Methodology
How we count
Every number in “By the numbers” on the homepage is a real aggregate from the platform. This page says what each one counts, over what window, how fresh it is, and what it leaves out. Customer data is never used in these numbers.
How these numbers are produced
- Live where possible. The page fetches current figures when you open it. If that fails, it shows the figures from the last site build, labelled as a snapshot with its date.
- Rounded down, never up. Figures shown with a plus sign are floored, so we don't overstate.
- Aggregates only. Nothing here names a customer, a brand we monitor for a customer, or a data source.
If the live figure can't be fetched, the page shows the snapshot taken when the site was last built, and says so.
Threats tracked
- What it counts
- Every distinct malicious indicator we have recorded: phishing and malware domains and URLs, command-and-control and other malicious addresses, and typosquatted domains. Each indicator is counted once, however many sources report it.
- Time window
- Since launch (all time).
- How often it refreshes
- Each page view, cached for up to 5 minutes.
- What it excludes
- Customer-reported material and anything from a customer's private data. Those are never added to the public count.
Threats by type
- What it counts
- The same indicators, split by what they are. Scanning hosts and malicious IP addresses are shown together as “Infrastructure signals” because they describe infrastructure rather than an attack on a brand. Percentages are each type's share of the classified threats shown, so they will not match the headline total exactly.
- Time window
- Since launch (all time).
- How often it refreshes
- Each page view, cached for up to 5 minutes.
- What it excludes
- Types with fewer than 1,000 indicators are left off the chart, and unclassified indicators have no bar. The hidden-table view lists every bar's exact count.
New today
- What it counts
- Indicators added across every source since 00:00 UTC on the current day.
- Time window
- The current UTC day, so it resets at midnight UTC and is not a rolling 24 hours.
- How often it refreshes
- Each page view, cached for up to 5 minutes.
- What it excludes
- Re-sightings of indicators we already track. Only new additions count.
Active operations
- What it counts
- Groups of threats we link together because they share hosting, certificates or registration patterns. A multi-part operator counts once, however many kinds of infrastructure link its threats.
- Time window
- Operations with activity in the last 30 days.
- How often it refreshes
- Each page view, cached for up to an hour.
- What it excludes
- Operations with no activity in the window, and single threats we have not linked to anything.
Lookalike domains found
- What it counts
- Registered domains that imitate a monitored brand, counted from the day we first observe them registered.
- Time window
- The last 30 days.
- How often it refreshes
- Each page view, cached for up to an hour. Shown as a rounded-down figure with a plus sign (for example “2,300+”).
- What it excludes
- Names that are available but not registered, and domains that were already registered before we began watching them.
Brands monitored
- What it counts
- Brands under continuous monitoring: lookalike, certificate and threat-feed coverage runs for each of them all the time.
- Time window
- Current count.
- How often it refreshes
- Each page view, cached for up to an hour.
- What it excludes
- Our wider brand catalog. The catalog holds many more names than we watch actively, and we never describe catalog entries as monitored. Customer names are never listed.
Hosting providers mapped
- What it counts
- Distinct hosting providers that appear in the infrastructure behind the threats we track, so you can see where attacks are hosted. Shown rounded down with a plus sign.
- Time window
- Since launch (all time).
- How often it refreshes
- Each page view, cached for up to 5 minutes.
- What it excludes
- Providers with no observed threat activity. We don't publish provider rankings.
Countries
- What it counts
- Distinct countries where the hosting for tracked threats is located.
- Time window
- Since launch (all time).
- How often it refreshes
- Each page view, cached for up to 5 minutes.
- What it excludes
- Threats whose location we can't determine.
Intelligence sources
- What it counts
- Phishing, malware and infrastructure data sources feeding the platform, shown as “40+”.
- Time window
- Current count.
- How often it refreshes
- Each page view, cached for up to 5 minutes.
- What it excludes
- We show a floor, not an exact figure, and we don't name or rank sources.
Questions about a number? Ask us. You can also see an illustrative operation report.