← Platform

Risk signals on every agent destination

Categories, your feeds, and the rank of every name.

Threat data, reputation and your own feeds, enforced at resolution in seconds.

control.securd.com/gateway/acme/logs
Traffic Logs action: threat
TimestampActionSiteQuery NameSource IPReason
2026-09-15 16:10:02threatcorp-officeupdate-check.pw10.1.9.14feed: isac-indicators
2026-09-15 16:10:31threatbuild-agentpkg-mirror-cdn.top10.40.8.2feed: supply-chain-iocs
2026-09-15 16:11:05blockcorp-officesinkholed-c2.net10.1.9.14category: sinkhole
2026-09-15 16:12:40threatcorp-officeexfil-data.click10.1.9.14push: SOAR-4412
Every threat event names the category, feed or push that produced it.
The problem

A destination is more than a name

Whether a lookup should answer depends on what is known about the name: its category, whether a feed lists it, and how established it is. The resolver has all three at the moment of the decision, and records them on the event.

Categories

Malware, C2, Porn, Parked and Sinkhole, maintained continuously. Public DoH providers as a blockable category.

Feeds

Your vendors, your ISAC, your research. Four formats, pulled on a schedule, with per-entry expiry.

Rank

Establishment rank on every event. A first-seen name with no rank is the review to do first.

How it works

Three signals, one decision

Capabilities

Intelligence capabilities

Security categories

Five categories, served to the console from the API, applied per policy.

Feed ingestion

STIX, CSV, TXT and JSON. One feed per list, scheduled, with added and retired counts per pull.

Push API

Verdicts from the SOAR with confidence, expiry and a case reference.

Establishment rank

dns_q.rank on every event, filterable in Traffic Logs and exportable.

Answer enrichment

ASN, AS name and country of the resolved address on every event.

Network categories

Bulletproof hosting ranges and anonymizer infrastructure blocked by resolved address.

Event fields

What the decision recorded

Category, feed reason, rank and the enriched answer travel with every event to the SIEM.

event
dns_q.name         update-check.pw
action             threat
reason             feed: isac-indicators
dns_q.categories   [c2]
dns_q.rank         0
dns_a_ip.as        AS208843
dns_a_ip.country   NL

Questions teams ask

Where do the categories come from?

Maintained by Securd from customer reports, partner threat intelligence and proprietary detection, published to the resolvers continuously.

Can I see why a name was blocked?

The reason field names the list, category, feed or push reference on every block and threat event.

Is rank a reputation score?

No. It is establishment: how widely and how long the domain has been observed. Zero means never.

Enforce your first feed today

Register one feed URL and watch the threat events arrive.