intelmq.bots.experts.idea package¶
Submodules¶
intelmq.bots.experts.idea.expert module¶
IDEA classification: https://idea.cesnet.cz/en/classifications
-
intelmq.bots.experts.idea.expert.
BOT
¶
-
class
intelmq.bots.experts.idea.expert.
IdeaExpertBot
(bot_id: str, start: bool = False, sighup_event=None, disable_multithreading: bool = None)¶ Bases:
intelmq.lib.bot.Bot
-
get_value
(src, value)¶
-
init
()¶
-
process
()¶
-
process_dict
(src, description)¶
-
process_list
(src, description)¶
-
type_to_category
= {'Unauthorised-information-access': 'Information.UnauthorizedAccess', 'Unauthorised-information-modification': 'Information.UnauthorizedModification', 'application-compromise': 'Intrusion.AppCompromise', 'backdoor': 'Intrusion.AdminCompromise', 'blacklist': 'Other', 'brute-force': 'Attempt.Login', 'burglary': 'Intrusion', 'c2server': 'Intrusion.Botnet', 'compromised': 'Intrusion.AdminCompromise', 'copyright': 'Fraud.Copyright', 'data-loss': 'Information', 'ddos': 'Availability.DDoS', 'ddos-amplifier': 'Intrusion.Botnet', 'defacement': 'Intrusion.AppCompromise', 'dga domain': 'Anomaly.Behaviour', 'dos': 'Availability.DoS', 'dropzone': 'Information.UnauthorizedAccess', 'exploit': 'Attempt.Exploit', 'harmful-speech': 'Abusive.Harassment', 'ids-alert': 'Attempt.Exploit', 'infected-system': 'Malware', 'information-disclosure': 'Information.UnauthorizedAccess', 'leak': 'Information', 'malware': 'Malware', 'malware-configuration': 'Malware', 'malware-distribution': 'Malware', 'masquerade': 'Fraud.Scam', 'other': 'Other', 'outage': 'Availability.Outage', 'phishing': 'Fraud.Phishing', 'potentially-unwanted-accessible': 'Vulnerable.Open', 'privileged-account-compromise': 'Intrusion.AdminCompromise', 'proxy': 'Vulnerable.Config', 'ransomware': 'Malware', 'sabotage': 'Availability.Sabotage', 'scanner': 'Recon.Scanning', 'sniffing': 'Recon.Sniffing', 'social-engineering': 'Recon.SocialEngineering', 'spam': 'Abusive.Spam', 'test': 'Test', 'tor': 'Other', 'unauthorized-command': 'Intrusion.AdminCompromise', 'unauthorized-login': 'Intrusion.AdminCompromise', 'unauthorized-use-of-resources': 'Fraud.UnauthorizedUsage', 'unknown': 'Other', 'unprivileged-account-compromise': 'Intrusion.UserCompromise', 'violence': 'Abusive.Violence', 'vulnerable client': 'Vulnerable.Config', 'vulnerable service': 'Vulnerable.Open', 'vulnerable-system': 'Vulnerable.Config', 'weak-crypto': 'Vulnerable.Config'}¶
-
type_to_source_type
= {'c2server': 'CC', 'dga domain': 'DGA', 'dropzone': 'Dropzone', 'malware-configuration': 'MalwareConf', 'malware-distribution': 'Malware', 'phishing': 'Phishing', 'proxy': 'Proxy', 'tor': 'Tor'}¶
-
-
intelmq.bots.experts.idea.expert.
addr4
(s)¶
-
intelmq.bots.experts.idea.expert.
addr6
(s)¶
-
intelmq.bots.experts.idea.expert.
quot
(s)¶