A domain claiming to be a known vendor service but absent from every major vendor allow-list it should belong to.
“Decline. Real vendor services accumulate trust signals across providers; the absence here suggests impersonation.”
Vendor-trust feeds: large vendor allow-lists, certified safe lists. Each fires with named evidence and a 3-question analyst Q&A trail.
Vendor-trust feeds: large vendor allow-lists, certified safe lists. Tier-1 SOC analysts use them to cut triage time on suspicious threat intelligence feed behavior; CTI teams pivot from them to the broader campaign graph.
Each row opens a leaf page with the signal's direction, named evidence, and 3-question Q&A trail. Use them as audit anchors when a verdict surfaces this subgroup.
Three real-world situations where Vendor Trust evidence dominates the decision. Verdict and explanation are how VerdictIQ would frame the outcome to an analyst, not raw signal slugs.
4 more subgroups in this group, each bundling signals that share a different mechanism. Tap one to inspect its signal names.
Free tier: 100 IOCs/day, LLM layer included.