Full list of Google Threat Intelligence tag modifier

One of the search modifiers available in Google Threat Intelligence is "tag". This modifier will search for files tagged with the literal provided. Google Threat Intelligence adds tags to all files processed based on hundreds of factors depending on the type of file, information extracted, behaviour, etc.

You can find the description and examples of the most common tags at the File search modifiers article.

List of Domains tags.

List of Files tags.

List of IPs tags.

List of URLs tags.

List of deprecated tags.

List of Domains tags


alternative-dnsdgadynamic-dnshex
non-asciinxdomainpotential-c2self-signed

List of Files tags


32lite64bitsabused-exe-patternacidcrypt
acprotectacroformactivemarkaes-encoded
ahpackainexealexprotectoralloy
alternative-dnsaluwainanorganixanskya
anti-analysisanywhereapatchapex
apfsapkarmarmadillo
arscas2as3aspack
asprotectassemblyattachmentauto-close
auto-createauto-modifyauto-openautoaction
axmlbambambase64-embeddedbase64-string
beriaberobladeblob
bobsoftcalls-wmicapabilitiescdcops
cexechecks-bioschecks-cpu-namechecks-disk-space
checks-gpschecks-hostnamechecks-memory-availablechecks-network-adapters
checks-usb-buschecks-user-inputchecks_gpscicompress
cipherwallclipboardcode injectioncode-injection
codelockcodesafecompackcontains-apk
contains-debcontains-dmgcontains-drvcontains-elf
contains-embedded-jscontains-machocontains-msicontains-pe
contains-romcontains-zipcopy-filecoredump
corruptcorruptedcreate-dircreate-file
create-olecreateinstallcrinklercrunch
crypkeycryptcryptocryptz
crypwrapcydiadbpeddem
dell-pfsdepackdetect-debug-environmentdetect_debug_environment
dexdiminisherdingboydiprotector
direct-cpu-clock-accessdjoindomain-patterndos-stub
downloaddropperdshielddxpack
dyn-callsdyn-classefiemail-pattern
email-spamembedpeemptyencrypted
encryptpeenigmaenum-windowsenviron
escargoteval-functionexe-embeddedexe-pattern
exe32packexecryptorexecutes-dropped-fileexeguarder
exejoinerexelockerexepackexepacker
exeshieldexesmasherexestealthexploit
exploit-kitexpressorext-interfaceext-prg
ezipfaultyfeokptfile-embedded
fixuppakflash-embeddedfresfreshbind
frusionfscommandfsgftp
ftp-communicationfucknjoyfusiongamehouse
gleamgoatsgoodwaregpt
hackstophandle-filehash-collisionhasp
heap-sprayhfshide-apphiding-window
high-entropyhoneypothosts-modifierhtml-control
idleiframeimpostorinstallshield
installstubintel-meinvalid-rich-pe-checksuminvalid-rich-pe-duplicated-entries
invalid-rich-pe-linker-versioninvalid-rich-pe-modified-iatinvalid-signatureinvalid-xref
iosipbprotectipv4-patternirc
irc-communicationjdpackjs-embeddedjspack
kbyskgcryptkkrunchyknown-distributor
krunchykryptonkryptorlamecrypt
large-filelaunch-actionlcclegit
liblicenseloadbyteslockless
lolbinlong-base64long-command-line-argumentslong-hex
long-sleepsltclzexelzma
mac-appmac-cmd-embeddermac-publishermacro-anti-analysis
macro-create-olemacro-powershellmacro-run-filemacros
malformedmalwarematchomew
microjoinermmbuildermobile-substratemolebox
morphinemulti-archmysqlmysql-communication
nakedpacknativeneolitenfo
niceprotectnoodlecryptnorthstarnpack
nsisnspacknsrlntkrnl
nullsoftnxdomainobfuscatedobsidium
odexole-autolinkole-controlole-embedded
ole-linkopen-fileopendirorien
os-checkingoverlaypack200packman
packmasterpassword-dialogpasswordprotectorpcguard
pcshrinkerpe-armorpearmorpebundle
pecompactpecrc32pecrypt32pelock
pemanglepenightmarepeninjapepack
peprotectpersistencepeshieldpeshit
pespinpetitepexpirit
pklitepklite32polyenepostinst
postrmpreinstprermpunisher
radpackrar-embeddedrcryptorreflection
registryrelocatablerepeated-clock-accessrevoked-cert
rlpackrun-dllrun-fileruntime-modules
save-workbooksdprotectsdprotectorself-delete
send-keyssends-smsservice-scansets-process-name
shared-libshellcodesignedsimplepack
smtpsmtp-communicationsoftdefendersoftware-collection
spreadersshssh-communicationstarforce
startup-folderstealthstonessudo
suspicious-dnssuspicious-eipsuspicious-udpsvkprotector
system-librarytar-bundletelephonytelnet
telnet-communicationtelockthemidathinstall
tlpacktrojantrustedtunneling
uefiupackupxurl-pattern
usb-autorunvcasmvia-torvirogen
webcopswinrarwinzipwise
wormwrite-filewwpackxcr
xorcryptyodayodaprotyodaprotect
zcodezero-filledzip-embeddedzipped

List of IPs tags


link-localloopbackmulticastprivate
proxyreservedself-signedsuspicious-udp
torunspecifiedvpn

List of URLs tags


32-bitadwareagentteslaandromeda
apkarmavemariaazorult
b-tdsbase64-embeddedbashlitebat
bazaloaderbazarcallbazarloadercerber
coinminercontains-apkcontains-dmgcontains-msi
contains-pecontains-zipcrypmodddos bot
dlldocdownloaderdownloads-apk
downloads-dmgdownloads-docdownloads-elfdownloads-pdf
downloads-pedownloads-zipdridexelf
emotetencodedencryptedepoch1
epoch2exeexploitfinderbot
flubotformbookgafgytgeofenced
gluptebagoziguloaderhajime
hancitorheodohtmlicedid
ipisfbitakovter
lokilokibotmaldocmalware
mikoponimipsmiraimozi
multiple-redirectsnanocoreneshtanetwire
njratnon-asciins-portopendir
phorpiexpylockyqakbotqbot
quakbotraccoonratredlinestealer
remcosremcosratriskwarescript
shellscriptsilentbuildersloadsnakekeylogger
trtrickbotursnifwebshell
xlsxlsbzenpakzip
zloaderzusy

List of deprecated tags


invalid-rich-pe-checksuminvalid-rich-pe-duplicated-entriesinvalid-rich-pe-linker-version
invalid-rich-pe-modified-iatnsrltrusted