Indicator Types in ThreatStream
The following table lists all available indicator types in ThreatStream.
The severity values listed in the table below represent the default severity values that Anomali assigns to observables of a given indicator types. However, default values are not displayed in the following cases:
- When severity value assigned to an observable by the source is used.
- When users modify the assigned value while editing observables that belong to their organizations on ThreatStream.
- Observables assigned indicator types which display String in the Type column below are not consumed by downstream integrations such as Anomali Match or those which receive intelligence through ThreatStream Integrator. Additionally, string-type observables cannot be cloned in ThreatStream.
- MD5 observables ingested from feeds are never made inactive by ThreatStream. However, MD5 observables imported through other means, such as the import assistant, adhere to the expiration dates you set.
| Indicator Type | Name | Type | Severity | Description |
|---|---|---|---|---|
| actor_ip | Actor IP | IP | Low |
IP address associated with a system involved in a malicious activity. Example: itype="actor_ip" |
| actor_ipv6 | Actor IPv6 | IP | Low |
IPv6 address associated with a system involved in a malicious activity. Example: itype="actor_ipv6" |
| actor_phone_number | Actor Phone Number | String | Low |
Phone number associated with a threat actor. Example: itype="actor_phone_number" |
| actor_subject | Actor Subject Line | String | High |
Subject from an email associated with a threat actor. Example: itype="actor_subject" |
| actor_username | Actor Username | String | Low |
Username associated with a threat actor. Example: itype="actor_username" |
| adware_domain | Adware Domain | Domain | Low |
Domain name associated with adware or other Potentially Unwanted Applications (PUA). Example: itype="adware_domain" |
| adware_registry_key | Adware Registry Key | String | Low |
Registry key associated with adware or other Potentially Unwanted Applications (PUA). Example: itype="adware_registry_key" |
| anon_proxy | Anonymous Proxy IP | IP | Low |
IP address of the system on which anonymous proxy software is hosted. Example: itype="anon_proxy" |
| anon_proxy_ipv6 | Anonymous Proxy IPv6 | IP | Low |
IPv6 address of the system on which anonymous proxy software is hosted. Example: itype="anon_proxy_ipv6" |
| anon_vpn | Anonymous VPN IP | IP | Low |
IP address associated with commercial or free Virtual Private Networks (VPN). Example: itype="anon_vpn" |
| anon_vpn_ipv6 | Anonymous | IP | Low |
IPv6 address associated with commercial or free Virtual Private Networks (VPN). Example: itype:"anon_vpn_ipv6" |
| apt_domain | APT Domain | Domain | Very High |
Domain name associated with a known Advanced Persistent Threat (APT) actor used for command and control, launching exploits, or data exfiltration. Example: itype=" apt_domain" |
| apt_email | APT Email | High |
Email address used by a known Advanced Persistent Threat (APT) actor for sending targeted, spear phishing emails. Example: itype="apt_email" |
|
| apt_email_subject_line | APT Email Subject Line | String | High |
Subject from an email associated with an Advanced Persistent Threat (APT) actor. Example: itype="apt_email_subject_line" |
| apt_file_name | APT File Name | String | Very High |
Name of a file used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_file_name" |
| apt_file_path | APT File Path | String | Very High |
File path used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_file_path" |
| apt_ip | APT IP | IP | Very High |
IP address associated with known Advanced Persistent Threat (APT) actor for command and control, data exfiltration, or targeted exploitation. Example: itype="apt_ip" |
| apt_ipv6 | APT IPv6 | IP | Very High |
IPv6 address associated with known Advanced Persistent Threat (APT) actor for command and control, data exfiltration, or targeted exploitation. Example: itype="apt_ipv6" |
| apt_md5 | APT File Hash | Hash | Very High |
MD5 or SHA hash of a malware sample used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_md5" |
| apt_mta | APT Mail Transfer Agent | String | Very High |
Mail transfer agent used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_mta" |
| apt_mutex | APT Mutex | String | Very High |
Mutex used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_mutex" |
| apt_registry_key | APT Registry Key | String | Very High |
Registry key used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_registry_key" |
| apt_service_description | APT Service Description | String | Very High |
Description used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_service_description" |
| apt_service_displayname | APT Service Display Name | String | Very High |
Service display name used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_service_displayname" |
| apt_service_name | APT Service Name | String | Very High |
Service name used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_service_name" |
| apt_ssdeep | APT SSDeep Hash | String | Very High |
SSDeep Hash used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_ssdeep" |
