---
title: "Severity and Confidence Levels"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/1640103988/Severity%20and%20Confidence%20Levels"
format: markdown
---
The following tables outline the severity and confidence levels that Infoblox uses to assess specific indicators that may pose security risks to your infrastructure. These levels appear in security reports and logging systems of cloud platform providers. For information about security reports, see *[Viewing Security Reports](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35437599)*.

## Severity Level Definition

| **Severity Level** | **Definition** | **Examples** |
| --- | --- | --- |
| High | These indicators are actively involved in or are confirmed to be a part of malicious campaigns. Accessing a high-risk domain could lead to severe consequences, such as malware infection, data theft, financial loss, or a system compromise. | Traffic distribution systems (TDSs), domain cloakers, malicious trackers and post back domains, as well as domains hosting exploit kits, active phishing sites targeting credentials, command and control (C2) servers for botnets, and sites distributing ransomware. |
| Medium | These indicators have characteristics or a history that suggests they could be used for malicious purposes, but they aren't currently confirmed to be active threats. This could be due to hosting potentially unwanted programs, exhibiting suspicious behavior, or having a history of being used in malicious activities that are now inactive. These domains may ultimately be at high risk, but we are unable to provide that assessment based on our current knowledge and visibility. | Indicators associated with adware or spyware, newly registered domains with suspicious characteristics, or domains linked to past spam campaigns. |
| Low | These indicators aren't classified as malicious, but they have minor characteristics that warrant a threat designation. They could include indicators with a history of spam or that are part of a network that has been linked to low-level abuse, but without a direct threat to the user. These indicators may ultimately be higher risk, but we are unable to provide that assessment based on our current knowledge and visibility. | Domains used for bulk email marketing (spam), or those with a history of minor policy violations. |
| Info | These indicators are not considered a threat. They are either benign, legitimate, or do not have enough data to be classified with a threat level. This is the baseline classification for the vast majority of domains on the internet. | Legitimate business websites, news sites, or any domain that is not associated with known malicious or suspicious activity. |

## Confidence Level Definition

| **Confidence Level** | **Definition** |
| --- | --- |
| High | Infoblox has high confidence in the assessment. |
| Medium | Infoblox has medium confidence in the assessment. |
| Low | Infoblox has low confidence in the assessment. |