Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New alarm: alarm_baddomain: domain has a 'bad' classification. #131

Open
xychix opened this issue Nov 27, 2020 · 5 comments
Open

New alarm: alarm_baddomain: domain has a 'bad' classification. #131

xychix opened this issue Nov 27, 2020 · 5 comments
Labels
alarm Related to RedELK alarms elkserver Related to RedELK server components enhancement New feature or request
Milestone

Comments

@xychix
Copy link
Collaborator

xychix commented Nov 27, 2020

alarm when a domain has a 'bad' classification.
Bad is defined in the list that is already added as comment to alarm_check4 in alarm.py.

This list of bad words comes from a review of classes defined by the domain checkers as currently supported by chameleon.py

@xychix xychix changed the title alarm domain has a 'bad' classification. NEW ALARM domain has a 'bad' classification. Nov 27, 2020
@xychix
Copy link
Collaborator Author

xychix commented Nov 27, 2020

is this a duplicate of issue #127 ?

@xychix xychix changed the title NEW ALARM domain has a 'bad' classification. New alarm domain has a 'bad' classification. Nov 27, 2020
@xychix xychix changed the title New alarm domain has a 'bad' classification. New alarm alarm_baddomain: domain has a 'bad' classification. Nov 27, 2020
@MarcOverIP
Copy link
Member

Not sure if duplicate.

@MarcOverIP
Copy link
Member

Below the full list of bad words that should be checked against. I created this by carving the documentation by the domain classifiers. Some words are cut short for easier checking.

abortion, adult, adware, alcohol, anonym, botnet, c2, command and control, compromised, controlled, copyright, crime, criminal, cryptocurrency, discrimination, early warning, extreme, file sharing, freeware, gambling, gore, gruesome, hacking, hate, illegal, intolerance, keyloggers, lottery, malicious, malnets, malware, marijuana, mature, military, moderated, nudity, p2p, phishing, piracy, placeholders, political, pornography, proxy, questionable, scam, sects, sex, shareware, spam, spyware, suspicious, tabacco, unwanted, usenet, violence, warez, weapons

@fastlorenzo fastlorenzo added the enhancement New feature or request label May 14, 2021
@fastlorenzo fastlorenzo added elkserver Related to RedELK server components alarm Related to RedELK alarms labels May 27, 2021
@fastlorenzo fastlorenzo changed the title New alarm alarm_baddomain: domain has a 'bad' classification. New alarm: alarm_baddomain: domain has a 'bad' classification. Nov 18, 2021
@MarcOverIP MarcOverIP added this to To Do in v2.0.0-beta.6 via automation Jan 17, 2022
@MarcOverIP MarcOverIP added this to the v2.0.0-beta.6 milestone Jan 24, 2022
@MarcOverIP MarcOverIP removed this from To Do in v2.0.0-beta.6 Jun 30, 2022
@fastlorenzo
Copy link
Collaborator

pending on #270

@MarcOverIP
Copy link
Member

After discussion with @fastlorenzo, decided that this first needs restructuring of how we handle domain info. So this is pending on #270

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
alarm Related to RedELK alarms elkserver Related to RedELK server components enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants