Back to News · Walkthrough

·Walkthrough

How to read a verdict

A two-minute tour of what you're looking at when you open an indicator — score, evidence, confidence, and what to do next.

A confidence gauge with a marked band.

Start by looking up an indicator: an IP, a domain, or a file hash. Within a moment you'll have a verdict — a severity from low to critical, with a confidence band around it. The band matters as much as the number. A tight band means the evidence is strong and consistent; a wide one means treat it with more care.

Below the score is the evidence. Each row is a claim from a source, with how much that source is trusted and when it was observed. Vendor reputation, community reports, internal telemetry — they're weighted differently on purpose, and you can see the weighting instead of guessing at it.

Watch for two things. First, whether the sources agree: a verdict built on one loud source reads differently than one where several independent sources line up. Second, completeness — if the picture is thin, the platform says so instead of pretending the score is airtight.

If the indicator has been seen in your environment, that's called out separately, because a known-bad that touched your network is a different priority than one that's only bad in the abstract. And if it slipped past a control, it rises higher still.

From there, the action is yours. The platform gives you the decision and the evidence; you decide whether to block, watch, or move on. Whatever you choose is recorded with the verdict, so the next person can see how the call was made.

  • The confidence band tells you how much to trust the score, not just the score.
  • Evidence is weighted by source and recency, and the weighting is visible.
  • Seen-in-your-environment and control-bypass are called out separately.

Open a lookupOpen the platform