Indicator Types in ThreatStream

The following table lists all available indicator types in ThreatStream.

The severity values listed in the table below represent the default severity values that Anomali assigns to observables of a given indicator types. However, default values are not displayed in the following cases:

  1. When severity value assigned to an observable by the source is used.
  2. When users modify the assigned value while editing observables that belong to their organizations on ThreatStream.
Notes: 
- Observables assigned indicator types which display String in the Type column below are not consumed by downstream integrations such as Anomali Security Analytics or those which receive intelligence through ThreatStream Integrator. Additionally, string-type observables cannot be cloned in ThreatStream.
- MD5 observables ingested from feeds are never made inactive by ThreatStream. However, MD5 observables imported through other means, such as the import assistant, adhere to the expiration dates you set.
Indicator Type Name Type Severity Description
actor_ip Actor IP IP Low

IP address associated with a system involved in a malicious activity.

Example: itype="actor_ip"

actor_ipv6 Actor IPv6 IP Low

IPv6 address associated with a system involved in a malicious activity.

Example: itype="actor_ipv6"

actor_phone_number Actor Phone Number String Low

Phone number associated with a threat actor.

Example: itype="actor_phone_number"

actor_subject Actor Subject Line String High

Subject from an email associated with a threat actor.

Example: itype="actor_subject"

actor_username Actor Username String Low

Username associated with a threat actor.

Example: itype="actor_username"

adware_domain Adware Domain Domain Low

Domain name associated with adware or other Potentially Unwanted Applications (PUA).

Example: itype="adware_domain"

adware_registry_key Adware Registry Key String Low

Registry key associated with adware or other Potentially Unwanted Applications (PUA).

Example: itype="adware_registry_key"

anon_proxy Anonymous Proxy IP IP Low

IP address of the system on which anonymous proxy software is hosted.

Example: itype="anon_proxy"

anon_proxy_ipv6 Anonymous Proxy IPv6 IP Low

IPv6 address of the system on which anonymous proxy software is hosted.

Example: itype="anon_proxy_ipv6"

anon_vpn Anonymous VPN IP IP Low

IP address associated with commercial or free Virtual Private Networks (VPN).

Example: itype="anon_vpn"

anon_vpn_ipv6 Anonymous IP Low

IPv6 address associated with commercial or free Virtual Private Networks (VPN).

Example: itype:"anon_vpn_ipv6"

apt_domain APT Domain Domain Very High

Domain name associated with a known Advanced Persistent Threat (APT) actor used for command and control, launching exploits, or data exfiltration.

Example: itype=" apt_domain"

apt_email APT Email Email High

Email address used by a known Advanced Persistent Threat (APT) actor for sending targeted, spear phishing emails.

Example: itype="apt_email"

apt_email_subject_line APT Email Subject Line String High

Subject from an email associated with an Advanced Persistent Threat (APT) actor.

Example: itype="apt_email_subject_line"

apt_file_name APT File Name String Very High

Name of a file used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_file_name"

apt_file_path APT File Path String Very High

File path used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_file_path"

apt_ip APT IP IP Very High

IP address associated with known Advanced Persistent Threat (APT) actor for command and control, data exfiltration, or targeted exploitation.

Example: itype="apt_ip"

apt_ipv6 APT IPv6 IP Very High

IPv6 address associated with known Advanced Persistent Threat (APT) actor for command and control, data exfiltration, or targeted exploitation.

Example: itype="apt_ipv6"

apt_md5 APT File Hash Hash Very High

MD5 or SHA hash of a malware sample used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_md5"

apt_mta APT Mail Transfer Agent String Very High

Mail transfer agent used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_mta"

apt_mutex APT Mutex String Very High

Mutex used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_mutex"

apt_registry_key APT Registry Key String Very High

Registry key used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_registry_key"

apt_service_description APT Service Description String Very High

Description used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_service_description"

apt_service_displayname APT Service Display Name String Very High

Service display name used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_service_displayname"

apt_service_name APT Service Name String Very High

Service name used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_service_name"

apt_ssdeep APT SSDeep Hash String Very High

SSDeep Hash used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_ssdeep"

apt_subject APT Subject Line String High

Email subject line used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_subject"

apt_ua APT User Agent String High

User agent string used by a known Advanced Persistent Threat (APT) actor.

Example: itype="apt_ua"

apt_url APT URL URL Very High

URL used by a known Advanced Persistent Threat (APT) actor for command and control, launching web based exploits, or data exfiltration.

Example: itype=" apt_url"

asn ASN String Medium

Autonomous System Number

Example: itype="asn"

aws_account_id AWS Account ID String High

AWS account identifier potentially involved in malicious activities.

