Threat Types in ThreatStream
During the import process, ThreatStream uses machine learning to assign indicator types to imported observables based on the threat type you select. The following table lists all available threat types in ThreatStream, in addition to the indicator types with which they are associated. For more on indicator types, see Indicator Types in ThreatStream.
| Threat Type | Name | Example | Associated Indicator Types |
|---|---|---|---|
| actor | Actor | threat_type="actor" | threat_actor_hostname |
| adware | Adware | threat_type="adware" | adware_domain |
| anomalous | Anomalous | threat_type="anomalous" | geolocation_url, ipcheck_url, speedtest_url |
| anonymization | Anonymization | threat_type="anonymization" | anon_proxy, anon_proxy_ipv6, anon_vpn, anon_vpn_ipv6, corp_vpn_ip, mal_relay_server_ip, mal_relay_server_ipv6, proxy_ip, proxy_ipv6, vpn_domain |
| apt | APT | threat_type="apt" | apt_domain, apt_email, apt_email_subject, apt_file_name, apt_file_path, apt_ip, apt_ipv6, apt_md5, apt_mta, apt_mutex, apt_registry_key, apt_service_description, apt_service_displayname, apt_service_name, apt_ssdeep, apt_subject, apt_ua apt_url |
| benign | Benign | threat_type="benign" | benign_email, benign_domain, benign_hash, benign_internal_email, benign_ip, benign_url |
| bot | Bot | threat_type="bot" | bot_domain, bot_ip, bot_ipv6, bot_md5, bot_url, botnet_user_agent |
| brute | Brute | threat_type="brute" | brute_ip, brute_ipv6, ssh_ip, ssh_ipv6 |
| c2 | C2 | threat_type="c2" | c2_domain, c2_dns_name, c2_ip, c2_ipv6, c2_url, suspected_c2_dns_name |
| communication | Communication | threat_type="communication" | tox_id, txampp_jabber_id |
| compromised | Compromised | threat_type="compromised" | compromised_company, compromised_domain, compromised_email, compromised_email_subject, compromised_ip, compromised_ipv6, compromised_password, compromised_port, compromised_url, compromised_username |
| crypto | Crypto | threat_type="crypto" | crypto_hash, crypto_ip, crypto_pool, crypto_url, crypto_wallet |
| crypto_currency | Crypto Currency | threat_type="crypto_currency" | bitcoin_wallet |
| data_leakage | Data Leakage | threat_type="data_leakage" | pastesite_url |
| ddos | DDOS | threat_type="ddos" | ddos_ip, ddos_ipv6 |
| dyn_dns | Dynamic DNS | threat_type="dyn_dns" | dyn_dns, freq_abused_dns_provider |
| exfil | Exfil | threat_type="exfil" | exfil_domain, exfil_ip, exfil_ipv6, exfil_url |
| exploit | Exploit | threat_type="exploit" | exploit_cve_id, exploit_domain, exploit_ip, exploit_ipv6, exploit_md5, exploit_url |
| fraud | Fraud | threat_type="fraud" |
aws_account_id, customer_account_id, fraud_domain, fraud_email, fraud_email_subject, fraud_ip, phone_number, fraud_md5, fraud_url, iam_user_id, platform_uid |
| gaming | Gaming | threat_type="gaming" | gaming_device_id, gaming_device_name, gaming_game_id, gaming_game_name, gaming_player_email, gaming_player_country, gaming_player_id, gaming_player_nickname, gaming_player_phone |
| hack_tool | Hacking Tool | threat_type="hack_tool" | hack_tool, hack_tool_md5 |
| i2p | I2P | threat_type="i2p" | i2p_ip, i2p_ipv6 |
| informational | Informational | threat_type="informational" | benign_device_id, cloud_instance_id, comm_proxy_domain, comm_proxy_ip, device_serial_number, disposable_email_domain, employee_id, free_email_domain, internal_dns_name, internal_host_id, internal_ticket_id, passphrase, session_token, ssl_cert_serial_number, sso_session_id, visitor_token, whois_bulk_reg_email, whois_privacy_domain, whois_privacy_email |
| infrastructure | Infrastructure | threat_type="infrastructure" | asn |
| ja3_md5 | JA3/JA3S TLS Fingerprint | threat_type="ja3_md" | ja3_md5 |
| ja4_tls_fingerprint | JA4 TLS Fingerprint | threat_type="ja4_tls_fingerprint" | ja4_tls_fingerprint |
| malware | Malware | threat_type="malware" | cobalt_strike_id, encrypted_file_ext, mal_domain, mal_email, mal_email_subject, email_attachment_subject, mal_file_name, mal_file_path, mal_ip, mal_ipv6, mal_md5, mal_mutex, mal_port, mal_registry_key, mal_service_description, mal_service_displayname, mal_service_name, mal_ssdeep, mal_sslcert_sha1, mal_ua, mal_url, mal_wildcard_domain, mal_wildcard_url, mobile_malware |
| p2p | P2P | threat_type="p2p" | actor_ip actor_ipv6, actor_phone_number, actor_subject, actor_username, p2pcnc, p2pcnc_ipv6, torrent_tracker_url |
| parked | Parked | threat_type="parked" | parked_domain, parked_ip, parked_ipv6, parked_url |
| phish | Phish | threat_type="phish" | phish_domain, phish_email, phish_email_subject, phish_file_name, phish_ip, phish_ipv6, phish_url, phishing_target |
| ransomware | Ransomware | threat_type="ransomware" | ransomware_domain, ransomware_group, ransomware_hash, ransomware_ip, ransomware_ipv6, ransomware_url, ransomware_victim_name, ransomware_victim_domain, ransomware_victim_url |
| scan | Scan | threat_type="scan" | scan_ip, scan_ipv6 |
| sinkhole | Sinkhole | threat_type="sinkhole" | sinkhole_domain, sinkhole_ip, sinkhole_ipv6 |
| social | Social | threat_type="social" | telegram_id, twitter_handle |
| spam | Spam | threat_type="spam" | adware_registry_key, spam_domain, spam_email, spam_email_subject, spam_ip, spam_ipv6, spam_mta spam_url |
| suppress | Suppress | threat_type="suppress" | suppress |
| suspicious | Suspicious | threat_type="suspicious" | new_domain, suspicious_domain, suspicious_email, suspicious_email_subject, suspicious_ip, suspicious_reg_email, suspicious_url, sus_wildcard_domain, sus_wildcard_url |
| tor | TOR | threat_type="tor" | tor_ip, tor_ipv6 |
| vps | VPS | threat_type="vps" | vps_ip, vps_ipv6 |
| web3 | Web3 | threat_type="web3" | web3_attack_vector, web3_compromised_wallet, web3_dns_hijacking, web3_exploitable_code, web3_malicious_contract, web3_malicious_token, web3_phishing_domain, web3_suspicious_txn_pattern |