From 5b7e2de87a1300b1666c4f3e642ef290d0cabc2b Mon Sep 17 00:00:00 2001 From: Deborah Servili Date: Tue, 24 Oct 2017 11:15:05 +0200 Subject: [PATCH 1/2] add cert EU govsectors galaxy --- clusters/cert-eu-govsector.json | 31 +++++++++++++++++++++++++++++++ galaxies/cert-eu-govsector.json | 8 ++++++++ 2 files changed, 39 insertions(+) create mode 100644 clusters/cert-eu-govsector.json create mode 100644 galaxies/cert-eu-govsector.json diff --git a/clusters/cert-eu-govsector.json b/clusters/cert-eu-govsector.json new file mode 100644 index 00000000..7c60f298 --- /dev/null +++ b/clusters/cert-eu-govsector.json @@ -0,0 +1,31 @@ +{ + "values": [ + { + "value": "Constituency" + }, + { + "value": "EU-Centric" + }, + { + "value": "EU-nearby" + }, + { + "value": "World-class" + }, + { + "value": "Unknown" + }, + { + "value": "Outside World" + } + ], + "version": 1, + "uuid": "69351b20-b898-11e7-a2f1-c3e696a74a48", + "description": "Cert EU GovSector", + "authors": [ + "Various" + ], + "source": "CERT-EU", + "type": "cert-seu-gocsector", + "name": "Cert EU GovSector" +} diff --git a/galaxies/cert-eu-govsector.json b/galaxies/cert-eu-govsector.json new file mode 100644 index 00000000..3e46c8c4 --- /dev/null +++ b/galaxies/cert-eu-govsector.json @@ -0,0 +1,8 @@ +{ + "type": "cert-seu-gocsector", + "name": "Cert EU GovSector", + "description": "Cert EU GovSector", + "version": 1, + "icon": "globe", + "uuid": "68858a48-b898-11e7-91ce-bf424ef9b662" +} From c8ac0e9e750cad8480b9718c9e224a299c766fdc Mon Sep 17 00:00:00 2001 From: Deborah Servili Date: Tue, 24 Oct 2017 11:38:09 +0200 Subject: [PATCH 2/2] update README.md --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 0bcd30e1..1b7ea12d 100644 --- a/README.md +++ b/README.md @@ -25,13 +25,14 @@ to localized information (which is not shared) or additional information (that c - [clusters/threat-actor.json](clusters/threat-actor.json) - Adversary groups - Known or estimated adversary groups targeting organizations and employees. Adversary groups are regularly confused with their initial operation or campaign. MISP - [clusters/tool.json](clusters/tool.json) - tool is an enumeration of tools used by adversaries. The list includes malware but also common software regularly used by the adversaries. - - [clusters/mitre_attack-pattern.json](clusters/mitre_attack-pattern.json) - Attack Pattern - MITRE Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) - [clusters/mitre_course-of-action.json](clusters/mitre_course-of-action.json) - Course of Action - MITRE Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) - [clusters/mitre_intrusion-set.json](clusters/mitre_intrusion-set.json) - Intrusion Test - MITRE Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) - [clusters/mitre_malware.json](clusters/mitre_malware.json) - Malware - MITRE Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) - [clusters/mitre_tool.json](clusters/mitre_tool.json) - Tool - MITRE Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) +- [clusters/sectors.json](clusters/sectors.json) - Activity sectors +- [clusters/cert-eu-govsector,json](clusters/cert-eu-govsector,json) - Cert EU GovSector # Available Vocabularies