Skip to content

Flagged by Limited Security Vendors

It means that one or more commercial security vendors — including antivirus engines, sandboxes, or threat intelligence providers — have classified or reported the domain as malicious. The number of vendors reporting it directly reflects the confidence level of the detection.

Also surfaces as:
Flagged by Several Security VendorsFlagged by Numerous Security VendorsHistorically Flagged by Limited VendorsHistorically Flagged by Several VendorsHistorically Flagged by Numerous Vendors
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Flagged by Security Vendors' mean?

It means that one or more commercial security vendors — including antivirus engines, sandboxes, or threat intelligence providers — have classified or reported the domain as malicious. The number of vendors reporting it directly reflects the confidence level of the detection.

Why it matters02

How should the number of vendors be interpreted?

A domain flagged by a limited number of vendors (1–2) usually represents an early or low-confidence detection. When several (3–5) or numerous (6+) vendors report the same domain, it indicates stronger validation and a high likelihood of confirmed malicious activity.

How analysts use it03

What does 'Historically Flagged' mean?

It shows that the domain appeared in vendor reports in the past but is no longer actively flagged. Such domains may have been cleaned, repurposed, or expired, yet their historical association still contributes to elevated risk scoring in threat intelligence analysis.

Often paired with:block_domain
Evidence shape

What Flagged by Limited Security Vendors looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "security_vendors_malware",
  "name": "Flagged by Limited Security Vendors",
  "group": "threat_intelligence_feed",
  "subgroup": "malware_association",
  "direction": "malicious",
  "evidence": {
    "sources_referencing": 12,
    "malware_families": [
      "emotet",
      "qakbot"
    ],
    "first_reference_days_ago": 11,
    "confidence": 0.91
  }
}
See in API reference
Siblings

Peers in Malware Association

1 other signal shares the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Listed in Malware Feeds (Domain-Level)

It means that the domain has appeared in public or open-source malware intelligence feeds. These feeds collect indicator

MaliciousCore
In the wild

See Flagged by Limited Security Vendors fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Flagged by Limited Security Vendors. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.