mirror of https://github.com/MISP/misp-objects
add definition.json for c2-list
parent
364f747e9d
commit
4e10e5501e
|
@ -0,0 +1,40 @@
|
|||
{
|
||||
"attributes": {
|
||||
"c2": {
|
||||
"categories": [
|
||||
"Network activity"
|
||||
],
|
||||
"description": "IP:Port of C2 server",
|
||||
"misp-attribute": "ip-src|port",
|
||||
"multiple": true,
|
||||
"ui-priority": 1
|
||||
},
|
||||
"report-url": {
|
||||
"description": "URL of source of information, e.g. blog post, ransomware analysis",
|
||||
"disable_correlation": true,
|
||||
"misp-attribute": "link",
|
||||
"multiple": true,
|
||||
"ui-priority": 1
|
||||
},
|
||||
"threat": {
|
||||
"categories": [
|
||||
"Attribution",
|
||||
"Payload type"
|
||||
],
|
||||
"description": "threat actor or malware",
|
||||
"misp-attribute": "text",
|
||||
"ui-priority": 1
|
||||
}
|
||||
},
|
||||
"description": "List of C2-servers with common ground, e.g. extracted from a blog post or ransomware analysis",
|
||||
"meta-category": "network",
|
||||
"name": "c2-list",
|
||||
"required": [
|
||||
"threat"
|
||||
],
|
||||
"requiredOneOf": [
|
||||
"c2"
|
||||
],
|
||||
"uuid": "12456351-ceb7-4d43-9a7e-d2275d8b5785",
|
||||
"version": 20230919
|
||||
}
|
Loading…
Reference in New Issue