diff --git a/objects/passive-dns/definition.json b/objects/passive-dns/definition.json index b832c40..38994ee 100644 --- a/objects/passive-dns/definition.json +++ b/objects/passive-dns/definition.json @@ -6,22 +6,25 @@ ], "attributes": { "zone_time_last": { - "description": "Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import", + "description": "Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import.", "ui-priority": 0, - "misp-attribute": "datetime" + "misp-attribute": "datetime", + "disable_correlation": true }, "text": { - "description": "", + "description": "Description of the passive DNS record.", "ui-priority": 0, - "misp-attribute": "text" + "misp-attribute": "text", + "disable_correlation": true }, "count": { - "description": "How many authoritative DNS answers were received at the Passive DNS Server's collectors with exactly the given set of values as answers", + "description": "How many authoritative DNS answers were received at the Passive DNS Server's collectors with exactly the given set of values as answers.", "ui-priority": 0, - "misp-attribute": "counter" + "misp-attribute": "counter", + "disable_correlation": true }, "rrname": { - "description": "Resource Record name of the queried resource", + "description": "Resource Record name of the queried resource.", "categories": [ "Network activity", "External analysis" @@ -30,7 +33,7 @@ "misp-attribute": "text" }, "rrtype": { - "description": "Resource Record type as seen by the passive DNS", + "description": "Resource Record type as seen by the passive DNS.", "categories": [ "Network activity", "External analysis" @@ -51,7 +54,8 @@ "NAPTR", "HINFO", "A6" - ] + ], + "disable_correlation": true }, "rdata": { "description": "Resource records of the queried resource", @@ -61,35 +65,41 @@ "zone_time_first": { "description": "First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import", "ui-priority": 0, - "misp-attribute": "datetime" + "misp-attribute": "datetime", + "disable_correlation": true }, "origin": { "description": "Origin of the Passive DNS response", "ui-priority": 0, - "misp-attribute": "text" + "misp-attribute": "text", + "disable_correlation": true }, "time_last": { "description": "Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS", "ui-priority": 0, - "misp-attribute": "datetime" + "misp-attribute": "datetime", + "disable_correlation": true }, "time_first": { "description": "First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS", "ui-priority": 0, - "misp-attribute": "datetime" + "misp-attribute": "datetime", + "disable_correlation": true }, "bailiwick": { "description": "Best estimate of the apex of the zone where this data is authoritative", "ui-priority": 0, - "misp-attribute": "text" + "misp-attribute": "text", + "disable_correlation": true }, "sensor_id": { "description": "Sensor information where the record was seen", "ui-priority": 0, - "misp-attribute": "text" + "misp-attribute": "text", + "disable_correlation": true } }, - "version": 2, + "version": 3, "description": "Passive DNS records as expressed in draft-dulaunoy-dnsop-passive-dns-cof-01", "meta-category": "network", "uuid": "b77b7b1c-66ab-4a41-8da4-83810f6d2d6c",