Probes and path scans
Repeated requests for admin paths, known vulnerable files and scanner signatures are abuse signals, not ordinary traffic.
Pattern, not one URLAbuse database
The abuse database is the part of CTIAD that holds scans, floods, credential stuffing and other protocol abuse so they can be correlated and reported.
Cases
Repeated requests for admin paths, known vulnerable files and scanner signatures are abuse signals, not ordinary traffic.
Pattern, not one URLA source that hammers a login or a form is stored as a flood, with the count and the window, not as an endless row of identical lines.
Count and windowMalformed requests, spoofed patterns and abusive connection behaviour are in scope when a protection system has already observed them.
Observed, then storedThe same source across several signals becomes one case. That case is what scoring and later reports use.
One case, many signalsUse
The abuse database exists so operators and protection systems can read a case. It is not a promise that every stored event is published on the internet.
The blacklist is how evaluated indicators are published. It does not replace this database.