DocsProtection
Attack Types
All 19 attack types Frabs detects.
| Attack type | In short |
|---|---|
| DDoS & Flooding | Floods of packets, connections or requests sent from a VM. |
| Port Scanning | One VM probing many ports on other machines. |
| Host & Network Discovery | Sweeps across many addresses or networks to find live hosts and services. |
| Vulnerability & Exploit Scanning | Probing other machines for known weaknesses. |
| Brute Force & Credential Attacks | Repeated login attempts against other machines. |
| Malware & Command-and-Control | Communication matching known command-and-control or botnet behaviour. |
| Malicious Payload Distribution | A VM serving or fetching known malicious payloads. |
| Spam & Email Abuse | Unusual volumes or patterns of outbound mail. |
| DNS Abuse | DNS floods, tunnelling, generated domains and resolver abuse. |
| Proxy, Relay & Anonymisation | A VM relaying other people's traffic. |
| Web & Application Abuse | Automated web traffic: floods, scraping, enumeration and login abuse. |
| Remote-Service Abuse | Scanning for exposed remote-access and database services. |
| Cryptomining | Communication with cryptocurrency mining pools. |
| Data Exfiltration & Suspicious Transfers | Unusual outbound transfers for this VM. |
| Network Tunnelling & Covert Traffic | Traffic carried inside other protocols. |
| Cryptocurrency & Blockchain Abuse | Scanning and abuse aimed at blockchain and wallet services. |
| Reconnaissance & Internet-Wide Abuse | Scanning at Internet scale. |
| Abnormal Network Behaviour | Behaviour far outside normal that matches no specific signature. |
| Reputation & Abuse Intelligence | Contact with destinations on threat-intelligence and abuse lists. |