Reputation

This page provides information on the Reputation in Netify's Network Intelligence Engine. To learn more about our full suite of intelligence drivers, see our intelligence capabilities page.

Risk Overview

Not all destinations on the Internet are trustworthy. IP addresses and domains can be linked to malware distribution, phishing, botnets, and other malicious activity. Without reputation insight, users and systems may unknowingly connect to high-risk endpoints.


Indicator Drivers

Domain Reputation Driver

Domain names are often the first touchpoint in phishing, malware delivery, and command-and-control activity. Attackers frequently rotate or generate new domains to evade detection, making static controls ineffective. Domain reputation intelligence continuously evaluates domains based on observed behavior and threat signals, allowing organizations to identify suspicious or high-risk destinations in real time.

Domain Reputation
Tag
domain_reputation
Score
Risk severity varies
Version
1.2.16

IP Reputation Driver

IP addresses often serve as the underlying infrastructure for malware hosting, botnet activity, scanning, and command-and-control communications. Unlike domains, IPs can be reused across multiple services, making context and reputation critical for accurate risk assessment. IP reputation intelligence evaluates addresses based on observed behavior and threat signals, helping organizations identify high-risk endpoints, detect suspicious connections, and enforce policies to limit exposure to known malicious infrastructure.

IP Reputation
Tag
ip_reputation
Score
Risk severity varies
Version
1.2.16