You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* Update threat_intelligence.md
Update documentation with correct categories and products.
* Update order of product
* Apply suggestions from code review
Co-authored-by: Michael Cretzman <58786311+michaelcretzman@users.noreply.github.com>
---------
Co-authored-by: Brett Blue <brett.blue@datadoghq.com>
Co-authored-by: Brett Blue <84536271+brett0000FF@users.noreply.github.com>
Co-authored-by: Michael Cretzman <58786311+michaelcretzman@users.noreply.github.com>
|[Minerstat](https://minerstat.com/mining-pool-whitelist.txt)|malware| Coinminer activity with known mining pools|CWS|
85
-
| Tor | tor | Policy violations for user activity |AAP, Cloud SIEM, and CWS|
86
-
|[Threatfox](https://threatfox.abuse.ch/)| malware | Identify hosts communicating with known malware infrastructure | Cloud SIEM, and CWS|
84
+
|[Minerstat](https://minerstat.com/mining-pool-whitelist.txt)|cryptomining| Coinminer activity with known mining pools|Workload Protection and Cloud SIEM|
85
+
| Tor | tor | Policy violations for user activity |App and API Protection, Cloud SIEM, and Workload Protection|
86
+
|[Threatfox](https://threatfox.abuse.ch/)| malware | Identify hosts communicating with known malware infrastructure | Cloud SIEM, and Workload Protection|
87
87
88
88
89
89
### Threat Intelligence Categories
@@ -93,11 +93,12 @@ Sources, categories, and intents are available as facets and filters on relevant
93
93
| residential_proxy | suspicious | IP addresses | Reputation for credential stuffing and fraud | AAP and Cloud SIEM |
94
94
| botnet_proxy | suspicious | IP addresses | Reputation for being part of a botnet and contributing to distributed attacks | AAP and Cloud SIEM |
95
95
| malware | malicious | application library versions, file hashes | Malicious packages and communication with mining pools| CWS |
96
-
| scanner | suspicious | IP addresses | Reputation for scanners |AAP and Cloud SIEM |
96
+
| scanner | suspicious | IP addresses | Reputation for scanners |App and API Protection, Workload Protection, and Cloud SIEM |
97
97
| hosting_proxy | suspicious | IP addresses | Datacenter IPs with a reputation of abuse, such as for distributed credential stuffing attacks | AAP and Cloud SIEM |
98
-
| tor | suspicious | IP addresses | Corporate policy violations for user activity |AAP and Cloud SIEM |
98
+
| tor | suspicious | IP addresses | Corporate policy violations for user activity |App and API Protection, Workload Protection, and Cloud SIEM |
0 commit comments