Commit Graph

243 Commits (28dfbb50f7f4dcde103a05b9f4081e436868103f)

Author SHA1 Message Date
Raphaël Vinot 28dfbb50f7 Remove the executable flag from the json files 2017-10-25 12:16:17 -04:00
Raphaël Vinot 3569c70407 Add report object 2017-10-24 13:04:41 -04:00
Raphaël Vinot b317712f4d Merge pull request #40 from CenturyLinkCIRT/master
Disabled correlation for software name in av-signature
2017-10-24 10:36:51 -04:00
Thomas Gardner 6e36c162a4 fixed av-signature merge conflicts with upstream 2017-10-24 10:26:24 -04:00
Thomas Gardner 1c4933c1ce disabled AV software correlation and re-ran jq-all-the-things 2017-10-24 10:23:46 -04:00
Alexandre Dulaunoy bbf3e45649
fix: missing description added in asciidoc files 2017-10-23 20:41:08 +02:00
Alexandre Dulaunoy 9410aa99a5
Fix the file object 2017-10-23 20:35:07 +02:00
Alexandre Dulaunoy 0f3261077b
State added to file like signed, harmless... 2017-10-23 20:28:30 +02:00
Raphaël Vinot b801bc6603 jq all the things 2017-10-23 11:51:05 -04:00
Raphaël Vinot d42e4b569b Merge pull request #39 from CenturyLinkCIRT/master
added av-signature and virustotal-report
2017-10-23 10:45:29 -04:00
Thomas Gardner f9204db304 added av-signature and virustotal-report 2017-10-23 10:43:12 -04:00
Alexandre Dulaunoy a5d2f71fef Merge pull request #34 from MISP/fix-31-2
Fix object name
2017-10-16 15:41:33 +02:00
Alexandre Dulaunoy 9375693f72 Merge pull request #33 from MISP/fix-31-1
Fix object name.
2017-10-16 15:41:15 +02:00
Raphaël Vinot 9078fa0e73 Fix object name
Related to: https://github.com/MISP/misp-objects/issues/31
2017-10-16 11:41:22 +02:00
Raphaël Vinot 60a375f85d Fix object name.
Related to: https://github.com/MISP/misp-objects/issues/31
2017-10-16 11:40:20 +02:00
Alexandre Dulaunoy 0ab002e94c
Fix typo in the field 2017-10-13 15:08:25 +02:00
Alexandre Dulaunoy 9b55a361ec
Some updates including description of fields 2017-10-13 15:02:04 +02:00
Alexandre Dulaunoy 94b9bc9aee
First version of Netflow object based on proposal from @JanKoDFNCERT
Open questions:

  - What is a minimal Netflow records? I relax a bit the required fields.
  - How does this work with IPFIX (and variable templates)?
  - How should we express the TCP flags expressed? (S/SA/SAF)
2017-10-13 14:30:10 +02:00
Alexandre Dulaunoy bf8f27d7f5
add: RTIR - Request Tracker for Incident Response added in index 2017-10-12 22:11:09 +02:00
Alexandre Dulaunoy 2b9ba3ac00
add: RTIR object added (as requested by CSP - Cyber Security Core Service Platform) 2017-10-12 22:08:09 +02:00
Alexandre Dulaunoy bc5795dc18
Merge branch 'ater49-patch-4' 2017-10-06 08:23:06 +02:00
Alexandre Dulaunoy deda8abfb1
use url attribute type for link inside a post 2017-10-06 08:22:41 +02:00
Alexandre Dulaunoy c4bc232be2
Merge branch 'patch-4' of https://github.com/ater49/misp-objects into ater49-patch-4 2017-10-06 08:22:00 +02:00
Alexandre Dulaunoy e3974c4e35 Merge pull request #29 from ater49/patch-2
New attribute: title
2017-10-04 19:26:17 +02:00
ater49 a13726c138 Update definition.json
Link attribute added in case of url present into the post.

Multiple set to true for "username-quoted"
2017-10-04 13:31:25 +02:00
ater49 71860b21e9 New attributes: title
In case of paste or post has a title.

Ghostbin.com origin added
2017-10-04 13:24:29 +02:00
Alexandre Dulaunoy 028bb2e0c1
Paste added 2017-09-29 16:18:26 +02:00
Alexandre Dulaunoy bc7c84ca5a
add: Paste or similar post from a website allowing to share privately or publicly posts. 2017-09-29 14:59:39 +02:00
Alexandre Dulaunoy 4b520f0d05
microblog object added 2017-09-29 14:33:54 +02:00
Alexandre Dulaunoy a52847edad Merge pull request #28 from deralexxx/patch-1
mention uuid
2017-09-29 11:36:47 +02:00
Alexander J 8a2745fe61 mention uuid
How to create a uuid and also mention the UUID in the example.

https://twitter.com/alexanderjaeger/status/913505371817435138
2017-09-29 10:52:04 +02:00
Alexandre Dulaunoy b210163927
Merge branch 'ater49-patch-1' 2017-09-28 22:07:45 +02:00
Alexandre Dulaunoy f10f361df0
jq all and fix the space ;-) 2017-09-28 22:07:15 +02:00
ater49 4c69154ad3 Attributes username-quoted added
Added Attributes: "username-quoted"
Added types: LinkedIn, Reddit, Google+, Instagram
2017-09-28 21:36:27 +02:00
Alexandre Dulaunoy 5a80d5c4d2
add: Microblog post object like a Twitter tweet or a post on a Facebook wall. 2017-09-28 19:32:31 +02:00
Alexandre Dulaunoy 5b66865268
Carbon copy field added 2017-09-27 16:43:21 +02:00
Alexandre Dulaunoy 81d242cf36
Documentation links added 2017-09-26 07:37:24 +02:00
Alexandre Dulaunoy 140b55254a
return-path added in email object 2017-09-25 20:37:02 +02:00
Alexandre Dulaunoy 1c3629ac3c
Fixed the release version 2017-09-24 23:43:23 +02:00
Alexandre Dulaunoy b97f0a1e1a
sane_default added in the documentation 2017-09-24 21:36:36 +02:00
Alexandre Dulaunoy dc73dd3e86
victim object added to the list 2017-09-24 21:27:08 +02:00
Alexandre Dulaunoy 9d14620739
Victim object added mainly based on the STIX 2.0 victim proposal 2017-09-24 21:21:33 +02:00
Alexandre Dulaunoy d3306be50c
ja3 and person added in the list 2017-09-24 20:22:08 +02:00
Alexandre Dulaunoy 3ecace4d12
First version of the ja3 object based on the proposal from @delbs 2017-09-24 20:10:59 +02:00
Alexandre Dulaunoy a5c0c4e192
Fixing typo in the credit-card object 2017-09-21 15:35:05 +02:00
Alexandre Dulaunoy 5d7bd3f1ea
2.4.80 released 2017-09-18 23:01:07 +02:00
Alexandre Dulaunoy d22ced3b82
whois template fixed 2017-09-18 09:01:57 +02:00
Alexandre Dulaunoy 3e00c3129c
Fix #22 2017-09-18 08:11:25 +02:00
Alexandre Dulaunoy 0e25309411
values_list added in the documentation 2017-09-17 13:55:49 +02:00
iglocska 10b21c6aac fix: Fixed typo 2017-09-17 12:46:51 +02:00