Become a Beta Tester

DocsProtection

Factory Protection Rules

The rule sets and thresholds every account starts with.

Every account starts with these rules already filled in. Change any of them under Protection. Each level has Back to the Frabs Preset and each detector has Restore Factory Settings.

Automatic Protection: what happens at each level

LevelFactory rules
WarningNotify Your Team, Open Support Ticket
IncidentNotify Your Team, Open Support Ticket, Contain the Attack
CriticalNotify Your Team, Open Support Ticket, Contain the Attack

Suspend VM at Critical

Suspending needs a billing integration that can suspend, such as WHMCS. Without one, the VM stays isolated and your team is told.

Contain the Attack

Attack typeBecomes
Floods, amplification, spam and most othersRate limit
Port scans, discovery, reconnaissance, brute force, remote-service abuseConnection limit
Botnet (C2), cryptomining and known-bad destinationsBlock the destination

Alert-only types

Data exfiltration and abnormal behaviour only ever notify your team: Frabs never acts on its own for them, whatever the rules.

Repeat offences

On top of each level's rules, repeat offences escalate. See Recovery and Repeat Offences.

Factory thresholds for every detector

DetectorMeasuresWarningIncidentCritical
TCP SYN FloodOutbound SYN packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
TCP ACK FloodOutbound ACK-only packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
TCP RST FloodOutbound RST packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
TCP Connection FloodNew outbound connections per second500 over 30 s2,000 over 30 s5,000 over 30 s
TCP Fragment FloodOutbound fragmented packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
UDP FloodOutbound UDP packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
ICMP FloodOutbound ICMP packets per second500 over 30 s2,000 over 30 s5,000 over 30 s
ICMPv6 FloodOutbound ICMPv6 packets per second500 over 30 s2,000 over 30 s5,000 over 30 s
GRE FloodOutbound GRE packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
ESP FloodOutbound ESP packets per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
HTTPS FloodOutbound TLS connections per second to web ports (443, 8443)500 over 30 s2,000 over 30 s5,000 over 30 s
DNS Query FloodOutbound DNS queries per second500 over 30 s2,000 over 30 s5,000 over 30 s
Generic Protocol FloodOutbound packets of other protocols per second1,000 over 30 s5,000 over 30 s10,000 over 30 s
High-Rate Outbound FloodOutbound packets per second10,000 over 30 s50,000 over 30 s100,000 over 30 s
Packet FloodOutbound packets per second10,000 over 30 s50,000 over 30 s100,000 over 30 s
Bandwidth FloodOutbound megabits per second300 over 1 min600 over 30 s1,000 over 15 s
TCP Port ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
UDP Port ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
SYN ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Connect ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
FIN ScanPackets with FIN, NULL or XMAS flag patterns per second10 over 1 min100 over 1 min1,000 over 1 min
NULL ScanPackets with FIN, NULL or XMAS flag patterns per second10 over 1 min100 over 1 min1,000 over 1 min
XMAS ScanPackets with FIN, NULL or XMAS flag patterns per second10 over 1 min100 over 1 min1,000 over 1 min
ACK ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Window ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Maimon ScanPackets with FIN, NULL or XMAS flag patterns per second10 over 1 min100 over 1 min1,000 over 1 min
SCTP ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
ICMP ScanDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
Mixed Protocol ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Randomised Port ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Vertical Port ScanDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Horizontal Port ScanDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
Host DiscoveryDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
ICMP Host SweepDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
TCP Host SweepDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
UDP Host SweepDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
ARP SweepDistinct destination addresses50 over 1 min200 over 5 min1,000 over 10 min
Subnet SweepDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
Network SweepDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
Internet-Wide Host ScanningDistinct destination addresses1,000 over 10 min5,000 over 30 min10,000 over 1 h
Random IP ScanningDistinct destination addresses1,000 over 10 min5,000 over 30 min10,000 over 1 h
Sequential IP ScanningDistinct destination addresses100 over 5 min1,000 over 10 min5,000 over 30 min
Service DiscoveryDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Service EnumerationDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Banner GrabbingDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
Network Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
Service Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
Web Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
SSH Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
RDP Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
FTP Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
SMB Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
Database Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
CMS Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
IoT Vulnerability ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
SSH Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
