Alexandre Dulaunoy
6b6c136b9c
chg: [vulnerability] vulnerability is is now a vulnerability type
...
The vulnerability type is an official CVE number.
We might need to add in the future a new attribute in the object
for non-CVE id of a vulnerability or adding other id type in the object.
This commit fixes #234
2020-08-28 11:23:10 +02:00
rmkml
cd49fe8d97
add SHA3 Hash on definition.json
2020-08-23 19:30:17 +02:00
Alexandre Dulaunoy
842d128ef3
chg: [misp-objects] newline newline newline is the evil
2020-08-20 10:53:06 +02:00
Alexandre Dulaunoy
dc70db0204
chg: [pe] multiple is true not 1 ;-)
2020-08-20 10:44:41 +02:00
Alexandre Dulaunoy
0c863f194f
chg: [pe] richpe
2020-08-20 10:39:49 +02:00
Andras Iklody
4a671ca739
chg: [RichPE] added
2020-08-20 10:14:35 +02:00
Alexandre Dulaunoy
bfec61d8b0
chg: [file] jq
2020-08-18 07:54:42 +02:00
Alexandre Dulaunoy
7fdfbd4110
UUID must be the same
2020-08-18 07:44:12 +02:00
rmkml
5bdc6c6592
add vhash (VirusTotal Hash) on definition.json
2020-08-17 17:35:58 +02:00
Emil Henry Flakk
097ea8c76c
Add more rrtypes to dns-record
2020-08-15 14:57:53 +02:00
VVX7
7bbcf0ed78
chg: [dev] add Parler app objects
2020-07-05 22:03:16 -04:00
Marc Hörsken
58fb163312
chg: [cortex-taxonomy] sort attributes
...
Make sure the attributes are sorted like a Cortex taxonomy
would normally be displayed/summarized:
`namespace:predicate="value"` with `level` as a meta information.
2020-07-02 13:29:32 +02:00
Raphaël Vinot
b7c2562a4f
new: android-app object template
2020-06-21 21:45:46 +02:00
Jean-Louis Huynen
c1b7b93526
add: [d4] authentication failure report object
2020-06-16 15:59:02 +02:00
Alexandre Dulaunoy
bffde5446e
Merge pull request #261 from VVX7/master
...
chg: [dev] disable correlation on some attributes.
2020-06-12 09:00:07 +02:00
VVX7
bbd5a2a94d
chg: [dev] disable correlation on some attributes. fix underscore typo in account profile-image.
2020-06-11 19:35:02 -04:00
Alexandre Dulaunoy
968a7a8212
Merge pull request #260 from VVX7/master
...
chg: [dev] make Reddit attributes reflect Reddit API.
2020-06-08 17:22:27 +02:00
VVX7
7577cbe59a
chg: [dev] make Reddit attributes (mostly) reflect Reddit API.
2020-06-08 11:16:59 -04:00
Alexandre Dulaunoy
75b71d6f3b
Merge pull request #258 from VVX7/master
...
chg: [dev] add object properties from #254
2020-06-02 19:00:35 +02:00
VVX7
53d2a18811
chg: [dev] run validate_all/jq
2020-06-02 11:11:43 -04:00
VVX7
56bd29d829
chg: [dev] make twitter object attributes more consistent with twitter api
2020-06-02 11:08:30 -04:00
Jesse Hedden
42d3dda12f
fixed order
2020-06-01 16:36:58 -07:00
Jesse Hedden
8256c0ada9
extending trustar_report object in order to provide fields in which enrichment data from a planned expansion module can be stored
2020-06-01 16:02:03 -07:00
VVX7
200ac19bad
chg: [dev] add object properties from #257
2020-05-31 09:52:49 -04:00
VVX7
b9e235a4f4
chg: [dev] fix attribute type
2020-05-30 18:36:09 -04:00
VVX7
cf5687b50d
new: [dev] add Twitter objects: twitter-account, twitter-list, twitter-post. add YouTube objects: youtube-channel, youtube-comment, youtube-playlist, youtube-video. add object: image.
2020-05-29 21:10:02 -04:00
VVX7
ed7a730a79
new: [dev] add Reddit objects: reddit-account, reddit-post, reddit-comment, reddit-subreddit
2020-05-29 16:34:00 -04:00
VVX7
c6da4c9e66
chg: [dev] add user avatar
2020-05-28 16:40:21 -04:00
VVX7
69467c133f
new: [dev] add facebook-account
2020-05-28 16:32:20 -04:00
VVX7
5aeac12979
chg: [dev] change post-id attribute type to text
2020-05-28 15:48:18 -04:00
VVX7
ede33742aa
chg: [dev] run rq
2020-05-28 15:32:43 -04:00
VVX7
ae95dd1834
new: [dev] add facebook-post object.
2020-05-28 15:31:50 -04:00
VVX7
5a9a0fe5ce
new: [dev] add facebook-page object.
2020-05-28 15:29:01 -04:00
VVX7
66f96da3d9
new: [dev] add facebook-group object.
2020-05-28 15:25:04 -04:00
VVX7
2164d80337
chg: [dev] update tracking-id to disable correlation on id description. minor changes to attribute descriptions.
2020-05-28 15:19:27 -04:00
Raphaël Vinot
093850f6c3
new: Preliminary version of git-vuln-finder object template
2020-05-26 12:31:45 +02:00
Alexandre Dulaunoy
9e73449ec7
chg: [sms] format fixed
2020-05-14 18:17:09 +02:00
Carlos Borges
546cd88918
Updating template version
2020-05-13 20:44:09 -03:00
Carlos Borges
02ea8d2afc
updating a missing comma
2020-05-13 20:43:37 -03:00
Carlos Borges
e5ed919e26
Adding phone company of the sending SMS number
...
While sharing some data using this object, we saw the need to add the phone company of the number sending the sms.
With it we can make good local correlations and have an idea of flaws ocurring on phone number release by these companies.
Using web services like Truecaller, it's possible to enrich an analysis with this data.
2020-05-13 20:42:55 -03:00
Raphaël Vinot
26a9d6b51f
new: Objects and relations for FollowTheMoney
2020-05-05 11:02:53 +02:00
Alexandre Dulaunoy
366a8bb121
chg: [boleto] JSON fixed
2020-05-04 13:19:59 +02:00
Carlos Borges
68fe7eed05
New object - Boleto
...
Boleto is a very common form of payment used in Brazil and used a lot by cybercriminals to execute fraud.
Basically a bank or financial instituion is allowed to generate boletos, that is a 40 digit number code.
This object will help institutions identify frauds sources and improve orgs protection.
2020-05-03 00:02:40 -03:00
VVX7
bb600ce627
chg: [publication] modify requiredOneOf, contributor type to text attribute
2020-04-28 18:58:59 -04:00
VVX7
738f32e27b
new: [publication] jq'd the object
2020-04-28 15:46:13 -04:00
VVX7
84633dbd32
new: [publication] add object to describe academic journals, books, etc.
2020-04-28 11:57:28 -04:00
Raphaël Vinot
d9f1db590a
chg: Sort all the entries in the templates by default
2020-04-26 02:13:18 +02:00
Raphaël Vinot
73d710cfbc
fix: Align directory names with object name
2020-04-26 02:07:26 +02:00
Alexandre Dulaunoy
3b5451c325
chg: [legal-entity] website and logo added for legal entity
...
Thanks to Emmanuel MANCIET for the proposal
2020-04-24 18:24:25 +02:00
VVX7
28b4b615ed
chg: [object] add new microblog attributes, change some of the descriptions to make them clearer
2020-04-17 00:11:48 -04:00