CertaDNS
Skip to lesson

Classifying a Finding · lesson 2 of 3

Ranking a queue

After this lesson you can

Order a day’s findings so the one that matters is worked first.

Assumes you have read Four outcomes.

A day’s findings arrive as a list. Working them in the order they arrived means the one that mattered was worked fourth, which is a detection programme producing the outcome of no detection programme.

A ranking that holds up

WeightSignal
HighestServing content resembling yours, with a login form
Very highMX record present
Very highCertificate issued in the last 48 hours
HighResolves, with content of any kind
ModerateRegistered within 30 days
ModerateClusters with other findings — shared nameservers or a shared certificate
LowResolves to nothing
NonePrivacy-protected registrant
NoneRegistered at a registrar you have seen abuse from before

The two at the bottom appear in automated risk scores constantly and carry no information. Including them does not merely waste attention — it inflates the score of findings that deserve none, which pushes real ones down the list.

A worked queue

Today's findings:

A  northwlnd.example    resolves, cloned login page, cert 6h old
B  northwind-pay.example  no content, MX present, cert 2d old
C  northwind.example.net  registered today, resolves to nothing
D  nrothwind.example      parked ad page, registered 2019
E  northwinds.example     real sailing club, site since 2011

Order: A, B, C, D, E
   A  active credential harvesting, right now
   B  prepared for invoice redirection — arguably worse
      per incident, and not yet operating
   C  new, unknown intent, watch
   D  parked. Log and close.
   E  unrelated. Close, and record why so nobody
      re-raises it next month.

A before B is a judgement call: A is causing loss now, B carries more loss per incident. Both are worked today; the argument is only about which hour.

Close findings explicitly, with a reason

E will be detected again next month by the same rule that found it today. A recorded closure with a reason stops it consuming an hour every cycle, and a queue that grows without closures is one people stop opening.

Last reviewed