Example: itype="aws_account_id"

benign_device_id Benign Device ID String Low

Trusted device identifier.

Example: itype="benign_device_id"

benign_domain Benign Domain Domain Low

Allowlisted domain.

Example: itype="benign_domain"

benign_email Benign Email Email Low

Allowlisted email address.

Example: itype="benign_email"

benign_hash Benign Hash String Low

Allowlisted hash value.

Example: itype="benign_hash"

benign_internal_email Benign Internal Email Email Medium

Internal email address.

Example: itype="benign_internal_email"

benign_ip Benign IP IP Low

Allowlisted IP address.

Example: itype="benign_ip"

benign_url Benign URL String Low

Allowlisted URL.

Example: itype="benign_url"

bitcoin_wallet Bitcoin Wallet Address String High

Bitcoin wallet used in transactions.

Example: itype="bitcoin_wallet'

bot_domain Infected Bot Domain Name Domain Low

Domain name of an infected machine acting as an autonomous bot.

Example: itype="bot_domain"

bot_ip Infected Bot IP IP Low

IP address of an infected machine acting as an autonomous bot.

Example: itype="bot_ip"

bot_ipv6 Infected Bot IPv6 IP Low

IPv6 address of an infected machine acting as an autonomous bot.

Example: itype="bot_ipv6"

bot_md5 Infected Bot Hash Hash Low

Hash related to a file used by an infected machine acting as an autonomous bot.

Example: itype="bot_md5"

bot_url Infected Bot URL URL Low

URL of an infected machine acting as an autonomous bot.

Example: itype="bot_url"

botnet_user_agent Botnert User Agent String Medium

User agent string used by a botnet for malicious activity.

Example: itype="botnet_user_agent"

browser_extension_id Browser Extension ID String High

Unique ID given to each browser extension, which is available in the Extension store of such browsers as Firefox, Chrome, and so on.

Example: itype="browser_extension_id"

brute_ip Brute Force IP IP Low

IP address associated with password brute force activity.

Example: itype="brute_ip"

brute_ipv6 Brute Force IPv6 IP Low

IPv6 address associated with password brute force activity.

Example: itype="brute_ipv6"

c2_domain Malware C&C Domain Name Domain High

Domain name used by malware for command and control communication.

Example: itype="c2_domain"

c2_dns_name Malware C&C DNS Name Domain High

DNS name used by malware for command and control communication.

Example: itype="c2_dns_name"

c2_ip Malware C&C IP Address IP High

IP address used by malware for command and control communication.

Example: itype="c2_ip"

c2_ipv6 Malware C&C IPv6 Address IP High

IPv6 address used by malware for command and control communication.

Example: itype="c2_ipv6"

c2_url Malware C&C URL URL High

URL used by malware for command and control communication.

Example: itype="c2_url"

cloud_instance_id Cloud Instance ID String High

Cloud VM or container instance identifier.

Example: itype="cloud_instance_id"

cobalt_strike_id Cobalt Strike ID String High

Cobalt Strike or malware identifier.

Example: itype="cobalt_strike_id"

corp_vpn_ip Corp VPN IP IP Medium

Internal VPN exit node IP for remote employees.

Example: itype="corp_vpn_ip"

comm_proxy_domain Commercial Webproxy Domain Domain Low

Domain of the system on which commercial proxy software is hosted.

Example: itype="comm_proxy_domain"

comm_proxy_ip Commercial Webproxy IP IP Low

IP address of the system on which commercial proxy software is hosted.

Example: itype="comm_proxy_ip"

comm_proxy_ipv6 Commercial Webproxy IPv6 IP Low

IPv6 address associated with a commercial web proxy.

Example: itype="comm_proxy_ipv6"

compromised_email Compromised Account Email Email Low

Email address that has been compromised and/or taken over by a threat actor.

Example: itype="compromised_email"

compromised_company Compromised Company String High

Name of a compromised company.

Example: itype="compromised_company"

compromised_domain Compromised Domain Domain Low

Domain name of website or server that has been compromised.

Example: itype="compromised_domain"

compromised_email_subject Compromised Email Subject String Low

Email subject from a known compromised email address.

Example: itype="compromised_email_subject"

compromised_ip Compromised IP IP Low

IP address of website or server that has been compromised.

Example: itype="compromised_ip"

compromised_ipv6 Compromised IPv6 IP Low

IPv6 address of website or server that has been compromised.

Example: itype="compromised_ipv6"

compromised_password Compromised Password String Low

Plaintext or hashed password value associated with a compromised credential record.

Example: itype="compromised_password"

compromised_port Compromised Port String Low

Network port associated with a compromised device or session.

