Alexandre Dulaunoy
755dbe5837
Merge branch 'master' of github.com:MISP/misp-objects
2018-09-09 12:30:26 +02:00
Alexandre Dulaunoy
c8ecf75fdc
new: [tracking-id] Analytics and tracking ID such as used in Google Analytics or other analytic platform.
2018-09-09 12:29:58 +02:00
chrisr3d
5f74fe8fa8
Merge branch 'master' of github.com:MISP/misp-objects into chrisr3d_patch
2018-09-07 11:33:45 +02:00
chrisr3d
344b8f002e
fix: Changed 'type' attribute that is more relevant as being called 'format'
2018-09-07 11:32:47 +02:00
Alexandre Dulaunoy
767b461429
chg: [file] following some CyBOX import adding a fullpath field which includes filename and path request
2018-09-07 11:26:37 +02:00
chrisr3d
1a02c6879e
chg: Deleted filename attribute since it is already contained in attachment
2018-09-06 14:54:39 +02:00
chrisr3d
0890420856
new: New Object describing original files usedd to import data in MISP
2018-09-06 11:20:26 +02:00
Alexandre Dulaunoy
38071f4bd9
chg: [forensic-evidence] updated to include other tools and correlation disabled for some fields
2018-09-04 20:48:51 +02:00
Alexandre Dulaunoy
3a81765d8f
jq all the things (tm)
2018-09-04 20:40:16 +02:00
aksha
d2550dffb6
update: Forensic-evidence object
2018-09-04 14:18:30 +01:00
aksha
4e66e692d4
fixed intendation
2018-09-04 12:46:00 +01:00
aksha
7ee2ff1901
Add: Object template for digital evidence
2018-09-04 12:31:13 +01:00
Aks6193
d92e482a96
Merge pull request #1 from MISP/master
...
chg: [forensic-case] object added based on the original one from @Aks…
2018-09-03 20:01:41 +01:00
Alexandre Dulaunoy
0c98a925f3
chg: [forensic-case] object added based on the original one from @Aks6193
...
The idea is to separate the evidences from the case itself as you can
have multiple acquisitions for a specific case. Another object template
is required such as [forensic-evidence] to be able to link between the
forensic-case object and one or more evidences.
2018-09-03 13:54:59 +02:00
aksha
b83e98bbd4
Add: Misp object for Digital Forensic - Case metadata
2018-09-03 11:28:40 +01:00
Alexandre Dulaunoy
e90b1ce457
chg: [ja3] categories removed (default attributes categories will be used)
...
Fix MISP/MISP/issues/3593
2018-08-28 14:30:29 +02:00
Alexandre Dulaunoy
ab58f01666
chg: [geolocation] disable correlation on specific attributes
2018-08-15 18:34:35 +02:00
Alexandre Dulaunoy
487ff53afe
fix: [geolocation] to include accuracy-radius as described by maxmind geoip2 API
2018-08-15 18:26:10 +02:00
Alexandre Dulaunoy
0b164141af
chg: [vehicle] Vehicle object template to describe a vehicle information and registration
2018-08-04 15:39:38 +02:00
Deborah Servili
60010ce556
fix file object version
2018-07-27 15:19:15 +02:00
Deborah Servili
4e23159cb0
fix RequiredOneOf list in fle object
2018-07-27 15:15:47 +02:00
Deborah Servili
c1f5e7342b
url is not a field of email object, then not one of the requiredOneOf
2018-07-26 15:49:44 +02:00
Alexandre Dulaunoy
3aa3247b09
chg: [paste object] add a link attribute when the paste reference is not malicious
2018-07-26 14:06:39 +02:00
Alexandre Dulaunoy
51d8e83b1f
Merge branch 'master' of github.com:MISP/misp-objects
2018-07-20 10:18:33 +02:00
Alexandre Dulaunoy
9a72b53923
chg: allow multiple domains too fix #108
2018-07-20 10:12:09 +02:00
Andras Iklody
5af0d31c49
Allow multiple "pattern-in-file" in file object, fixes #109
2018-07-20 07:03:22 +02:00
Alexandre Dulaunoy
6bfa279701
new: [short-message-service] Short Message Service (SMS) object template describing one or more SMS message added
2018-07-18 09:52:31 +02:00
Raphaël Vinot
0244bce6ef
new: threatgrid-report object template
2018-07-16 13:48:56 +02:00
Alexandre Dulaunoy
9918cc393d
chg: [coin-address] ETN symbol added
2018-07-13 17:07:35 +02:00
Alexandre Dulaunoy
88819d6fa3
chg: [exploit-poc] a same context can contains multiple PoC samples
2018-07-10 09:32:12 +02:00
Alexandre Dulaunoy
021b06bacd
new: exploit-poc object describing a proof of concept or exploit of a vulnerability. This object has often a relationship with a vulnerability object.