RDP Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
FTP Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
Telnet Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
SMTP Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
HTTP Brute ForceShort connections to authentication ports100 over 5 min500 over 10 min2,000 over 30 min
HTTPS Brute ForceShort connections to authentication ports100 over 5 min500 over 10 min2,000 over 30 min
Database Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
SMB Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
VNC Brute ForceDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
API Brute ForceShort connections to authentication ports100 over 5 min500 over 10 min2,000 over 30 min
Password SprayingDistinct targets on the service's ports20 over 5 min100 over 10 min500 over 30 min
Credential StuffingShort connections to authentication ports100 over 5 min500 over 10 min2,000 over 30 min
Authentication FloodingShort connections to authentication ports100 over 5 min500 over 10 min2,000 over 30 min
Known C2 CommunicationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Malicious DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Botnet CommunicationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Botnet BeaconingRegularity of repeated connections (0-100)50 over 10 min70 over 30 min90 over 1 h
Malware BeaconingRegularity of repeated connections (0-100)50 over 10 min70 over 30 min90 over 1 h
Periodic BeaconingRegularity of repeated connections (0-100)50 over 10 min70 over 30 min90 over 1 h
HTTP C2Contacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
HTTPS C2Contacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
DNS C2Tunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
IRC C2Contacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Custom Protocol C2Regularity of repeated connections (0-100)50 over 10 min70 over 30 min90 over 1 h
Encrypted C2Regularity of repeated connections (0-100)50 over 10 min70 over 30 min90 over 1 h
Domain Generation ActivityAverage entropy of queried names3.5 over 5 min4 over 10 min4.5 over 30 min
Remote Access Trojan TrafficContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Backdoor CommunicationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Malware DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Trojan DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
RAT DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Stealer DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Botnet DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Ransomware DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Exploit Kit TrafficContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Malicious Payload DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Malware Download TrafficContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Malicious Script DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
SMTP SpamSMTP sessions to distinct mail servers500 over 1 h2,000 over 1 h5,000 over 1 h
Bulk SMTPOutbound SMTP connections (25, 465, 587)100 over 1 h500 over 1 h1,000 over 1 h
Mass Email SendingSMTP sessions to distinct mail servers500 over 1 h2,000 over 1 h5,000 over 1 h
SMTP Connection FloodNew outbound connections per second20 over 1 min100 over 1 min500 over 1 min
Spam Campaign ActivitySMTP sessions to distinct mail servers500 over 1 h2,000 over 1 h5,000 over 1 h
Phishing Email DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Malware Email DistributionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
High-Volume Outbound EmailOutbound SMTP connections (25, 465, 587)100 over 1 h500 over 1 h1,000 over 1 h
SMTP Reputation AbuseContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
DNS FloodOutbound DNS queries per second500 over 30 s2,000 over 30 s5,000 over 30 s
Excessive DNS QueriesOutbound DNS queries per second100 over 1 min500 over 1 min2,000 over 1 min
DNS EnumerationDistinct subdomains queried under one domain200 over 10 min1,000 over 30 min5,000 over 1 h
DNS TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
DNS ExfiltrationTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
DNS BeaconingRegularity of repeated connections (0-100)50 over 10 min70 over 30 min90 over 1 h
Randomised Subdomain ActivityDistinct subdomains queried under one domain200 over 10 min1,000 over 30 min5,000 over 1 h
DGA ActivityAverage entropy of queried names3.5 over 5 min4 over 10 min4.5 over 30 min
High-Entropy DNS QueriesAverage entropy of queried names3.5 over 5 min4 over 10 min4.5 over 30 min
Suspicious DNS ResolutionContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Proxy Pool BehaviourDistinct destination addresses50 over 1 h100 over 1 h500 over 1 h
Tor Relay TrafficContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Tor Exit TrafficContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
HTTPS Request FloodOutbound TLS connections per second to web ports (443, 8443)500 over 30 s2,000 over 30 s5,000 over 30 s
Aggressive CrawlingDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Web Application ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
CMS ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
WordPress ScanningDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
Login Brute ForceShort connections to authentication ports100 over 5 min500 over 10 min2,000 over 30 min
Web Vulnerability ProbingDistinct targets on the service's ports50 over 10 min250 over 30 min1,000 over 1 h
SSH ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
RDP ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
