Edit

Global Secure Access Threat intelligence threat types

Overview

When you set up threat intelligence rules blocking access to high severity threat sites, Microsoft assigns each transaction a threat type. This article provides a list of categories along with explanations.

Note

You can check a destination's threat type using the Threat Type column in Global Secure Access Traffic Logs. If you would like to report a false positive, in addition to adding a new rule, you can make a request via email using this template.

Threat types

Threat Type Description
Botnet Indicator is detailing a botnet node/member.
BruteForce Indicator is detailing a Brute Force attack. It can be either victim or attacker.
C2 Indicator is detailing a C2 (Command & Control) node of a botnet.
CryptoMining Traffic involving this network address / URL is an indication of Crypto Mining / Resource abuse.
Darknet Indicator is that of a Darknet node/network.
DDoS Indicators relating to an active or upcoming DDoS (distributed denial of service) campaign.
MaliciousUrl URL that is serving malware.
Malware Indicator describing a malicious file or files.
Phishing Indicators relating to a phishing campaign.
Proxy Indicator is that of a proxy service.
PUA PUA (Potentially Unwanted Application).
WatchList or Suspicious This is the generic bucket into which indicators are placed when it cannot be determined exactly what the threat is or will require manual interpretation.