2018-07-10 07:41:09 +02:00
Alexandre Dulaunoy
856cec8d09
chg: [vulnerability] is now in its own vulnerability meta-category
2018-07-10 07:38:28 +02:00
Alexandre Dulaunoy
9eb578d747
chg: [vulnerability] updated following NATO and CIRCL feedback
...
- CVSS score added
- CVSS string added
- credit attribute added
- text -> description
- vulnerability attribute can now be any format (not only the CVE
format)
2018-07-10 07:21:36 +02:00
Alexandre Dulaunoy
2b5592cfa6
fix: [suricata] allow multiple Suricata rules in the object (similar context) and fix the rule to be in Snort format
...
Fix #106
2018-07-09 21:50:44 +02:00
Alexandre Dulaunoy
6c36a1df69
chg: [coin-address] XMR type address added in addition to the default Bitcoin address format
2018-07-04 11:10:50 +02:00
Alexandre Dulaunoy
3b21125acd
add: missing timesketch-timeline object template
2018-06-22 07:44:20 +02:00
Alexandre Dulaunoy
d9a616095a
Chg: jq all the things
2018-06-19 21:11:24 +02:00
AH
7d1e3747d0
STIX AIS Information source
2018-06-18 19:24:31 -04:00
Thirion Aurélien
d2c9ae007a
modify ail-leak object for the tagging system
2018-06-12 11:47:44 +02:00
Alexandre Dulaunoy
b6f12a9f46
chg: new script template object
...
Object describing a computer program written to be run in a special run-time environment. The script or shell
script can be used for malicious activities but also as support tools for threat analysts.
Fix #101
2018-06-09 11:36:58 +02:00
Alexandre Dulaunoy
1ca25a39ad
fix: missing ui-priority
2018-06-09 10:59:01 +02:00
Alexandre Dulaunoy
07f41b0444
chg: EPSG and spacial-reference add fix #102
...
Following feedback during the last ENISA Cyber Europe 2018, we updated
the geolocation object to the following:
- Fixing ui-priority to ensure lat,long in order
- Adding the ability to specify an EPSG value instead of coordinates
(handy if you want to quickly express a known location/area)
- Set a default spacial-reference to avoid confusion between reported
value from GPS versus values projected into a specific spacial
projection. default is WGS-84.
2018-06-09 10:46:12 +02:00
Corsin Camichel
85901f995a
renamed url attributed, versioning date based
2018-06-05 14:39:12 +02:00
Corsin Camichel
69ed89cef0
updated definition, removed some attributes
2018-06-05 14:35:42 +02:00
Corsin Camichel
19f7c90d1a
Shortened link and its redirect target
2018-06-05 11:04:15 +02:00
Alexandre Dulaunoy
d17d11df1a
chg: username of the author added + disable correlation for origin
2018-06-04 19:46:58 +02:00
Alexandre Dulaunoy
fe3a91b8d9
chg: change version of the SS7 template object
2018-05-29 16:07:50 +02:00
chrisr3d
00bf1999fc
Merge branch 'master' of github.com:MISP/misp-objects
2018-05-25 09:13:44 +02:00
chrisr3d
e754719c00
Attribute typo
2018-05-25 09:13:14 +02:00
Alexandre Dulaunoy
52e1316717
chg: Timecode object to describe a start of video sequence (e.g. CCTV evidence) and the end of the video sequence.
2018-05-21 10:19:54 +02:00
chrisr3d
b5f352e8c2
add: Added protocol attribute in the network socket object
2018-05-08 09:26:24 +02:00
chrisr3d
536f647135
add: Added hostname (src & dst) attributes
2018-05-08 09:03:57 +02:00
Alexandre Dulaunoy
4d47c41f5e
Network socket connection template object added
2018-05-08 07:53:58 +02:00
Alexandre De Oliveira
13ec601820
Update definition.json
...
To avoid having multiple object for each similar attacks coming from the same source, we allow multiple attack source in the same attack.
2018-05-04 19:09:54 +02:00
chrisr3d
6faf42cbd2
First version of process object
...
- Potentially more attributes to come
2018-05-04 16:34:35 +02:00
Raphaël Vinot
956e649315
chg: Update email template
2018-05-03 20:49:48 +02:00
chrisr3d
4cdfd7b0a0
fix: RequiredOneOf field
...