| apt_subject | APT Subject Line | String | High |
Email subject line used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_subject" |
| apt_ua | APT User Agent | String | High |
User agent string used by a known Advanced Persistent Threat (APT) actor. Example: itype="apt_ua" |
| apt_url | APT URL | URL | Very High |
URL used by a known Advanced Persistent Threat (APT) actor for command and control, launching web based exploits, or data exfiltration. Example: itype=" apt_url" |
| asn | ASN | String | Medium |
Autonomous System Number Example: itype="asn" |
| aws_account_id | AWS Account ID | String | High |
AWS account identifier potentially involved in malicious activities. Example: itype="aws_account_id" |
| benign_device_id | Benign Device ID | String | Low |
Trusted device identifier. Example: itype="benign_device_id" |
| benign_domain | Benign Domain | Domain | Low |
Allowlisted domain. Example: itype="benign_domain" |
| benign_email | Benign Email | Low |
Allowlisted email address. Example: itype="benign_email" |
|
| benign_hash | Benign Hash | String | Low |
Allowlisted hash value. Example: itype="benign_hash" |
| benign_internal_email | Benign Internal Email | Medium |
Internal email address. Example: itype="benign_internal_email" |
|
| benign_ip | Benign IP | IP | Low |
Allowlisted IP address. Example: itype="benign_ip" |
| benign_url | Benign URL | String | Low |
Allowlisted URL. Example: itype="benign_url" |
| bitcoin_wallet | Bitcoin Wallet Address | String | High |
Bitcoin wallet used in transactions. Example: itype="bitcoin_wallet' |
| bot_domain | Infected Bot Domain Name | Domain | Low |
Domain name of an infected machine acting as an autonomous bot. Example: itype="bot_domain" |
| bot_ip | Infected Bot IP | IP | Low |
IP address of an infected machine acting as an autonomous bot. Example: itype="bot_ip" |
| bot_ipv6 | Infected Bot IPv6 | IP | Low |
IPv6 address of an infected machine acting as an autonomous bot. Example: itype="bot_ipv6" |
| bot_md5 | Infected Bot Hash | Hash | Low |
Hash related to a file used by an infected machine acting as an autonomous bot. Example: itype="bot_md5" |
| bot_url | Infected Bot URL | URL | Low |
URL of an infected machine acting as an autonomous bot. Example: itype="bot_url" |
| botnet_user_agent | Botnert User Agent | String | Medium |
User agent string used by a botnet for malicious activity. Example: itype="botnet_user_agent" |
| browser_extension_id | Browser Extension ID | String | High |
Unique ID given to each browser extension, which is available in the Extension store of such browsers as Firefox, Chrome, and so on. Example: itype="browser_extension_id" |
| brute_ip | Brute Force IP | IP | Low |
IP address associated with password brute force activity. Example: itype="brute_ip" |
| brute_ipv6 | Brute Force IPv6 | IP | Low |
IPv6 address associated with password brute force activity. Example: itype="brute_ipv6" |
| c2_domain | Malware C&C Domain Name | Domain | High |
Domain name used by malware for command and control communication. Example: itype="c2_domain" |
| c2_dns_name | Malware C&C DNS Name | Domain | High |
DNS name used by malware for command and control communication. Example: itype="c2_dns_name" |
| c2_ip | Malware C&C IP Address | IP | High |
IP address used by malware for command and control communication. Example: itype="c2_ip" |
| c2_ipv6 | Malware C&C IPv6 Address | IP | High |
IPv6 address used by malware for command and control communication. Example: itype="c2_ipv6" |
| c2_url | Malware C&C URL | URL | High |
URL used by malware for command and control communication. Example: itype="c2_url" |
| cloud_instance_id | Cloud Instance ID | String | High |
Cloud VM or container instance identifier. Example: itype="cloud_instance_id" |
| cobalt_strike_id | Cobalt Strike ID | String | High |
Cobalt Strike or malware identifier. Example: itype="cobalt_strike_id" |
| corp_vpn_ip | Corp VPN IP | IP | Medium |
Internal VPN exit node IP for remote employees. Example: itype="corp_vpn_ip" |
| comm_proxy_domain | Commercial Webproxy Domain | Domain | Low |
Domain of the system on which commercial proxy software is hosted. Example: itype="comm_proxy_domain" |
| comm_proxy_ip | Commercial Webproxy IP | IP | Low |
IP address of the system on which commercial proxy software is hosted. Example: itype="comm_proxy_ip" |
| comm_proxy_ipv6 | Commercial Webproxy IPv6 | IP | Low |
IPv6 address associated with a commercial web proxy. Example: itype="comm_proxy_ipv6" |
| compromised_email | Compromised Account Email | Low |
Email address that has been compromised and/or taken over by a threat actor. Example: itype="compromised_email" |
|
| compromised_company | Compromised Company | String | High |
Name of a compromised company. Example: itype="compromised_company" |
| compromised_domain | Compromised Domain | Domain | Low |
Domain name of website or server that has been compromised. Example: itype="compromised_domain" |
| compromised_email_subject | Compromised Email Subject | String | Low |
Email subject from a known compromised email address. Example: itype="compromised_email_subject" |
