Anomali Takedown Service

The Anomali Takedown Service enrichment allows you to request takedowns of malicious or brand-infringing domains and URLs. After activating the Anomali Takedown Service enrichment in the APP Store, you can send takedown requests and track their progress.

Refer to the following sections for details:

Activating Anomali Takedown Service

Requesting a Takedown

Viewing a Takedown History

Activating Anomali Takedown Service

To request takedowns of domains and URLs, you must activate the Anomali Takedown Service enrichment first. Also, to activate the service you must obtain the API Key and API Secret from an Anomali Customer Support representative.

To activate the Anomali Takedown Service enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.

  2. Select the Enrichment Product Type and locate the Anomali Takedown Service enrichment.

  3. Click Get Access.

  4. In the window that opens, click I have credentials.

  5. In the window that opens, click Credentials.
  6. Enter your API Key and API Secret.

  7. Click Activate.
    The Anomali Takedown Service is now active.

Requesting a Takedown

You can request a domain or URL takedown from observable details pages.

Note: You can submit only one takedown request per observable.

To request a takedown of a domain or URL:

  1. Navigate to ThreatStream > Analyze > Observables.

  2. Click the observable of your interest.

  3. Right-click the observable node and select Enrichments > Anomali Takedown Service.

  4. Select one of the following Request Takedown options:

    Request Takedown: Spear Phishing

    Request Takedown: Phishing

    Request Takedown: Brand Impersonation

    Request Takedown: Email Scam Domain

When the takedown request is processed, the following tags indicating a takedown ID, status, and type are added to the observable and Threat Bulletins associated with the observable:

  • anomali-takedown-id: <id>

  • anomali-takedown- status: <status>

  • anomali-takedown-type:<type>

Possible status options are "open", "suspended", "successful", "canceled", and "closed".

The tags are utilized for creating widgets and alerts for the Anomali Takedown Service dashboard.

The status polling runs every 15 minutes. An in-app notification appears in ThreatStream every time a takedown request status changes. To learn more about receiving in-app notifications from ThreatStream, see Receiving In-App Notifications From ThreatStream.

When the takedown process is completed, the taken-down domain or URL no longer appears on the list of compromised domains or URLs.

Viewing a Takedown History

The takedown history of an observable can be viewed on the observable details page.

To view a takedown history:

1. Navigate to the observable that you have requested to take down.

2. In the Enrichment section, select Anomali Takedown Service.

3. View the takedown status and takedown history in the Check Takedown Status tab.

Alternatively, you can track the takedown progress of all takedown requests on the Anomali Takedown Service dashboard. See Utilizing Themed Custom Dashboards from the Anomali Threat Research Team to learn how to add existing ATR dashboards to your ThreatStream home page.

Note: The terms observable and indicator of compromise (IOC) are used interchangeably in ThreatStream.

The Anomali Takedown Service dashboard includes the following widgets:

IOCs to be taken down

Open Takedowns - Count

Completed Takedowns - Count

Open Takedown Requests (over the selected timeframe)

Completed Takedowns - List (over the selected timeframe)

Below is an example of the Anomali Takedown Service dashboard: