Commit Graph

1435 Commits (b6c6de5632bb412b559532205db3e78ff8cc9977)

Author SHA1 Message Date
kx1499 46c244ad08 Merge branch 'master' of https://github.com/kx499/misp-objects 2018-09-06 13:20:52 -04:00
kx1499 4ffac9da5e updated disabling correlation for userid 2018-09-06 13:20:20 -04:00
chrisr3d 1a02c6879e
chg: Deleted filename attribute since it is already contained in attachment 2018-09-06 14:54:39 +02:00
chrisr3d 0890420856
new: New Object describing original files usedd to import data in MISP 2018-09-06 11:20:26 +02:00
Alexandre Dulaunoy 38071f4bd9
chg: [forensic-evidence] updated to include other tools and correlation disabled for some fields 2018-09-04 20:48:51 +02:00
Alexandre Dulaunoy 3a81765d8f
jq all the things (tm) 2018-09-04 20:40:16 +02:00
Alexandre Dulaunoy 258b6830b2
Merge pull request #112 from Aks6193/master
Forensic-evidence
2018-09-04 20:39:22 +02:00
chrisr3d e04a9a570b Merge branch 'master' of github.com:MISP/misp-objects 2018-09-04 16:16:07 +02:00
chrisr3d d84b499d3a
fix: Some relationships typo fixed 2018-09-04 16:15:08 +02:00
aksha d2550dffb6 update: Forensic-evidence object 2018-09-04 14:18:30 +01:00
aksha 4e66e692d4 fixed intendation 2018-09-04 12:46:00 +01:00
aksha 7ee2ff1901 Add: Object template for digital evidence 2018-09-04 12:31:13 +01:00
Aks6193 d92e482a96
Merge pull request #1 from MISP/master
chg: [forensic-case] object added based on the original one from @Aks…
2018-09-03 20:01:41 +01:00
Alexandre Dulaunoy 0c98a925f3
chg: [forensic-case] object added based on the original one from @Aks6193
The idea is to separate the evidences from the case itself as you can
have multiple acquisitions for a specific case. Another object template
is required such as [forensic-evidence] to be able to link between the
forensic-case object and one or more evidences.
2018-09-03 13:54:59 +02:00
aksha b83e98bbd4 Add: Misp object for Digital Forensic - Case metadata 2018-09-03 11:28:40 +01:00
Alexandre Dulaunoy e90b1ce457
chg: [ja3] categories removed (default attributes categories will be used)
Fix MISP/MISP/issues/3593
2018-08-28 14:30:29 +02:00
Alexandre Dulaunoy a2384e9032
added "signed-by" relationship fix #87 2018-08-21 10:22:42 +02:00
Alexandre Dulaunoy ab58f01666
chg: [geolocation] disable correlation on specific attributes 2018-08-15 18:34:35 +02:00
Alexandre Dulaunoy 487ff53afe
fix: [geolocation] to include accuracy-radius as described by maxmind geoip2 API 2018-08-15 18:26:10 +02:00
Alexandre Dulaunoy 0b164141af
chg: [vehicle] Vehicle object template to describe a vehicle information and registration 2018-08-04 15:39:38 +02:00
Alexandre Dulaunoy 3036ec875c
Merge pull request #111 from Delta-Sierra/master
fix requiredOneOf lists regarding non-existing attributes
2018-07-27 16:24:56 +02:00
Deborah Servili 60010ce556
fix file object version 2018-07-27 15:19:15 +02:00
Deborah Servili 4e23159cb0
fix RequiredOneOf list in fle object 2018-07-27 15:15:47 +02:00
Deborah Servili c1f5e7342b
url is not a field of email object, then not one of the requiredOneOf 2018-07-26 15:49:44 +02:00
Alexandre Dulaunoy 3aa3247b09
chg: [paste object] add a link attribute when the paste reference is not malicious 2018-07-26 14:06:39 +02:00