| compromised_ip | Compromised IP | IP | Low |
IP address of website or server that has been compromised. Example: itype="compromised_ip" |
| compromised_ipv6 | Compromised IPv6 | IP | Low |
IPv6 address of website or server that has been compromised. Example: itype="compromised_ipv6" |
| compromised_password | Compromised Password | String | Low |
Plaintext or hashed password value associated with a compromised credential record. Example: itype="compromised_password" |
| compromised_port | Compromised Port | String | Low |
Network port associated with a compromised device or session. Example: itype="compromised_port" |
| compromised_serv_account | Compromised Service Account | String | Low |
Account information associated with a service account that has been compromised and/or taken over by a threat actor. Example: itype="compromised_serv_account" |
| compromised_url | Compromised URL | URL | Medium |
URL of the website or server that has been compromised. Example: itype="compromised_url" |
| compromised_username | Compromised Username | String | Medium |
Username that has been compromised and/or taken over by a threat actor. Must have a length of 128 characters or less. Example: itype="compromised_username" |
| crypto_hash | Cryptocurrency Mining Software | Hash | High |
File hash for cryptocurrency mining software. Example: itype="crypto_hash" |
| crypto_ip | Cryptocurrency IP | IP | High |
IP address associated with a cryptocurrency mining software. Example: itype="crypto_ip" |
| crypto_ipv6 | Cryptocurrency IPv6 | IPv6 | Medium |
IPv6 address associated with a cryptocurrency mining software. Example: itype="crypto_ipv6" |
| crypto_pool | Cryptocurrency Pool Domain | Domain | High |
Domain for cryptocurrency pool. Example: itype="crypto_pool" |
| crypto_url | Cryptocurrency URL | URL | High |
URL where cryptocurrency mining software is hosted. Example: itype="crypto_url" |
| crypto_wallet | Cryptocurrency Wallet Address | String | Very High |
Public or private cryptocurrency wallet key. Example: itype="crypto_wallet" |
| customer_account_id | Customer Account ID | String | High |
Identifier for an internal customer account. Example: itype="customer_account_id" |
| ddos_ip | DDOS IP | IP | Low |
IP address associated with Distributed Denial of Service (DDoS) attacks. Example: itype="ddos_ip" |
| ddos_ipv6 | DDOS IPv6 | IP | Low |
IPv6 address associated with Distributed Denial of Service (DDoS) attacks. Example: itype="ddos_ipv6" |
| device_serial_number | Device Serial Number | String | Medium |
Unique serial number of an endpoint, laptop, or mobile device. Example: itype="device_serial_number" |
| disposable_email_domain | Disposable Email Domain | Domain | Low |
Domain associated with disposable email activity. Example: itype="disposable_email_domain" |
| downloader_domain | Downloader Domain | Domain | High |
Domain associated with a downloader, which is a type of malware that downloads and runs other malware. Example: itype="downloader_domain" |
| downloader_hash | Downloader File Hash | Hash | High |
Hash of a malicious file associated with a downloader, which is a type of malware that downloads and runs other malware. Example: itype="downloader_hash" |
| downloader_ip | Downloader IP | IP | High |
IP address associated with a downloader, which is a type of malware that downloads and runs other malware. Example: itype="downloader_ip" |
| downloader_ipv6 | Downloader IPv6 | IP | High |
IPv6 address associated with a downloader, which is a type of malware that downloads and runs other malware. Example: itype="downloader_ipv6" |
| downloader_url | Downloader URL | URL | High |
URL associated with a downloader, which is a type of malware that downloads and runs other malware. Example: itype="downloader_url" |
| dyn_dns | Dynamic DNS | Domain | Low |
Domain name used for hosting Dynamic DNS services. Example: itype="dyn_dns" |
| email_attachment_subject | Email Attachment Subject | String | Low |
Email subject from a known compromised email attachment. Example: itype="email_attachment_subject" |
| employee_id | Employee ID | String | Medium |
Internal identifier assigned to an employee. Example: itype="employee_id" |
| encrypted_file_ext | Encrypted File EXT | String | High |
Encrypted file extension used by malware. Example: itype="encrypted_file_ext" |
| exfil_domain | Data Exfiltration Domain | Domain | High |
Domain name associated with the infrastructure used for data exfiltration. Example: itype="exfil_domain" |
| exfil_ip | Data Exfiltration IP | IP | High |
IP address used for data exfiltration. Example: itype="exfil_ip" |
| exfil_ipv6 | Data Exfiltration IP | IP | High |
IPv6 address used for data exfiltration. Example: itype="exfil_ipv6" |
| exfil_url | Data Exfiltration URL | URL | High |
URL used for data exfiltration. Example: itype="exfil_url" |
| exploit_domain | Exploit Kit Domain | Domain | Very High |
Domain name associated with the web server hosting an exploit kit or launching web-based exploits. Example: itype="exploit_domain" |
| exploit_ip | Exploit Kit IP | IP | High |
IP address associated with the web server hosting an exploit kit or launching web-based exploits. Example: itype="exploit_ip" |
