A day’s findings arrive as a list. Working them in the order they arrived means the one that mattered was worked fourth, which is a detection programme producing the outcome of no detection programme.
A ranking that holds up
| Weight | Signal |
|---|---|
| Highest | Serving content resembling yours, with a login form |
| Very high | MX record present |
| Very high | Certificate issued in the last 48 hours |
| High | Resolves, with content of any kind |
| Moderate | Registered within 30 days |
| Moderate | Clusters with other findings — shared nameservers or a shared certificate |
| Low | Resolves to nothing |
| None | Privacy-protected registrant |
| None | Registered at a registrar you have seen abuse from before |
The two at the bottom appear in automated risk scores constantly and carry no information. Including them does not merely waste attention — it inflates the score of findings that deserve none, which pushes real ones down the list.
A worked queue
Today's findings:
A northwlnd.example resolves, cloned login page, cert 6h old
B northwind-pay.example no content, MX present, cert 2d old
C northwind.example.net registered today, resolves to nothing
D nrothwind.example parked ad page, registered 2019
E northwinds.example real sailing club, site since 2011
Order: A, B, C, D, E
A active credential harvesting, right now
B prepared for invoice redirection — arguably worse
per incident, and not yet operating
C new, unknown intent, watch
D parked. Log and close.
E unrelated. Close, and record why so nobody
re-raises it next month.A before B is a judgement call: A is causing loss now, B carries more loss per incident. Both are worked today; the argument is only about which hour.
Close findings explicitly, with a reason
E will be detected again next month by the same rule that found it today. A recorded closure with a reason stops it consuming an hour every cycle, and a queue that grows without closures is one people stop opening.