Methodology

How we count

Every number in “By the numbers” on the homepage is a real aggregate from the platform. This page says what each one counts, over what window, how fresh it is, and what it leaves out. Customer data is never used in these numbers.

How these numbers are produced

  • Live where possible. The page fetches current figures when you open it. If that fails, it shows the figures from the last site build, labelled as a snapshot with its date.
  • Rounded down, never up. Figures shown with a plus sign are floored, so we don't overstate.
  • Aggregates only. Nothing here names a customer, a brand we monitor for a customer, or a data source.

If the live figure can't be fetched, the page shows the snapshot taken when the site was last built, and says so.

Threats tracked

What it counts
Every distinct malicious indicator we have recorded: phishing and malware domains and URLs, command-and-control and other malicious addresses, and typosquatted domains. Each indicator is counted once, however many sources report it.
Time window
Since launch (all time).
How often it refreshes
Each page view, cached for up to 5 minutes.
What it excludes
Customer-reported material and anything from a customer's private data. Those are never added to the public count.

Threats by type

What it counts
The same indicators, split by what they are. Scanning hosts and malicious IP addresses are shown together as “Infrastructure signals” because they describe infrastructure rather than an attack on a brand. Percentages are each type's share of the classified threats shown, so they will not match the headline total exactly.
Time window
Since launch (all time).
How often it refreshes
Each page view, cached for up to 5 minutes.
What it excludes
Types with fewer than 1,000 indicators are left off the chart, and unclassified indicators have no bar. The hidden-table view lists every bar's exact count.

New today

What it counts
Indicators added across every source since 00:00 UTC on the current day.
Time window
The current UTC day, so it resets at midnight UTC and is not a rolling 24 hours.
How often it refreshes
Each page view, cached for up to 5 minutes.
What it excludes
Re-sightings of indicators we already track. Only new additions count.

Active operations

What it counts
Groups of threats we link together because they share hosting, certificates or registration patterns. A multi-part operator counts once, however many kinds of infrastructure link its threats.
Time window
Operations with activity in the last 30 days.
How often it refreshes
Each page view, cached for up to an hour.
What it excludes
Operations with no activity in the window, and single threats we have not linked to anything.

Lookalike domains found

What it counts
Registered domains that imitate a monitored brand, counted from the day we first observe them registered.
Time window
The last 30 days.
How often it refreshes
Each page view, cached for up to an hour. Shown as a rounded-down figure with a plus sign (for example “2,300+”).
What it excludes
Names that are available but not registered, and domains that were already registered before we began watching them.

Brands monitored

What it counts
Brands under continuous monitoring: lookalike, certificate and threat-feed coverage runs for each of them all the time.
Time window
Current count.
How often it refreshes
Each page view, cached for up to an hour.
What it excludes
Our wider brand catalog. The catalog holds many more names than we watch actively, and we never describe catalog entries as monitored. Customer names are never listed.

Hosting providers mapped

What it counts
Distinct hosting providers that appear in the infrastructure behind the threats we track, so you can see where attacks are hosted. Shown rounded down with a plus sign.
Time window
Since launch (all time).
How often it refreshes
Each page view, cached for up to 5 minutes.
What it excludes
Providers with no observed threat activity. We don't publish provider rankings.

Countries

What it counts
Distinct countries where the hosting for tracked threats is located.
Time window
Since launch (all time).
How often it refreshes
Each page view, cached for up to 5 minutes.
What it excludes
Threats whose location we can't determine.

Intelligence sources

What it counts
Phishing, malware and infrastructure data sources feeding the platform, shown as “40+”.
Time window
Current count.
How often it refreshes
Each page view, cached for up to 5 minutes.
What it excludes
We show a floor, not an exact figure, and we don't name or rank sources.

Questions about a number? Ask us. You can also see an illustrative operation report.