diff --git a/objects/abuseipdb/definition.json b/objects/abuseipdb/definition.json index da5030e..6f1b309 100644 --- a/objects/abuseipdb/definition.json +++ b/objects/abuseipdb/definition.json @@ -5,6 +5,11 @@ "misp-attribute": "counter", "ui-priority": 0 }, + "is-malicious": { + "description": "If the IP is malicious based on the abuse-confidence-score and threshold", + "misp-attribute": "boolean", + "ui-priority": 0 + }, "is-public": { "description": "If an IP is public", "misp-attribute": "boolean", diff --git a/objects/google-safe-browsing/definition.json b/objects/google-safe-browsing/definition.json new file mode 100644 index 0000000..2c39a38 --- /dev/null +++ b/objects/google-safe-browsing/definition.json @@ -0,0 +1,24 @@ +{ + "attributes": { + "malicious": { + "description": "If the URL comes back as malicious", + "misp-attribute": "boolean", + "ui-priority": 0 + }, + "platforms": { + "description": "The platform identified (windows, linux, etc...)", + "misp-attribute": "text", + "ui-priority": 0 + }, + "threats": { + "description": "The threat type related to that URL (malware, social engineering, etc...)", + "misp-attribute": "text", + "ui-priority": 0 + } + }, + "description": "Google Safe checks a URL against Google's constantly updated list of unsafe web resources.", + "meta-category": "network", + "name": "google-safe-browsing", + "uuid": "1f8af312-dfbb-4572-b894-dabe7c8798d8", + "version": 1 +} \ No newline at end of file