The Bambenek connector ingests indicators of compromise (IOCs) from Bambenek Consulting Feeds. The connector supports the ingestion of the following data collections:
- c2_dga: Domain feed of known DGA domains from -2 to +3 days
- c2_dga_high_conf: High confidence domain feed of known DGA domains from -2 to +3 days
- c2_domain: Master feed of known, active and non-sinkholed C&Cs domain names
- c2_domain_highconf: High confidence master feed of known, active and non-sinkholed C&Cs domain names
- c2_ip: Master feed of known, active and non-sinkholed C&Cs IP Addresses
- c2_ip_highconf: High confidence master feed of known, active and non-sinkholed C&Cs IP Addresses