Registry methodology & appeals
A threat registry is only as good as its false-positive rate. This page documents exactly how the Omega Point Threat ID registry decides what is listed, how listings expire, and how anyone can request removal.
What we list — and what we never list
The public feed contains IP addresses only, and only those meeting a strict, corroborated bar (see below). We never publish personal identities, account handles, case data, or any investigative information — that data is internal-only by policy and is technically walled off from the public feed.
How an IP gets listed
Every listing is an observation, not an accusation. An IP is published only when all of the following hold:
- Classification = malicious — from a fused verdict, not a single signal.
- Confidence ≥ 0.85 on a 0–1 scale.
- ≥ 2 independent corroborating sources — e.g. a honeypot sensor observation plus an external reputation source (GreyNoise), not one source echoing itself.
Sources include our own $1 honeypot sensor network, GreyNoise scanner intelligence, Shodan infrastructure data, and community reporting. Verdicts are computed deterministically and each listing records its sources, threat types, first-seen, last-seen, and sighting count.
Aging & expiry
IP reputation is perishable — addresses on cloud and shared hosting get reassigned to innocent parties. Listings therefore age out: entries that stop being observed decay in confidence and drop below the publication bar, removing them from the public feed automatically. A listing reflects recent, repeated malicious behavior — not a permanent brand.
Appeals & de-listing
If your IP is listed and you believe it is a false positive — or you have remediated the issue (e.g. patched a compromised host) — request removal. We review de-listing requests promptly and remove any listing we cannot re-corroborate.
Request removal two ways:
- Email abuse@omegapointsolutions.com with the IP and any context.
- Or use the report form on our homepage (select "false positive / de-listing").
Using the data responsibly
Threat data is corroborating evidence, not proof. Use the feed to inform defensive controls (firewall/WAF blocklists, alerting, triage) — not as the sole basis for an accusation or an adverse action against a person. Consumable formats: .txt, .csv, STIX 2.1, JSON.
