Malware
Tarsier Threat Index
Also called TTI.
Tarsier Threat Index is Tarsier's own list of hostile hosts and script patterns, used by Hack Check to flag pages that load them. It is a curated list, not a score of how safe your site feels.
How it is measured
A Hack Check scan loads the page, collects the hosts it contacts and the scripts it runs, and compares them with entries in the index. A match is a yes or no per host or pattern, shown in the report with the URL where it appeared.
The index is only as good as its upkeep. Treat a match as evidence to check, a non-match as 'not on our list', and read the page's actual script sources if something looks wrong. Entries are removed or changed as hosts are cleaned or retired.
Worked example
A florist's WordPress site runs Hack Check and the report names one hit: a script from a host on the index, loaded on /checkout by a 'cart tracking' snippet in the theme's footer. The florist never added it; the footer was edited through a stolen admin login.
Removing the snippet and rotating admin passwords clears the match on the next scan. The florist also learns the snippet was present on /checkout only, which narrows the exposure window for customers entering cards.
How it differs
An indicator of compromise is any single piece of evidence that a system was breached, such as a file hash, an IP, or a registry key, and it comes out of an investigation. The Tarsier Threat Index is a maintained list of hostile hosts and patterns that Hack Check compares pages against. IOCs describe an incident; the index is a standing reference.
Common errors
Reading a clean result as a clean bill of health. Assuming a hit means your server was breached, when it may be a third-party script. Ignoring the page and context for a hit. Treating the index as a replacement for patching. Not re-scanning after cleanup.
In practice
Run Hack Check on key pages: home, checkout, login, and a few deep URLs. If a host matches, find where it is injected (theme, plugin, tag manager, database), remove that source, then re-scan. Combine it with file-integrity checks, because a miss only means the host is not listed.