> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# One IP, 13,287 Reports

> Breaking down a single indicator of compromise and what four months of accumulated intelligence look like in practice

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/mGgHxMsQTm71_QZa/images/case3.png?fit=max&auto=format&n=mGgHxMsQTm71_QZa&q=85&s=67ae4047b0fee19f0caf996a5ad6d220" width="1460" height="434" data-path="images/case3.png" />

This is a single IPv4 address, looked up on demand: a **Crime Score of 546**, flagged **Critical**, backed by **13,287 reports** from **19 members**, contributing **35 CTI points**, first observed **four months prior**, and last active **26 minutes** before this lookup.

***

## Score composition

A Crime Score is a weighted correlation across independent Alliance members, each carrying a trust weight based on historical accuracy and false-positive rate, combined with confidence metadata describing how the activity was validated. An observed exploitation attempt is weighted differently from a heuristic suspicion. Nineteen members independently reporting the same address over four months is what places the score in the Critical range rather than a single flagged event.

## Persistence versus decay

IPv4 Crime Scores decay over time when no new activity is observed, accounting for infrastructure churn, botnet reassignment, and host remediation. This address has not decayed: it registered a new attack 26 minutes before the lookup, on top of four months of continuous activity. The combination of a long track record and current activity distinguishes an indicator warranting active blocking from one that was flagged once and has since gone quiet.

## Hosting provider is not a scoring input

The ASN attached to this indicator belongs to Alibaba's US technology arm. Cloud infrastructure from major providers is regularly abused, and provenance alone is a weak signal since legitimate traffic originates from the same ASNs. The three feeds marked "Protected" in this panel — two Checkpoint deployments and one Fortinet deployment, with six more not shown — already have this indicator enforced, meaning policy was applied automatically based on the score rather than a manual review of the ASN.

***

Proof of Value engagements surface indicators like this one already present in a client's own traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
