Trust, published
How We Score Threat Intelligence
Every indicator RST Cloud delivers carries a score you can inspect, not a black-box confidence number. We publish the methodology because a trust layer that asks you to verify everything else should not ask you to simply trust its own math. Three complementary layers combine — each one covering the blind spots of the other two.
The three-layer actuality model
Statistical Decay
Type-specific decay curves, modulated by observed frequency.
Active Verification
Adversary-aware live checks — reachability is not maliciousness.
Multi-Source Confidence
Per-source trust, weighted and cross-checked over time.
Statistical Decay
Different indicator types decay at different rates — a phishing URL degrades faster than a C2 domain — so each IOC type is modelled with its own empirically derived decay curve, modulated by observed frequency. Sustained high frequency over a long period is often a negative signal (sinkholed infrastructure, background scanning); a sudden spike in a short window is a strong positive signal of active use; low-and-slow patterns are treated carefully, since deliberately quiet APT infrastructure is not the same as low confidence. Decay rates update continuously as new observations and verification results arrive.
Active Verification, With Adversarial Awareness
Live checks confirm operational status — but only after accounting for how adversaries defeat naive probing. A resolving domain means less than it appears to behind fast-flux DNS or CDN fronting; a reachable IP is not the same as an actively malicious one once geofencing and victim-profile filtering are in play; and the absence of a response is scored as unverified, never as confirmed takedown, until corroborated by other signals. Verified-live indicators with corroborating source agreement decay far more slowly than indicators that have simply gone quiet.
Multi-Source Confidence and Source Scoring
Sources are modelled individually over time: a source whose indicators are later confirmed active scores higher than one whose indicators are frequently stale on arrival or unverifiable. High agreement across high-confidence sources accelerates a score and slows its decay; a single low-confidence source is treated with appropriate skepticism regardless of recency; and disagreement between sources is surfaced as an explicit analytical flag rather than silently averaged away — which is also how the model catches stale intelligence being recycled and re-shared as fresh.
What you actually see
Three methods in. Three dimensions out.
The three layers above are the machinery. What every RST product exposes on the surface — on an indicator, a leaked credential, or a proxy caught driving automation — is the same three dimensions, in the same words.
Source confidence
How much we trust where the observation came from — scored per source, over time, not asserted once.
from multi-source confidenceContext score
What the indicator actually is and what it was doing — not merely that it responded to a probe.
from active verificationTime relevance
How recent and how live it is, on a curve fitted to that indicator type rather than a flat TTL.
from statistical decayNo single method is reliable in isolation — the point is that their failure modes are partially orthogonal. The result is a continuously updated relevance score that is harder to game than any single signal, with full auditability: analysts can inspect the decay trend, the latest verification result, and the source-agreement profile side by side, and understand why a score is what it is.— Yury Sergeev, Director of RST Cloud
This page is the short version. For the full technical write-up — including the failure-mode comparison table — read Beyond Decay Curves: Rethinking IOC Scoring. This scoring runs under RST Threat Feed and RST Noise Control today.