A domain cited by multiple feeds as a malware C2 endpoint in the last 30 days.
“Decline. Active malware association is the strongest single block signal. Treat as hostile until the attribution clears.”
Association with malware C2, payload delivery, sample distribution. Each fires with named evidence and a 3-question analyst Q&A trail.
Association with malware C2, payload delivery, sample distribution. Tier-1 SOC analysts use them to cut triage time on suspicious threat intelligence feed behavior; CTI teams pivot from them to the broader campaign graph.
Each row opens a leaf page with the signal's direction, named evidence, and 3-question Q&A trail. Use them as audit anchors when a verdict surfaces this subgroup.
Three real-world situations where Malware Association evidence dominates the decision. Verdict and explanation are how VerdictIQ would frame the outcome to an analyst, not raw signal slugs.
4 more subgroups in this group, each bundling signals that share a different mechanism. Tap one to inspect its signal names.
Free tier: 100 IOCs/day, LLM layer included.