Closed pukkita closed 5 years ago
It is based on IP Reputation-related tags. There is a dictionary ip_rep_basic.yml
that is built from various OSINT sources. All public IPs are checked to determine any relevant reputation tags. The ip_rep_basic.yml
dictionary will be updated with each release.
Superb, thanks!
What causes e.g. bruteforce to appear? Does Elastiflow analyze traffic patterns for this?