RedELK icon indicating copy to clipboard operation
RedELK copied to clipboard

New alarm: alarm_baddomain: domain has a 'bad' classification.

Open xychix opened this issue 4 years ago • 5 comments

alarm when a domain has a 'bad' classification. Bad is defined in the list that is already added as comment to alarm_check4 in alarm.py.

This list of bad words comes from a review of classes defined by the domain checkers as currently supported by chameleon.py

xychix avatar Nov 27 '20 14:11 xychix

is this a duplicate of issue #127 ?

xychix avatar Nov 27 '20 14:11 xychix

Not sure if duplicate.

MarcOverIP avatar Nov 27 '20 15:11 MarcOverIP

Below the full list of bad words that should be checked against. I created this by carving the documentation by the domain classifiers. Some words are cut short for easier checking.

abortion, adult, adware, alcohol, anonym, botnet, c2, command and control, compromised, controlled, copyright, crime, criminal, cryptocurrency, discrimination, early warning, extreme, file sharing, freeware, gambling, gore, gruesome, hacking, hate, illegal, intolerance, keyloggers, lottery, malicious, malnets, malware, marijuana, mature, military, moderated, nudity, p2p, phishing, piracy, placeholders, political, pornography, proxy, questionable, scam, sects, sex, shareware, spam, spyware, suspicious, tabacco, unwanted, usenet, violence, warez, weapons

MarcOverIP avatar Nov 27 '20 15:11 MarcOverIP

pending on #270

fastlorenzo avatar Aug 19 '22 11:08 fastlorenzo

After discussion with @fastlorenzo, decided that this first needs restructuring of how we handle domain info. So this is pending on #270

MarcOverIP avatar Aug 19 '22 11:08 MarcOverIP