DocsProtection
Factory Protection Rules
The rule sets and thresholds every account starts with.
Every account starts with these rules already filled in. Change any of them under Protection. Each level has Back to the Frabs Preset and each detector has Restore Factory Settings.
Automatic Protection: what happens at each level
| Level | Factory rules |
|---|---|
| Warning | Notify Your Team, Open Support Ticket |
| Incident | Notify Your Team, Open Support Ticket, Contain the Attack |
| Critical | Notify Your Team, Open Support Ticket, Contain the Attack |
Suspend VM at Critical
Suspending needs a billing integration that can suspend, such as WHMCS. Without one, the VM stays isolated and your team is told.
Contain the Attack
| Attack type | Becomes |
|---|---|
| Floods, amplification, spam and most others | Rate limit |
| Port scans, discovery, reconnaissance, brute force, remote-service abuse | Connection limit |
| Botnet (C2), cryptomining and known-bad destinations | Block the destination |
Alert-only types
Data exfiltration and abnormal behaviour only ever notify your team: Frabs never acts on its own for them, whatever the rules.
Repeat offences
On top of each level's rules, repeat offences escalate. See Recovery and Repeat Offences.
Factory thresholds for every detector
| Detector | Measures | Warning | Incident | Critical |
|---|---|---|---|---|
| TCP SYN Flood | Outbound SYN packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| TCP ACK Flood | Outbound ACK-only packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| TCP RST Flood | Outbound RST packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| TCP Connection Flood | New outbound connections per second | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| TCP Fragment Flood | Outbound fragmented packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| UDP Flood | Outbound UDP packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| ICMP Flood | Outbound ICMP packets per second | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| ICMPv6 Flood | Outbound ICMPv6 packets per second | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| GRE Flood | Outbound GRE packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| ESP Flood | Outbound ESP packets per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| HTTPS Flood | Outbound TLS connections per second to web ports (443, 8443) | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| DNS Query Flood | Outbound DNS queries per second | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| Generic Protocol Flood | Outbound packets of other protocols per second | 1,000 over 30 s | 5,000 over 30 s | 10,000 over 30 s |
| High-Rate Outbound Flood | Outbound packets per second | 10,000 over 30 s | 50,000 over 30 s | 100,000 over 30 s |
| Packet Flood | Outbound packets per second | 10,000 over 30 s | 50,000 over 30 s | 100,000 over 30 s |
| Bandwidth Flood | Outbound megabits per second | 300 over 1 min | 600 over 30 s | 1,000 over 15 s |
| TCP Port Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| UDP Port Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| SYN Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Connect Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| FIN Scan | Packets with FIN, NULL or XMAS flag patterns per second | 10 over 1 min | 100 over 1 min | 1,000 over 1 min |
| NULL Scan | Packets with FIN, NULL or XMAS flag patterns per second | 10 over 1 min | 100 over 1 min | 1,000 over 1 min |
| XMAS Scan | Packets with FIN, NULL or XMAS flag patterns per second | 10 over 1 min | 100 over 1 min | 1,000 over 1 min |
| ACK Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Window Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Maimon Scan | Packets with FIN, NULL or XMAS flag patterns per second | 10 over 1 min | 100 over 1 min | 1,000 over 1 min |
| SCTP Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| ICMP Scan | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Mixed Protocol Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Randomised Port Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Vertical Port Scan | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Horizontal Port Scan | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Host Discovery | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| ICMP Host Sweep | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| TCP Host Sweep | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| UDP Host Sweep | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| ARP Sweep | Distinct destination addresses | 50 over 1 min | 200 over 5 min | 1,000 over 10 min |
| Subnet Sweep | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Network Sweep | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Internet-Wide Host Scanning | Distinct destination addresses | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Random IP Scanning | Distinct destination addresses | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Sequential IP Scanning | Distinct destination addresses | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Service Discovery | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Service Enumeration | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Banner Grabbing | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| Network Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| Service Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| Web Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| SSH Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| RDP Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| FTP Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| SMB Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| Database Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| CMS Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| IoT Vulnerability Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| SSH Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| RDP Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| FTP Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| Telnet Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| SMTP Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| HTTP Brute Force | Short connections to authentication ports | 100 over 5 min | 500 over 10 min | 2,000 over 30 min |
