Grounded on your own response
The narrative cites the same signals[] and evidence[] that produced the verdict. No external lookup, no hallucinated context, no model speculation.
01 · WHAT IT DOES
One call returns the verdict, the evidence behind it, and the recommended action. Tier 1 ships decisions in seconds, no investigation queue, no senior-analyst escalation per IOC.
VerdictIQ AI reads each verdict and its signals, then ships a write-up your most senior analyst would defend. Opt-in inside the VerdictIQ portal, per verdict. The verdict path stays deterministic; AI only narrates what already fired. The AI layer uses an internally-managed model; sub-processor list at /trust#ai-subprocessors.
The narrative cites the same signals[] and evidence[] that produced the verdict. No external lookup, no hallucinated context, no model speculation.
risk_score, risk_level and recommended_action don't move when AI is on. Same input still produces the same verdict; the narrative is layered on top.
Open a verdict in the VerdictIQ portal and run Enrich with VerdictIQ AI. On-demand only; stateless, nothing about the verdict is retained for model training.
Maestro is your VerdictIQ guide on this site. Ask anything about the product, how scoring works, integrations, pricing, or how we compare to feeds and TIPs. Answers are grounded on our docs and product knowledge, not scripted bots.
Domains are infinite. Adversary patterns are finite, and statistically repeatable. Our behavioral signals fire on infrastructure shape, not on feed coverage.
Gap between registration and activation; dormant-then-active fingerprint.
Fast-flux, round-robin and geo-rotation patterns.
Co-tenancy with known-malicious; cloud vs dedicated profile.
Unexpected age combined with activity bursts.
Graph-level proximity to known campaign nodes.
Shared signals with other malicious nodes in the same window.
Sat dormant for six months. Most reputation feeds: clean.
IP assigned, free SSL provisioned, lands on a host with 6 known-malicious neighbors.
VerdictIQ ships block_domain · 87 the moment infrastructure goes live, before the first phishing email or malicious request leaves the host. Reputation feeds: still clean. (illustrative)
Forensic tools tell you what was malicious. The SOC needs to know what to do with traffic landing right now. The verdict ships before the IOC fires, not as a report after it.
“Is this domain truly malicious? Prove it.”
“Should I pass, block or escalate this right now?”
If your workflow needs payload analysis or campaign forensics, pair VerdictIQ with payload-analysis or threat-hunting tooling. We trigger the action; we don't reproduce the payload.
A wire-stable enum your playbook reads without parsing. No per-vendor mapping, no glue code, no analyst tap to route.
recommended_action returns one of four values. Your playbook switches on four cases, not a regex parser.
Single IOC or batch: the same recommended_action field with the same four values.
The engine picks the action. The playbook executes it. No analyst interpretation between them.
No model temperature. No last_scanned lag. No silent rescore after a vendor update. The verdict is a function of the signals, recomputed against today's warehouse on every call.
Each call recomputes against today's DNS, HTTP, WHOIS, CTI and relational signals. No cached verdict reuse, no batch refresh window.
Same IOC, same signals, same score. Analyst A and analyst B querying the same IOC reach the same call, and so does audit, six months later.
Black-box scores fail when someone asks why. Every VerdictIQ verdict carries the signals that fired, the evidence behind each one, and a prepared answer to the analyst's most likely question.
Every verdict opens to the signals that actually fired against the IOC. Your analyst reads what drove the score, not just how high it landed.
Each signal carries the telemetry that triggered it. No follow-up tickets to data engineering, no screenshot collection, the trail ships with the verdict.
A prepared Q&A pair sits next to each verdict. Tier 1 closes the ticket without paging a senior analyst at 3 a.m.
Our warehouse runs DNS probes, HTTP crawls, WHOIS lineage, popularity graphs, threat-intel ingestion and relational fusion on a schedule we control. By the time /enrich returns, the signals are already fused into a verdict.
Single POST /enrich request enters the engine. Signals fuse, score lands, action is selected, all in the same response. The "understand" depth (Q&A and VerdictIQ AI narrative) is opt-in on the same call, not a second trip.
One HTTPS POST. domain · ip · cidr · asn · sha256: pick the IOC type, payload is one field.
All signals fuse against today's warehouse. Group → Subgroup → Signal hierarchy collapses into a score, level and action.
signals[] + risk_score + risk_level + recommended_action return on the same call. Wire-stable shape, every time.
Open the verdict in the VerdictIQ portal and run Enrich with VerdictIQ AI to add a senior-analyst narrative grounded on the same signals[] and evidence[]. The verdict doesn't move; the narrative is layered on top.
Send your first IOC to /enrich. Get the signals, the score, the recommended action and, if you ask, a senior-analyst narrative. The free tier includes VerdictIQ AI, no credit card.