Information Provided By ATTM Alerts
Anomali Targeted Threat Monitoring (ATTM ) service generates a Threat Bulletin for every alert related to your organization. You can use the information in these Threat Bulletins to remediate the threats related to each alert. Further, ATTM provides a consistent tagging structure for Threat Bulletins and associated intelligence, thus enabling you to operationalize ATTM data in search filters.
Exposed Subdomains
If a subdomain of your organization is exposed, ATTM creates a Threat Bulletin based on an Exposed Subdomains alert. The Threat Bulletin contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the subdomain that triggered the alert. Example: |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
|
||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
Leaked Credentials
When a password is reused, a password leak may result in unauthorized access by attackers, scams, and phishing attacks. A Threat Bulletin generated for a Leaked Credentials alert notifies about potentially leaked employee credentials. The information is obtained from database leaks of compromised websites on which employees registered using their corporate email credentials. A Threat Bulletin generated for this type of alert contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the keyword that triggered the alert. <number> Employee Credentials Found in Initial Scan - <keyword> |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
|
||||||
| Recommendations |
Depending on the context available, one or more of the following recommendations is included:
Examples: Use observables/ThreatModel search filter to find:
|
Similar Domain Registration
New domains that are similar to your organization's domains may be used for phishing, domain squatting, brand abuse, and other types of attacks. ATTM detects similar domains, monitors issuing of an SSL certificate to identify suspicious SSL certificates, and provides open source phishing feed monitoring to prevent potential phishing attacks. A Threat Bulletin generated for the Similar Domain Registration alert contains one or more of the following information:
| Field | Description | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the domain that triggered the alert. Example: |
||||||||||||||||||
| Description |
Descriptions include the following:
|
||||||||||||||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||||||||||||||
| Attachments |
Depending on the information available, one or more of the following letter templates are attached to the Threat Bulletin:
You can use these letters and the contact information listed in the Threat Bulletin description to complete threat remediation. |
||||||||||||||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
|
||||||||||||||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included: Similar domain registration
|
Domain Expiration
To ensure timely domain registration renewal, a Threat Bulletin is sent to you a month before the domain expiration date and when it expires. The Threat Bulletin contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the domain that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Domain Expiration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
Note: Observables associated with domain expiration alerts are imported with a confidence value of 20 to ensure they are not blocked by downstream integrations. |
||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
Domain Hijacking
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
When an attacker gains access to your account at the Registrar, they can change the IP address associated with your domain. ATTM generates a Threat Bulletin for Domain Hijacking alerts to notify you that your website points to a suspicious IP address or that DNSSEC is not properly configured. The Threat Bulletin contains one or more of the following information:
| Field | Description | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the domain that triggered the alert. |
||||||||||||
| Description |
Descriptions include the following:
|
||||||||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
|
||||||||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
Rogue Apps
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
Anomali monitors over 40 app stores worldwide to identify mobile apps that are offered under your brand's name without authorization. For a Rogue Apps type of alerts, ATTM generates a Threat Bulletin containing one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the brand that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
|
||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
Fake Twitter Accounts
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
For Fake Twitter Account alerts, ATTM creates a Threat Bulletin to notify you that a fake Twitter account doing brand impersonation is identified. A Threat Bulletin for this type of alerts contains one or more of the following information.
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the fake Twitter account that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Fake Twitter account Threat Bulletins are appended with the following tags:
Example:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
|
||||||
| Recommendations |
If the account is found to be abusing Anomali's brand, trademark, or intellectual property, request Twitter to take it down. To report the account, do the following:
You will be requested to provide Anomali's real Twitter account as well as a contact email to send the report to the Twitter's abuse team. Note that you must be logged in to your Twitter account to report an account. |
Pastebin Brand Mentions
Note:
-
This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
-
Employee Doxing alerts are now merged with Pastebin Brand Mentions alerts and are no longer delivered as a separate alert type.