Example: itype="compromised_port"

compromised_serv_account Compromised Service Account String Low

Account information associated with a service account that has been compromised and/or taken over by a threat actor.

Example: itype="compromised_serv_account"

compromised_url Compromised URL URL Medium

URL of the website or server that has been compromised.

Example: itype="compromised_url"

compromised_username Compromised Username String Medium

Username that has been compromised and/or taken over by a threat actor. Must have a length of 128 characters or less.

Example: itype="compromised_username"

crypto_hash Cryptocurrency Mining Software Hash High

File hash for cryptocurrency mining software.

Example: itype="crypto_hash"

crypto_ip Cryptocurrency IP IP High

IP address associated with a cryptocurrency mining software.

Example: itype="crypto_ip"

crypto_ipv6 Cryptocurrency IPv6 IPv6 Medium

IPv6 address associated with a cryptocurrency mining software.

Example: itype="crypto_ipv6"

crypto_pool Cryptocurrency Pool Domain Domain High

Domain for cryptocurrency pool.

Example: itype="crypto_pool"

crypto_url Cryptocurrency URL URL High

URL where cryptocurrency mining software is hosted.

Example: itype="crypto_url"

crypto_wallet Cryptocurrency Wallet Address String Very High

Public or private cryptocurrency wallet key.

Example: itype="crypto_wallet"

customer_account_id Customer Account ID String High

Identifier for an internal customer account.

Example: itype="customer_account_id"

ddos_ip DDOS IP IP Low

IP address associated with Distributed Denial of Service (DDoS) attacks.

Example: itype="ddos_ip"

ddos_ipv6 DDOS IPv6 IP Low

IPv6 address associated with Distributed Denial of Service (DDoS) attacks.

Example: itype="ddos_ipv6"

device_serial_number Device Serial Number String Medium

Unique serial number of an endpoint, laptop, or mobile device.

Example: itype="device_serial_number"

disposable_email_domain Disposable Email Domain Domain Low

Domain associated with disposable email activity.

Example: itype="disposable_email_domain"

downloader_domain Downloader Domain Domain High

Domain associated with a downloader, which is a type of malware that downloads and runs other malware.

Example: itype="downloader_domain"

downloader_hash Downloader File Hash Hash High

Hash of a malicious file associated with a downloader, which is a type of malware that downloads and runs other malware.

Example: itype="downloader_hash"

downloader_ip Downloader IP IP High

IP address associated with a downloader, which is a type of malware that downloads and runs other malware.

Example: itype="downloader_ip"

downloader_ipv6 Downloader IPv6 IP High

IPv6 address associated with a downloader, which is a type of malware that downloads and runs other malware.

Example: itype="downloader_ipv6"

downloader_url Downloader URL URL High

URL associated with a downloader, which is a type of malware that downloads and runs other malware.

Example: itype="downloader_url"

dyn_dns Dynamic DNS Domain Low

Domain name used for hosting Dynamic DNS services.

Example: itype="dyn_dns"

email_attachment_subject Email Attachment Subject String Low

Email subject from a known compromised email attachment.

Example: itype="email_attachment_subject"

employee_id Employee ID String Medium

Internal identifier assigned to an employee.

Example: itype="employee_id"

encrypted_file_ext Encrypted File EXT String High

Encrypted file extension used by malware.

Example: itype="encrypted_file_ext"

exfil_domain Data Exfiltration Domain Domain High

Domain name associated with the infrastructure used for data exfiltration.

Example: itype="exfil_domain"

exfil_ip Data Exfiltration IP IP High

IP address used for data exfiltration.

Example: itype="exfil_ip"

exfil_ipv6 Data Exfiltration IP IP High

IPv6 address used for data exfiltration.

Example: itype="exfil_ipv6"

exfil_url Data Exfiltration URL URL High

URL used for data exfiltration.

Example: itype="exfil_url"

exploit_domain Exploit Kit Domain Domain Very High

Domain name associated with the web server hosting an exploit kit or launching web-based exploits.

Example: itype="exploit_domain"

exploit_ip Exploit Kit IP IP High

IP address associated with the web server hosting an exploit kit or launching web-based exploits.

Example: itype="exploit_ip"

exploit_ipv6 Exploit Kit IPv6 IP High

IPv6 address associated with the web server hosting an exploit kit or launching web-based exploits.

Example: itype="exploit_ipv6"

exploit_cve_id Exploit CVE ID String High

CVE identifier for a vulnerability being exploited.

Example: itype="exploit_cve_id"

exploit_md5 Exploit Hash Hash Low

Hash related to a file used to exploit a known vulnerability.

Example: itype="exploit_md5"

exploit_url Exploit Kit URL URL Very High

URL used for launching web-based exploits.

