Skip to content
Pre-hoc decision verification

Turn raw IOCs into explainable verdicts, in one API call.

Deterministic multi-signal risk scoring for domains, IPs, ASNs, CIDRs, and SHA256. Same input, same score. Every decision auditable down to the evidence; drops into your SIEM/SOAR/EDR stack with one API call.

cdn-xxx-service[.]net
87
Recommended actionblock_domain
Risk Levels
DNS HistoryHigh Risk
HTTP Crawling HistorySuspicious
Threat Intelligence FeedClean
Popularity and BacklinkLow Risk
WhoisCritical

These are summary samples. To see full evidence and run a detailed analysis, run your own query.

Make your own queries
01 · WHAT YOU GET BACK

One call. Three first-class outputs.

Each /enrich response carries three independent artifacts. Signals are Day 0 value; score and action are layered on top. Adopt them in your own order.

01 · signals[]

All signals per IOC

DNS history, WHOIS lifecycle, IP rotation, SSL behavior, popularity, backlinks, threat intel, behavioral patterns, relational infra. Pre-analyzed, labeled, grouped. The analyst's working material: every signal we used to reach the score, returned with it.

87across 6 groups, ms-fresh from our warehouse

Skip the multi-tool pivot. Read the signals you would have hunted for.

02 · risk_score · risk_level

Deterministic risk score

A 0 to 100 number plus a six-tier level (clean / low risk / moderate / suspicious / high risk / critical). Same input, same score, every call. Same score always lands in the same tier, by design.

CleanLow RiskModerateSuspiciousHigh RiskCritical

Trust the score when it matches the signals you would weigh yourself.

03 · recommended_action

SOAR-ready recommended action

block_domain, allow, alert, monitor: the wire-stable verdict your SOAR or EDR playbook reads. Not executed by us; routed by your runbook.

allowmonitoralertblock_domainescalate

Adopt this when score-trust is built. We propose; your playbook decides.

03 · FIRST-PARTY DATA

We own the data. Every signal, every probe, every archive.

VerdictIQ is not an aggregator. We run our own crawl infrastructure: HTTP, DNS, WHOIS, SSL/TLS probes, passive scanning, threat-feed ingestion, backlink graphs, popularity rankings. When you query /enrich, the answer comes from our warehouse, not from a chain of third-party APIs we hope are awake.

Our crawls, our cadence

HTTP, DNS, WHOIS, SSL/TLS: VerdictIQ runs the probes on our own schedule. No external rate limits, no aggregator lag, no methodology opacity.

Years of archived history

Each IOC carries the historical depth of VerdictIQ's own warehouse. Not a single point-in-time fetch: a multi-year trail of how the IOC has behaved over time.

NOT AN AGGREGATOR

Aggregator-style platforms wrap third-party APIs. Their freshness depends on their providers; their methodology changes when the provider's API changes. VerdictIQ owns the pipeline end-to-end: same query, same answer, deterministically.

04 · SCORE HIERARCHY

One number. Four layers down.

The 0–100 score is not opaque. It rolls up from group scores; each group rolls up from subgroup scores; each subgroup is fired by individual signals that carry their own evidence. Drill where you need, ignore where you don't.

Layer 1: Overall risk_score
IOC: cdn-xxx-service[.]net87High Risk
Layer 2: Group scores
DNS History · 80HTTP Crawling History · 60Threat Intelligence Feed · 10Popularity and Backlink · 25Whois · 90

Groups that apply to this IOC type compose the overall score.

Layer 3: Subgroup scores
Domain Lifecycle · 88IP Diversity & Rotation · 62DNS Records (MX/NS) · 28

Each group breaks down into its subgroups (showing DNS History).

Layer 4: Signal + evidence
Newly-Activated Domain

First DNS resolution observed 2026-04-29 (domain registered months earlier with no traffic); SSL provisioned the same day; resolves to an IP shared with 6 IOCs flagged in the last 30 days.

Each subgroup is fired by individual signals; every signal exposes the evidence that produced it.

