Lyo.ContentThreatScan.Intel
1.0.1
dotnet add package Lyo.ContentThreatScan.Intel --version 1.0.1
NuGet\Install-Package Lyo.ContentThreatScan.Intel -Version 1.0.1
<PackageReference Include="Lyo.ContentThreatScan.Intel" Version="1.0.1" />
<PackageVersion Include="Lyo.ContentThreatScan.Intel" Version="1.0.1" />
<PackageReference Include="Lyo.ContentThreatScan.Intel" />
paket add Lyo.ContentThreatScan.Intel --version 1.0.1
#r "nuget: Lyo.ContentThreatScan.Intel, 1.0.1"
#:package Lyo.ContentThreatScan.Intel@1.0.1
#addin nuget:?package=Lyo.ContentThreatScan.Intel&version=1.0.1
#tool nuget:?package=Lyo.ContentThreatScan.Intel&version=1.0.1
Lyo.ContentThreatScan.Intel
Optional DefaultContentThreatReputationPipeline for Malware Bazaar, VirusTotal, and clamd INSTREAM (TCP).
Composition
Construct DefaultContentThreatReputationPipeline with a shared HttpClient (often from IHttpClientFactory), ReputationPipelineOptions bound from configuration, and an optional ILogger. Register the instance as IContentThreatReputationPipeline wherever ContentThreatMalwareScanner or other hosts need reputation. Probes are omitted when keys are absent: empty VirusTotalApiKey skips VT; empty MalwareBazaarAuthKey skips Bazaar; Clamd.Enabled == false skips clamd.
ReputationPipelineOptions
| Property | Notes |
|---|---|
MalwareBazaarAuthKey / VirusTotalApiKey |
API keys; provider is skipped when blank. |
MalwareBazaarEndpoint / VirusTotalApiRoot |
Override default base URLs (sovereign clouds, internal proxies). |
ProviderTimeout |
Per-call HTTP timeout. |
MalwareBazaarKnownSamplePoints |
Score added when MalwareBazaar reports a known sample. |
VirusTotalPointsPerMaliciousEngine |
Score multiplied by the number of engines flagging the sample. |
VirusTotalMinimumMaliciousEnginesForIntelConfirmation |
Threshold to flip IntelConfirmedMalicious. |
ProviderFailureSuspectBump / ProviderFailureThreatBump |
Score bumps applied when a provider's ExternalReputationFailureDisposition is TreatAsSuspect / ImmediateThreatBump. |
DigestCacheMaximumEntries |
Maximum entries in ReputationDigestLookupCache. |
NegativeCacheMinutes / PositiveMalwareCacheMinutes |
Negative and positive TTLs used by the digest cache. |
Clamd (ClamdInstreamScanOptions) |
Enabled, Host, Port, TcpConnectTimeoutMilliseconds, InstreamChunkSize, EngineDetectionPoints, EngineDetectionMarksIntelConfirmed, FailureDisposition. |
Outages and quotas
Ignore— swallow (logged); no score bumpTreatAsSuspect— addsProviderFailureSuspectBumpunder a stable rule idImmediateThreatBump— large contribution capped by disposition options (policy-driven “fail closed”)
Digest cache
ReputationDigestLookupCache is an in-process LRU keyed by lowercase hex SHA-256 (DigestCacheMaximumEntries, positive/negative TTL minutes).
Dependencies
Generated from ProjectReference / PackageReference (same model as docs/Lyo.ProjectGraph.html).
Lyo.Common— (direct, lyo)Lyo.ContentThreatScan— (direct, lyo)Lyo.Exceptions— (direct, lyo)Microsoft.Bcl.AsyncInterfaces10.0.5— (direct, microsoft, netstandard2.0)Microsoft.Extensions.Logging.Abstractions10.0.5— (direct, microsoft)System.Text.Json10.0.5— (direct, microsoft)Lyo.Hashing— (transitive, lyo)Microsoft.Extensions.DependencyInjection.Abstractions10.0.5— (transitive, microsoft)System.IO.Hashing10.0.5— (transitive, microsoft, net10.0)System.Memory4.6.3— (transitive, microsoft, netstandard2.0)
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 was computed. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net461 was computed. net462 was computed. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.0
- Lyo.Common (>= 1.0.1)
- Lyo.ContentThreatScan (>= 1.0.1)
- Lyo.Exceptions (>= 1.0.1)
- Microsoft.Bcl.AsyncInterfaces (>= 10.0.5)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.5)
- System.Text.Json (>= 10.0.5)
-
net10.0
- Lyo.Common (>= 1.0.1)
- Lyo.ContentThreatScan (>= 1.0.1)
- Lyo.Exceptions (>= 1.0.1)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.5)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.