| exploit_ipv6 | Exploit Kit IPv6 | IP | High |
IPv6 address associated with the web server hosting an exploit kit or launching web-based exploits. Example: itype="exploit_ipv6" |
| exploit_cve_id | Exploit CVE ID | String | High |
CVE identifier for a vulnerability being exploited. Example: itype="exploit_cve_id" |
| exploit_md5 | Exploit Hash | Hash | Low |
Hash related to a file used to exploit a known vulnerability. Example: itype="exploit_md5" |
| exploit_url | Exploit Kit URL | URL | Very High |
URL used for launching web-based exploits. Example: itype="exploit_url" |
| fraud_domain | Fraud Domain | Domain | High |
Domain associated with a fraudulent activity. Example: itype="fraud_domain" |
| fraud_email | Fraud Email | Low |
Email address associated with a fraudulent activity. Example: itype="fraud_email" |
|
| fraud_email_subject | Fraud Email Subject | String | Medium |
Subject from an email associated with fraud activity. Example: itype="fraud_email_subject" |
| fraud_file_name | Fraud File Name | String | Medium |
File name used in a fraud scheme. Example: itype="fraud_file_name" |
| fraud_ip | Fraud IP Address | IP | High |
IP address associated with a fraudulent activity. Example: itype="fraud_ip" |
| fraud_ipv6 | Fraud IPv6 | IP | High |
An IPv6 address associated with a fraudulent activity. Example: itype="fraud_ipv6" |
| fraud_md5 | Fraud Hash | Hash | Very High |
Hash associated with a fraudulent activity. Example: itype="fraud_md5" |
| fraud_url | Fraud URL | URL | Medium |
URL associated with a fraudulent activity. Example: itype="fraud_url" |
| free_email_domain | Free Email Domain | Domain | Low |
Domain associated with free email service activity. Example: itype="free_email_domain" |
| freq_abused_dns_provider | Frequently Abused DNS Provider | String | Medium |
Name of a frequently abused DNS provider. Example: itype="freq_abused_dns_provider". |
| gaming_device_id | Device ID | String | High |
ID of the gaming device associated with a malicious activity. Example: itype="gaming_device_id" |
| gaming_device_name | Device Name | String | High |
Name of the gaming device associated with a malicious activity. Example: itype="gaming_device_name" |
| gaming_game_id | Game ID | String | High |
ID of the game associated with a malicious activity. Example: itype="gaming_game_id" |
| gaming_game_name | Game Name | String | Low |
Name of the game associated with a malicious activity. Example: itype="gaming_game_name" |
| gaming_player_country | Player Country | String | Low |
Country of the player associated with a malicious activity. Example: itype="gaming_player_country" |
| gaming_player_email | Player Email | High |
Player's email address associated with a malicious activity. Example: itype="gaming_player_email" |
|
| gaming_player_id | Player ID | String | High |
Player's ID associated with a malicious activity. Example: itype="gaming_player_id" |
| gaming_player_nickname | Player Nickname | String | Medium |
Player's nickname associated with a malicious activity. Example: itype="gaming_player_nickname" |
| gaming_player_phone | Player Phone | Phone Number | Medium |
Player's phone number associated with a malicious activity. Example: itype="gaming_player_phone" |
| geolocation_url | IP Geolocation URL | URL | Low |
URL that can be used to provide IP Geo location services. Example: itype="geolocation_url" |
| hack_tool | Hacking Tool | String | High |
Name of general hacking software tools used by threat actors. Example: itype="hack_tool" |
| hack_tool_md5 | Hack Tool File Hash | Hash | Very High |
MD5 or SHA hash of general hacking software tools used by threat actors. Example: itype="hack_tool_md5" |
| iam_user_id | IAM User ID | String | High |
User identity in an internal IAM system. Example: itype="iam_user_id" |
| i2p_ip | I2P IP Address | IP | Low |
IP address observed to be connecting to the I2P (Invisible Internet Project) network. Example: itype="i2p_ip" |
| i2p_ipv6 | I2P IPv6 Address | IP | Low |
IPv6 address observed to be connecting to the I2P (Invisible Internet Project) network. Example: itype="i2p_ipv6" |
| image_hash | Image Hash | String | Low |
Cryptographic hash of the image used for comparing two different images. It differs from typical MD5, SHA1, SHA2 hashes. Example: itype="image_hash" |
| infostealer_domain | Information Stealer Domain | Domain | Very High |
Domain associated with an information stealer. Example: itype="infostealer_domain" |
| infostealer_hash | Information Stealer File Hash | Hash | Very High |
Hash of a malicious file associated with an information stealer. Example: itype="infostealer_hash" |
| infostealer_ip | Information Stealer IP | IP | Very High |
IP address associated with an information stealer. Example: itype="infostealer_ip" |
| infostealer_ipv6 | Information Stealer IPv6 | IP | Very High |
IPv6 address associated with an information stealer. Example: itype="infostealer_ipv6" |
| infostealer_url | Information Stealer URL | URL | Very High |
URL associated with an information stealer. Example: itype="infostealer_url" |
| internal_dns_name | Internal DNS Name | String | Medium |
