external lookup, no hallucinated context, no model speculation.

Deterministic core, narrated outcome

risk_score, risk_level and recommended_action don't move when AI is on. Same input still produces the same verdict; the narrative is layered on top.

Opt-in inside the portal, free tier included

Open a verdict in the VerdictIQ portal and run Enrich with VerdictIQ AI. On-demand only; stateless, nothing about the verdict is retained for model training.

Meet Maestro

Have a question? Just ask.

Maestro is your VerdictIQ guide on this site. Ask anything about the product, how scoring works, integrations, pricing, or how we compare to feeds and TIPs. Answers are grounded on our docs and product knowledge, not scripted bots.

  • Available on every key section of this site
  • Trained on VerdictIQ docs, schema, and product copy
  • Cites sources when relevant, so you can verify the answer
03 · BEHAVIORAL DETECTION

Catch infrastructure that hasn't earned a reputation yet.

Domains are infinite. Adversary patterns are finite, and statistically repeatable. Our behavioral signals fire on infrastructure shape, not on feed coverage.

Activation timing anomalies

Gap between registration and activation; dormant-then-active fingerprint.

DNS rotation strategies

Fast-flux, round-robin and geo-rotation patterns.

Hosting reuse patterns

Co-tenancy with known-malicious; cloud vs dedicated profile.

Lifecycle anomalies

Unexpected age combined with activity bursts.

Infrastructure clustering

Graph-level proximity to known campaign nodes.

Relational campaign signals

Shared signals with other malicious nodes in the same window.

Scenario · 6-month dormant phishing domain
  1. T-180 days

    Registered, silent

    Sat dormant for six months. Most reputation feeds: clean.

  2. Today

    Activated

    IP assigned, free SSL provisioned, lands on a host with 6 known-malicious neighbors.

  3. Pre-attack

    Blocked at activation

    VerdictIQ ships block_domain · 87 the moment infrastructure goes live, before the first phishing email or malicious request leaves the host. Reputation feeds: still clean. (illustrative)

04 · DECIDE BEFORE, NOT AFTER

Pre-hoc decision engine. Stop chasing IOCs after they fire.

Forensic tools tell you what was malicious. The SOC needs to know what to do with traffic landing right now. The verdict ships before the IOC fires, not as a report after it.

The forensic question
Is this domain truly malicious? Prove it.
Forensic report, hours-to-days; arrives after the action.
The operational question
Should I pass, block or escalate this right now?
Score, reason and recommended action; in seconds at traffic time.

If your workflow needs payload analysis or campaign forensics, pair VerdictIQ with payload-analysis or threat-hunting tooling. We trigger the action; we don't reproduce the payload.

06 · SOAR-READY OUTPUT

Decision your playbook executes, not parses.

A wire-stable enum your playbook reads without parsing. No per-vendor mapping, no glue code, no analyst tap to route.

Wire-stable enum, not free text

recommended_action returns one of four values. Your playbook switches on four cases, not a regex parser.

block_domainalertmonitorallow
Same enum, single IOC and batch

Single IOC or batch: the same recommended_action field with the same four values.

The engine picks the action. The playbook executes it. No analyst interpretation between them.

07 · DETERMINISTIC & REAL-TIME

Same input. Same score. Live, every call.

No model temperature. No last_scanned lag. No silent rescore after a vendor update. The verdict is a function of the signals, recomputed against today's warehouse on every call.

Live recalculation

Each call recomputes against today's DNS, HTTP, WHOIS, CTI and relational signals. No cached verdict reuse, no batch refresh window.

Deterministic scoring

Same IOC, same signals, same score. Analyst A and analyst B querying the same IOC reach the same call, and so does audit, six months later.

What we don't do

  • No last_scanned timestamps.
  • No silent rescore between calls.
  • No cached verdict reuse.
08 · EXPLAINABLE EVIDENCE

Every verdict shows its work.

Black-box scores fail when someone asks why. Every VerdictIQ verdict carries the signals that fired, the evidence behind each one, and a prepared answer to the analyst's most likely question.

01
See the signals, not just the score.

Every verdict opens to the signals that actually fired against the IOC. Your analyst reads what drove the score, not just how high it landed.

02
Evidence the analyst can act on.

Each signal carries the telemetry that triggered it. No follow-up tickets to data engineering, no screenshot collection, the trail ships with the verdict.

03
Answers before the question.

A prepared Q&A pair sits next to each verdict. Tier 1 closes the ticket without paging a senior analyst at 3 a.m.

09 · SIGNAL ENGINE

Every signal across 6 groups, weighed before you query.

Our warehouse runs DNS probes, HTTP crawls, WHOIS lineage, popularity graphs, threat-intel ingestion and relational fusion on a schedule we control. By the time /enrich returns, the signals are already fused into a verdict.

DNS History
A/AAAA/NS/MX rotation lineage, fast-flux fingerprints.
HTTP Crawling History
Page content, redirects, SSL/TLS chain, header behavior.
Popularity & Backlink
Traffic rank, referring domain graph, audience footprint.
Relational Intelligence
Co-tenancy, infrastructure clustering, campaign neighbors.
Threat Intelligence Feed
Aggregated 3rd-party reputation feeds, cross-checked.
WHOIS
Registration lineage, ownership history, age signals.
10 · ONE-CALL FLOW

POST → engine → verdict → understand. In one call.

Single POST /enrich request enters the engine. Signals fuse, score lands, action is selected, all in the same response. The "understand" depth (Q&A and VerdictIQ AI narrative) is opt-in on the same call, not a second trip.

01

Send

One HTTPS POST. domain · ip · cidr · asn · sha256: pick the IOC type, payload is one field.

02

Engine

All signals fuse against today's warehouse. Group → Subgroup → Signal hierarchy collapses into a score, level and action.

03

Verdict

signals[] + risk_score + risk_level + recommended_action return on the same call. Wire-stable shape, every time.

OPT-IN · VERDICTIQ AI

Open the verdict in the VerdictIQ portal and run Enrich with VerdictIQ AI to add a senior-analyst narrative grounded on the same signals[] and evidence[]. The verdict doesn't move; the narrative is layered on top.

Start with one query. Decide in seconds.

Send your first IOC to /enrich. Get the signals, the score, the recommended action and, if you ask, a senior-analyst narrative. The free tier includes VerdictIQ AI, no credit card.

GDPR alignedLLM-free by defaultOwn infrastructureAudit-ready signal trailSOC 2 Type IISub-processors disclosedEU + US data residency