Example: itype="exploit_url"

fraud_domain Fraud Domain Domain High

Domain associated with a fraudulent activity.

Example: itype="fraud_domain"

fraud_email Fraud Email Email Low

Email address associated with a fraudulent activity.

Example: itype="fraud_email"

fraud_email_subject Fraud Email Subject String Medium

Subject from an email associated with fraud activity.

Example: itype="fraud_email_subject"

fraud_file_name Fraud File Name String Medium

File name used in a fraud scheme.

Example: itype="fraud_file_name"

fraud_ip Fraud IP Address IP High

IP address associated with a fraudulent activity.

Example: itype="fraud_ip"

fraud_ipv6 Fraud IPv6 IP High

An IPv6 address associated with a fraudulent activity.

Example: itype="fraud_ipv6"

fraud_md5 Fraud Hash Hash Very High

Hash associated with a fraudulent activity.

Example: itype="fraud_md5"

fraud_url Fraud URL URL Medium

URL associated with a fraudulent activity.

Example: itype="fraud_url"

free_email_domain Free Email Domain Domain Low

Domain associated with free email service activity.

Example: itype="free_email_domain"

freq_abused_dns_provider Frequently Abused DNS Provider String Medium

Name of a frequently abused DNS provider.

Example: itype="freq_abused_dns_provider".

gaming_device_id Device ID String High

ID of the gaming device associated with a malicious activity.

Example: itype="gaming_device_id"

gaming_device_name Device Name String High

Name of the gaming device associated with a malicious activity.

Example: itype="gaming_device_name"

gaming_game_id Game ID String High

ID of the game associated with a malicious activity.

Example: itype="gaming_game_id"

gaming_game_name Game Name String Low

Name of the game associated with a malicious activity.

Example: itype="gaming_game_name"

gaming_player_country Player Country String Low

Country of the player associated with a malicious activity.

Example: itype="gaming_player_country"

gaming_player_email Player Email Email High

Player's email address associated with a malicious activity.

Example: itype="gaming_player_email"

gaming_player_id Player ID String High

Player's ID associated with a malicious activity.

Example: itype="gaming_player_id"

gaming_player_nickname Player Nickname String Medium

Player's nickname associated with a malicious activity.

Example: itype="gaming_player_nickname"

gaming_player_phone Player Phone Phone Number Medium

Player's phone number associated with a malicious activity.

Example: itype="gaming_player_phone"

geolocation_url IP Geolocation URL URL Low

URL that can be used to provide IP Geo location services.

Example: itype="geolocation_url"

hack_tool Hacking Tool String High

Name of general hacking software tools used by threat actors.

Example: itype="hack_tool"

hack_tool_md5 Hack Tool File Hash Hash Very High

MD5 or SHA hash of general hacking software tools used by threat actors.

Example: itype="hack_tool_md5"

iam_user_id IAM User ID String High

User identity in an internal IAM system.

Example: itype="iam_user_id"

i2p_ip I2P IP Address IP Low

IP address observed to be connecting to the I2P (Invisible Internet Project) network.

Example: itype="i2p_ip"

i2p_ipv6 I2P IPv6 Address IP Low

IPv6 address observed to be connecting to the I2P (Invisible Internet Project) network.

Example: itype="i2p_ipv6"

image_hash Image Hash String Low

Cryptographic hash of the image used for comparing two different images. It differs from typical MD5, SHA1, SHA2 hashes.

Example: itype="image_hash"

infostealer_domain Information Stealer Domain Domain Very High

Domain associated with an information stealer.

Example: itype="infostealer_domain"

infostealer_hash Information Stealer File Hash Hash Very High

Hash of a malicious file associated with an information stealer.

Example: itype="infostealer_hash"

infostealer_ip Information Stealer IP IP Very High

IP address associated with an information stealer.

Example: itype="infostealer_ip"

infostealer_ipv6 Information Stealer IPv6 IP Very High

IPv6 address associated with an information stealer.

Example: itype="infostealer_ipv6"

infostealer_url Information Stealer URL URL Very High

URL associated with an information stealer.

Example: itype="infostealer_url"

internal_dns_name Internal DNS Name String Medium

Internal hostname or DNS record.

Example: itype="internal_dns_name"

internal_host_id Internal Host ID String High

Identifier for workstation, server, or Cloud VM.

Example: itype="internal_host_id"

internal_ticket_id Internal Ticket ID String Low

Internal support or security ticket ID.

Example: itype="internal_ticket_id"

iot_domain Internet of Things Malicious Domain Domain Medium

Domain associated with malware targeting Internet of Things devices.

