2017-09-24 21:21:33 +02:00
|
|
|
{
|
|
|
|
"requiredOneOf": [
|
2018-12-21 12:27:11 +01:00
|
|
|
"name",
|
|
|
|
"regions",
|
|
|
|
"sectors"
|
2017-09-24 21:21:33 +02:00
|
|
|
],
|
|
|
|
"attributes": {
|
|
|
|
"description": {
|
|
|
|
"description": "Description of the victim",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"misp-attribute": "text"
|
|
|
|
},
|
|
|
|
"name": {
|
2017-12-04 10:48:01 +01:00
|
|
|
"description": "The name of the department(s) or organisation(s) targeted.",
|
2017-09-24 21:21:33 +02:00
|
|
|
"ui-priority": 1,
|
2017-12-04 10:48:01 +01:00
|
|
|
"misp-attribute": "target-org",
|
|
|
|
"multiple": true
|
|
|
|
},
|
|
|
|
"external": {
|
|
|
|
"description": "External target organisations affected by this attack.",
|
2017-12-04 10:49:44 +01:00
|
|
|
"ui-priority": 1,
|
2017-12-04 10:48:01 +01:00
|
|
|
"misp-attribute": "target-external",
|
|
|
|
"multiple": true
|
2017-09-24 21:21:33 +02:00
|
|
|
},
|
|
|
|
"classification": {
|
|
|
|
"description": "The type of entity being targeted.",
|
|
|
|
"misp-attribute": "text",
|
2017-12-03 12:07:54 +01:00
|
|
|
"disable_correlation": true,
|
2017-09-24 21:21:33 +02:00
|
|
|
"ui-priority": 1,
|
|
|
|
"sane_default": [
|
|
|
|
"individual",
|
|
|
|
"group",
|
|
|
|
"organization",
|
|
|
|
"class",
|
|
|
|
"unknown"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"roles": {
|
|
|
|
"description": "The list of roles targeted within the victim.",
|
|
|
|
"multiple": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
|
|
|
"sectors": {
|
|
|
|
"description": "The list of sectors that the victim belong to",
|
|
|
|
"multiple": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"sane_default": [
|
|
|
|
"agriculture",
|
|
|
|
"aerospace",
|
|
|
|
"automotive",
|
|
|
|
"communications",
|
|
|
|
"construction",
|
|
|
|
"defence",
|
|
|
|
"education",
|
|
|
|
"energy",
|
|
|
|
"engineering",
|
|
|
|
"entertainment",
|
2017-12-04 15:28:29 +01:00
|
|
|
"financial services",
|
|
|
|
"government national",
|
|
|
|
"government regional",
|
|
|
|
"government local",
|
|
|
|
"government public services",
|
2017-09-24 21:21:33 +02:00
|
|
|
"healthcare",
|
2017-12-04 15:28:29 +01:00
|
|
|
"hospitality leisure",
|
2017-09-24 21:21:33 +02:00
|
|
|
"infrastructure",
|
|
|
|
"insurance",
|
|
|
|
"manufacturing",
|
|
|
|
"mining",
|
2017-12-04 15:28:29 +01:00
|
|
|
"non profit",
|
2017-09-24 21:21:33 +02:00
|
|
|
"pharmaceuticals",
|
|
|
|
"retail",
|
|
|
|
"technology",
|
|
|
|
"telecommunications",
|
|
|
|
"transportation",
|
|
|
|
"utilities"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"regions": {
|
|
|
|
"description": "The list of regions or locations from the victim targeted. ISO 3166 should be used.",
|
|
|
|
"multiple": true,
|
2017-12-04 10:48:01 +01:00
|
|
|
"misp-attribute": "target-location",
|
2017-09-24 21:21:33 +02:00
|
|
|
"ui-priority": 1
|
2017-12-04 10:48:01 +01:00
|
|
|
},
|
|
|
|
"user": {
|
|
|
|
"description": "The username(s) of the user targeted.",
|
|
|
|
"misp-attribute": "target-user",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"multiple": true
|
|
|
|
},
|
|
|
|
"email": {
|
|
|
|
"description": "The email address(es) of the user targeted.",
|
|
|
|
"misp-attribute": "target-email",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"multiple": true
|
|
|
|
},
|
|
|
|
"node": {
|
|
|
|
"description": "Name(s) of node that was targeted.",
|
|
|
|
"misp-attribute": "target-machine",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"multiple": true
|
|
|
|
},
|
|
|
|
"ip-address": {
|
|
|
|
"description": "IP address(es) of the node targeted.",
|
|
|
|
"misp-attribute": "ip-dst",
|
|
|
|
"ui-priority": 1,
|
|
|
|
"multiple": true
|
2017-09-24 21:21:33 +02:00
|
|
|
}
|
|
|
|
},
|
2017-12-04 15:28:29 +01:00
|
|
|
"version": 4,
|
2017-09-24 21:21:33 +02:00
|
|
|
"description": "Victim object describes the target of an attack or abuse.",
|
|
|
|
"meta-category": "misc",
|
|
|
|
"uuid": "a8806e40-39ad-435f-be02-ac2a13d6fc7d",
|
|
|
|
"name": "victim"
|
|
|
|
}
|