Sorry, ate too much ananas in my pizza
2018-05-03 14:28:46 +02:00
chrisr3d
3a78d64644
Merge branch 'master' of github.com:MISP/misp-objects
2018-05-03 14:21:56 +02:00
chrisr3d
554cfe29fe
Added definition
2018-05-03 14:21:36 +02:00
Alexandre Dulaunoy
453fd31797
fix: jq all
2018-05-03 14:18:15 +02:00
chrisr3d
d221a5e68e
Merge branch 'master' of github.com:MISP/misp-objects
2018-05-03 14:11:39 +02:00
chrisr3d
e07f2d5c62
Network connection object
2018-05-03 14:11:14 +02:00
Alexandre Dulaunoy
e9e1bdd56c
add: Context where the YARA rule can be applied
2018-05-01 11:21:05 +02:00
Alexandre Dulaunoy
3382e18393
add: new timestamp object
2018-04-30 16:27:17 +02:00
Raphaël Vinot
2da5eabbd0
Merge branch 'master' of github.com:MISP/misp-objects
2018-04-27 14:21:23 +02:00
Raphaël Vinot
1fe1f12026
new: Add EML to the email template
2018-04-27 14:20:39 +02:00
StefanKelm
f7b17ab62a
Update definition.json
2018-04-26 16:53:24 +02:00
StefanKelm
ef1bcc7067
Allow multiple domains and/or IP addresses per object
2018-04-26 16:50:25 +02:00
Raphaël Vinot
196991c73f
fix: Bump email template version
2018-04-26 15:07:12 +02:00
Raphaël Vinot
3d75d48051
chg: [email] add email-body in requiredOneOf
2018-04-26 15:05:19 +02:00
ater49
2991d58b0b
Adding ui-priority fields
2018-04-23 11:22:39 +02:00
ater49
df38573a3e
Correction for multiple parameter
2018-04-23 11:17:41 +02:00
ater49
24c4a68acd
Modifying version number
2018-04-23 11:11:29 +02:00
ater49
da216650d7
dding comment fields in VT report objects
2018-04-23 11:09:43 +02:00
Deborah Servili
a3f8b1a0ba
regexp object - change version
2018-04-13 10:56:56 +02:00
Deborah Servili
55a5508a76
regexp object - disable correlation on type
2018-04-13 10:54:28 +02:00
chrisr3d
05873aefaf
Course of Action object
2018-04-11 16:48:05 +02:00
Dennis Rand
8744ff50a3
moved object into internal
2018-04-10 16:08:04 +00:00
Dennis Rand
c8e7cea45b
Added target-system as object
2018-04-10 16:03:05 +00:00
Alexandre Dulaunoy
c8e9155a3e
fix: add hostname to ip-port template and make attributes multiple
2018-04-10 14:46:36 +02:00
Alexandre Dulaunoy
bd89d1cd01
fix: file path added in file object
2018-04-09 15:56:39 +02:00
Alexandre Dulaunoy
1ff6cbf67a
fix: Feedback from @sheidan
2018-03-28 15:26:35 +02:00
Alexandre Dulaunoy
62e782b589
add: Suricata object added with context
2018-03-28 14:32:53 +02:00
Alexandre Dulaunoy
405d4e6bff
fix: name of the object template was incorrect
2018-03-28 14:31:32 +02:00
Raphaël Vinot
7c9e0420e1
Merge branch 'master' of github.com:MISP/misp-objects
2018-03-27 10:26:21 +02:00
Raphaël Vinot
206da3b100
new: Attach logfile to fail2ban
2018-03-27 10:25:54 +02:00
Alexandre Dulaunoy
d87336b5c9
version fixed for X509 object
2018-03-27 08:55:02 +02:00
Sheidan
b3c348f4ab
x509-add-required-one-of-serial-number
2018-03-26 18:16:29 +02:00
Raphaël Vinot
4708caffb5
Merge branch 'master' of github.com:MISP/misp-objects
2018-03-26 17:28:03 +02:00
Raphaël Vinot
3d0540a671
chg: disable correlations in fail2ban
2018-03-26 17:27:55 +02:00
Alexandre Dulaunoy
0a0778bb86
add: new yara object added with a version number
2018-03-26 14:26:15 +02:00
Raphaël Vinot
7c2e07a50b
fix: wrong attribute name
2018-03-26 12:05:17 +02:00
Raphaël Vinot
d51c3712b9
Merge branch 'master' of github.com:MISP/misp-objects
2018-03-26 11:41:12 +02:00
Raphaël Vinot
1f8fd57d69
chg: Fix&update fail2ban def
2018-03-26 11:41:00 +02:00
Alexandre Dulaunoy
b0755e3ca8
jq all
2018-03-26 11:37:38 +02:00
Alexandre Dulaunoy
aa30a49796
fix: attribute type fixed
2018-03-26 11:28:32 +02:00
Raphaël Vinot
61fd6728d9
Merge branch 'master' of github.com:MISP/misp-objects
2018-03-26 10:54:52 +02:00
Raphaël Vinot
1f8a26fa3e
new: Fail2ban object
2018-03-26 10:54:44 +02:00
Alexandre Dulaunoy
c92ee2e461
fix: version field added if stix2-pattern has multiple version in the future
2018-03-19 17:33:45 +01:00
Alexandre Dulaunoy
e7e3878042
fix: whois record object updated to cover both cases: domain or IP address
2018-03-16 13:29:39 +01:00