Example: itype="iot_domain"

iot_hash Internet of Things Malicious File Hash Hash High

Hash of a malicious sample targeting Internet of Things devices.

Example: itype="iot_hash"

iot_ip Internet of Things Malicious IP IP Medium

IP address associated with malware targeting Internet of Things devices.

Example: itype="iot_ip"

iot_ipv6 Internet of Things Malicious IPv6 IP Medium

IPv6 associated with malware targeting Internet of Things devices.

Example: itype="iot_ipv6"

iot_url Internet of Things Malicious URL URL Medium

URL associated with malware targeting Internet of Things devices and services.

Example: itype="iot_url"

ipcheck_url IP Check URL URL Low

URL that can be used to provide IP checking services, such as echoing the Internet facing IP address of the client.

Example: itype="ipcheck_url"

ja3_md5 JA3/JA3S TLS Fingerprint Hash Medium

TLS Client/Server fingerprint.

Example: itype="ja3_md5"

ja4_tls_fingerprint JA4 TLS Fingerprint Hash Medium

TLS Client/Server fingerprint.

Example: itype="ja4_tls_fingerprint"

mal_domain Malware Domain Domain Very High

Domain contacted by malware sample; could be for command and control commands, or to check if the client is online.

Example: itype="mal_domain"

mal_email Malware Email Email Low

Email address used to send malware through malicious links or attachments.

Example: itype="mal_email"

mal_email_subject Malware Email Subject String Medium

Subject from an email associated with malware activity.

Example: itype="mal_email_subject"

mal_file_name Malware File Name String Very High

File name of malware sample.

Example: itype="mal_file_name"

mal_file_path Malware File Path String Very High

File path of malware sample.

Example: itype="mal_file_path"

mal_http_header Malicious HTTP Header String High

HTTP header related to malicious requests.

Example: itype="mal_http_header"

mal_ip Malware IP IP Very High

IP address contacted by malware sample; could be for command and control commands, or to check if the client is online.

Example: itype="mal_ip"

mal_ipv6 Malware IPv6 IP Very High

IPv6 address contacted by malware sample; could be for command and control commands, or to check if the client is online.

Example: itype="mal_ipv6"

mal_md5 Malware File Hash Hash Very High

MD5 or SHA hash of malware sample.

Example: itype="mal_md5"

mal_mutex Malware Mutex String Very High

Mutex of malware sample.

Example: itype="mal_mutex"

mal_port Malware Port String Very High

Malware-associated network port or IP-port composite value.

Example: itype="mal_port"

mal_registry_key Malware Registry Key String High

Registry key of malware sample.

Example: itype="mal_registry_key"

mal_relay_server_ip Malicious Relay Server IP IP Medium

IP address of a malicious relay server.

Example: itype="mal_relay_server_ip"

mal_relay_relay_server_ipv6 Malicious Relay Server IPv6 IP Medium

IPv6 address of a malicious relay server.

Example: itype="mal_relay_server_ipv6"

mal_service_description Malware Service Description String Very High

Service description associated with the malware sample.

Example: itype="mal_service_description"

mal_service_displayname Malware Service Display Name String Very High

Service display name associated with the malware sample.

Example: itype="mal_service_displayname"

mal_service_name Malware Service Name String Very High

Service name associated with the malware sample.

Example: itype="mal_service_name"

mal_smtp_header Malicious SMTP Header String High

SMTP header related to a malicious email activity.

Example: itype="mal_smtp_header"

mal_ssdeep Malware SSDeep Hash String Very High

SSDeep Hash associated with the malware sample.

Example: itype="mal_ssdeep"

mal_sslcert_sha1 SSL Certificate Hash Hash High

MD5 or SHA hash of SSL certificate associated with malware or botnet activities.

Example: itype="mal_sslcert_sha1"

mal_ua Malware User Agent String Low

User agent string used by malware sample when communicating via HTTP.

Example: itype="mal_ua"

mal_url Malware URL URL Very High

URL contacted by malware sample when run on an infected host.

Example: itype="mal_url"

mal_wildcard_domain Malware Wildcard Domain String High

A wildcard domain associated with malware activities.

Example: itype="mal_wildcard_domain"

mal_wildcard_url Malware Wildcard URL String High

A wildcard URL associated with malware activities.

itype="mal_wildcard_url"

mobile_malware Mobile Malware String High

Indicator related to mobile malware.

Example: itype="mobile_malware"

new_domain New Domain Domain Low

Recently registered domain with insufficient history to fully evaluate.

Example: itype="new_domain"

p2pcnc Peer-to-Peer C&C IP Address IP Medium

IP addressed associated with a peer-to-peer command and control infrastructure.

