User Tools

Site Tools


threat_analyzer_-_mail_plugin

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
threat_analyzer_-_mail_plugin [2018/05/24 08:51] lucythreat_analyzer_-_mail_plugin [2019/06/03 16:15] lucy
Line 37: Line 37:
   - Threat Details can be viewed by clicking on the date   - Threat Details can be viewed by clicking on the date
  
 +{{ threat1.png?600 }}
 ===== Automatic Incident Analysis (Threat Analyzer) ===== ===== Automatic Incident Analysis (Threat Analyzer) =====
  
Line 56: Line 56:
 The current sources (LUCY 3.7) are: The current sources (LUCY 3.7) are:
  
-  * https://safebrowsing.googleapis.com/v4/threatMatches:find (port 443)+  * https://developers.google.com/safe-browsing/v4/lookup-api
   * http://data.phishtank.com/data/online-valid.csv (port 80)   * http://data.phishtank.com/data/online-valid.csv (port 80)
   * DNS BL queries to bl.spamcop.net and zen.spamhaus.org   * DNS BL queries to bl.spamcop.net and zen.spamhaus.org
   * CI Army (list) (http://cinsscore.com/) - Network security Block Lists.   * CI Army (list) (http://cinsscore.com/) - Network security Block Lists.
-  * Palevo Blocklists (https://palevotracker.abuse.ch/blocklists.php) - Botnet C&C blocklists. 
   * Cybercrime tracker (http://cybercrime-tracker.net/) -   * Cybercrime tracker (http://cybercrime-tracker.net/) -
  
threat_analyzer_-_mail_plugin.txt · Last modified: 2019/07/25 12:49 by 127.0.0.1