Threat Types in ThreatStream

During the import process, ThreatStream uses machine learning to assign indicator types to imported observables based on the threat type you select. The following table lists all available threat types in ThreatStream, in addition to the indicator types with which they are associated. For more on indicator types, see Indicator Types in ThreatStream.

Threat Type Name Example Associated Indicator Types
actor Actor threat_type="actor" threat_actor_hostname
adware Adware threat_type="adware" adware_domain
anomalous Anomalous threat_type="anomalous" geolocation_url, ipcheck_url, speedtest_url
anonymization Anonymization threat_type="anonymization" anon_proxy, anon_proxy_ipv6, anon_vpn, anon_vpn_ipv6, corp_vpn_ip, mal_relay_server_ip, mal_relay_server_ipv6, proxy_ip, proxy_ipv6, vpn_domain
apt APT threat_type="apt" apt_domain, apt_email, apt_email_subject, apt_file_name, apt_file_path, apt_ip, apt_ipv6, apt_md5, apt_mta, apt_mutex, apt_registry_key, apt_service_description, apt_service_displayname, apt_service_name, apt_ssdeep, apt_subject, apt_ua apt_url
benign Benign threat_type="benign" benign_email, benign_domain, benign_hash, benign_internal_email, benign_ip, benign_url
bot Bot threat_type="bot" bot_domain, bot_ip, bot_ipv6, bot_md5, bot_url, botnet_user_agent
brute Brute threat_type="brute" brute_ip, brute_ipv6, ssh_ip, ssh_ipv6
c2 C2 threat_type="c2" c2_domain, c2_dns_name, c2_ip, c2_ipv6, c2_url, suspected_c2_dns_name
communication Communication threat_type="communication" tox_id, txampp_jabber_id
compromised Compromised threat_type="compromised" compromised_company, compromised_domain, compromised_email, compromised_email_subject, compromised_ip, compromised_ipv6, compromised_password, compromised_port, compromised_url, compromised_username
crypto Crypto threat_type="crypto" crypto_hash, crypto_ip, crypto_pool, crypto_url, crypto_wallet
crypto_currency Crypto Currency threat_type="crypto_currency" bitcoin_wallet
data_leakage Data Leakage threat_type="data_leakage" pastesite_url
ddos DDOS threat_type="ddos" ddos_ip, ddos_ipv6
dyn_dns Dynamic DNS threat_type="dyn_dns" dyn_dns, freq_abused_dns_provider
exfil Exfil threat_type="exfil" exfil_domain, exfil_ip, exfil_ipv6, exfil_url
exploit Exploit threat_type="exploit" exploit_cve_id, exploit_domain, exploit_ip, exploit_ipv6, exploit_md5, exploit_url
fraud Fraud threat_type="fraud"

aws_account_id, customer_account_id, fraud_domain, fraud_email, fraud_email_subject, fraud_ip, phone_number, fraud_md5, fraud_url, iam_user_id, platform_uid

gaming Gaming threat_type="gaming" gaming_device_id, gaming_device_name, gaming_game_id, gaming_game_name, gaming_player_email, gaming_player_country, gaming_player_id, gaming_player_nickname, gaming_player_phone
hack_tool Hacking Tool threat_type="hack_tool" hack_tool, hack_tool_md5
i2p I2P threat_type="i2p" i2p_ip, i2p_ipv6
informational Informational threat_type="informational" benign_device_id, cloud_instance_id, comm_proxy_domain, comm_proxy_ip, device_serial_number, disposable_email_domain, employee_id, free_email_domain, internal_dns_name, internal_host_id, internal_ticket_id, passphrase, session_token, ssl_cert_serial_number, sso_session_id, visitor_token, whois_bulk_reg_email, whois_privacy_domain, whois_privacy_email
infrastructure Infrastructure threat_type="infrastructure" asn
ja3_md5 JA3/JA3S TLS Fingerprint threat_type="ja3_md" ja3_md5
ja4_tls_fingerprint JA4 TLS Fingerprint threat_type="ja4_tls_fingerprint" ja4_tls_fingerprint
malware Malware threat_type="malware" cobalt_strike_id, encrypted_file_ext, mal_domain, mal_email, mal_email_subject, email_attachment_subject, mal_file_name, mal_file_path, mal_ip, mal_ipv6, mal_md5, mal_mutex, mal_port, mal_registry_key, mal_service_description, mal_service_displayname, mal_service_name, mal_ssdeep, mal_sslcert_sha1, mal_ua, mal_url, mal_wildcard_domain, mal_wildcard_url, mobile_malware
p2p P2P threat_type="p2p" actor_ip actor_ipv6, actor_phone_number, actor_subject, actor_username, p2pcnc, p2pcnc_ipv6, torrent_tracker_url
parked Parked threat_type="parked" parked_domain, parked_ip, parked_ipv6, parked_url
phish Phish threat_type="phish" phish_domain, phish_email, phish_email_subject, phish_file_name, phish_ip, phish_ipv6, phish_url, phishing_target
ransomware Ransomware threat_type="ransomware" ransomware_domain, ransomware_group, ransomware_hash, ransomware_ip, ransomware_ipv6, ransomware_url, ransomware_victim_name, ransomware_victim_domain, ransomware_victim_url
scan Scan threat_type="scan" scan_ip, scan_ipv6
sinkhole Sinkhole threat_type="sinkhole" sinkhole_domain, sinkhole_ip, sinkhole_ipv6
social Social threat_type="social" telegram_id, twitter_handle
spam Spam threat_type="spam" adware_registry_key, spam_domain, spam_email, spam_email_subject, spam_ip, spam_ipv6, spam_mta spam_url
suppress Suppress threat_type="suppress" suppress
suspicious Suspicious threat_type="suspicious" new_domain, suspicious_domain, suspicious_email, suspicious_email_subject, suspicious_ip, suspicious_reg_email, suspicious_url, sus_wildcard_domain, sus_wildcard_url
tor TOR threat_type="tor" tor_ip, tor_ipv6
vps VPS threat_type="vps" vps_ip, vps_ipv6
web3 Web3 threat_type="web3" web3_attack_vector, web3_compromised_wallet, web3_dns_hijacking, web3_exploitable_code, web3_malicious_contract, web3_malicious_token, web3_phishing_domain, web3_suspicious_txn_pattern