| HTTPS Brute Force | Short connections to authentication ports | 100 over 5 min | 500 over 10 min | 2,000 over 30 min |
| Database Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| SMB Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| VNC Brute Force | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| API Brute Force | Short connections to authentication ports | 100 over 5 min | 500 over 10 min | 2,000 over 30 min |
| Password Spraying | Distinct targets on the service's ports | 20 over 5 min | 100 over 10 min | 500 over 30 min |
| Credential Stuffing | Short connections to authentication ports | 100 over 5 min | 500 over 10 min | 2,000 over 30 min |
| Authentication Flooding | Short connections to authentication ports | 100 over 5 min | 500 over 10 min | 2,000 over 30 min |
| Known C2 Communication | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Malicious Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Botnet Communication | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Botnet Beaconing | Regularity of repeated connections (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Malware Beaconing | Regularity of repeated connections (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Periodic Beaconing | Regularity of repeated connections (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| HTTP C2 | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| HTTPS C2 | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| DNS C2 | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| IRC C2 | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Custom Protocol C2 | Regularity of repeated connections (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Encrypted C2 | Regularity of repeated connections (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Domain Generation Activity | Average entropy of queried names | 3.5 over 5 min | 4 over 10 min | 4.5 over 30 min |
| Remote Access Trojan Traffic | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Backdoor Communication | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Malware Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Trojan Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| RAT Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Stealer Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Botnet Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Ransomware Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Exploit Kit Traffic | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Malicious Payload Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Malware Download Traffic | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Malicious Script Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| SMTP Spam | SMTP sessions to distinct mail servers | 500 over 1 h | 2,000 over 1 h | 5,000 over 1 h |
| Bulk SMTP | Outbound SMTP connections (25, 465, 587) | 100 over 1 h | 500 over 1 h | 1,000 over 1 h |
| Mass Email Sending | SMTP sessions to distinct mail servers | 500 over 1 h | 2,000 over 1 h | 5,000 over 1 h |
| SMTP Connection Flood | New outbound connections per second | 20 over 1 min | 100 over 1 min | 500 over 1 min |
| Spam Campaign Activity | SMTP sessions to distinct mail servers | 500 over 1 h | 2,000 over 1 h | 5,000 over 1 h |
| Phishing Email Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Malware Email Distribution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| High-Volume Outbound Email | Outbound SMTP connections (25, 465, 587) | 100 over 1 h | 500 over 1 h | 1,000 over 1 h |
| SMTP Reputation Abuse | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| DNS Flood | Outbound DNS queries per second | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| Excessive DNS Queries | Outbound DNS queries per second | 100 over 1 min | 500 over 1 min | 2,000 over 1 min |
| DNS Enumeration | Distinct subdomains queried under one domain | 200 over 10 min | 1,000 over 30 min | 5,000 over 1 h |
| DNS Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| DNS Exfiltration | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| DNS Beaconing | Regularity of repeated connections (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Randomised Subdomain Activity | Distinct subdomains queried under one domain | 200 over 10 min | 1,000 over 30 min | 5,000 over 1 h |
| DGA Activity | Average entropy of queried names | 3.5 over 5 min | 4 over 10 min | 4.5 over 30 min |
| High-Entropy DNS Queries | Average entropy of queried names | 3.5 over 5 min | 4 over 10 min | 4.5 over 30 min |
| Suspicious DNS Resolution | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Proxy Pool Behaviour | Distinct destination addresses | 50 over 1 h | 100 over 1 h | 500 over 1 h |
| Tor Relay Traffic | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Tor Exit Traffic | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| HTTPS Request Flood | Outbound TLS connections per second to web ports (443, 8443) | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| Aggressive Crawling | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Web Application Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| CMS Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| WordPress Scanning | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| Login Brute Force | Short connections to authentication ports | 100 over 5 min | 500 over 10 min | 2,000 over 30 min |
| Web Vulnerability Probing | Distinct targets on the service's ports | 50 over 10 min | 250 over 30 min | 1,000 over 1 h |