When “Employee Doxing Incidents” or “ Leaked Employee Emails” subscriptions are not signed up for, a Pastebin Brand alert notifies that a customer’s brand mentioning is observed. A Threat Bulletin generated for this type of alerts contains one or more of the following information:
| Field | Description | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the brand that triggered the alert. |
|||||||||||||||
| Description |
Descriptions include the following:
|
|||||||||||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
|||||||||||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
Note: Observables associated with these alerts are imported with a confidence value of 20 to ensure they are not blocked by downstream integrations. |
|||||||||||||||
| Recommendations | Determine whether the content of the paste is malicious. Request Pastebin to take the paste down if it has malicious content. A Pastebin account is required to access the page. |
Leaked Documents
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
A Leaked Documents alert is triggered when your sensitive documents are indexed by search engines, uploaded to malware analysis sites, or become available via publicly accessible AWS S3 buckets, Azure Blobs, and Digital Ocean. A Threat Bulletin generated for this type of alerst contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the document that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
Note: Observables associated with these alerts are imported with a confidence value of 20 to ensure they are not blocked by downstream integrations. |
||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
Leaked Code Monitor
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
A Leaked Code Monitor alert is triggered when a source code from GitHub, GitHub Gist, or Ideone becomes publicly available due to an invalid configuration of repository access permissions. A Threat Bulletin generated for this type of alerts contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the brand that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
Note: Observables associated with these alerts are imported with a confidence value of 20 to ensure they are not blocked by downstream integrations. |
||||||
|
Recommendations
|
Depending on the context, one or more of the following recommendations is included:
|
Trademark Application Filing
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
ATTM monitors trademark filings in over 120 countries to identify trademarks filed by third parties that infringe on customers’ brands and intellectual property. The detection is based on the data submitted by local trademark authorities to the World Intellectual Property Organization (WIPO) and supplemented by monitoring of trademark offices from specific countries that do not often report to WIPO. A Threat Bulletin generated for this type of alerts contains one or more of the following information:
| Field | Description |
|---|---|
| Title |
Lists the type of alert and the brand that triggered the alert. |
| Description |
Descriptions include the following:
|
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
E-Mail Vulnerability
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
ATTM constantly scans email configuration of domains for potential vulnerabilities and analyzes the setup of SPF and DMARC protocols used to prevent malicious activities. When an email vulnerability is detected, a Threat Bulletin is generated. The Threat Bulletin for this type of alerts contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the keyword that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
Note: Observables associated with these alerts are imported with a confidence value of 20 to ensure they are not blocked by downstream integrations. |
||||||
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
SSL Certificate Validity
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
When an SSL certificate of your website is about to expire, ATTM creates an alert 7 days prior to the SSL certificate expiration date and on the expiration date. It also generates a Threat Bulletin containing one or more of the following information:
| Field | Description |
|---|---|
| Title |
Lists the type of alert and the domain that triggered the alert. |
| Description |
Descriptions include the following:
|
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
| Recommendations |
Depending on the context, one or more of the following recommendations is included:
|
Leaked Employee Emails
Note: This alert is available to ATTM+ subscribers only. See Get even more with ATTM+ for more information.
A Leaked Employee Email alert is created when an email address of your employee is posted on Pastebin or becomes available on open PGP key servers that attackers often use for phishing attacks. A Threat Bulletin generated for this type of alerts contains one or more of the following information:
| Field | Description | ||||||
|---|---|---|---|---|---|---|---|
| Title |
Lists the type of alert and the domain that triggered the alert. |
||||||
| Description |
Descriptions include the following:
|
||||||
| Tags |
Similar domain registration Threat Bulletins are appended with the following tags:
|
||||||
| Associations |
Observables extracted from the alert. In addition to the tags listed below, all associated observables carry the tags appended to the parent Threat Bulletin.
Note: Observables associated with these alerts are imported with a confidence value of 20 to ensure they are not blocked by downstream integrations. |
||||||
| Recommendations | If your corporate emails are made up of a unique code rather than employee's name or last name, they can be easily leaked and targeted during phishing campaigns. |