From aa3bbd44faf137d3fd83afadca5b133f58151a90 Mon Sep 17 00:00:00 2001 From: Martin Waleczek Date: Tue, 19 Sep 2023 16:58:06 +0200 Subject: [PATCH] add c2-ip to definition.json --- objects/c2-list/definition.json | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/objects/c2-list/definition.json b/objects/c2-list/definition.json index b47ea30..bf6a19f 100644 --- a/objects/c2-list/definition.json +++ b/objects/c2-list/definition.json @@ -1,6 +1,6 @@ { "attributes": { - "c2": { + "c2-ipport": { "categories": [ "Network activity" ], @@ -9,6 +9,15 @@ "multiple": true, "ui-priority": 1 }, + "c2-ip": { + "categories": [ + "Network activity" + ], + "description": "IP of C2 server with unknown port", + "misp-attribute": "ip-src", + "multiple": true, + "ui-priority": 1 + }, "report-url": { "description": "URL of source of information, e.g. blog post, ransomware analysis", "disable_correlation": true, @@ -33,7 +42,8 @@ "threat" ], "requiredOneOf": [ - "c2" + "c2-ipport", + "c2-ip" ], "uuid": "12456351-ceb7-4d43-9a7e-d2275d8b5785", "version": 20230919