Skip to content
Signal Library

211 named signals behind every verdict.

Every VerdictIQ verdict is built from named, evidence-backed signals. Browse the taxonomy, see what each one detects, and read the analyst Q&A behind it.

  • 211 signals · 26 subgroups · 6 groups
  • Live recalculation per IOC, not a static feed
  • Every signal carries evidence + Q&A explanation
Architecture

Signal Group → Subgroup → Signal → Evidence → Q&A

Five layers in order. Three structural (group, subgroup, signal) drill down into each other. The last two ride along with every fired signal so analysts never get a score without the reasoning.

  1. Structural6 categories

    Signal Group

    Top-level data domains we model: DNS, HTTP, WHOIS, popularity, relational, threat feed.

  2. Structural26 families

    Signal Subgroup

    Behavioral families inside each group, e.g. Domain Lifecycle, SSL Behavior, IP Diversity.

  3. Structural211 named

    Signal

    What actually fires when the engine sees a pattern, e.g. Newly-Activated Domain.

  4. Attachedobject payload

    Evidence

    Structured payload attached to every fired signal: raw values, timestamps, source fields.

  5. Attached3 per signal

    Q&A

    Three analyst-grade questions per signal: what it detects, why it matters, how to use it.

The 6 groups

Six top-level signal groups · 211 signals

Each group is a data domain we model. Tap a group to reveal its signals; each name links to its leaf page.

See group detail
See group detail
See group detail
See group detail
See group detail
See group detail
Anatomy

What a signal entry looks like

Every leaf page follows the same shape. Display name, direction, a short Q&A, evidence sample, and analyst guidance.

DNS History/Domain Lifecycle

Newly-Activated Domain

MaliciousSupport
What does 'Newly-Activated Domain' mean in DNS-layer or SOC analysis?
It indicates that the domain has recently become active for the first time, either by starting to resolve in DNS or by responding to network probes. This behavior is common in newly registered or reactivated malicious domains, which threat actors often deploy shortly before launching attacks.
Why is the activation timing of a domain important for analysts?
Because newly activated domains often precede phishing, malware distribution, or command-and-control operations. Monitoring domain activation recency helps analysts detect emerging threats before they gain reputation or traffic volume.
Can legitimate domains also appear as newly activated?
Yes, legitimate organizations may launch new services or migrate infrastructure, causing domains to appear newly active. Analysts should cross-check WHOIS registration time, SSL issuance date, and reputation data to distinguish between benign and malicious activations.
Open the full signal page
Keep exploring

From taxonomy to live verdicts

See these signals fire on real IOCs, or wire them into your stack.

Verdict Gallery

Curated real-IOC verdicts. See which signals fire together in the wild.

IOC Enrichment

The product surface where these signals are returned.

Decision Verification

Replay yesterday's queue and see which signals would have changed the call.

See these signals on your own IOCs

Free tier: 100 IOCs/day, LLM layer included. No card.