Internal hostname or DNS record. Example: itype="internal_dns_name" |
| internal_host_id | Internal Host ID | String | High |
Identifier for workstation, server, or Cloud VM. Example: itype="internal_host_id" |
| internal_ticket_id | Internal Ticket ID | String | Low |
Internal support or security ticket ID. Example: itype="internal_ticket_id" |
| iot_domain | Internet of Things Malicious Domain | Domain | Medium |
Domain associated with malware targeting Internet of Things devices. Example: itype="iot_domain" |
| iot_hash | Internet of Things Malicious File Hash | Hash | High |
Hash of a malicious sample targeting Internet of Things devices. Example: itype="iot_hash" |
| iot_ip | Internet of Things Malicious IP | IP | Medium |
IP address associated with malware targeting Internet of Things devices. Example: itype="iot_ip" |
| iot_ipv6 | Internet of Things Malicious IPv6 | IP | Medium |
IPv6 associated with malware targeting Internet of Things devices. Example: itype="iot_ipv6" |
| iot_url | Internet of Things Malicious URL | URL | Medium |
URL associated with malware targeting Internet of Things devices and services. Example: itype="iot_url" |
| ipcheck_url | IP Check URL | URL | Low |
URL that can be used to provide IP checking services, such as echoing the Internet facing IP address of the client. Example: itype="ipcheck_url" |
| ja3_md5 | JA3/JA3S TLS Fingerprint | Hash | Medium |
TLS Client/Server fingerprint. Example: itype="ja3_md5" |
| ja4_tls_fingerprint | JA4 TLS Fingerprint | Hash | Medium |
TLS Client/Server fingerprint. Example: itype="ja4_tls_fingerprint" |
| mal_domain | Malware Domain | Domain | Very High |
Domain contacted by malware sample; could be for command and control commands, or to check if the client is online. Example: itype="mal_domain" |
| mal_email | Malware Email | Low |
Email address used to send malware through malicious links or attachments. Example: itype="mal_email" |
|
| mal_email_subject | Malware Email Subject | String | Medium |
Subject from an email associated with malware activity. Example: itype="mal_email_subject" |
| mal_file_name | Malware File Name | String | Very High |
File name of malware sample. Example: itype="mal_file_name" |
| mal_file_path | Malware File Path | String | Very High |
File path of malware sample. Example: itype="mal_file_path" |
| mal_http_header | Malicious HTTP Header | String | High |
HTTP header related to malicious requests. Example: itype="mal_http_header" |
| mal_ip | Malware IP | IP | Very High |
IP address contacted by malware sample; could be for command and control commands, or to check if the client is online. Example: itype="mal_ip" |
| mal_ipv6 | Malware IPv6 | IP | Very High |
IPv6 address contacted by malware sample; could be for command and control commands, or to check if the client is online. Example: itype="mal_ipv6" |
| mal_md5 | Malware File Hash | Hash | Very High |
MD5 or SHA hash of malware sample. Example: itype="mal_md5" |
| mal_mutex | Malware Mutex | String | Very High |
Mutex of malware sample. Example: itype="mal_mutex" |
| mal_port | Malware Port | String | Very High |
Malware-associated network port or IP-port composite value. Example: itype="mal_port" |
| mal_registry_key | Malware Registry Key | String | High |
Registry key of malware sample. Example: itype="mal_registry_key" |
| mal_relay_server_ip | Malicious Relay Server IP | IP | Medium |
IP address of a malicious relay server. Example: itype="mal_relay_server_ip" |
| mal_relay_relay_server_ipv6 | Malicious Relay Server IPv6 | IP | Medium |
IPv6 address of a malicious relay server. Example: itype="mal_relay_server_ipv6" |
| mal_service_description | Malware Service Description | String | Very High |
Service description associated with the malware sample. Example: itype="mal_service_description" |
| mal_service_displayname | Malware Service Display Name | String | Very High |
Service display name associated with the malware sample. Example: itype="mal_service_displayname" |
| mal_service_name | Malware Service Name | String | Very High |
Service name associated with the malware sample. Example: itype="mal_service_name" |
| mal_smtp_header | Malicious SMTP Header | String | High |
SMTP header related to a malicious email activity. Example: itype="mal_smtp_header" |
| mal_ssdeep | Malware SSDeep Hash | String | Very High |
SSDeep Hash associated with the malware sample. Example: itype="mal_ssdeep" |
| mal_sslcert_sha1 | SSL Certificate Hash | Hash | High |
MD5 or SHA hash of SSL certificate associated with malware or botnet activities. Example: itype="mal_sslcert_sha1" |
| mal_ua | Malware User Agent | String | Low |
User agent string used by malware sample when communicating via HTTP. Example: itype="mal_ua" |
| mal_url | Malware URL | URL | Very High |
URL contacted by malware sample when run on an infected host. Example: itype="mal_url" |
| mal_wildcard_domain | Malware Wildcard Domain | String | High |
A wildcard domain associated with malware activities. Example: itype="mal_wildcard_domain" |
| mal_wildcard_url | Malware Wildcard URL | String | High |
A wildcard URL associated with malware activities. itype="mal_wildcard_url" |
