mirror of https://github.com/MISP/misp-objects
add definition.json for c2-list
parent
364f747e9d
commit
4e10e5501e
|
@ -0,0 +1,40 @@
|
||||||
|
{
|
||||||
|
"attributes": {
|
||||||
|
"c2": {
|
||||||
|
"categories": [
|
||||||
|
"Network activity"
|
||||||
|
],
|
||||||
|
"description": "IP:Port of C2 server",
|
||||||
|
"misp-attribute": "ip-src|port",
|
||||||
|
"multiple": true,
|
||||||
|
"ui-priority": 1
|
||||||
|
},
|
||||||
|
"report-url": {
|
||||||
|
"description": "URL of source of information, e.g. blog post, ransomware analysis",
|
||||||
|
"disable_correlation": true,
|
||||||
|
"misp-attribute": "link",
|
||||||
|
"multiple": true,
|
||||||
|
"ui-priority": 1
|
||||||
|
},
|
||||||
|
"threat": {
|
||||||
|
"categories": [
|
||||||
|
"Attribution",
|
||||||
|
"Payload type"
|
||||||
|
],
|
||||||
|
"description": "threat actor or malware",
|
||||||
|
"misp-attribute": "text",
|
||||||
|
"ui-priority": 1
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"description": "List of C2-servers with common ground, e.g. extracted from a blog post or ransomware analysis",
|
||||||
|
"meta-category": "network",
|
||||||
|
"name": "c2-list",
|
||||||
|
"required": [
|
||||||
|
"threat"
|
||||||
|
],
|
||||||
|
"requiredOneOf": [
|
||||||
|
"c2"
|
||||||
|
],
|
||||||
|
"uuid": "12456351-ceb7-4d43-9a7e-d2275d8b5785",
|
||||||
|
"version": 20230919
|
||||||
|
}
|
Loading…
Reference in New Issue