2018-09-04 13:31:13 +02:00
|
|
|
{
|
|
|
|
"attributes": {
|
2018-09-04 20:40:16 +02:00
|
|
|
"acquisition-method": {
|
|
|
|
"description": "Method used for acquisition of the evidence.",
|
2020-04-26 02:10:02 +02:00
|
|
|
"disable_correlation": true,
|
2018-09-04 20:40:16 +02:00
|
|
|
"misp-attribute": "text",
|
|
|
|
"sane_default": [
|
|
|
|
"Live acquisition",
|
|
|
|
"Dead/Offline acquisition",
|
|
|
|
"Physical collection",
|
|
|
|
"Logical collection",
|
|
|
|
"File system extraction",
|
|
|
|
"Chip-off",
|
|
|
|
"Other"
|
2018-09-04 20:48:51 +02:00
|
|
|
],
|
2020-04-26 02:10:02 +02:00
|
|
|
"ui-priority": 0
|
2018-09-04 20:40:16 +02:00
|
|
|
},
|
|
|
|
"acquisition-tools": {
|
|
|
|
"description": "Tools used for acquisition of the evidence.",
|
2020-04-26 02:10:02 +02:00
|
|
|
"disable_correlation": true,
|
2018-09-04 20:40:16 +02:00
|
|
|
"misp-attribute": "text",
|
|
|
|
"multiple": true,
|
|
|
|
"sane_default": [
|
2018-09-04 20:48:51 +02:00
|
|
|
"dd",
|
|
|
|
"dc3dd",
|
|
|
|
"dcfldd",
|
2018-09-04 20:40:16 +02:00
|
|
|
"EnCase",
|
|
|
|
"FTK Imager",
|
|
|
|
"FDAS",
|
|
|
|
"TrueBack",
|
|
|
|
"Guymager",
|
|
|
|
"IXimager",
|
|
|
|
"Other"
|
2018-09-04 20:48:51 +02:00
|
|
|
],
|
2020-04-26 02:10:02 +02:00
|
|
|
"ui-priority": 0
|
|
|
|
},
|
|
|
|
"additional-comments": {
|
|
|
|
"description": "Comments.",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 0
|
|
|
|
},
|
|
|
|
"case-number": {
|
|
|
|
"description": "A unique number assigned to the case for unique identification.",
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 0
|
|
|
|
},
|
|
|
|
"evidence-number": {
|
|
|
|
"description": "A unique number assigned to the evidence for unique identification.",
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 0
|
|
|
|
},
|
|
|
|
"name": {
|
|
|
|
"description": "Name of the evidence acquired.",
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 0
|
2018-09-04 20:40:16 +02:00
|
|
|
},
|
|
|
|
"references": {
|
|
|
|
"description": "External references",
|
2020-04-26 02:10:02 +02:00
|
|
|
"misp-attribute": "link",
|
2018-09-04 20:40:16 +02:00
|
|
|
"multiple": true,
|
2020-04-26 02:10:02 +02:00
|
|
|
"ui-priority": 0
|
2018-09-04 20:40:16 +02:00
|
|
|
},
|
2020-04-26 02:10:02 +02:00
|
|
|
"type": {
|
|
|
|
"description": "Evidence type.",
|
|
|
|
"disable_correlation": true,
|
2018-09-04 20:48:51 +02:00
|
|
|
"misp-attribute": "text",
|
2020-04-26 02:10:02 +02:00
|
|
|
"multiple": true,
|
|
|
|
"sane_default": [
|
|
|
|
"Computer",
|
|
|
|
"Network",
|
|
|
|
"Mobile Device",
|
|
|
|
"Multimedia",
|
|
|
|
"Cloud",
|
|
|
|
"IoT",
|
|
|
|
"Other"
|
|
|
|
],
|
|
|
|
"ui-priority": 0
|
2018-09-04 20:40:16 +02:00
|
|
|
}
|
2018-09-04 13:31:13 +02:00
|
|
|
},
|
|
|
|
"description": "An object template to describe a digital forensic evidence.",
|
|
|
|
"meta-category": "misc",
|
2020-04-26 02:10:02 +02:00
|
|
|
"name": "forensic-evidence",
|
|
|
|
"required": [
|
|
|
|
"case-number",
|
|
|
|
"evidence-number"
|
|
|
|
],
|
2018-09-04 13:31:13 +02:00
|
|
|
"uuid": "fe44c648-63ef-43fc-b3de-af71a2e023e4",
|
2020-04-26 02:10:02 +02:00
|
|
|
"version": 2
|
|
|
|
}
|