The incident window
See the resolutions, hosting patterns, and responses as they stood during the incident window.
Incident response
Point-in-time history for the hours the incident actually covers, available while it is still open.
Challenge
Our unmatched history allows you to find the record that actually caused the alert to trigger
What this changes
A confirmed indicator is the starting point. The history establishes the extent of the exposure.
See the resolutions, hosting patterns, and responses as they stood during the incident window.
Find the other hosts that shared an IP address or response features at the same time.
Quickly determine exposure and scope.
In practice
Identify a domain that's already been taken offline.
The domain currently resolves to a parking IP with no meaningful history attached to it.
At the time of the beacon it resolved to a server in a different region and served content.
It was serving other domains during the same time window.
A host that had not yet been flagged. The scope is established during the incident window rather than days after it.
We retain the full history for everything we collect, with no age-out
Platform features behind this use case
Get in touch
Validin is the first tab I open every morning.