Same hierarchy on every IOC type. Use what you need; the rest stays in the response for your audit log.

This is the score view. The full signal set is returned alongside; if our scoring methodology doesn't match your risk model, compute your own aggregation on top of the same evidence.

05 · INPUT COVERAGE

One API. Every IOC type your stack throws at it.

Domain, IP, CIDR, ASN, file hash: the call shape stays the same, the verdict shape stays the same. Switch IOC type, your playbook does not.

Domaindomain

Phishing URLs in email security and SIEM alerts.

cdn-xxx-service[.]nethigh · 87block_domain
IPip

Scanner traffic and brute-force in firewall logs and EDR.

185.220.101.45suspicious · 64alert
CIDRcidr

Cloud range reputation in network audit and DLP.

185.220.100.0/22high · 78monitor
ASNasn

Hosting risk profiles in threat hunting and triage.

AS14061moderate · 45monitor
SHA256sha256

File hashes from EDR detonation and file-analysis events.

e3b0c44…critical · 92alert
Write the parser once

One contract drives every endpoint. A new IOC type entering your pipeline does not require a new branch in your SOAR; the response shape is identical to what you already handle.

Audit reads one shape

Every verdict in your evidence log carries the same fields. Reviewer or auditor doesn't switch mental models per IOC type, the format is the contract.

06 · BEHAVIORAL

Score what the IOC does,
not what someone wrote about it.

Behavioral analysis traces what the IOC does across its lifetime: when it was created, where it has lived, where it has moved, and how its infrastructure neighbors behaved. Each event becomes a signal; together, they decide whether the trajectory matches a known malicious pattern. Reputation feeds see only the last hour.

Lifecycle timing

When the IOC first appeared in our telemetry, when it first became active, and the gap between creation and activation. Aged-then-activated reads very differently from created-and-immediate, and the gap shape itself is a signal.

Infrastructure residency

Where the IOC has lived: hosting providers, IP ranges, ASN footprints, file-execution hosts. Long tenancy on a single provider and minute-by-minute churn produce opposite verdicts; we score the duration, not just the address.

Trajectory and rotation

Geo jumps, ASN-to-ASN moves, provider swaps, infrastructure rotation over the IOC's life. Legitimate operators do not cross three continents in a week or hop ASNs every other day; the trajectory is its own tell.

Many signals, one pattern match

Each lifetime event becomes one signal, regardless of IOC type. Fused together, the full trajectory is matched against known malicious-campaign profiles. The score is the goodness of fit, computed live every call, not a feed lookup.

Reputation says 'someone reported it.'
Behavior says 'this one is about to act malicious, watch it.'
07 · DETERMINISM

Same evidence in, same score out.
Computed live, every call.

Two axes, kept separate. The scoring function is fixed by version: identical evidence produces an identical score, replayable in audit. Evidence itself is computed live from current DNS, HTTP, WHOIS, CTI, popularity and relational telemetry, so a score can change between queries, but only when a specific signal changed, and you can see which one.

Live evidence, every call

Every query recomputes the input set from current telemetry; no last_scanned timestamp, no cached verdict reuse. The score reflects what we know today, not last week's snapshot. If the world moved, the score moves with it.

Deterministic scoring function

Weights are pinned per release. Replay the same evidence and you get the same score, every analyst, every audit. The evidence itself is reproducible because the data is ours, not pulled fresh from third-party APIs.

Every score shows its work

When the same IOC scores 23 today and 87 next week, the response itself is the explanation: every signal that fired, every evidence string, in the call that returned the new number. Diff the two responses and the delta is the story; we never return a number without showing how it got there.

10 · NEAR THIS

One more endpoint, same scoring engine.

/enrich handles one IOC at a time. When you have a list to replay, use the bulk endpoint. Same scoring logic, same response shape per item.

Start with one query. Decide in seconds.

Hit /enrich with a domain or an IP. Get a verdict, the evidence behind it, and a recommended action. Same response shape every time.

GDPR alignedLLM-free by defaultOwn infrastructureAudit-ready signal trail
See our security posture