| mobile_malware | Mobile Malware | String | High |
Indicator related to mobile malware. Example: itype="mobile_malware" |
| new_domain | New Domain | Domain | Low |
Recently registered domain with insufficient history to fully evaluate. Example: itype="new_domain" |
| p2pcnc | Peer-to-Peer C&C IP Address | IP | Medium |
IP addressed associated with a peer-to-peer command and control infrastructure. Example: itype="p2pcnc" |
| p2pcnc_ipv6 | Peer-to-Peer C&C IPv6 Address | IP | Medium |
IPv6 addressed associated with a peer-to-peer command and control infrastructure. Example: itype="p2pcnc_ipv6" |
| parked_domain | Parked Domain | Domain | Low |
Domain name of a website which is currently parked. Example: itype="parked_domain" |
| parked_ip | Domain Parking IP | IP | Low |
IP addressed used for parking newly registered or inactive domain names. Example: itype="parked_ip" |
| parked_ipv6 | Domain Parking IPv6 | IP | Low |
IPv6 addressed used for parking newly registered or inactive domain names. Example: itype="parked_ipv6" |
| parked_url | Parked URL | URL | Low |
URL of a website that is currently parked. Example: itype="parked_url" |
| pastesite_url | Paste Site URL | URL | Low |
URL that can be used for sharing pastes or text content anonymously. Example: itype="pastesite_url" |
| phish_domain | Phishing Domain | Domain | Very High |
Domain used to perform phishing or spear phishing attacks or contained in a phishing email. Example: itype="phish_domain" |
| phish_email | Phishing Email Address | Very High |
Email address associated with sending phishing or spear phishing emails to victims. Example: itype="phish_email" |
|
| phish_email_subject | Phishing Email Subject | String | High |
Subject from an email associated with phishing activity. Example: itype="phish_email_subject" |
| phish_file_name | Phishing File Name | String | Medium |
File name used in a phishing attack. Example: itype="phish_file_name" |
| phishing_target | Phishing Target | String | High |
Identifier for phishing victims. Example: itype="phishing_target" |
| phish_ip | Phishing IP Address | IP | Very High |
IP address that has been used to perform phishing or spear phishing or is contained in a phishing email. Example: itype="phish_ip" |
| phish_ipv6 | Phishing IPv6 Address | IP | Very High |
IPv6 address that has been used to perform phishing or spear phishing or is contained in a phishing email. Example: itype="phish_ipv6" |
| phish_md5 | Phishing File Hash | Hash | Very High |
Hash related to a file used to perform phishing or spear phishing attacks or contained in a phishing email. Example: itype="phish_md5" |
| phish_url | Phishing URL | URL | Very High |
URL used to perform phishing or spear phishing attacks or contained in a phishing email. Example: itype="phish_url" |
| phish_victim_email | Phishing Victim Email | Low |
Email of a user who was a victim of a phishing attack. Example: itype="phish_victim_email" |
|
| phone_number | Phone Number | String | Medium |
Phone number used in fraudulent activities. Example: itype="phone_number" |
| platform_uid | Platform UID | String | Medium |
Unique user ID from a specific platform. Example: itype="platform_uid" |
| pos_domain | Point of Sale Malicious Domain | Domain | Medium |
Domain associated with malware targeting Point of Sales systems. Example: itype="pos_domain" |
| pos_hash | Point of Sale Malicious File Hash | Hash | High |
Malicious file hash targeting Point of Sales systems. Example: itype="pos_hash" |
| pos_ip | Point of Sale Malicious IP | IP | Medium |
IP address associated with malware targeting Point of Sale systems. Example: itype="pos_ip" |
| pos_ipv6 | Point of Sale Malicious IPv6 | IP | Medium |
IPv6 address associated with malware targeting Point of Sales systems. Example: itype="pos_ipv6" |
| pos_url | Point of Sale Malicious URL | URL | Medium |
URL associated with malware targeting Point of Sales systems. Example: itype="pos_url" |
| proxy_ip | Open Proxy IP | IP | Low |
IP address hosting open or anonymous proxy software. Allows user to hide their IP address from target. Example: itype="proxy_ip" |
| proxy_ipv6 | Open Proxy IPv6 | IP | Low |
IPv6 address hosting open or anonymous proxy software. Allows user to hide their IP address from target. Example: itype="proxy_ipv6" |
| ransomware_domain | Ransomware Domain | Domain | Very High |
Domain associated with ransomware. Example: itype="ransomware_domain" |
| ransomware_hash | Ransomware File Hash | Hash | Very High |
File hash of a malicious ransomware sample. Example: itype="ransomware_hash" |
| ransomware_ip | Ransomware IP | IP | Very High |
IP address associated with ransomware. Example: itype="ransomware_ip" |
| ransomware_ipv6 | Ransomware IPv6 | IP | Very High |
IPv6 address associated with ransomware. Example: itype="ransomware_ipv6" |
| ransomware_group | Ransomware Group | String | Low |
Group associated with ransomware. Example: itype="ransomware_group" |
| ransomware_url | Ransomware URL | URL | Very High |
URL associated with ransomware. Example: itype="ransomware_url" |
| ransomware_victim_domain | Ransomware Victim Domain | Domain | Low |
Domain of a ransomware victim. Example: itype="ransomware_victim_domain" |
