Skip to content

Commit 5acea90

Browse files
flaso-gironbrett0000FFmichaelcretzman
authored
Update threat_intelligence.md (#26983)
* Update threat_intelligence.md Update documentation with correct categories and products. * Update order of product * Apply suggestions from code review Co-authored-by: Michael Cretzman <58786311+michaelcretzman@users.noreply.github.com> --------- Co-authored-by: Brett Blue <brett.blue@datadoghq.com> Co-authored-by: Brett Blue <84536271+brett0000FF@users.noreply.github.com> Co-authored-by: Michael Cretzman <58786311+michaelcretzman@users.noreply.github.com>
1 parent df9c150 commit 5acea90

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

content/en/security/threat_intelligence.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -81,9 +81,9 @@ Sources, categories, and intents are available as facets and filters on relevant
8181
| [Spur](https://spur.us/) | residential_proxy | Proxies associated credential stuffing and fraud | AAP and Cloud SIEM |
8282
| [Spur](https://spur.us/) | malware_proxy | Proxies associated with malware command and control | Cloud SIEM |
8383
| [Abuse.ch](https://abuse.ch/) Malware Bazaar| malware | Malware on hosts | CWS |
84-
| [Minerstat](https://minerstat.com/mining-pool-whitelist.txt) | malware | Coinminer activity with known mining pools| CWS |
85-
| Tor | tor | Policy violations for user activity | AAP, Cloud SIEM, and CWS |
86-
| [Threatfox](https://threatfox.abuse.ch/) | malware | Identify hosts communicating with known malware infrastructure | Cloud SIEM, and CWS |
84+
| [Minerstat](https://minerstat.com/mining-pool-whitelist.txt) | cryptomining | Coinminer activity with known mining pools| Workload Protection and Cloud SIEM |
85+
| Tor | tor | Policy violations for user activity | App and API Protection, Cloud SIEM, and Workload Protection |
86+
| [Threatfox](https://threatfox.abuse.ch/) | malware | Identify hosts communicating with known malware infrastructure | Cloud SIEM, and Workload Protection |
8787

8888

8989
### Threat Intelligence Categories
@@ -93,11 +93,12 @@ Sources, categories, and intents are available as facets and filters on relevant
9393
| residential_proxy | suspicious | IP addresses | Reputation for credential stuffing and fraud | AAP and Cloud SIEM |
9494
| botnet_proxy | suspicious | IP addresses | Reputation for being part of a botnet and contributing to distributed attacks | AAP and Cloud SIEM |
9595
| malware | malicious | application library versions, file hashes | Malicious packages and communication with mining pools| CWS |
96-
| scanner | suspicious | IP addresses | Reputation for scanners | AAP and Cloud SIEM |
96+
| scanner | suspicious | IP addresses | Reputation for scanners | App and API Protection, Workload Protection, and Cloud SIEM |
9797
| hosting_proxy | suspicious | IP addresses | Datacenter IPs with a reputation of abuse, such as for distributed credential stuffing attacks | AAP and Cloud SIEM |
98-
| tor | suspicious | IP addresses | Corporate policy violations for user activity | AAP and Cloud SIEM |
98+
| tor | suspicious | IP addresses | Corporate policy violations for user activity | App and API Protection, Workload Protection, and Cloud SIEM |
9999
| disposable_email | suspicious | Domain | Detect product usage from disposable email addresses | AAP |
100100
| corp_vpn | benign | IP addresses | IPs associated to corporate VPNs | AAP and Client SIEM |
101+
| cryptomining | malicious | IP addresses | IP addresses associated with cryptomining activities | AAP, CWS, and Cloud SIEM |
101102

102103
### Threat Intelligence Intents
103104
| Intent | Use Case |

0 commit comments

Comments
 (0)