
Scoring after the fact, not instead of
This isn’t a re-evaluation of a blocking decision — it’s a second, independent classification applied to traffic that already passed. The firewall made an allow/deny call based on its own rules; OneFirewall separately matches the same traffic against the Alliance’s threat intelligence and Crime Score data. The two systems can disagree, and this chart is where that disagreement becomes visible: 1,939 events, roughly 12% of everything permitted, carried an indicator the existing rule set had no way to recognize.Where this number goes next
1,939 isn’t a flat category. It’s the starting point for the severity breakdown that follows — Low, Medium, High, and Critical — which is what turns “this was malicious” into a prioritized list of what to act on first.Proof of Value engagements run this same clean-versus-malicious split against a client’s own permitted traffic. Start a Proof of Value.