| ransomware_victim_name | Ransomware Victim Name | String | Low |
Name of a ransomware victim. Example: itype="ransomware_victim_name" |
| ransomware_victim_url | Ransomware Victim URL | URL | Low |
URL of a ransomware victim. Example: itype="ransomware_victim_url" |
| rootkit_hash | Rootkit File Hash | Hash | Very High |
File hash of rootkit malware that provides root-level access to an attacker. Example: itype="rootkit_hash" |
| scan_ip | Scanning IP | IP | Medium |
IP address observed to perform port scanning and vulnerability scanning activities. Example: itype="scan_ip" |
| scan_ipv6 | Scanning IPv6 | IP | Medium |
IPv6 address observed to perform port scanning and vulnerability scanning activities. Example: itype="scan_ipv6" |
| session_token | Session Token | String | High |
Temporary authentication token for session management. Example: itype="session_token" |
| sinkhole_domain | Sinkhole Domain | Domain | Low |
Domain name that researchers or security companies typically sinkhole. Example: itype="sinkhole_domain" |
| sinkhole_ip | Sinkhole IP | IP | Low |
IP address that is known to be used to sinkhole malicious domain names. Example: itype="sinkhole_ip" |
| sinkhole_ipv6 | Sinkhole IPv6 | IP | Low |
IPv6 address that is known to be used to sinkhole malicious domain names. Example: itype="sinkhole_ipv6" |
| social_forum_name | Forum Name | String | Low |
Name of the social forum associated with a malicious activity. Example: itype="social_forum_name" |
| social_media_name | Social Media Name | String | Medium |
Name of the social media associated with a malicious activity. Example: itype="social_media_name" |
| social_media_url | Social Media URL | URL | Medium |
URL related to social media activity. This indicator type is provided by select feeds and cannot be imported through the ThreatStream user interface. Example: itype="social_media_url" |
| social_messaging_services | Messaging Services | String | Low |
Messaging service used for malicious activity. Example: itype="social_messaging services" |
| spam_domain | Spam Domain | Domain | Low |
Malicious domain name contained in the SPAM email messages. Example: itype="spam_domain" |
| spam_email | Spammer Email Address | Low |
Email address that has been observed sending SPAM emails. Example: itype="spam_email" |
|
| spam_email_subject | Spam Email Subject | String | Low |
Subject from an email associated with spam activity. Example: itype="spam_email_subject" |
| spam_ip | Spammer IP | IP | Low |
IP address that is known to send SPAM emails. Example: itype="spam_ip" |
| spam_ipv6 | Spammer IPv6 | IP | Low |
IPv6 address that is known to send SPAM emails. Example: itype="spam_ipv6" |
| spam_mta | Spam Mail Transfer Agent | String | Low |
Mail transfer agent known to be associated with SPAM emails. Example: itype="spam_mta" |
| spam_url | Spam URL | URL | Low |
Malicious URL contained in the SPAM email messages. Example: itype="spam_url" |
| speedtest_url | Speed Test URL | URL | Low |
URL that can be used to run internet speed tests or bandwidth measurements of the client's network connection. Example: itype="speedtest_url" |
| ssh_ip | SSH Brute Force IP | IP | Low |
IP addresses associated with SSH brute force attempts. Example: itype="ssh_ip" |
| ssh_ipv6 | SSH Brute Force IPv6 | IP | Low |
IPv6 addresses associated with SSH brute force attempts. Example: itype="ssh_ipv6" |
| ssl_cert_serial_number | SSL Certificate Serial Number | String | Low |
Serial number unique to the TLS certificate issuer that identifies the entity being signed. Example: itype="ssl_cert_serial_number" |
| sso_session_id | SSO Session ID | String | High |
Identifier for an active SSO session. Example: itype="sso_session_id" |
| suppress | Suppress | n/a | n/a |
Not a true indicator type. Used by Arcsight for suppressing false positives. Default severity: n/a Example: itype="suppress" |
| suppress_ipv6 | Suppress Alerts IPv6 | IP | Low |
IPv6 address related to alert suppression. Example: itype="suppress_ipv6" |
| suspected_c2_dns_name | Suspected C&C DNS Name | Domain | Medium |
Suspected DNS name used by malware for command and control communication. Example: itype="suspected_c2_dns_name" |
| suspicious_cmd_line | Suspicious CMD Line | String | Medium |
Command-line arguments used in execution. Example: itype="suspicious_cmd_line" |
| suspicious_domain | Suspicious Domain | Domain | Medium |
Domain name that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_domain" |
| suspicious_email | Suspicious Email | Low |
Email address that appears to be used for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_email" |
|
| suspicious_email_subject | Suspicious Email Subject | String | Low |
Email subject from a suspicious email address. Example: itype="suspicious-email_subject" |
| suspicious_ip | Suspicious IP | IP | Medium |
IP address that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_ip" |
| suspicious_ipv6 | Suspicious Ipv6 | IP | Medium |
IPv6 address related to a suspcious activity. Example: itype="suspicious_ipv6" |
| suspicious_md5 | Suspicious Hash | Hash | Low |
Hash related to a suspicious activity. Example: itype="suspicious_md5" |
