A domain present on multiple fraud-abuse feeds in the last 14 days, with at least one citing brand impersonation.
“Decline. Multiple recent fraud feeds converging on the same asset is high-confidence external signal. Block until the feeds clear it.”
Fraud and abuse-feed presence: phishing, scam, fake-shop, brand-impersonation. Each fires with named evidence and a 3-question analyst Q&A trail.
Fraud and abuse-feed presence: phishing, scam, fake-shop, brand-impersonation. Tier-1 SOC analysts use them to cut triage time on suspicious threat intelligence feed behavior; CTI teams pivot from them to the broader campaign graph.
Each row opens a leaf page with the signal's direction, named evidence, and 3-question Q&A trail. Use them as audit anchors when a verdict surfaces this subgroup.
Three real-world situations where Fraud & Abuse evidence dominates the decision. Verdict and explanation are how VerdictIQ would frame the outcome to an analyst, not raw signal slugs.
4 more subgroups in this group, each bundling signals that share a different mechanism. Tap one to inspect its signal names.
Free tier: 100 IOCs/day, LLM layer included.