> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How Old Are Your Threats

> Cross-tabulating High and Critical events by how long the underlying indicator has been known, alongside where the traffic originated and which device stopped it

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/7Yf8Ws5Z8YCDAhoV/images/case23.png?fit=max&auto=format&n=7Yf8Ws5Z8YCDAhoV&q=85&s=f9304d1af575edce757a2306f12e2903" width="2752" height="716" data-path="images/case23.png" />

The table on the left sorts every High and Critical event by the age of the indicator behind it — how long ago that source was first observed, not how long ago the event itself happened.

***

## Reading the age buckets

The counts run from **less than 1 hour** old up to **more than 1 year** old: 1 High / 1 Critical in the newest bucket, climbing to **93 High / 118 Critical** in the 1–7 day range, tapering through the older buckets down to **45 High / 102 Critical** for indicators first seen over a year ago. Two things stand out. First, the 1–7 day bucket carries the highest volume in both columns: most of the current High and Critical activity comes from sources that are recent, not long-tenured signatures on a static list. Second, the over-a-year bucket is not small. 102 Critical events are tied to sources with a track record stretching back more than twelve months, meaning the score never fully decayed because the source kept generating validated activity recently enough to stay elevated.

## Why age matters alongside severity

A Critical score by itself says how confident the system is that a source is malicious right now. Age adds a second axis: whether that's a source that just appeared, or one that's been through the decay model repeatedly and kept re-triggering it. A 1–7 day Critical indicator and a >1 year Critical indicator carry the same enforcement weight, but they describe different attacker behavior: one is a fresh campaign, the other a persistent source that has never gone fully quiet.

## The origin map and device breakdown alongside it

The map in the middle and the bar chart on the right cover the same ground as the origin and enforcement-point breakdowns elsewhere in this report — geographic concentration, with the US region carrying the highest count at 266, and blocked volume split across the same four devices (Checkpoint-3472409, Checkpoint-198365, Fortigate-infra1, Fortigate-infra2). They're included here as the surrounding context for the age data, not a separate finding.

***

Proof of Value engagements produce this same age-versus-severity breakdown against a client's own traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
