| TXN ID | Route | Amount | Channel | Location | Time | Status |
|---|---|---|---|---|---|---|
| txn-4f8a2c1d |
ACC-7291
→
ACC-APEX-001
|
$47,200.00 | WIRE | New York |
21h ago | FLAGGED · 2 alerts |
| txn-9b3e7f12 |
ACC-8834
→
ACC-PRIME-007
|
$150.00 | WEB | San Francisco |
14h ago | CLEAN |
| txn-2d5c8a31 |
ACC-GEO-01
→
ACC-SMITH-789
|
$300.00 | ATM | Los Angeles |
12h ago | FLAGGED · 1 alert |
| txn-7a1f4e9b |
ACC-1199
→
ACC-RETAIL-44
|
$89.99 | POS | Chicago |
12h ago | CLEAN |
| txn-c3d9b7a2 |
ACC-VEL-01
→
ACC-FAST-001
|
$300.00 | MOBILE | New York |
12h ago | FLAGGED · 1 alert |
| txn-5e8f2c07 |
ACC-4455
→
ACC-INTL-003
|
$15,000.00 | WIRE | London |
11h ago | FLAGGED · 1 alert |
| txn-0a4d6e19 |
ACC-9923
→
ACC-SAVE-112
|
$5,000.00 | WEB | Houston |
11h ago | CLEAN |
| txn-b6f3a812 |
ACC-3317
→
ACC-APEX-002
|
$11,200.00 | ATM | Amsterdam |
11h ago | FLAGGED · 1 alert |
| txn-d1c7e540 |
ACC-5588
→
ACC-SHOP-001
|
$450.00 | MOBILE | Phoenix |
11h ago | CLEAN |
| txn-e9a2f671 |
ACC-7291
→
ACC-APEX-001
|
$9,800.00 | WEB | New York |
11h ago | FLAGGED · 1 alert |
Transaction txn-4f8a2c1d amount 47,200.00 USD exceeds high-value threshold of 10,000.00 (overage: +372.0%)
Impossible geographic jump for account ACC-7291: 3459.2 miles in 18.0 minutes (max allowed: 500 miles)
Account ACC-VEL-01 made 6 transactions in the last 60s (threshold: >5)
Transaction txn-5e8f2c07 amount 15,000.00 USD exceeds high-value threshold of 10,000.00 (overage: +50.0%)
Impossible geographic jump for account ACC-GEO-01: 2451.0 miles in 30.0 minutes
Transaction txn-b6f3a812 amount 11,200.00 USD exceeds high-value threshold of 10,000.00 (overage: +12.0%)
Account ACC-7291 made 7 transactions in the last 60s (threshold: >5). Potential structuring pattern.
Fires when an account submits more than N transactions within a rolling time window. Detects scripted bursts, credential stuffing, and rapid card-testing patterns.
Flags any single transaction that exceeds the configured USD threshold. Pure-domain rule — no external state required. Pairs with SAR/CTR reporting requirements.
Compares consecutive transaction geolocations within a time window. Flags physically impossible travel — indicative of account takeover, VPN abuse, or card cloning.
Add New Rule
Implement domain.Rule in Go and register it in cmd/server/main.go