> ## Documentation Index
> Fetch the complete documentation index at: https://docs.infrawatch.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Intelligence taxonomy

> Canonical categories, classifications, and tags used across Infrawatch

The taxonomy gives detections a stable meaning across search, rules, projects,
and the API. Categories describe **what a signal is**. Classification describes
**how to interpret it**. Tags name the specific match.

<img src="https://mintcdn.com/infrawatch/hFIgmGIh7O3VGQHG/images/sections/taxonomy.svg?fit=max&auto=format&n=hFIgmGIh7O3VGQHG&q=85&s=9a9968d59d38d6096d4de2c6f5f8a197" alt="A category branching into nested taxonomy paths" className="rounded-2xl" width="640" height="320" data-path="images/sections/taxonomy.svg" />

## Search by category

This is what the taxonomy is for. Because every detection carries a category
path, you can ask for a class of behaviour without knowing which detector fired.

| Goal                               | Query                                 |
| ---------------------------------- | ------------------------------------- |
| One exact detector                 | `tags:"example-detector"`             |
| One category                       | `tags.category:"malware/infostealer"` |
| A category and everything under it | `tags.category:"malware/*"`           |
| A category on a specific service   | `services.tags.category:proxy/*`      |

Paths use `/` for hierarchy and `/*` to include descendants, so
`malware/*` covers every malware path while `malware/infostealer` stays narrow.
When searching hosts, prefix the field with `services.` to keep the condition on
one observed endpoint.

Worked examples:

```text theme={null}
tags.category:"malware/infostealer"
```

```text theme={null}
same_service(
  services.tags.category:"exposure/admin-panel"
  AND services.last_seen>=now-30d
)
```

## Classification

Every tag also carries a classification, which tells you how to read a match
rather than what it is.

| Value           | Meaning                                       |
| --------------- | --------------------------------------------- |
| `informational` | Useful context without a security judgment    |
| `benign`        | Known legitimate infrastructure or behaviour  |
| `suspicious`    | Worth review, but not confirmed malicious     |
| `malicious`     | Confirmed hostile infrastructure or behaviour |

Detection rules use `benign`, `suspicious`, or `malicious`. Informational tags
can still add context without changing the security posture of a result.

## Threat categories

| Category         | Canonical child paths                                                                                             |
| ---------------- | ----------------------------------------------------------------------------------------------------------------- |
| `investigation`  | `investigation/triage`, `investigation/watchlist`                                                                 |
| `malware`        | `malware/botnet`, `malware/c2`, `malware/infostealer`, `malware/loader`, `malware/ransomware`, `malware/webshell` |
| `phishing`       | `phishing/credential-harvest`, `phishing/kit`, `phishing/reverse-proxy`                                           |
| `exposure`       | `exposure/admin-panel`, `exposure/dangling-dns`, `exposure/directory-listing`, `exposure/remote-access`           |
| `infrastructure` | `infrastructure/certificate`, `infrastructure/dns`, `infrastructure/hosting`                                      |
| `identity`       | `identity/certificate`, `identity/domain`                                                                         |
| `tooling`        | `tooling/framework`, `tooling/scanner`                                                                            |
| `proxy`          | `proxy/datacenter`, `proxy/hosted`, `proxy/isp`, `proxy/residential`, `proxy/self-hosted`                         |
| `vpn`            | `vpn/commercial`, `vpn/corporate`, `vpn/criminal`, `vpn/hosted`, `vpn/self-hosted`                                |
| `fraud`          | `fraud/payment`, `fraud/scam`                                                                                     |
| `reconnaissance` | `reconnaissance/fingerprinting`, `reconnaissance/scanner`                                                         |

## Software categories

Software paths identify a product class without making a security judgment.

| Branch              | Canonical paths                                                                                                                                                                                                                                                                                                                                                     |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Edge                | `software/edge`, `software/edge/cdn`, `software/edge/waf`, `software/edge/ddos-protection`                                                                                                                                                                                                                                                                          |
| AI                  | `software/ai`, `software/ai/agent`, `software/ai/application`, `software/ai/chat`, `software/ai/data-labeling`, `software/ai/developer-tools`, `software/ai/llm-gateway`, `software/ai/media`, `software/ai/mlops`, `software/ai/model-runtime`, `software/ai/observability`, `software/ai/rag`, `software/ai/web-automation`, `software/ai/workflow`               |
| Infrastructure      | `software/api-gateway`, `software/application-server`, `software/database`, `software/database-admin`, `software/firewall`, `software/infrastructure`, `software/load-balancer`, `software/network`, `software/network-inventory`, `software/network-management`, `software/operating-system`, `software/storage`, `software/virtualization`, `software/web-server` |
| Operations          | `software/analytics`, `software/automation`, `software/backup`, `software/ci-cd`, `software/dashboard`, `software/developer-tools`, `software/management`, `software/observability`, `software/rmm`, `software/ticketing`                                                                                                                                           |
| Business apps       | `software/collaboration`, `software/crm`, `software/document-management`, `software/ecommerce`, `software/erp`, `software/file-sharing`, `software/file-transfer`, `software/mail`, `software/media`, `software/messaging`, `software/presentation`                                                                                                                 |
| Devices and control | `software/appliance`, `software/camera`, `software/healthcare`, `software/ics`, `software/iot`, `software/kvm`, `software/physical-security`, `software/power-management`, `software/printing`, `software/remote-access`, `software/telephony`                                                                                                                      |
| Security            | `software/ddos-protection`, `software/dlp`, `software/email-security`, `software/endpoint-management`, `software/identity`, `software/security`                                                                                                                                                                                                                     |
| Other               | `software/cms`, `software/hosting-control-panel`                                                                                                                                                                                                                                                                                                                    |

## What a tag is

A tag has a stable slug, a display name, one or more category paths, and a
classification. The slug is the detector; the category is what it means. Slugs
change less often than detector implementations, and categories change less
often than slugs, so prefer the broadest level that still answers your question.

<CardGroup cols={2}>
  <Card title="Write a rule" icon="https://mintcdn.com/infrawatch/gCEz_Bv1hOrMPG8n/images/products/rules.svg?fit=max&auto=format&n=gCEz_Bv1hOrMPG8n&q=85&s=7e3cb3f0ad32cc0e44ddfc18a2bba0e8" href="/scanning/rules/writing-rules" width="32" height="32" data-path="images/products/rules.svg">
    Turn typed scan evidence into a classified tag.
  </Card>

  <Card title="Search tagged infrastructure" icon="https://mintcdn.com/infrawatch/gCEz_Bv1hOrMPG8n/images/products/search.svg?fit=max&auto=format&n=gCEz_Bv1hOrMPG8n&q=85&s=e80dbe9b7724f88ce870e69cb367b435" href="/infraql/patterns" width="32" height="32" data-path="images/products/search.svg">
    Use exact tags, parent categories, and classifications in InfraQL.
  </Card>
</CardGroup>
