Skip to content

Not Listed in Open-Source Threat Feeds

It indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases. This means no external OSINT provider has associated the domain with any known malicious campaigns or infrastructure.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Not Listed in Open-Source Threat Feeds' mean?

It indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases. This means no external OSINT provider has associated the domain with any known malicious campaigns or infrastructure.

Why it matters02

Does this confirm the domain is safe?

Not necessarily. It simply means the domain has not been reported as malicious by open-source intelligence sources. Newly registered domains or previously inactive domains might not yet be indexed in public feeds, so further contextual analysis is recommended.

How analysts use it03

How should analysts interpret this indicator?

It should be considered a neutral-to-positive signal. While the absence from OSINT feeds suggests the domain is not widely recognized as malicious, analysts should still validate this with internal telemetry, DNS behaviors, and proprietary threat intelligence data.

Evidence shape

What Not Listed in Open-Source Threat Feeds looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "no_malware_sources",
  "name": "Not Listed in Open-Source Threat Feeds",
  "group": "threat_intelligence_feed",
  "subgroup": "vendor_trust",
  "direction": "safe",
  "evidence": {
    "trusted_vendor_count": 14,
    "no_malware_references": true,
    "last_clean_scan_days_ago": 2
  }
}
See in API reference
Siblings

Peers in Vendor Trust

1 other signal shares the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Not Flagged by Any Security Vendor

It means that none of the commercial or open-source security vendors — such as antivirus engines, sandbox platforms, or

SafeCore
In the wild

See Not Listed in Open-Source Threat Feeds fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Not Listed in Open-Source Threat Feeds. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.