0–1000Universal risk scale
6Scoring components
290+Validating members
≥190Optimal block threshold
Score Bands

Higher scores mean stronger, multi-source confirmation

Use the bands below to calibrate your enforcement policy.

RangeBandRecommended Action
0–80Clean / UnobservedNo enforcement action recommended
80–140Watchlist / MonitorLogging and alerting only
140–250Block RecommendedStart here with ≥400 for safe initial deployment
250–1000Immediate BlockHigh-confidence, multi-sector confirmed — immediate enforcement

Alliance validation ≥190 balances accuracy and prevention for most first deployments.

Crime Score band chart from Clean (0-80) through Watchlist, Block Recommended, to Immediate Block (250-1000), with a recommended threshold of 130-150
False Positives

Automatic blocking, only when it's certain

It's not how often an IP attacks that counts — it's how many trusted members confirm it.

Scenario A

A single member, attacked 10,000 times

Volume is not enough: a single reporter, however noisy, never triggers a block.

Crime Score max 60 · not blocked

Scenario B

At least 4 high-trust members, in the last 2 hours

Independent sources, each given a trust level by OneFirewall, confirm the same threat actor.

Above threshold · blocked automatically

You set the threshold, whenever you want.

Sample Response

Every score, fully explained

Every lookup returns not just the score, but the confidence level, how many independent members reported it, and the specific MITRE techniques observed.

GET /api/v1/score?ip=185.220.101.45
{
  "ip": "185.220.101.45",
  "score": 847,
  "band": "IMMEDIATE_BLOCK",
  "confidence": 0.94,
  "members_seen": 23,
  "components": {
    "alliance_freq": 340,
    "trust_weight": 180,
    "confidence_meta": 165,
    "stix_enrichment": 100,
    "temporal_decay": 62
  },
  "mitre_ttps": ["T1190", "T1133"],
  "tags": ["tor-exit", "brute-force"]
}
Six Scoring Components

No single signal determines the score

Alliance Member Frequency

Multiple independent organisations reporting the same asset increases the score nonlinearly — a dozen confirmations raises certainty.

Source Trust Weight

Each contributing member is weighted by their historical accuracy and false-positive rate.

Confidence Metadata

Per-submission confidence ratings feed directly into the composite score.

STIX Enrichment

Structured context from STIX bundles adds weight where corroborating detail exists.

Temporal Decay

Scores age naturally as sightings become less recent, reflecting infrastructure churn.

Sector Weighting

Targeting patterns across industries adjust relevance for your specific sector.

See your own Crime Score exposure.

Free Proof of Value against your real traffic.

Start a Proof of Value