Risk signals on every agent destination
Categories, your feeds, and the rank of every name.
Threat data, reputation and your own feeds, enforced at resolution in seconds.
| Timestamp | Action | Site | Query Name | Source IP | Reason |
|---|---|---|---|---|---|
| 2026-09-15 16:10:02 | threat | corp-office | update-check.pw | 10.1.9.14 | feed: isac-indicators |
| 2026-09-15 16:10:31 | threat | build-agent | pkg-mirror-cdn.top | 10.40.8.2 | feed: supply-chain-iocs |
| 2026-09-15 16:11:05 | block | corp-office | sinkholed-c2.net | 10.1.9.14 | category: sinkhole |
| 2026-09-15 16:12:40 | threat | corp-office | exfil-data.click | 10.1.9.14 | push: SOAR-4412 |
A destination is more than a name
Whether a lookup should answer depends on what is known about the name: its category, whether a feed lists it, and how established it is. The resolver has all three at the moment of the decision, and records them on the event.
Categories
Malware, C2, Porn, Parked and Sinkhole, maintained continuously. Public DoH providers as a blockable category.
Feeds
Your vendors, your ISAC, your research. Four formats, pulled on a schedule, with per-entry expiry.
Rank
Establishment rank on every event. A first-seen name with no rank is the review to do first.
Three signals, one decision
Enable the categories
All five security categories and the DoH provider category on every policy.
Register the feeds
URL, format, schedule and the list it populates. The feed.polled webhook reports each pull.
Read the rank
Filter Traffic Logs on rank and first-seen. Sort the review queue by what has never been seen anywhere.
Intelligence capabilities
Security categories
Five categories, served to the console from the API, applied per policy.
Feed ingestion
STIX, CSV, TXT and JSON. One feed per list, scheduled, with added and retired counts per pull.
Push API
Verdicts from the SOAR with confidence, expiry and a case reference.
Establishment rank
dns_q.rank on every event, filterable in Traffic Logs and exportable.
Answer enrichment
ASN, AS name and country of the resolved address on every event.
Network categories
Bulletproof hosting ranges and anonymizer infrastructure blocked by resolved address.
What the decision recorded
Category, feed reason, rank and the enriched answer travel with every event to the SIEM.
dns_q.name update-check.pw
action threat
reason feed: isac-indicators
dns_q.categories [c2]
dns_q.rank 0
dns_a_ip.as AS208843
dns_a_ip.country NLQuestions teams ask
Where do the categories come from?
Maintained by Securd from customer reports, partner threat intelligence and proprietary detection, published to the resolvers continuously.
Can I see why a name was blocked?
The reason field names the list, category, feed or push reference on every block and threat event.
Is rank a reputation score?
No. It is establishment: how widely and how long the domain has been observed. Zero means never.
Enforce your first feed today
Register one feed URL and watch the threat events arrive.