User Tools

Site Tools


ids:emerging_threats:emerging_threat_categories

This is an old revision of the document!


IDS - Emerging Threats - Emerging Threat Categories

CategoryDescriptionReference
3CORESecGenerated automatically from the 3CORESec team IP block lists; based on malicious activity from their Honeypots.https://blacklist.3coresec.net/lists/et-open.txt
ActiveXProtects against attacks and exploits against Microsoft ActiveX controls.
Adware-PUPAd tracking and spyware related activity.
Attack ResponseIdentifies responses indicative of intrusion; such as LMHost file download, presence of certain web banners and the detection of Metasploit Meterpreter kill command.
Botcc (Bot Command and Control)Autogenerated from several sources of known and confirmed active botnet and other Command and Control (C2) hosts.https://www.shadowserver.org
Botcc PortgroupedSimilar to the Botcc category but grouped by destination port. Rules grouped by port can offer higher fidelity than those not grouped by port.
ChatTraffic related to numerous chat clients such as Internet Relay Chat (IRC). Chat traffic can be indicative of possible check-in activity by threat actors.
CIArmyGenerated using Collective Intelligence IP rules for blocking.https://www.cinsscore.com
CoinminingRules that detect malware which performs coin mining.
CompromisedBased on a list of known compromised hosts that is confirmed and updated daily from several private but highly reliable data sources.

References

ids/emerging_threats/emerging_threat_categories.1626783433.txt.gz · Last modified: 2021/07/20 12:17 by peter

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki