> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Clean vs Malicious

> Of the traffic a firewall already allowed through, how much OneFirewall's intelligence identifies as malicious

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/case14.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=a56b1be90ca9f178641cb089ae61fc54" width="748" height="590" data-path="images/case14.webp" />

Of the **16,055** events the client's firewall allowed through, OneFirewall's scoring identifies **14,116** as clean and **1,939** as malicious.

***

## Scoring after the fact, not instead of

This isn't a re-evaluation of a blocking decision. It's a second, independent classification applied to traffic that already passed. The firewall made an allow/deny call based on its own rules; OneFirewall separately matches the same traffic against the Alliance's threat intelligence and Crime Score data. The two systems can disagree, and this chart is where that disagreement becomes visible: **1,939** events, roughly 12% of everything permitted, carried an indicator the existing rule set had no way to recognize.

## Where this number goes next

**1,939** isn't a flat category. It's the starting point for the severity breakdown that follows: Low, Medium, High, and Critical. That breakdown is what turns "this was malicious" into a prioritized list of what to act on first.

***

Proof of Value engagements run this same clean-versus-malicious split against a client's own permitted traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
