Operators: com.teracloud.streams.cybersecurity 5.0.0

Operators

BWListTagger
The BWListTagger operator loads lists of domains and IP addresses into a lookup table.
DNSTunneling
The DNSTunneling operator analyzes DNS response traffic and reports suspicious behaviour that may indicate the presence of DNS tunneling in the network.
DomainProfiling
The DomainProfiling operator analyzes DNS response traffic and reports whether or not the behaviour of the domain is suspicious.
HostProfiling
The HostProfiling operator analyzes DNS response traffic and reports whether or not the behaviour of the hosts are suspicious.
PredictiveBlocklisting
The PredictiveBlocklisting operator analyzes the feature vector produced by the PredictiveBlocklistingFE operator using an SPSS model.
PredictiveBlocklistingFE
The PredictiveBlocklistingFE operator ingests DNS response traffic and outputs a feature vector that is used by the PredictiveBlocklisting operator.
QRadarSink
This operator allows Streams applications to send syslog messages to a QRadar host.