Example: itype="p2pcnc"

p2pcnc_ipv6 Peer-to-Peer C&C IPv6 Address IP Medium

IPv6 addressed associated with a peer-to-peer command and control infrastructure.

Example: itype="p2pcnc_ipv6"

parked_domain Parked Domain Domain Low

Domain name of a website which is currently parked.

Example: itype="parked_domain"

parked_ip Domain Parking IP IP Low

IP addressed used for parking newly registered or inactive domain names.

Example: itype="parked_ip"

parked_ipv6 Domain Parking IPv6 IP Low

IPv6 addressed used for parking newly registered or inactive domain names.

Example: itype="parked_ipv6"

parked_url Parked URL URL Low

URL of a website that is currently parked.

Example: itype="parked_url"

pastesite_url Paste Site URL URL Low

URL that can be used for sharing pastes or text content anonymously.

Example: itype="pastesite_url"

phish_domain Phishing Domain Domain Very High

Domain used to perform phishing or spear phishing attacks or contained in a phishing email.

Example: itype="phish_domain"

phish_email Phishing Email Address Email Very High

Email address associated with sending phishing or spear phishing emails to victims.

Example: itype="phish_email"

phish_email_subject Phishing Email Subject String High

Subject from an email associated with phishing activity.

Example: itype="phish_email_subject"

phish_file_name Phishing File Name String Medium

File name used in a phishing attack.

Example: itype="phish_file_name"

phishing_target Phishing Target String High

Identifier for phishing victims.

Example: itype="phishing_target"

phish_ip Phishing IP Address IP Very High

IP address that has been used to perform phishing or spear phishing or is contained in a phishing email.

Example: itype="phish_ip"

phish_ipv6 Phishing IPv6 Address IP Very High

IPv6 address that has been used to perform phishing or spear phishing or is contained in a phishing email.

Example: itype="phish_ipv6"

phish_md5 Phishing File Hash Hash Very High

Hash related to a file used to perform phishing or spear phishing attacks or contained in a phishing email.

Example: itype="phish_md5"

phish_url Phishing URL URL Very High

URL used to perform phishing or spear phishing attacks or contained in a phishing email.

Example: itype="phish_url"

phish_victim_email Phishing Victim Email Email Low

Email of a user who was a victim of a phishing attack.

Example: itype="phish_victim_email"

phone_number Phone Number String Medium

Phone number used in fraudulent activities.

Example: itype="phone_number"

platform_uid Platform UID String Medium

Unique user ID from a specific platform.

Example: itype="platform_uid"

pos_domain Point of Sale Malicious Domain Domain Medium

Domain associated with malware targeting Point of Sales systems.

Example: itype="pos_domain"

pos_hash Point of Sale Malicious File Hash Hash High

Malicious file hash targeting Point of Sales systems.

Example: itype="pos_hash"

pos_ip Point of Sale Malicious IP IP Medium

IP address associated with malware targeting Point of Sale systems.

Example: itype="pos_ip"

pos_ipv6 Point of Sale Malicious IPv6 IP Medium

IPv6 address associated with malware targeting Point of Sales systems.

Example: itype="pos_ipv6"

pos_url Point of Sale Malicious URL URL Medium

URL associated with malware targeting Point of Sales systems.

Example: itype="pos_url"

proxy_ip Open Proxy IP IP Low

IP address hosting open or anonymous proxy software. Allows user to hide their IP address from target.

Example: itype="proxy_ip"

proxy_ipv6 Open Proxy IPv6 IP Low

IPv6 address hosting open or anonymous proxy software. Allows user to hide their IP address from target.

Example: itype="proxy_ipv6"

ransomware_domain Ransomware Domain Domain Very High

Domain associated with ransomware.

Example: itype="ransomware_domain"

ransomware_hash Ransomware File Hash Hash Very High

File hash of a malicious ransomware sample.

Example: itype="ransomware_hash"

ransomware_ip Ransomware IP IP Very High

IP address associated with ransomware.

Example: itype="ransomware_ip"

ransomware_ipv6 Ransomware IPv6 IP Very High

IPv6 address associated with ransomware.

Example: itype="ransomware_ipv6"

ransomware_group Ransomware Group String Low

Group associated with ransomware.

Example: itype="ransomware_group"

ransomware_url Ransomware URL URL Very High

URL associated with ransomware.

Example: itype="ransomware_url"

ransomware_victim_domain Ransomware Victim Domain Domain Low

Domain of a ransomware victim.

Example: itype="ransomware_victim_domain"

ransomware_victim_name Ransomware Victim Name String Low

Name of a ransomware victim.

Example: itype="ransomware_victim_name"

ransomware_victim_url Ransomware Victim URL URL Low

URL of a ransomware victim.

