Skip to content

HTTP Crawling History

TLS posture, response anomalies, page templates, and tech-stack fingerprints captured when we crawl the asset. Each signal cites the certificate fact, header anomaly, or template hash that triggered it.

  • 40 named signals across 5 subgroups
  • Recomputed live per IOC, not pulled from a static feed
  • Every signal ships with evidence + 3-question Q&A trail
About

What HTTP Crawling History models

Captures the TLS, response, and content fingerprints observed when VerdictIQ crawls the asset.

What it models
Captures the TLS, response, and content fingerprints observed when VerdictIQ crawls the asset.
How it fires
Each signal cites the certificate fact, header anomaly, page template, or stack fingerprint that triggered it; diffable across crawl snapshots.
Why it matters
Surfaces parked-then-armed pages, short-cert phishing kits, and copycat templates that DNS-only context would miss.
Subgroups

5 subgroups · 40 signals in HTTP Crawling History

Each subgroup bundles signals that share a mechanism: same evidence shape, same direction logic. Tap one to inspect its signal names; every name opens a leaf page with the underlying Q&A trail.

See subgroup detail
See subgroup detail
See subgroup detail
See subgroup detail
See subgroup detail
Verdict scenarios

How HTTP Crawling History shapes the call

Three real-world situations where this group's evidence dominates the decision. The verdict and explanation are how VerdictIQ would frame the outcome to an analyst, not raw signal slugs.

High riskVERDICT · BLOCK
The situation

A domain serving a self-signed TLS certificate issued yesterday, returning a near-empty homepage that mimics a known bank's login template.

VerdictIQ explains

Decline this domain. The web layer shows three classic phishing tells: throwaway certificate, almost-no real content, and a stolen-template fingerprint. Treat the asset as hostile until the certificate and template fingerprints diverge from the impersonated brand.

Medium riskVERDICT · REVIEW
The situation

A site with a valid commercial CA certificate but inconsistent HTTP availability, frequent server header changes, and a thin tech stack.

VerdictIQ explains

Send to analyst review. The TLS posture is acceptable, but the response volatility and shifting server fingerprints suggest infrastructure under active reconfiguration. Likely benign migration; possibly staging for an attack; analyst eyes warranted.

Low riskVERDICT · ALLOW
The situation

A site on a long-validity OV certificate, stable response headers across months, and a tech stack consistent with its claimed business category.

VerdictIQ explains

Allow. The web crawl evidence is steady and coherent: real organization-validated certificate, mature stack, and predictable response behavior. Standard production property.

See HTTP Crawling History signals fire on your data

Free tier: 100 IOCs/day, LLM layer included.