Anomali Targeted Threat Monitoring (ATTM)
Anomali Targeted Threat Monitoring (ATTM), also known as Premium Digital Risk Protection (PDRP), is a premium threat intelligence feed that identifies threats to your organizational brand and assets. The Anomali Threat Research (ATR) team curates the threat intelligence data that subscribers receive through ATTM. ATTM is continuously tailored over the course of subscriptions to deliver a low-noise, high fidelity feed of threat intelligence that is individually targeted to individual organizations.
Anomali offers ATTM on a 14 day free trial basis to enable you to gauge its impact on intelligence workflows before purchasing a yearly subscription. See Subscribing to Anomali Targeted Threat Monitoring for more information.
ATTM provides data tailored to your organization based on the following alerts:
| Alert Type | Description |
|---|---|
| Exposed Subdomains |
Detects internal subdomains that have been publicly exposed to the web. See Exposed Subdomains for more details on information provided by this alert. |
| Leaked Employee Credentials |
Detects potential leaked employee credentials in credential repositories. See Leaked Credentials for more details on information provided by this alert. |
| Similar Domain Registration |
Detects newly registered domains similar to your own that may be used for phishing, domain squatting, brand abuse, or other attacks. Additionally, this alert identifies suspicious SSL certificates and phishing attacks. See Similar Domain Registration for more details on information provided by this alert. |
| Domain Expiration |
Detects when domains that belong to your organization are close to expiration. See Domain Expiration for more details on information provided by this alert. |
Get even more with ATTM+
ATTM+ is the premium version of the Anomali Targeted Threat Monitoring feed. With ATTM+, you get all of the alerts provided by ATTM plus the set of alerts detailed below.
If you are interested in subscribing to ATTM+, indicate your interest to Anomali when you provide the ATTM questionnaire during registration. See Subscribing to Anomali Targeted Threat Monitoring for more information.
| Alert Type | Description |
|---|---|
| Domain Hijacking |
Detects incidents that may indicate a domain has been hijacked. See Domain Hijacking for more details on information provided by this alert. |
| Rogue Apps |
Detects mobile apps used to infringe on intellectual property through using brand names or interacting with services without the authorization of the intellectual property holder. See Rogue Apps for more details on information provided by this alert. |
| Fake Twitter Accounts |
Detects fake Twitter accounts doing brand impersonation. See Fake Twitter Accounts for more details on information provided by this alert. |
| Pastebin Brand Mentions |
Detects instances of your brand on Pastebin. Pastebin allows users to post content in text format and generate unique, public URLs. See Pastebin Brand Mentions for more details on information provided by this alert. |
| Leaked Documents |
Monitors a variety of sources for leaked internal documents that may contain sensitive information. See Leaked Documents for more details on information provided by this alert. |
| Leaked Code Monitor |
Monitors Github, Github Gist, and Ideone for potential leaked source code. See Leaked Code Monitor for more details on information provided by this alert. |
| Trademark Application Filing |
Monitors trademark filings reported by the World Intellectual Property Organization in 120+ countries for trademarks filed by third parties that infringe your brands and intellectual property. On its initial scan, the service provides relevant trademark filings from the last 4 years. See Trademark Application Filing for more details on information provided by this alert. |
| E-mail Vulnerability |
Detects potential vulnerabilities in email domains that enable threat actors to spoof email messages. This subscription analyzes SPF and DMARC protocols, which are configured to prevent malicious activities. See E-Mail Vulnerability for more details on information provided by this alert. |
| SSL Certificate Validity |
Provides warnings 30 days before website SSL certificates expire. See SSL Certificate Validity for more details on information provided by this alert. |
| Leaked Employee Emails |
Detects employee emails that can be found online. Leaked employee emails can indicate susceptibility to spear phishing attacks and other scams. See Leaked Employee Emails for more details on information provided by this alert. |
ATTM+ subscribers also get access to an ATTM+ dashboard. See Using the ATTM+ Dashboard for more information.
Subscribing to Anomali Targeted Threat Monitoring
Use the steps in this section to gain access to ATTM on a 14 day free trial basis.
-
Navigate to APP Store > APP Store.
-
Locate the Anomali Targeted Threat Monitoring box and click Get Access.
-
On the resulting popup window, click Request Access. The status changes to Access requested.
Anomali responds to your request and sends you a questionnaire.
-
Use the questionnaire to provide the ATR team details on the assets you wish to monitor. When complete, send the questionnaire to attm-atr@anomali.com.
The ATR team then configures your personalized ATTM feed and sends you an API key. You will use this API key to activate the ATTM feed from the ThreatStream APP Store.
-
After receiving your API key, navigate to APP Store > APP Store.
-
Locate the Anomali Targeted Threat Monitoring box and click Manage and then I have credentials.
-
Enter the API key provided by the ATR team.
-
Click Activate. The status of the feed changes to Active on the APP Store box.
Your ATTM integration is now active.