| suspicious_reg_email | Suspicious Registrant Email | Low |
Registrant email address that appears to be used for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_reg_email" |
|
| sus_wildcard_domain | Suspicious Wildcard Domain | String | Medium |
A wildcard domain that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="sus_wildcard_domain" |
| sus_wildcard_url | Suspicious Wildcard URL | String | Medium |
A wildcard URL that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="sus_wildcard_url" |
| suspicious_url | Suspicious URL | URL | Medium |
URL that appears to be registered for suspect reasons, but may not be associated with known malicious activity yet. Example: itype="suspicious_url" |
| telegram_id | Telegram ID | String | Medium |
Telegram user or group ID. Example: itype="telegram_id" |
| threat_actor_hostname | Threat Actor Hostname | String | High |
Hostname associated with a threat actor. Example: itype="threat_actor_hostname" |
| tor_ip | TOR Node IP | IP | Low |
IP address operating as part of The Onion Router (TOR) Network, also know as a TOR exit node. Example: itype="tor_ip" |
| tor_ipv6 | TOR Node IPv6 | IP | Low |
IPv6 address operating as part of The Onion Router (TOR) Network, also know as a TOR exit node. Example: itype="tor_ipv6" |
| torrent_tracker_url | Torrent Tracker URL | URL | Low |
URL used for tracking bittorrent file transfer activity. Example: itype="torrent_tracker_url" |
| tox_id | Tox ID | String | Medium |
TOX messaging platform ID. Example: itype="tox_id" |
| trojan_domain | Trojan Domain | Domain | High |
Domain associated with Trojan malware that disguises as a legitimate code or software. Example: itype="trojan_domain" |
| trojan_hash | Trojan File Hash | Hash | High |
File hash associated with Trojan malware that disguises as a legitimate code or software. Example: itype="trojan_hash" |
| trojan_ip | Trojan IP Address | IP | High |
IP address associated with Trojan malware that disguises as a legitimate code or software. Example: itype="trojan_ip" |
| trojan_ipv6 | Trojan IPv6 Address | IP | High |
IPv6 address associated with a Trojan malware that disguises as a legitimate code of software. Example: itype="trojan_ipv6" |
| trojan_url | Trojan URL | URL | High |
URL associated with a Trojan malware that disguises as a legitimate code or software. Example: itype="trojan_url" |
| twitter_handle | Twitter Handle | String | Medium |
Twitter handle or social media identifier. Example: itype="twitter_handle" |
| visitor_token | Visitor Token | String | High |
Token used for session tracking. Example: itype="visitor_token" |
| vpn_domain | Anonymous VPN Domain | Domain | Low |
Domain name associated with commercial or free Virtual Private Networks (VPN). Example: itype="vpn_domain" |
| vps_ip | Cloud Server IP | IP | Low |
IP address that is used for hosting Virtual Private Servers (VPS) or other server rentals. Example: itype="vps_ip" |
| vps_ipv6 | Cloud Server IPv6 | IP | Low |
IPv6 address that is used for hosting Virtual Private Servers (VPS) or other server rentals. Example: itype="vps_ipv6" |
| vuln_risk_score | Vulnerability Risk Score | String | Low |
Risk score for a vulnerability. Example: itype="vuln_risk_score" |
| web3_attack_vector | Web 3 Attack Vector | String | High |
Address of a known malicious smart contract. Example: itype="web3_attack_vector" |
| web3_compromised_wallet | Web3 Compromised Wallet | String | High |
Wallet address involved in fraudulent or malicious transactions. Example: itype="web3_compromised_wallet" |
| web3_dns_hijacking | Web3 DNS Hijacking | String | Medium |
Detection of tampering attempts on decentralized DNS (for example, ENS). Example: itype="web3_dns_hijacking" |
| web3_exploitable_code | Web3 Exploitable Code | String | High |
Code pattern within dApps or smart contracts vulnerable to attacks. Example: itype="web3_exploitable_code" |
| web3_malicious_contract | Web3 Malicious Contract | String | High |
Address of a known malicious smart contract. Example: itype="web3_malicious_contract" |
| web3_malicious_token | Web3 Malicious Token | String | High |
Identifier of a fraudulent or scam-related token contract. Example: itype="web3_malicious_token" |
| web3_phishing_domain | Web3 Phishing Domain | String | High |
Domain or URL used for Web3 phishing attacks. Example: itype="web3_phishing_domain" |
| web3_suspicious_pattern | Web3 Suspisious Pattern | String | High |
Transaction behavior indicative of exploits or attacks. Example: itype="web3_suspicious_pattern" |
| whois_bulk_reg_email | Whois Bulk Registrant Email | Low |
Registrant email address associated with privacy domain purchased from Whois. Example: itype="whois_bulk_reg_email" |
|
| whois_privacy_domain | Whois Privacy Email Domain | Domain | Low |
Privacy domain purchased from Whois. Example: itype="whois_privacy_domain" |
| whois_privacy_email | Whois Privacy Email | Low |
Email address associated with a privacy domain purchased from Whois. Example: itype="whois_privacy_email" |
|
| xampp_jabber_id | Xampp Jabber ID | String | Medium |
XAMPP/Jabber messaging ID. Example: itype="xampp_jabber_id" |