Skip to content

Long-lived HTTP Service Detected

This term refers to a web service (HTTP/HTTPS) that has been continuously active and reachable for a long duration without significant downtime. In SOC analysis, such long-lived HTTP services are typically associated with legitimate, well-maintained infrastructures, such as business websites, content delivery networks (CDNs), or long-established online platforms.

Also surfaces as:
Very Long-lived HTTP Service Detected
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Long-lived HTTP Service Detected' mean in SOC or web analysis?

This term refers to a web service (HTTP/HTTPS) that has been continuously active and reachable for a long duration without significant downtime. In SOC analysis, such long-lived HTTP services are typically associated with legitimate, well-maintained infrastructures, such as business websites, content delivery networks (CDNs), or long-established online platforms.

Why it matters02

How is 'Long-lived HTTP Service' evaluated from a cybersecurity perspective?

From a defensive or threat-hunting perspective, a long-lived HTTP service generally represents stability and lower risk. Malicious domains used in phishing, C2 communication, or exploit campaigns tend to have a short lifespan due to takedowns and reputation-based blocking. Therefore, sustained uptime over months or years is often viewed as an indicator of trustworthiness, though continuous monitoring is still recommended.

How analysts use it03

What does 'Very Long-lived HTTP Service Detected' indicate in SOC terminology?

In SOC and threat intelligence contexts, 'Very Long-lived HTTP Service' refers to domains that have been operational for an exceptionally extended period—often multiple years—without significant configuration or IP changes. Such persistence typically aligns with legitimate enterprise infrastructure, but may also describe legacy or abandoned services that could become targets for future compromise.

Evidence shape

What Long-lived HTTP Service Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "http_long_time_up_and_running",
  "name": "Long-lived HTTP Service Detected",
  "group": "http_crawling_history",
  "subgroup": "http_availability_stability",
  "direction": "safe",
  "evidence": {
    "uptime_30d_pct": 99.4,
    "status_code_mode": 200,
    "intermittent_failures_30d": 2,
    "last_unreachable_days_ago": 14
  }
}
See in API reference
Siblings

Peers in HTTP Availability & Stability

4 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Newly Active HTTP Service Detected

It indicates that the domain has recently started serving web content over HTTP or HTTPS after a long period of inactivi

Malicious
Inactive HTTP Service Detected (Base Domain)

It indicates that the base domain’s web service (HTTP/HTTPS) is no longer responding or has gone offline. This behavior

Malicious
Non-Public Domain

It refers to a domain that operates with restricted accessibility — its HTTP/HTTPS services are either protected, limite

Malicious
Unstable or Intermittent HTTP Service Detected

It refers to a domain whose HTTP or HTTPS service repeatedly switches between being online and offline within short time

Malicious
In the wild

See Long-lived HTTP Service Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Long-lived HTTP Service Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.