intelmq.bots.experts.idea package

Submodules

intelmq.bots.experts.idea.expert module

IDEA classification: https://idea.cesnet.cz/en/classifications

intelmq.bots.experts.idea.expert.BOT

alias of intelmq.bots.experts.idea.expert.IdeaExpertBot

class intelmq.bots.experts.idea.expert.IdeaExpertBot(bot_id: str, start: bool = False, sighup_event=None, disable_multithreading: bool = None)

Bases: intelmq.lib.bot.Bot

get_value(src, value)
init()
process()
process_dict(src, description)
process_list(src, description)
type_to_category = {'Unauthorised-information-access': 'Information.UnauthorizedAccess', 'Unauthorised-information-modification': 'Information.UnauthorizedModification', 'application-compromise': 'Intrusion.AppCompromise', 'backdoor': 'Intrusion.AdminCompromise', 'blacklist': 'Other', 'brute-force': 'Attempt.Login', 'burglary': 'Intrusion', 'c2server': 'Intrusion.Botnet', 'compromised': 'Intrusion.AdminCompromise', 'copyright': 'Fraud.Copyright', 'data-loss': 'Information', 'ddos': 'Availability.DDoS', 'ddos-amplifier': 'Intrusion.Botnet', 'defacement': 'Intrusion.AppCompromise', 'dga domain': 'Anomaly.Behaviour', 'dos': 'Availability.DoS', 'dropzone': 'Information.UnauthorizedAccess', 'exploit': 'Attempt.Exploit', 'harmful-speech': 'Abusive.Harassment', 'ids-alert': 'Attempt.Exploit', 'infected-system': 'Malware', 'information-disclosure': 'Information.UnauthorizedAccess', 'leak': 'Information', 'malware': 'Malware', 'malware-configuration': 'Malware', 'malware-distribution': 'Malware', 'masquerade': 'Fraud.Scam', 'other': 'Other', 'outage': 'Availability.Outage', 'phishing': 'Fraud.Phishing', 'potentially-unwanted-accessible': 'Vulnerable.Open', 'privileged-account-compromise': 'Intrusion.AdminCompromise', 'proxy': 'Vulnerable.Config', 'ransomware': 'Malware', 'sabotage': 'Availability.Sabotage', 'scanner': 'Recon.Scanning', 'sniffing': 'Recon.Sniffing', 'social-engineering': 'Recon.SocialEngineering', 'spam': 'Abusive.Spam', 'test': 'Test', 'tor': 'Other', 'unauthorized-command': 'Intrusion.AdminCompromise', 'unauthorized-login': 'Intrusion.AdminCompromise', 'unauthorized-use-of-resources': 'Fraud.UnauthorizedUsage', 'unknown': 'Other', 'unprivileged-account-compromise': 'Intrusion.UserCompromise', 'violence': 'Abusive.Violence', 'vulnerable client': 'Vulnerable.Config', 'vulnerable service': 'Vulnerable.Open', 'vulnerable-system': 'Vulnerable.Config', 'weak-crypto': 'Vulnerable.Config'}
type_to_source_type = {'c2server': 'CC', 'dga domain': 'DGA', 'dropzone': 'Dropzone', 'malware-configuration': 'MalwareConf', 'malware-distribution': 'Malware', 'phishing': 'Phishing', 'proxy': 'Proxy', 'tor': 'Tor'}
intelmq.bots.experts.idea.expert.addr4(s)
intelmq.bots.experts.idea.expert.addr6(s)
intelmq.bots.experts.idea.expert.quot(s)

Module contents