Tags
Tag groups
Updated: September 15, 2025
Tag Groups
Specific grouping of FireTail tags. Tag colors indicate relevance to security posture.
SQL Injection detected in logs
Display Name | Description | Tag Key | Color |
---|---|---|---|
SQL injection present | Tags if a SQL injection is present | sql_injection | red |
SQL injection present in header | SQL injection present in header | sql_injection_header | red |
SQL injection present in header | SQL injection present in header | sql_injection_headers | red |
SQL injection present in body | A SQL injection is present in body | sql_injection_body | red |
GraphQL variable with SQL injection present | A SQL injection exists in graphql variable | graphql_variable_sql_injection | red |
SQL injection in GraphQL | Tags if SQL injection in GraphQL | graphql_sql_injection | red |
PII detected in logs
Display Name | Description | Tag Key | Color |
---|---|---|---|
Request contains PII data | This tag is used to identify requests with PII data. | pii | red |
PII: Credit Card Number | This tag is used to identify credit card numbers. | pii_credit_card | red |
PII: Credit Card Number | This tag is used to identify AMEX credit card numbers. | pii_credit_card_amex | red |
PII: Credit Card Number | This tag is used to identify BC Global credit card numbers. | pii_credit_card_bcglobal | red |
PII: Credit Card Number | This tag is used to identify Diners credit card numbers. | pii_credit_card_diners | red |
PII: Credit Card Number | This tag is used to identify Discover credit card numbers. | pii_credit_card_discover | red |
PII: Credit Card Number | This tag is used to identify JCB credit card numbers. | pii_credit_card_jcb | red |
PII: Credit Card Number | This tag is used to identify Maestro credit card numbers. | pii_credit_card_maestro | red |
PII: Credit Card Number | This tag is used to identify MasterCard credit card numbers. | pii_credit_card_mastercard | red |
PII: Credit Card Number | This tag is used to identify Union Pay credit card numbers. | pii_credit_card_union_pay | red |
PII: Credit Card Number | This tag is used to identify VISA credit card numbers. | pii_credit_card_visa | red |
PII: Email address present | An email address is present in request | pii_email_address | red |
PII: Email address present in input | An email address is present in message input | pii_email_address_in_input | red |
PII: Email address present in output | An email address is present in message output | pii_email_address_in_output | red |
Request contains a banking IBAN number | Tag if the request contains a banking IBAN number | pii_bank_account_number | red |
Malicious requests in logs
Display Name | Description | Tag Key | Color |
---|---|---|---|
The request is malicious | The request is malicious | malicious | orange |
Suspicious requests in logs
Display Name | Description | Tag Key | Color |
---|---|---|---|
Request path contains an IPv4 address | Request path contains an IPv4 address, which is often associated with suspicious activity. | ipv4_in_path | red |
Request path contains non-standard characters | Request path contains non-standard characters (e.g., emojis, special characters), which may indicate suspicious activity. | nonstandard_characters_in_path | red |
Request path contains 'zhttpd' | Request path contains 'zhttpd', which is often associated with suspicious activity. | zhttpd_in_path | red |
The request is suspicious | The request is suspicious | suspicious | red |
Secret keys detected in logs
Display Name | Description | Tag Key | Color |
---|---|---|---|
Request contains a MailChimp API Keyn | Tag if the request contains a MailChimp API Key | secret_mailchimp_api_key | red |
Request contains an AWS Secret Access Key | Tag if the request contains an AWS Secret Access Key | secret_aws_key | red |
Request contains an AWS MWS Auth Token | Tag if the request contains an AWS MWS Auth Token | secret_aws_mws_auth_token | red |
Request contains a Meta (Facebook) Access Token | Tag if the request contains a Meta (Facebook) Access Token | secret_facebook_access_token | red |
Request contains a Github Personal Access Token | Tag if the request contains a Github Personal Access Token | secret_gitlab_pat | red |
Request contains a Gitlab Trigger Token | Tag if the request contains a Gitlab Trigger Token | secret_gitlab_trigger_token | red |
Request contains a Gitlab Runner Registration Token | Tag if the request contains a Gitlab Runner Registration Token | secret_gitlab_runner_registration_token | red |
Request contains a Google API Key | Tag if the request contains a Google API Key | google_api_key | red |
Request contains a Google OAuth Token | Tag if the request contains a Google OAuth Token | google_oauth_token | red |
Request contains a Google OAuth Access Token | Tag if the request contains a Google OAuth Access Token | google_oauth_access_token | red |
Request contains a MailGun API Keyn | Tag if the request contains a MailGun API Key | secret_mailgun_api_key | red |
Request contains a PayPal Braintree Access Token | Tag if the request contains a PayPal Braintree Access Token | secret_paypal_braintree_access_token | red |
Request contains a Picatic API Key | Tag if the request contains a Picatic API Key | secret_picatic_api_key | red |
Request contains a SendGrid API Key | Tag if the request contains a SendGrid API Key | secret_sendgrid_api_key | red |
Request contains a Slack Token | Tag if the request contains a Slack Token | secret_slack_token | red |
Request contains a Slack Webhook | Tag if the request contains a Slack Webhook | secret_slack_webhook | red |
Request contains a Square Access Token | Tag if the request contains a Square Access Token | secret_square_access_token | red |
Request contains a Stripe API Key | Tag if the request contains a Stripe API Key | stripe_api_key | red |
Request contains a Twilio API Key | Tag if the request contains a Twilio API Key | twilio_api_key | red |
Request contains an AWS Bedrock API Key | The request contains an AWS Bedrock API Key | bedrock_api_key | red |
Weak auth detected in logs
Display Name | Description | Tag Key | Color |
---|---|---|---|
Request contains basic authentication | Request contains basic authentication | basic_auth | red |
API key authentication | Request contains API key authentication | api_key_auth | orange |