Example: itype="ransomware_victim_url"

rootkit_hash Rootkit File Hash Hash Very High

File hash of rootkit malware that provides root-level access to an attacker.

Example: itype="rootkit_hash"

scan_ip Scanning IP IP Medium

IP address observed to perform port scanning and vulnerability scanning activities.

Example: itype="scan_ip"

scan_ipv6 Scanning IPv6 IP Medium

IPv6 address observed to perform port scanning and vulnerability scanning activities.

Example: itype="scan_ipv6"

session_token Session Token String High

Temporary authentication token for session management.

Example: itype="session_token"

sinkhole_domain Sinkhole Domain Domain Low

Domain name that researchers or security companies typically sinkhole.

Example: itype="sinkhole_domain"

sinkhole_ip Sinkhole IP IP Low

IP address that is known to be used to sinkhole malicious domain names.

Example: itype="sinkhole_ip"

sinkhole_ipv6 Sinkhole IPv6 IP Low

IPv6 address that is known to be used to sinkhole malicious domain names.

Example: itype="sinkhole_ipv6"

social_forum_name Forum Name String Low

Name of the social forum associated with a malicious activity.

Example: itype="social_forum_name"

social_media_name Social Media Name String Medium

Name of the social media associated with a malicious activity.

Example: itype="social_media_name"

social_media_url Social Media URL URL Medium

URL related to social media activity. This indicator type is provided by select feeds and cannot be imported through the ThreatStream user interface.

Example: itype="social_media_url"

social_messaging_services Messaging Services String Low

Messaging service used for malicious activity.

Example: itype="social_messaging services"

spam_domain Spam Domain Domain Low

Malicious domain name contained in the SPAM email messages.

Example: itype="spam_domain"

spam_email Spammer Email Address Email Low

Email address that has been observed sending SPAM emails.

Example: itype="spam_email"

spam_email_subject Spam Email Subject String Low

Subject from an email associated with spam activity.

Example: itype="spam_email_subject"

spam_ip Spammer IP IP Low

IP address that is known to send SPAM emails.

Example: itype="spam_ip"

spam_ipv6 Spammer IPv6 IP Low

IPv6 address that is known to send SPAM emails.

Example: itype="spam_ipv6"

spam_mta Spam Mail Transfer Agent String Low

Mail transfer agent known to be associated with SPAM emails.

Example: itype="spam_mta"

spam_url Spam URL URL Low

Malicious URL contained in the SPAM email messages.

Example: itype="spam_url"

speedtest_url Speed Test URL URL Low

URL that can be used to run internet speed tests or bandwidth measurements of the client's network connection.

Example: itype="speedtest_url"

ssh_ip SSH Brute Force IP IP Low

IP addresses associated with SSH brute force attempts.

Example: itype="ssh_ip"

ssh_ipv6 SSH Brute Force IPv6 IP Low

IPv6 addresses associated with SSH brute force attempts.

Example: itype="ssh_ipv6"

ssl_cert_serial_number SSL Certificate Serial Number String Low

Serial number unique to the TLS certificate issuer that identifies the entity being signed.

Example: itype="ssl_cert_serial_number"

sso_session_id SSO Session ID String High

Identifier for an active SSO session.

Example: itype="sso_session_id"

suppress Suppress n/a n/a

Not a true indicator type. Used by Arcsight for suppressing false positives.

Default severity: n/a

Example: itype="suppress"

suppress_ipv6 Suppress Alerts IPv6 IP Low

IPv6 address related to alert suppression.

Example: itype="suppress_ipv6"

suspected_c2_dns_name Suspected C&C DNS Name Domain Medium

Suspected DNS name used by malware for command and control communication.

Example: itype="suspected_c2_dns_name"

suspicious_cmd_line Suspicious CMD Line String Medium

Command-line arguments used in execution.

Example: itype="suspicious_cmd_line"

suspicious_domain Suspicious Domain Domain Medium

Domain name that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="suspicious_domain"

suspicious_email Suspicious Email Email Low

Email address that appears to be used for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="suspicious_email"

suspicious_email_subject Suspicious Email Subject String Low

Email subject from a suspicious email address.

Example: itype="suspicious-email_subject"

suspicious_ip Suspicious IP IP Medium

IP address that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="suspicious_ip"

suspicious_ipv6 Suspicious Ipv6 IP Medium

IPv6 address related to a suspcious activity.

Example: itype="suspicious_ipv6"

suspicious_md5 Suspicious Hash Hash Low

Hash related to a suspicious activity.

