Skip to main content
Data Quality

SOC-ready evidence, not just a score

Each IOC verdict now exposes source agreement, data freshness, reliability weighting, contradictory signals, and a recommended analyst action.

The public JSON includes current source reliability, blocklist freshness, warning counts, and recent source-health history once the production cron has run.

1014
Configured Sources
839
Verified Feeds
497
High Reliability
444
Noise-aware Feeds
Verifiable

What visitors can verify

Data quality should be easy to inspect without reading an implementation guide. These checks translate the registry and source-health history into plain-language proof.

Fresh means recent enough to trust

The registry separates current source state from historical snapshots so visitors can see whether feeds are healthy now and whether that health is stable over time.

Reliability is weighted, not counted blindly

A single authoritative provider can matter more than many noisy contextual lists, which helps avoid overreacting to ads, trackers, or privacy blocklists.

Evidence explains the action

Every SOC-ready verdict is designed to answer: what did we see, which sources agree, what conflicts exist, and should an analyst allow, monitor, review, escalate, or block?

Source Reliability

Every feed is weighted by provider quality so authoritative detections outweigh noisy contextual blocklists.

Provider Agreement

Scanner, blocklist, OTX, WHOIS, certificate, and infrastructure signals are cross-checked for agreement or conflict.

Freshness

Responses include observed time, last update, first seen, last seen, and stale-data warnings when available.

Analyst Evidence

API and bulk outputs expose reasons, contradictory signals, confidence, and recommended SOC action.

Verified Source Registry

A compact view of the highest-weighted feeds used by the scoring and evidence pipeline.

Scoring methodology

summary

Totals and warning counts for a quick health read.

sources

Configured providers with reliability and noise profile.

blocklists

Feed freshness, record counts, and stale or empty warnings.

history

Recent cron snapshots once production has recorded them.

SourceTypeCategoryReliabilityNoise Profile
FireHOL - Et Spamhausipattack0.98Alow
FireHOL - Feodo Badipsipmalware0.98Alow
FireHOL - Iblocklist Spamhaus Dropipattack0.98Alow
FireHOL - Spamhaus Dropipmalware0.98Alow
FireHOL - Spamhaus Edropipmalware0.98Alow
Alienvault Reputation Genericipmalware0.98Alow
Bambenek DGA Feed Highdomainmalware0.98Alow
Threatview C2 Hunt Feedmixedc20.98Alow
URLhaus MISPmixedmalware0.98Alow
URLhaus Host Filedomainmalware0.98Alow
Feodo Tracker (Abuse.ch)ipmalware0.98Alow
Malware-Filter - URLhaus Domainsdomainmalware0.98Alow