Publication
What the dashboard exposes
The hourly publisher revalidates recent archives against the current registry, merges compatible observations, limits output, and atomically replaces one static snapshot.
- Indicator
- A normalized, defanged domain or URL. Credentials, query strings, fragments, and unsafe path data are removed.
- Timeline
- First-seen and last-seen timestamps from accepted observations, normalized to UTC.
- Source
- CertStream, URLScan, or a configured HECAVEX public export. Multiple observations can merge into one host row.
- Status
- CertStream and URLScan rows remain suspected. Active, offline, or mitigated lifecycle states require a configured HECAVEX observation.
- Target
- Exactly one brand resolved through the current reviewed registry and collision checks.
- Evidence
- Optional URLScan report, screenshot, primary-document SHA-256 hashes, host summary, and country metadata.
- Confidence
- An integer ranking score from 0 to 100. It orders evidence strength; it is not a probability or verdict.
Merge behaviorOne row represents one observed host. Merging keeps the earliest first-seen value, latest last-seen value, union of sources and hashes, most specific safe path, and highest confidence. Conflicting non-null brands invalidate the merged row.