> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Clean vs Malicious

> Of the traffic a firewall already allowed through, how much OneFirewall's intelligence identifies as malicious

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/XtQuNxdDTqAwCnod/images/case14.png?fit=max&auto=format&n=XtQuNxdDTqAwCnod&q=85&s=0142f9e85e6b2fea6b63efafc4e6d610" width="748" height="590" data-path="images/case14.png" />

Of the **16,055** events the client's firewall allowed through, OneFirewall's scoring identifies **14,116** as clean and **1,939** as malicious.

***

## Scoring after the fact, not instead of

This isn't a re-evaluation of a blocking decision — it's a second, independent classification applied to traffic that already passed. The firewall made an allow/deny call based on its own rules; OneFirewall separately matches the same traffic against the Alliance's threat intelligence and Crime Score data. The two systems can disagree, and this chart is where that disagreement becomes visible: **1,939** events, roughly 12% of everything permitted, carried an indicator the existing rule set had no way to recognize.

## Where this number goes next

**1,939** isn't a flat category. It's the starting point for the severity breakdown that follows — Low, Medium, High, and Critical — which is what turns "this was malicious" into a prioritized list of what to act on first.

***

Proof of Value engagements run this same clean-versus-malicious split against a client's own permitted traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
