[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs-threat-intelligence":3},[4,9,12,16,18,21,23,26,28,31,33,35,38,40],{"type":5,"level":6,"text":7,"id":8},"heading",1,"Threat Intelligence","threat-intelligence",{"type":10,"text":11},"paragraph","Scam sites are rarely built one at a time. Operators clone the same toolkit across hundreds of domains and rotate identities after takedowns. The **Threat Intelligence** registry exposes those connections.",{"type":5,"level":13,"text":14,"id":15},2,"Networks","networks",{"type":10,"text":17},"A [Network](\u002Fnetworks) is a cluster of domains forensically linked through shared infrastructure, build artefacts and operational patterns. Each network groups the brands and domains run by a single operation.",{"type":5,"level":13,"text":19,"id":20},"Signals","signals",{"type":10,"text":22},"A [Signal](\u002Fsignals) is a genome signature: a content or code fingerprint (build hash, favicon hash, DOM structure, tracking ID) shared across cloned deployments. Any domain matching a signal was built from the same kit.",{"type":5,"level":13,"text":24,"id":25},"Infrastructure","infrastructure",{"type":10,"text":27},"The [Infrastructure](\u002Finfrastructure) section lets you pivot across the hosting layer (IP addresses, ASNs, registrars, nameservers, mail servers, SSL issuers and favicon hashes) to see which domains share a host or a certificate.",{"type":5,"level":13,"text":29,"id":30},"Watchdog warnings","watchdog-warnings",{"type":10,"text":32},"The [Watchdogs](\u002Fwarnings) hub aggregates fraud alerts from financial regulators worldwide. Each warning links to its source and feeds the scoring of every flagged domain.",{"type":10,"text":34},"Each authority has its own page, carrying what the authority itself says its list is and means: the [FCA Warning List](\u002Fwarnings\u002Ffca) of unauthorised firms, [ASIC's Investor Alert List](\u002Fwarnings\u002Fasic), the [AMF blacklists](\u002Fwarnings\u002Famf), and the [Bank of Russia's warning list](\u002Fwarnings\u002Fcbr), which is the largest archive here. Reading the authority's own wording matters, because the lists are not making the same claim: [FINMA states outright](\u002Fwarnings\u002Ffinma) that being listed does not automatically make an activity unlawful, while [BCSC publishes a caution list](\u002Fwarnings\u002Fbcsc).",{"type":5,"level":13,"text":36,"id":37},"How it connects to scans","how-it-connects-to-scans",{"type":10,"text":39},"Every domain in the registry links back to its full scan result page. The Trust Score's scam-farm and regulator chains are driven by these same connections: if a domain belongs to a known network or is named in a regulator warning, that raises its risk.",{"type":10,"text":41},"For the model that makes these connections possible, see [The graph behind every scan](\u002Fdocs\u002Fthe-graph)."]