2018-02-28 17:41:29 +01:00
|
|
|
{
|
|
|
|
"requiredOneOf": [
|
|
|
|
"session"
|
|
|
|
],
|
|
|
|
"attributes": {
|
|
|
|
"eventid": {
|
|
|
|
"description": "Eventid of the session in the cowrie honeypot",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"system": {
|
|
|
|
"description": "System origin in cowrie honeypot",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"username": {
|
|
|
|
"description": "Username related to the password(s)",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
2018-03-01 16:20:58 +01:00
|
|
|
"password": {
|
2018-02-28 17:41:29 +01:00
|
|
|
"description": "Password",
|
|
|
|
"multiple": true,
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"session": {
|
|
|
|
"description": "Session id",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"timestamp": {
|
|
|
|
"description": "When the event happened",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "datetime",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
|
|
|
"message": {
|
|
|
|
"description": "Message of the cowrie honeypot",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
|
|
|
"protocol": {
|
|
|
|
"description": "Protocol used in the cowrie honeypot",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
|
|
|
"sensor": {
|
|
|
|
"description": "Cowrie sensor name",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
|
|
|
"src_ip": {
|
|
|
|
"description": "Source IP address of the session",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "ip-src"
|
|
|
|
},
|
|
|
|
"dst_ip": {
|
2018-02-28 17:47:02 +01:00
|
|
|
"description": "Destination IP address of the session",
|
2018-02-28 17:41:29 +01:00
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "ip-dst",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
2018-02-28 17:47:02 +01:00
|
|
|
"src_port": {
|
|
|
|
"description": "Source port of the session",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "port",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
|
|
|
"dst_port": {
|
|
|
|
"description": "Destination port of the session",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "port",
|
|
|
|
"disable_correlation": true
|
|
|
|
},
|
2018-02-28 17:41:29 +01:00
|
|
|
"isError": {
|
|
|
|
"description": "isError",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"disable_correlation": true
|
2018-03-01 21:08:16 +01:00
|
|
|
},
|
|
|
|
"input": {
|
|
|
|
"description": "Input of the session",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"macCS": {
|
|
|
|
"description": "SSH MAC supported in the sesssion",
|
|
|
|
"multiple": true,
|
|
|
|
"disable_correlation": true,
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"keyAlgs": {
|
|
|
|
"description": "SSH public-key algorithm supported in the session",
|
|
|
|
"multiple": true,
|
|
|
|
"disable_correlation": true,
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"encCS": {
|
|
|
|
"description": "SSH symmetric encryption algorithm supported in the session",
|
|
|
|
"multiple": true,
|
|
|
|
"disable_correlation": true,
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"compCS": {
|
|
|
|
"description": "SSH compression algorithm supported in the session",
|
|
|
|
"multiple": true,
|
|
|
|
"ui-priority": 1,
|
2018-03-01 21:09:04 +01:00
|
|
|
"misp-attribute": "text",
|
|
|
|
"disable_correlation": true
|
2019-10-05 10:05:26 +02:00
|
|
|
},
|
|
|
|
"hassh": {
|
|
|
|
"description": "HASSH of the client SSH session following Salesforce algorithm",
|
|
|
|
"misp-attribute": "hassh-md5",
|
|
|
|
"ui-priority": 1
|
2018-02-28 17:41:29 +01:00
|
|
|
}
|
|
|
|
},
|
2019-10-05 10:05:26 +02:00
|
|
|
"version": 3,
|
2018-02-28 17:41:29 +01:00
|
|
|
"description": "Cowrie honeypot object template",
|
|
|
|
"meta-category": "network",
|
|
|
|
"uuid": "ae085d32-6534-4d52-b3eb-063fccb753e7",
|
|
|
|
"name": "cowrie"
|
|
|
|
}
|