211 named signals behind every verdict.
Every VerdictIQ verdict is built from named, evidence-backed signals. Browse the taxonomy, see what each one detects, and read the analyst Q&A behind it.
- 211 signals · 26 subgroups · 6 groups
- Live recalculation per IOC, not a static feed
- Every signal carries evidence + Q&A explanation
Signal Group → Subgroup → Signal → Evidence → Q&A
Five layers in order. Three structural (group, subgroup, signal) drill down into each other. The last two ride along with every fired signal so analysts never get a score without the reasoning.
Signal Group
Top-level data domains we model: DNS, HTTP, WHOIS, popularity, relational, threat feed.
Signal Subgroup
Behavioral families inside each group, e.g. Domain Lifecycle, SSL Behavior, IP Diversity.
Signal
What actually fires when the engine sees a pattern, e.g. Newly-Activated Domain.
Evidence
Structured payload attached to every fired signal: raw values, timestamps, source fields.
Q&A
Three analyst-grade questions per signal: what it detects, why it matters, how to use it.
Six top-level signal groups · 211 signals
Each group is a data domain we model. Tap a group to reveal its signals; each name links to its leaf page.
- ASN Domain Flagged By Security Vendors
- Low-Control General Hosting Network
- Malicious Infrastructure Observed in ASN
- ASN Domain Algorithmic Naming Pattern
- ASN Domain Low Popularity
- ASN Domain Newly Registered
- ASN Domain Short Uptime
- Geolocation Mismatch or High-Risk Region
- High-Risk TLD Usage Observed in ASN
- Newly Allocated ASN Lifecycle
- Risky Domain Behavior Observed in ASN
- ASN Allocated Long Time Ago
- Major Cloud or CDN Infrastructure
- Strict-Policy RIR Region
- Double-Flux Behavior Detected
- Self-Managed Mail Infrastructure Detected
- Free or Disposable Mail Service Used
- Mail-Flux Behavior Detected
- Self-Managed Name Server Detected
- Paid Mail Service Detected
- Paid Public NS Usage Premium Provider
- Stable MX Usage Long Term
- Stable NS Usage Long Term
- Reputation Hijacked Domain
- Newly-Activated Domain
- Newly-Activated Subdomain
- Newly-Associated IP
- Subdomain-Only Active Domain
- Extensive Subdomain Infrastructure Detected
- Multi-IP Infrastructure Detected
- Centralized IP-Subdomain Infrastructure Detected
- Current and Historical Geolocation Divergence
- Fake EU Membership Flag
- Geolocation Alignment Conflict
- Small-Scale Multi-Country IP Dispersion
- Country-Level IP Geolocation Centralization
- Current and Historical Geolocation Alignment
- EU Compliance Location
- Large-Scale Multi-Country IP Distribution
- Observed and Registered Geolocation Consistency
- Single DC Hub Footprint
- Large-Scale Enterprise IP Block
- Assigned IP Block
- IP Block Recently Allocated
- Small Allocation Abuse Pattern
- Small IP Block Allocation
- Registry–Geo CIDR Full Match
- Dedicated Hosting Detected
- Long IP Lifespan
- Long-Lived Active Domain
- Dead Domain
- DNS A Record Resolves to Private IP
- Newly-Activated Domain
- Non-Stable Domain
- Short IP Lifespan
- Long-lived HTTP Service Detected
- Inactive HTTP Service Detected (Base Domain)
- Newly Active HTTP Service Detected
- Non-Public Domain
- Unstable or Intermittent HTTP Service Detected
- Multi-Page Web Infrastructure
- Default Web Page Detected
- Limited Web Structure Detected
- Low Content Density (Homepage)
- Content-Rich Homepage
- Critical SSL Certificate Authentication Failure
- Invalid Hostname Validation (CN/SAN Mismatch)
- Self-Signed SSL Certificate Detected
- Untrusted Certificate Authority (CA) Detected
- Untrusted or Misconfigured SSL Certificate
- Organization-Validated (OV) SSL Certificate Detected
- Valid Hostname Validation (CN/SAN Match)
- Free-Issued SSL Certificate
- Newly-Issued SSL Certificate
- No SSL Encryption Detected
- Short-Term SSL Certificate Validity
- Long-Term SSL Certificate Validity
- OCSP-Stapled SSL Certificate Detected
- Private Certificate Authority (CA) Signed SSL Detected
- Valid SSL Certificate Authentication
- Valid SSL Certificate from Recognized CA
- Tracker ID Reuse
- Active Web Defense Mechanisms Detected
- Commercial Tech Stack Detected
- E-Commerce Platform Detected
- Payment Gateway Detected
- Web Technology Stack Detected
- Injected Iframe
- Malicious Redirect Behavior
- Direct Connection to an IP Address
- HTTP Service on Non-standard Port
- JavaScript-based Redirect
- Malicious Activity Observed During Browser Interaction
- Suspicious Auto Page Refresh Activity
- URL Shortener Detected
- Trusted Brand Domain
- High-Reputation Domain
- Weak Popularity Domain
- Regionally Trusted Domain
- Reputation Decay Domain
- Gradual Popularity Growth Domain
- Managed by an Attacker Group
- Fast-Flux Behavior Detected
- Highly Shared IP
- Low Popularity Public NS Usage Rare Provider
- Active Association with Malicious Domain
- Malicious External Link
- High Number of Inbound Links
- High DGA Score Detected
- Brand-Impersonating Domain Detected
- High-Risk TLD Zone Detected
- Previously Risky Category Detected
- Fast Emerging Blacklist IP
- High-Risk Blacklist Sources
- IP Blacklisted Recently (High Freshness)
- Multi Group Blacklist Match
- Flagged by Limited Security Vendors
- Listed in Malware Feeds (Domain-Level)
- Not Flagged by Any Security Vendor
- Not Listed in Open-Source Threat Feeds
- Registered for 10+ Years
- Registered in Last Week
- WHOIS-Based Reputation-Hijacked (Inactive) Domain
- Domain Ownership Transition in Last Month
- WHOIS Record Updated in Last Week
- Trusted Registrar (WHOIS-Based)
What a signal entry looks like
Every leaf page follows the same shape. Display name, direction, a short Q&A, evidence sample, and analyst guidance.
Newly-Activated Domain
Signals analysts ask about most.
Six entries from the catalog analysts reach for first, across DNS history, NS posture, relational infra, threat intel, WHOIS and brand authority.
It indicates that the domain has recently become active for the first time, either by starting to resolve in DNS or by responding to network…
It indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers. This often aligns with …
It indicates that a single IP address is used by a significantly large number of domains. This assessment is based on a statistically derive…
It means that the domain has appeared in public or open-source malware intelligence feeds. These feeds collect indicators of compromise (IOC…
It indicates that the domain was registered very recently — within the last week, month, or few months. Newly registered domains are frequen…
It represents a domain that belongs to a globally recognized and reputable organization. These domains are considered highly trustworthy due…
From taxonomy to live verdicts
See these signals fire on real IOCs, or wire them into your stack.
See these signals on your own IOCs
Free tier: 100 IOCs/day, LLM layer included. No card.