Data Quality

SOC-ready evidence, not just a score

Each IOC verdict now exposes source agreement, data freshness, reliability weighting, contradictory signals, and a recommended analyst action.

The public JSON includes current source reliability, blocklist freshness, warning counts, and recent source-health history once the production cron has run.

569
Configured Sources
568
Verified Feeds
44
High Reliability
120
Noise-aware Feeds

What visitors can verify

Data quality should be easy to inspect without reading an implementation guide. These checks translate the registry and source-health history into plain-language proof.

Fresh means recent enough to trust

The registry separates current source state from historical snapshots so visitors can see whether feeds are healthy now and whether that health is stable over time.

Reliability is weighted, not counted blindly

A single authoritative provider can matter more than many noisy contextual lists, which helps avoid overreacting to ads, trackers, or privacy blocklists.

Evidence explains the action

Every SOC-ready verdict is designed to answer: what did we see, which sources agree, what conflicts exist, and should an analyst allow, monitor, review, escalate, or block?

Source Reliability

Every feed is weighted by provider quality so authoritative detections outweigh noisy contextual blocklists.

Provider Agreement

Scanner, blocklist, OTX, WHOIS, certificate, and infrastructure signals are cross-checked for agreement or conflict.

Freshness

Responses include observed time, last update, first seen, last seen, and stale-data warnings when available.

Analyst Evidence

API and bulk outputs expose reasons, contradictory signals, confidence, and recommended SOC action.

Verified Source Registry

A compact view of the highest-weighted feeds used by the scoring and evidence pipeline.

Scoring methodology

summary

Totals and warning counts for a quick health read.

sources

Configured providers with reliability and noise profile.

blocklists

Feed freshness, record counts, and stale or empty warnings.

history

Recent cron snapshots once production has recorded them.

SourceTypeCategoryReliabilityNoise Profile
Feodo Tracker - Botnet C2 IPsipc20.98low
MITRE ATT&CK Enterprise STIXmitrethreat-context0.98low
AbuseIPDB - IP Blacklistipabuse0.98medium
VulnCheck - Vulnerability Intelligencecvevulnerability0.98low
MalwareBazaar - Recent SHA-256 Hasheshashmalware0.98low
MalwareBazaar - Recent MD5 Hasheshashmalware0.98low
DigitalSide-IT OSINT - Latest Malicious Domainsdomainmalware0.98low
DigitalSide-IT OSINT - Latest Malicious IPsipmalware0.98low
DigitalSide-IT OSINT - Latest Malicious URLsurlmalware0.98low
DigitalSide-IT OSINT - Latest Malware SHA-256hashmalware0.98low
Phishing.Database - Active Phishing Domainsdomainphishing0.98low
duggytuxy - Ransomware IP Addressesipransomware0.98low