misp-objects/objects/passive-dns/definition.json

149 lines
4.7 KiB
JSON
Raw Normal View History

2016-02-13 18:19:27 +01:00
{
2017-02-13 11:18:42 +01:00
"attributes": {
"bailiwick": {
"description": "Best estimate of the apex of the zone where this data is authoritative",
"disable_correlation": true,
"misp-attribute": "domain",
"ui-priority": 0
2017-07-03 12:15:50 +02:00
},
"count": {
"description": "How many authoritative DNS answers were received at the Passive DNS Server's collectors with exactly the given set of values as answers.",
"disable_correlation": true,
"misp-attribute": "counter",
"ui-priority": 0
},
"origin": {
"description": "Origin of the Passive DNS response",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 0
},
"raw_rdata": {
"description": "Resource records of the queried resource, in hexadecimal. *All* rdata entries at once.",
"misp-attribute": "text",
"ui-priority": 0
},
"rdata": {
"description": "Resource records of the queried resource. Note that this field is added for *each* rdata entry in the rrset.",
"misp-attribute": "text",
"ui-priority": 1
2017-07-03 12:15:50 +02:00
},
"rdata_ip": {
"categories": [
"Network activity",
"External analysis"
],
"description": "Resource records of the queried resource. Mapped to MISP 'ip' address type. Valid for rrtypes (A, AAAA, A6, ...).",
"misp-attribute": "ip-src",
"ui-priority": 1
},
"rdata_domain": {
"categories": [
"Network activity",
"External analysis"
],
"description": "Resource records of the queried resource. Mapped to MISP 'domain' address type. Valid for rrtypes (CNAME, etc.).",
"misp-attribute": "domain",
"ui-priority": 1
},
2017-07-03 12:15:50 +02:00
"rrname": {
2017-02-13 11:18:42 +01:00
"categories": [
"Network activity",
"External analysis"
2017-07-03 12:15:50 +02:00
],
"description": "Resource Record name of the queried resource.",
"misp-attribute": "text",
"ui-priority": 1
2017-02-13 11:18:42 +01:00
},
"rrname_domain": {
"categories": [
"Network activity",
"External analysis"
],
"description": "Resource Record name of the queried resource. Same as the field 'rrname', however already mapped to the MISP 'domain' type so that we can correlate.",
"misp-attribute": "domain",
"ui-priority": 1
},
"rrname_ip": {
"categories": [
"Network activity",
"External analysis"
],
"description": "Resource Record name of the queried resource. Same as the field 'rrname', however already mapped to the MISP 'ip' type so that we can correlate. Note that this is only valid if 'rrtype' is 'PTR'.",
"misp-attribute": "ip-src",
"ui-priority": 1
},
2017-07-03 12:15:50 +02:00
"rrtype": {
2017-02-13 11:18:42 +01:00
"categories": [
"Network activity",
"External analysis"
2017-07-03 12:15:50 +02:00
],
"description": "Resource Record type as seen by the passive DNS.",
"disable_correlation": true,
2017-08-29 18:36:46 +02:00
"misp-attribute": "text",
"sane_default": [
"A",
"AAAA",
"CNAME",
"PTR",
"SOA",
"TXT",
"DNAME",
"NS",
"SRV",
"RP",
"NAPTR",
"HINFO",
"A6"
],
"ui-priority": 1
2017-08-29 18:36:46 +02:00
},
"sensor_id": {
"description": "Sensor information where the record was seen",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 0
2017-02-13 11:18:42 +01:00
},
"text": {
"description": "Description of the passive DNS record.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 0
},
"time_first": {
"description": "First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 0
2017-02-13 11:18:42 +01:00
},
2017-07-03 12:15:50 +02:00
"time_last": {
2017-08-29 18:36:46 +02:00
"description": "Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 0
2017-02-13 11:18:42 +01:00
},
"zone_time_first": {
"description": "First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 0
2017-02-13 11:18:42 +01:00
},
"zone_time_last": {
"description": "Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import.",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 0
2017-02-13 11:18:42 +01:00
}
},
2017-07-03 12:15:50 +02:00
"description": "Passive DNS records as expressed in draft-dulaunoy-dnsop-passive-dns-cof-01",
"meta-category": "network",
"name": "passive-dns",
"required": [
"rrtype",
"rrname",
"rdata"
],
2017-07-03 12:15:50 +02:00
"uuid": "b77b7b1c-66ab-4a41-8da4-83810f6d2d6c",
"version": 3
}