From 241f4455ac573b512afc664a5d41944c7170126f Mon Sep 17 00:00:00 2001 From: Michael Trenker <74047317+MichaelTrenker@users.noreply.github.com> Date: Wed, 14 Jun 2023 11:54:46 +0000 Subject: [PATCH] ran jq_all_the_things.sh --- objects/diamond/definition.json | 134 ++++++++++++++++---------------- 1 file changed, 67 insertions(+), 67 deletions(-) diff --git a/objects/diamond/definition.json b/objects/diamond/definition.json index 5e88db1..0833e14 100644 --- a/objects/diamond/definition.json +++ b/objects/diamond/definition.json @@ -1,70 +1,24 @@ { - "required": [ - "EventID", - "Advesary", - "Capability", - "Infrastructure", - "Victim" - ], - "version": 1, - "description": "A diamond model event object consisting of the four diamond features advesary, infrastructure, capability and victim, several meta-features and ioc attributes.", - "meta-category": "internal", - "uuid": "a9618450-694d-4c73-9f76-35ea0150c19e", - "name": "diamond-event", "attributes": { - "EventID": { - "description": "Id of the event", - "ui-priority": 0, - "misp-attribute": "counter" - }, "Advesary": { "description": "The advesary who attacks the victim", - "ui-priority": 0, - "misp-attribute": "text" + "misp-attribute": "text", + "ui-priority": 0 }, "Capability": { "description": "The capability used to attack the victim", - "ui-priority": 0, - "misp-attribute": "text" - }, - "Infrastructure": { - "description": "The infrastructure used in the attack", - "ui-priority": 0, - "misp-attribute": "text" - }, - "Victim": { - "description": "The attacked victim", - "ui-priority": 0, - "misp-attribute": "text" - }, - "Timestamp": { - "description": "Timestamp when the event happened", - "ui-priority": 0, - "misp-attribute": "datetime" - }, - "Phase": { - "description": "The event mapped to a phase of the killchain", - "ui-priority": 0, "misp-attribute": "text", - "values_list": [ - "Reconnaissance", - "Weaponization", - "Delivery", - "Exploitation", - "Installation", - "C2", - "Action on Objectives" - ] + "ui-priority": 0 }, - "Result": { - "description": "The result of the event", - "ui-priority": 0, - "misp-attribute": "text" + "Description": { + "description": "Further context to the event", + "misp-attribute": "text", + "ui-priority": 0 }, "Direction": { "description": "The network-based direction of the event", - "ui-priority": 0, "misp-attribute": "text", + "ui-priority": 0, "values_list": [ "Victim-to-Infrastructure", "Infrastructure-to-Victim", @@ -75,32 +29,78 @@ "Unknown" ] }, + "EventID": { + "description": "Id of the event", + "misp-attribute": "counter", + "ui-priority": 0 + }, + "Infrastructure": { + "description": "The infrastructure used in the attack", + "misp-attribute": "text", + "ui-priority": 0 + }, "Methodology": { "description": "Mitre-Attack mapping of the event", + "misp-attribute": "text", + "ui-priority": 0 + }, + "Phase": { + "description": "The event mapped to a phase of the killchain", + "misp-attribute": "text", "ui-priority": 0, - "misp-attribute": "text" + "values_list": [ + "Reconnaissance", + "Weaponization", + "Delivery", + "Exploitation", + "Installation", + "C2", + "Action on Objectives" + ] }, "Resources": { - "description": "The resources the attacker needed for the event to succeed", - "ui-priority": 0, - "misp-attribute": "text" + "description": "The resources the attacker needed for the event to succeed", + "misp-attribute": "text", + "ui-priority": 0 }, - "Description": { - "description": "Further context to the event", - "ui-priority": 0, - "misp-attribute": "text" + "Result": { + "description": "The result of the event", + "misp-attribute": "text", + "ui-priority": 0 + }, + "Timestamp": { + "description": "Timestamp when the event happened", + "misp-attribute": "datetime", + "ui-priority": 0 + }, + "Victim": { + "description": "The attacked victim", + "misp-attribute": "text", + "ui-priority": 0 }, "ioc": { "description": "Generic IOC", - "ui-priority": 0, + "misp-attribute": "text", "multiple": true, - "misp-attribute": "text" + "ui-priority": 0 }, "textfield": { "description": "Generic textfield", - "ui-priority": 0, + "misp-attribute": "text", "multiple": true, - "misp-attribute": "text" + "ui-priority": 0 } - } + }, + "description": "A diamond model event object consisting of the four diamond features advesary, infrastructure, capability and victim, several meta-features and ioc attributes.", + "meta-category": "internal", + "name": "diamond-event", + "required": [ + "EventID", + "Advesary", + "Capability", + "Infrastructure", + "Victim" + ], + "uuid": "a9618450-694d-4c73-9f76-35ea0150c19e", + "version": 1 } \ No newline at end of file