| SSH Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| RDP Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| FTP Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Telnet Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| VNC Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| SMB Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| WinRM Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Database Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Redis Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Elasticsearch Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Docker API Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Kubernetes API Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Remote Service Enumeration | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Mining Pool Communication | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Stratum Mining | Connections speaking the Stratum mining protocol | 1 over 10 min | 3 over 30 min | 5 over 1 h |
| Stratum V1 Traffic | Connections speaking the Stratum mining protocol | 1 over 10 min | 3 over 30 min | 5 over 1 h |
| Stratum V2 Traffic | Connections speaking the Stratum mining protocol | 1 over 10 min | 3 over 30 min | 5 over 1 h |
| Mining Proxy Communication | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Cryptocurrency Pool Discovery | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Mining Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Large Outbound Transfer | Bytes sent to external destinations | 1,000,000,000 over 1 h | 10,000,000,000 over 1 h | 50,000,000,000 over 1 h |
| High-Volume External Upload | Bytes sent to external destinations | 1,000,000,000 over 1 h | 10,000,000,000 over 1 h | 50,000,000,000 over 1 h |
| Suspicious External Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Exfiltration Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Encrypted Tunnel Activity | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| ICMP Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| HTTP Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| HTTPS Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| SSH Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| TCP Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| UDP Tunnelling | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Reverse Tunnel | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Unexpected VPN Tunnel | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Proxy Tunnel | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Covert Channel Behaviour | Tunnelling indicators (0-100) | 50 over 10 min | 70 over 30 min | 90 over 1 h |
| Blockchain Node Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Cryptocurrency Service Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Wallet Service Scanning | Distinct targets on the service's ports | 100 over 5 min | 1,000 over 10 min | 5,000 over 30 min |
| Mining Pool Activity | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Crypto Botnet Activity | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Crypto Infrastructure Communication | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Internet-Wide Scanning | Distinct destination addresses | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Mass Port Scanning | Distinct destination ports | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Mass Host Scanning | Distinct destination addresses | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Mass Service Discovery | Distinct targets on the service's ports | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Mass Banner Grabbing | Distinct targets on the service's ports | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Internet-Wide Vulnerability Scanning | Distinct targets on the service's ports | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Continuous Reconnaissance | Distinct destination addresses | 5,000 over 6 h | 20,000 over 12 h | 50,000 over 24 h |
| Randomised Internet Scanning | Distinct destination addresses | 1,000 over 10 min | 5,000 over 30 min | 10,000 over 1 h |
| Excessive Outbound Connections | Distinct destination addresses | 1,000 over 1 h | 5,000 over 1 h | 10,000 over 1 h |
| Excessive New Connections | New outbound connections per second | 500 over 30 s | 2,000 over 30 s | 5,000 over 30 s |
| Excessive Destination Count | Distinct destination addresses | 1,000 over 1 h | 5,000 over 1 h | 10,000 over 1 h |
| Excessive Port Count | Distinct destination ports | 100 over 1 min | 500 over 5 min | 1,000 over 10 min |
| Excessive Packet Rate | Outbound packets per second | 10,000 over 30 s | 50,000 over 30 s | 100,000 over 30 s |
| Excessive Bandwidth | Outbound megabits per second | 300 over 1 min | 600 over 30 s | 1,000 over 15 s |
| Connection Burst | New outbound connections per second | 1,000 over 10 s | 5,000 over 10 s | 10,000 over 10 s |
| Destination Burst | Distinct destination addresses | 500 over 1 min | 2,000 over 1 min | 5,000 over 1 min |
| Port Burst | Distinct destination ports | 200 over 10 s | 1,000 over 10 s | 5,000 over 10 s |
| Persistent High-Rate Traffic | Outbound packets per second | 10,000 over 30 min | 50,000 over 30 min | 100,000 over 1 h |
| Known C2 Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Malware Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Phishing Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Spam Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Known Botnet Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| IP Blocklist Match | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| DNSBL Match | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Abuse Feed Match | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Threat Intelligence Match | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Repeated Abuse Destination | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |
| Outbound IP Reputation Event | Contacts with addresses on threat-intelligence lists | 1 over 10 min | 10 over 1 h | 100 over 1 h |