Example: itype="suspicious_md5"

suspicious_reg_email Suspicious Registrant Email Email Low

Registrant email address that appears to be used for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="suspicious_reg_email"

sus_wildcard_domain Suspicious Wildcard Domain String Medium

A wildcard domain that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="sus_wildcard_domain"

sus_wildcard_url Suspicious Wildcard URL String Medium

A wildcard URL that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="sus_wildcard_url"

suspicious_url Suspicious URL URL Medium

URL that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet.

Example: itype="suspicious_url"

telegram_id Telegram ID String Medium

Telegram user or group ID.

Example: itype="telegram_id"

threat_actor_hostname Threat Actor Hostname String High

Hostname associated with a threat actor.

Example: itype="threat_actor_hostname"

tor_ip TOR Node IP IP Low

IP address operating as part of The Onion Router (TOR) Network, also know as a TOR exit node.

Example: itype="tor_ip"

tor_ipv6 TOR Node IPv6 IP Low

IPv6 address operating as part of The Onion Router (TOR) Network, also know as a TOR exit node.

Example: itype="tor_ipv6"

torrent_tracker_url Torrent Tracker URL URL Low

URL used for tracking bittorrent file transfer activity.

Example: itype="torrent_tracker_url"

tox_id Tox ID String Medium

TOX messaging platform ID.

Example: itype="tox_id"

trojan_domain Trojan Domain Domain High

Domain associated with Trojan malware that disguises as a legitimate code or software.

Example: itype="trojan_domain"

trojan_hash Trojan File Hash Hash High

File hash associated with Trojan malware that disguises as a legitimate code or software.

Example: itype="trojan_hash"

trojan_ip Trojan IP Address IP High

IP address associated with Trojan malware that disguises as a legitimate code or software.

Example: itype="trojan_ip"

trojan_ipv6 Trojan IPv6 Address IP High

IPv6 address associated with a Trojan malware that disguises as a legitimate code of software.

Example: itype="trojan_ipv6"

trojan_url Trojan URL URL High

URL associated with a Trojan malware that disguises as a legitimate code or software.

Example: itype="trojan_url"

twitter_handle Twitter Handle String Medium

Twitter handle or social media identifier.

Example: itype="twitter_handle"

visitor_token Visitor Token String High

Token used for session tracking.

Example: itype="visitor_token"

vpn_domain Anonymous VPN Domain Domain Low

Domain name associated with commercial or free Virtual Private Networks (VPN).

Example: itype="vpn_domain"

vps_ip Cloud Server IP IP Low

IP address that is used for hosting Virtual Private Servers (VPS) or other server rentals.

Example: itype="vps_ip"

vps_ipv6 Cloud Server IPv6 IP Low

IPv6 address that is used for hosting Virtual Private Servers (VPS) or other server rentals.

Example: itype="vps_ipv6"

vuln_risk_score Vulnerability Risk Score String Low

Risk score for a vulnerability.

Example: itype="vuln_risk_score"

web3_attack_vector Web 3 Attack Vector String High

Address of a known malicious smart contract.

Example: itype="web3_attack_vector"

web3_compromised_wallet Web3 Compromised Wallet String High

Wallet address involved in fraudulent or malicious transactions.

Example: itype="web3_compromised_wallet"

web3_dns_hijacking Web3 DNS Hijacking String Medium

Detection of tampering attempts on decentralized DNS (for example, ENS).

Example: itype="web3_dns_hijacking"

web3_exploitable_code Web3 Exploitable Code String High

Code pattern within dApps or smart contracts vulnerable to attacks.

Example: itype="web3_exploitable_code"

web3_malicious_contract Web3 Malicious Contract String High

Address of a known malicious smart contract.

Example: itype="web3_malicious_contract"

web3_malicious_token Web3 Malicious Token String High

Identifier of a fraudulent or scam-related token contract.

Example: itype="web3_malicious_token"

web3_phishing_domain Web3 Phishing Domain String High

Domain or URL used for Web3 phishing attacks.

Example: itype="web3_phishing_domain"

web3_suspicious_pattern Web3 Suspisious Pattern String High

Transaction behavior indicative of exploits or attacks.

Example: itype="web3_suspicious_pattern"

whois_bulk_reg_email Whois Bulk Registrant Email Email Low

Registrant email address associated with privacy domain purchased from Whois.

Example: itype="whois_bulk_reg_email"

whois_privacy_domain Whois Privacy Email Domain Domain Low

Privacy domain purchased from Whois.

Example: itype="whois_privacy_domain"

whois_privacy_email Whois Privacy Email Email Low

Email address associated with a privacy domain purchased from Whois.

Example: itype="whois_privacy_email"

xampp_jabber_id Xampp Jabber ID String Medium

XAMPP/Jabber messaging ID.

Example: itype="xampp_jabber_id"