Trust, published

How We Score Threat Intelligence

Every indicator RST Cloud delivers carries a score you can inspect, not a black-box confidence number. We publish the methodology because a trust layer that asks you to verify everything else should not ask you to simply trust its own math. Three complementary layers combine — each one covering the blind spots of the other two.

The three-layer actuality model

Input
5.181.156.7
01

Statistical Decay

Type-specific decay curves, modulated by observed frequency.

02

Active Verification

Adversary-aware live checks — reachability is not maliciousness.

03

Multi-Source Confidence

Per-source trust, weighted and cross-checked over time.

Output
87
Auditable score

Statistical Decay

Different indicator types decay at different rates — a phishing URL degrades faster than a C2 domain — so each IOC type is modelled with its own empirically derived decay curve, modulated by observed frequency. Sustained high frequency over a long period is often a negative signal (sinkholed infrastructure, background scanning); a sudden spike in a short window is a strong positive signal of active use; low-and-slow patterns are treated carefully, since deliberately quiet APT infrastructure is not the same as low confidence. Decay rates update continuously as new observations and verification results arrive.

Active Verification, With Adversarial Awareness

Live checks confirm operational status — but only after accounting for how adversaries defeat naive probing. A resolving domain means less than it appears to behind fast-flux DNS or CDN fronting; a reachable IP is not the same as an actively malicious one once geofencing and victim-profile filtering are in play; and the absence of a response is scored as unverified, never as confirmed takedown, until corroborated by other signals. Verified-live indicators with corroborating source agreement decay far more slowly than indicators that have simply gone quiet.

Multi-Source Confidence and Source Scoring

Sources are modelled individually over time: a source whose indicators are later confirmed active scores higher than one whose indicators are frequently stale on arrival or unverifiable. High agreement across high-confidence sources accelerates a score and slows its decay; a single low-confidence source is treated with appropriate skepticism regardless of recency; and disagreement between sources is surfaced as an explicit analytical flag rather than silently averaged away — which is also how the model catches stale intelligence being recycled and re-shared as fresh.

What you actually see

Three methods in. Three dimensions out.

The three layers above are the machinery. What every RST product exposes on the surface — on an indicator, a leaked credential, or a proxy caught driving automation — is the same three dimensions, in the same words.

Source confidence

How much we trust where the observation came from — scored per source, over time, not asserted once.

from multi-source confidence

Context score

What the indicator actually is and what it was doing — not merely that it responded to a probe.

from active verification

Time relevance

How recent and how live it is, on a curve fitted to that indicator type rather than a flat TTL.

from statistical decay

No single method is reliable in isolation — the point is that their failure modes are partially orthogonal. The result is a continuously updated relevance score that is harder to game than any single signal, with full auditability: analysts can inspect the decay trend, the latest verification result, and the source-agreement profile side by side, and understand why a score is what it is.— Yury Sergeev, Director of RST Cloud

This page is the short version. For the full technical write-up — including the failure-mode comparison table — read Beyond Decay Curves: Rethinking IOC Scoring. This scoring runs under RST Threat Feed and RST Noise Control today.

Request a demoStart free trial