FTP ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Telnet ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
VNC ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
SMB ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
WinRM ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Database ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Redis ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Elasticsearch ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Docker API ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Kubernetes API ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Remote Service EnumerationDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Mining Pool CommunicationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Stratum MiningConnections speaking the Stratum mining protocol1 over 10 min3 over 30 min5 over 1 h
Stratum V1 TrafficConnections speaking the Stratum mining protocol1 over 10 min3 over 30 min5 over 1 h
Stratum V2 TrafficConnections speaking the Stratum mining protocol1 over 10 min3 over 30 min5 over 1 h
Mining Proxy CommunicationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Cryptocurrency Pool DiscoveryContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Mining DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Large Outbound TransferBytes sent to external destinations1,000,000,000 over 1 h10,000,000,000 over 1 h50,000,000,000 over 1 h
High-Volume External UploadBytes sent to external destinations1,000,000,000 over 1 h10,000,000,000 over 1 h50,000,000,000 over 1 h
Suspicious External DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Exfiltration DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Encrypted Tunnel ActivityTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
ICMP TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
HTTP TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
HTTPS TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
SSH TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
TCP TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
UDP TunnellingTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
Reverse TunnelTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
Unexpected VPN TunnelTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
Proxy TunnelTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
Covert Channel BehaviourTunnelling indicators (0-100)50 over 10 min70 over 30 min90 over 1 h
Blockchain Node ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Cryptocurrency Service ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Wallet Service ScanningDistinct targets on the service's ports100 over 5 min1,000 over 10 min5,000 over 30 min
Mining Pool ActivityContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Crypto Botnet ActivityContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Crypto Infrastructure CommunicationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Internet-Wide ScanningDistinct destination addresses1,000 over 10 min5,000 over 30 min10,000 over 1 h
Mass Port ScanningDistinct destination ports1,000 over 10 min5,000 over 30 min10,000 over 1 h
Mass Host ScanningDistinct destination addresses1,000 over 10 min5,000 over 30 min10,000 over 1 h
Mass Service DiscoveryDistinct targets on the service's ports1,000 over 10 min5,000 over 30 min10,000 over 1 h
Mass Banner GrabbingDistinct targets on the service's ports1,000 over 10 min5,000 over 30 min10,000 over 1 h
Internet-Wide Vulnerability ScanningDistinct targets on the service's ports1,000 over 10 min5,000 over 30 min10,000 over 1 h
Continuous ReconnaissanceDistinct destination addresses5,000 over 6 h20,000 over 12 h50,000 over 24 h
Randomised Internet ScanningDistinct destination addresses1,000 over 10 min5,000 over 30 min10,000 over 1 h
Excessive Outbound ConnectionsDistinct destination addresses1,000 over 1 h5,000 over 1 h10,000 over 1 h
Excessive New ConnectionsNew outbound connections per second500 over 30 s2,000 over 30 s5,000 over 30 s
Excessive Destination CountDistinct destination addresses1,000 over 1 h5,000 over 1 h10,000 over 1 h
Excessive Port CountDistinct destination ports100 over 1 min500 over 5 min1,000 over 10 min
Excessive Packet RateOutbound packets per second10,000 over 30 s50,000 over 30 s100,000 over 30 s
Excessive BandwidthOutbound megabits per second300 over 1 min600 over 30 s1,000 over 15 s
Connection BurstNew outbound connections per second1,000 over 10 s5,000 over 10 s10,000 over 10 s
Destination BurstDistinct destination addresses500 over 1 min2,000 over 1 min5,000 over 1 min
Port BurstDistinct destination ports200 over 10 s1,000 over 10 s5,000 over 10 s
Persistent High-Rate TrafficOutbound packets per second10,000 over 30 min50,000 over 30 min100,000 over 1 h
Known C2 DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Malware DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Phishing DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Spam DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Known Botnet DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
IP Blocklist MatchContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
DNSBL MatchContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Abuse Feed MatchContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Threat Intelligence MatchContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Repeated Abuse DestinationContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h
Outbound IP Reputation EventContacts with addresses on threat-intelligence lists1 over 10 min10 over 1 h100 over 1 h