Skip to main content
Designed for US customers. Each customer has their own dedicated credentials and data does not leave the US region. Customers are not part of any consortium. This page documents the Device Intelligence module, including its variants, capabilities, and the result values it returns.

Capabilities

The module returns the following capabilities.

Threat device score

Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.

Behavioral indicators

Behavioral Indicators

Users seen on device

Users Seen on Device

Threat BOT score

Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).

Identity device score

Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).

Days since user first seen

Days Since User First Seen

IP address indicators

IP Address Indicators

Days since device last seen

Days Since Device Last Seen

Times user seen

Times User Seen

Devices seen on user

Devices Seen on User

Threat keystrokes score

Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.

Bot and RAT indicators

Bot and RAT Indicators

Malware indicators

Malware Indicators

Identity mouse score

Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.

Threat RAT score

Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).

Days since user last seen

Days Since User Last Seen

Internet connection type

Internet Connection Type

Threat location score

Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).

IP address geo-Location

IP Address Geo-Location

Device language

Device Language

Location type

Location Type

Threat score

Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.

Identity keystrokes score

Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.

Device indicators

Device Indicators

Device model error

Device Model Error

Time based indicators

Time Based Indicators

Times device seen

Times Device Seen

Compromise indicators

Compromise Indicators

Threat mouse score

Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.

Location indicators

Location Indicators

Device OS

Device OS

Identity score

Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.

Time zone offset

Time Zone Offset

Identity location score

Location match — how consistent the location is with the user’s known mobility / location history.

Time zone region

Time Zone Region

Device type

Device Type

Device category

Device Category

Device language country

Device Language Country

Threat indicators

Threat Indicators

Keystrokes and mouse behavior

Keystrokes and Mouse Behavior

Days since device first seen

Days Since Device First Seen

Default outcomes

The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.

Input payload

The following is a sample payload used to submit data to the Device Intelligence - Single Tenant - US module for processing.
JSON

Sample response

The following is a sample response returned by the module.
JSON

Capabilities

The module returns the following capabilities.

Threat device score

Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.

Behavioral indicators

Behavioral Indicators

Users seen on device

Users Seen on Device

Threat BOT score

Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).

Identity device score

Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).

Days since user first seen

Days Since User First Seen

IP address indicators

IP Address Indicators

Days since device last seen

Days Since Device Last Seen

Times user seen

Times User Seen

Devices seen on user

Devices Seen on User

Threat keystrokes score

Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.

Bot and RAT indicators

Bot and RAT Indicators

Malware indicators

Malware Indicators

Identity mouse score

Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.

Threat RAT score

Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).

Days since user last seen

Days Since User Last Seen

Internet connection type

Internet Connection Type

Threat location score

Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).

IP address geo-Location

IP Address Geo-Location

Device language

Device Language

Location type

Location Type

Threat score

Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.

Identity keystrokes score

Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.

Device indicators

Device Indicators

Device model error

Device Model Error

Time based indicators

Time Based Indicators

Times device seen

Times Device Seen

Compromise indicators

Compromise Indicators

Threat mouse score

Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.

Location indicators

Location Indicators

Device OS

Device OS

Identity score

Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.

Time zone offset

Time Zone Offset

Identity location score

Location match — how consistent the location is with the user’s known mobility / location history.

Time zone region

Time Zone Region

Device type

Device Type

Device category

Device Category

Device language country

Device Language Country

Threat indicators

Threat Indicators

Keystrokes and mouse behavior

Keystrokes and Mouse Behavior

Days since device first seen

Days Since Device First Seen

Default outcomes

The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.

Input payload

The following is a sample payload used to submit data to the Device Intelligence - Single Tenant - AU module for processing.
JSON

Sample response

The following is a sample response returned by the module.
JSON

Capabilities

The module returns the following capabilities.

Threat device score

Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.

Behavioral indicators

Behavioral Indicators

Users seen on device

Users Seen on Device

Threat BOT score

Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).

Identity device score

Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).

Days since user first seen

Days Since User First Seen

IP address indicators

IP Address Indicators

Days since device last seen

Days Since Device Last Seen

Times user seen

Times User Seen

Devices seen on user

Devices Seen on User

Threat keystrokes score

Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.

Bot and RAT indicators

Bot and RAT Indicators

Malware indicators

Malware Indicators

Identity mouse score

Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.

Threat RAT score

Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).

Days since user last seen

Days Since User Last Seen

Internet connection type

Internet Connection Type

Threat location score

Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).

IP address geo-Location

IP Address Geo-Location

Device language

Device Language

Location type

Location Type

Threat score

Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.

Identity keystrokes score

Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.

Device indicators

Device Indicators

Device model error

Device Model Error

Time based indicators

Time Based Indicators

Times device seen

Times Device Seen

Compromise indicators

Compromise Indicators

Threat mouse score

Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.

Location indicators

Location Indicators

Device OS

Device OS

Identity score

Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.

Time zone offset

Time Zone Offset

Identity location score

Location match — how consistent the location is with the user’s known mobility / location history.

Time zone region

Time Zone Region

Device type

Device Type

Device category

Device Category

Device language country

Device Language Country

Threat indicators

Threat Indicators

Keystrokes and mouse behavior

Keystrokes and Mouse Behavior

Days since device first seen

Days Since Device First Seen

Default outcomes

The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.

Input payload

The following is a sample payload used to submit data to the Device Intelligence - Single Tenant - EU module for processing.
JSON

Sample response

The following is a sample response returned by the module.
JSON

Capabilities

The module returns the following capabilities.

Threat device score

Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.

Behavioral indicators

Behavioral Indicators

Users seen on device

Users Seen on Device

Threat BOT score

Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).

Identity device score

Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).

Days since user first seen

Days Since User First Seen

IP address indicators

IP Address Indicators

Days since device last seen

Days Since Device Last Seen

Times user seen

Times User Seen

Devices seen on user

Devices Seen on User

Threat keystrokes score

Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.

Bot and RAT indicators

Bot and RAT Indicators

Malware indicators

Malware Indicators

Identity mouse score

Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.

Threat RAT score

Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).

Days since user last seen

Days Since User Last Seen

Internet connection type

Internet Connection Type

Threat location score

Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).

IP address geo-Location

IP Address Geo-Location

Device language

Device Language

Location type

Location Type

Threat score

Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.

Identity keystrokes score

Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.

Device indicators

Device Indicators

Device model error

Device Model Error

Time based indicators

Time Based Indicators

Times device seen

Times Device Seen

Compromise indicators

Compromise Indicators

Threat mouse score

Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.

Location indicators

Location Indicators

Device OS

Device OS

Identity score

Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.

Time zone offset

Time Zone Offset

Identity location score

Location match — how consistent the location is with the user’s known mobility / location history.

Time zone region

Time Zone Region

Device type

Device Type

Device category

Device Category

Device language country

Device Language Country

Threat indicators

Threat Indicators

Keystrokes and mouse behavior

Keystrokes and Mouse Behavior

Days since device first seen

Days Since Device First Seen

Default outcomes

The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.

Input payload

The following is a sample payload used to submit data to the Device Intelligence - Consortium module for processing.
JSON

Sample response

The following is a sample response returned by the module.
JSON