Alexandre Dulaunoy aae03a3db2
chg: [misp-objects] multiple flag is now visible in asciidoctor output 2018-07-22 08:04:26 +02:00
Alexandre Dulaunoy 51d8e83b1f
Merge branch 'master' of github.com:MISP/misp-objects 2018-07-20 10:18:33 +02:00
Alexandre Dulaunoy 9a72b53923
chg: allow multiple domains too fix #108 2018-07-20 10:12:09 +02:00
Andras Iklody 5af0d31c49
Allow multiple "pattern-in-file" in file object, fixes #109 2018-07-20 07:03:22 +02:00
kx1499 bf64122d32 Merge remote-tracking branch 'upstream/master' 2018-07-18 15:57:56 -04:00
Alexandre Dulaunoy 6bfa279701
new: [short-message-service] Short Message Service (SMS) object template describing one or more SMS message added 2018-07-18 09:52:31 +02:00
Alexandre Dulaunoy 319c2a3e96
chg: [threadgrid-report] added in the list of objects 2018-07-17 08:29:14 +02:00
Raphaël Vinot 0244bce6ef new: threatgrid-report object template 2018-07-16 13:48:56 +02:00
Alexandre Dulaunoy 9918cc393d
chg: [coin-address] ETN symbol added 2018-07-13 17:07:35 +02:00
chrisr3d 498c6f114b
fix: Fixed exploits relationship properties 2018-07-10 10:47:31 +02:00
chrisr3d 6585ec3329
add: Updated relationships list with Cybox relationships best practices 2018-07-10 10:40:03 +02:00
Alexandre Dulaunoy b92ab93c80
chg: [relationship] exploits added 2018-07-10 09:41:27 +02:00
Alexandre Dulaunoy 88819d6fa3
chg: [exploit-poc] a same context can contains multiple PoC samples 2018-07-10 09:32:12 +02:00
Alexandre Dulaunoy 26d142d37f
chg: [exploit-poc] added to the list of objects 2018-07-10 07:42:47 +02:00
Alexandre Dulaunoy 021b06bacd
new: exploit-poc object describing a proof of concept or exploit of a vulnerability. This object has often a relationship with a vulnerability object. 2018-07-10 07:41:09 +02:00
Alexandre Dulaunoy 1a491dfd23
chg: [JSON schema] vulnerability added as meta-category 2018-07-10 07:39:58 +02:00
Alexandre Dulaunoy 856cec8d09
chg: [vulnerability] is now in its own vulnerability meta-category 2018-07-10 07:38:28 +02:00
Alexandre Dulaunoy 9eb578d747
chg: [vulnerability] updated following NATO and CIRCL feedback
- CVSS score added
- CVSS string added
- credit attribute added
- text -> description
- vulnerability attribute can now be any format (not only the CVE
format)
2018-07-10 07:21:36 +02:00
Alexandre Dulaunoy 2b5592cfa6
fix: [suricata] allow multiple Suricata rules in the object (similar context) and fix the rule to be in Snort format
Fix #106
2018-07-09 21:50:44 +02:00
Alexandre Dulaunoy eff3a5f3f5
Merge branch 'master' of github.com:MISP/misp-objects 2018-07-04 11:11:47 +02:00
Alexandre Dulaunoy 6c36a1df69
chg: [coin-address] XMR type address added in addition to the default Bitcoin address format 2018-07-04 11:10:50 +02:00
Alexandre Dulaunoy e9fd65cecb
Merge pull request #105 from chrisr3d/master
Added some relations used on stix1 files
2018-06-22 17:37:36 +02:00
chrisr3d 8a916627dd Merge branch 'master' of github.com:MISP/misp-objects 2018-06-22 17:28:12 +02:00
chrisr3d 99b4a20ebb
add: Added some relations seen on stix 2018-06-22 17:27:21 +02:00
Alexandre Dulaunoy 3b21125acd
add: missing timesketch-timeline object template 2018-06-22 07:44:20 +02:00