Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Overview
When you set up threat intelligence rules blocking access to high severity threat sites, Microsoft assigns each transaction a threat type. This article provides a list of categories along with explanations.
Note
You can check a destination's threat type using the Threat Type column in Global Secure Access Traffic Logs. If you would like to report a false positive, in addition to adding a new rule, you can make a request via email using this template.
Threat types
| Threat Type | Description |
|---|---|
| Botnet | Indicator is detailing a botnet node/member. |
| BruteForce | Indicator is detailing a Brute Force attack. It can be either victim or attacker. |
| C2 | Indicator is detailing a C2 (Command & Control) node of a botnet. |
| CryptoMining | Traffic involving this network address / URL is an indication of Crypto Mining / Resource abuse. |
| Darknet | Indicator is that of a Darknet node/network. |
| DDoS | Indicators relating to an active or upcoming DDoS (distributed denial of service) campaign. |
| MaliciousUrl | URL that is serving malware. |
| Malware | Indicator describing a malicious file or files. |
| Phishing | Indicators relating to a phishing campaign. |
| Proxy | Indicator is that of a proxy service. |
| PUA | PUA (Potentially Unwanted Application). |
| WatchList or Suspicious | This is the generic bucket into which indicators are placed when it cannot be determined exactly what the threat is or will require manual interpretation. |