User Tools

Site Tools


ids:emerging_threats:emerging_threat_categories

This is an old revision of the document!


IDS - Emerging Threats - Emerging Threat Categories

3CORESec

CategoryDescriptionReference
3CORESecGenerated automatically from the 3CORESec team IP block lists; based on malicious activity from their Honeypots.https://blacklist.3coresec.net/lists/et-open.txt
ActiveXProtects against attacks and exploits against Microsoft ActiveX controls.
Adware-PUPAd tracking and spyware related activity.
Attack ResponseIdentifies responses indicative of intrusion; such as LMHost file download, presence of certain web banners and the detection of Metasploit Meterpreter kill command.
Botcc (Bot Command and Control)Autogenerated from several sources of known and confirmed active botnet and other Command and Control (C2) hosts.https://www.shadowserver.org
Botcc PortgroupedSimilar to the Botcc category but grouped by destination port. Rules grouped by port can offer higher fidelity than those not grouped by port.

References

ids/emerging_threats/emerging_threat_categories.1626782112.txt.gz · Last modified: 2021/07/20 11:55 by peter

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki