Commit Graph

1098 Commits (cd27802aab06f02e9e4d02e74feaec3d73427298)

Author SHA1 Message Date
Raphaël Vinot 2fe41c1c46 new: IntelQM objects 2019-11-25 14:43:28 +01:00
Raphaël Vinot 3d7b09e9c4 chg: Update crypto-material and url 2019-11-18 18:03:01 +01:00
Alexandre Dulaunoy 4b76b30061
chg: [microblog] verified field added to add the state of the username 2019-11-16 21:13:10 +01:00
Deborah Servili bdad48d587
switch requiredOneOf list to required since it contains only one element 2019-11-08 15:35:14 +01:00
Jean-Louis Huynen 7b2e5061bb chg: [x509, crypto-material] several changes:
- enables correlation on n, p, q;
- allows for only providing modulus for crypto material;
- specifies the expected data format of several fields.
2019-10-31 10:09:40 +01:00
Alexandre Dulaunoy 58d6722f5e
chg: [crypto-material] new object to described key materials (public and private) 2019-10-17 15:41:01 +02:00
Alexandre Dulaunoy 0859a97535
chg: [x509] to map with D4 project snakeoil database 2019-10-17 14:48:21 +02:00
Alexandre Dulaunoy edf8b59af7
chg: [cowrie] to add HASSH of the client SSH session following Salesforce algorithm
As mentioned in #84
2019-10-05 10:05:26 +02:00
Raphaël Vinot 2cd5329b00 fix: duplicate in coin-address 2019-10-01 13:21:28 -07:00
Alexandre Dulaunoy 49e6c989d5
chg: [coin-address] DASH cryptocurrency address added 2019-10-01 20:17:44 +02:00
Alexandre Dulaunoy ffc120106c
Update definition.json
Following discussion during MISP training - new language seen in a malware campaign.
2019-09-25 12:15:04 +02:00
Deborah Servili 6622083a2b
rename object misc to organization + update version 2019-09-23 12:57:09 +02:00
Deborah Servili d116b7e4b2
Update version of paste object 2019-09-23 09:54:41 +02:00
Alexandre Dulaunoy 4ab14e785a
chg: [translation] double entry fixed in requiredOneOf
Signed-off by:  By de leaduh of JavaScript and decayin' indicatawhs
2019-09-20 09:05:49 +02:00
Alexandre Dulaunoy 52e8f9e98b
chg: [translation] list of sane default for the languages + type of translation 2019-09-20 07:30:30 +02:00
Deborah Servili 4081dc8f8f
jq 2019-09-19 16:26:41 +02:00
Deborah Servili 2721d103e5
add translation object 2019-09-19 16:14:48 +02:00
Deborah Servili a210cb0490
add hashtag attribute in microblog object 2019-09-19 13:33:45 +02:00
Deborah Servili 85f9aee365 Merge https://github.com/MISP/misp-objects 2019-09-17 15:00:51 +02:00
Deborah Servili ca70c9ca9b
update microblog object - use link for non malicious link of the microblog post and embedded-link forlink into the microblog post 2019-09-17 14:59:34 +02:00
Alexandre Dulaunoy a7157678af
Merge pull request #204 from saadkadhi/patch-1
Better wording
2019-09-12 11:12:36 +02:00
Saad Kadhi 0f76563ffc
Better wording 2019-09-11 22:02:48 +02:00
Saad Kadhi a98631d533
Better wording 2019-09-11 21:59:37 +02:00
Alexandre Dulaunoy 0910f0b15f
chg: [credential] adding disable correlation when required 2019-09-11 10:27:27 +02:00
Alexandre Dulaunoy 951abf10fe
chg: [new object templates] various updates 2019-09-11 09:11:28 +02:00
Alexandre Dulaunoy ebcb886037
Merge branch 'master' of https://github.com/Delta-Sierra/misp-objects into Delta-Sierra-master 2019-09-11 08:52:20 +02:00
Deborah Servili b9d16a38ad
draft command object 2019-09-10 16:15:40 +02:00
Deborah Servili 0d40f64815
add impersonation object 2019-09-09 16:36:16 +02:00
Christophe Vandeplas a347aa78fe fix: [virustotal] corrected typo in category 2019-08-08 14:01:09 +02:00
Christophe Vandeplas 7c3ee740fa fix: [timesketch] fix incorrect attribute type 2019-08-08 12:11:13 +02:00
Pierre-Jean Grenier 006e792829
fix: [process] change undefined attributes
misp-attributes 'uuid' and 'src-port' do not exist, change those to something else so that we can use this object properly
2019-08-06 10:39:43 +02:00
Pierre-Jean Grenier fc182be371
Change undefined category to "External analysis" 2019-08-02 14:37:08 +02:00
chrisr3d 29febb2de0
fix: JQed all the things 2019-08-01 15:50:29 +02:00
chrisr3d ad83a3a56f
new: Weakness & attack-pattern objects to describe CWE & CAPEC related to a CVE
- The attack-pattern object is using a new
  attribute type called weakness to describe CWE
  id, which will link to its own information as
  described in https://cve.circl.lu
2019-08-01 14:34:30 +02:00
Raphaël Vinot e5cd4c761a chg: Rename category environment -> climate 2019-07-24 09:31:15 +02:00
Raphaël Vinot 5650664665 new: Objects for Scripps CO2 2019-07-23 16:36:18 +02:00
Alexandre Dulaunoy ab9c1e4cd6
chg: [process] updated following the "mess" of representation in process object
Ref: https://twitter.com/cyb3rops/status/1150315962501095424
2019-07-15 15:58:55 +02:00
Alexandre Dulaunoy fbeb34ccb7
Merge pull request #193 from kx499/master
Adds employee object, dns-record object, and shodan object
2019-07-14 07:59:30 +02:00
Alexandre Dulaunoy 17f1b75973
chg: [network-connection] community-id added 2019-07-13 10:22:18 +02:00
Alexandre Dulaunoy d504979f10
chg: [netflow] attribute community-id added in netflow object template
Ref: https://github.com/corelight/community-id-spec

Ref: 020e67c154
2019-07-13 10:02:15 +02:00
Steve Clement e67b937f73
chg: [process] revert back to single char in light of the new process-attribute 2019-07-13 12:28:31 +09:00
Steve Clement eaf0301fe3
chg: [process] Added sane defaults. 2019-07-12 16:04:38 +09:00
Steve Clement c1a5a52155
chg: [process] Updated process object 2019-07-12 14:33:51 +09:00
Alexandre Dulaunoy 919f6638e1
Merge branch 'master' of github.com:MISP/misp-objects 2019-07-11 23:00:29 +02:00
Alexandre Dulaunoy ce8d6a93c3
chg: [yara] add a yara-rule-name field which can be optional or the only field
As requested in https://github.com/MISP/MISP/issues/4858
2019-07-11 22:59:05 +02:00
Sascha Rommelfangen fd15381cc2
disable correlation on the text field 2019-07-11 16:01:06 +02:00
Sascha Rommelfangen e26a2b6d81
transaction number must be multiple (and text) 2019-07-11 15:51:07 +02:00
Sascha Rommelfangen 1459302dd1
Merge pull request #191 from MISP/rommelfs-patch-5
fixed issue with requirements
2019-07-11 15:24:50 +02:00
Sascha Rommelfangen 07987dc1dd
bumped version 2019-07-11 15:19:37 +02:00
Sascha Rommelfangen aab46e38ea
bumped version 2019-07-11 15:18:55 +02:00
Sascha Rommelfangen 139c190c6a
fixed issue with requirements 2019-07-11 14:56:38 +02:00
Sascha Rommelfangen 78e6b95465
missing parts for balance corrected 2019-07-11 14:34:44 +02:00
Sascha Rommelfangen 873b5cc5a1
removed unneeded characters 2019-07-10 16:35:07 +02:00
Sascha Rommelfangen 2ad020bf15 Merge commit 'ad1300767f7b7757867a8c01ffb4c7d6fa308540' 2019-07-10 15:34:35 +02:00
Sascha Rommelfangen ad1300767f add: btc wallet and transaction object templates 2019-07-10 15:15:16 +02:00
kx1499 c8f6c97da0 Merge remote-tracking branch 'upstream/master' 2019-07-09 22:13:31 -04:00
chrisr3d 0caf4a9edc
chg: Added user-id attribute as one of the required ones 2019-07-09 17:05:48 +02:00
chrisr3d ddff56f52c
fix: TYPO 2019-07-08 11:38:11 +02:00
chrisr3d b96e7ed8be
new: New object describing user accounts 2019-07-08 11:18:21 +02:00
chrisr3d d502c254cc
add: [ip-port] Added ip-dst as one of the required attributes 2019-07-05 16:11:31 +02:00
chrisr3d bfb325b907
add: [ip-port] Added ip-dst attribute eeeeeeeeeeeeeeeeeeeeeee
- Users can then choose between "ip" when they do
  not know whever it is a source or destination IP
  address, or "ip-src" & "ip-dst" to have more
  clarity about the IP address
2019-07-05 15:57:11 +02:00
Alexandre Dulaunoy c3618fcf52
new: [imsi-catcher] object based on the output format of IMSI-catcher open source tools
The object has been created to show the flexibility of the object
template during the PassTheSalt 2019 conference and the D4 presentation.
2019-07-02 10:19:54 +02:00
ater49 e2f12cebd6 Adding IIN and bank_name 2019-06-18 21:45:42 +02:00
Alexandre Dulaunoy 41a6d596ff
chg: [rogue-dns] new object template expressing rogue dns
Thanks to CERT.br for the contribution
2019-06-18 17:39:47 +02:00
Alexandre Dulaunoy e7bb12af7d
chg: [shell-commands] fix typo in object name 2019-06-01 10:13:06 +02:00
Alexandre Dulaunoy 48c64c52fc
new: [shell-commands] Object describing a series of shell commands executed. This object can be linked with malicious files in order to describe a specific execution of shell commands. 2019-06-01 10:04:46 +02:00
Alexandre Dulaunoy a1b2db8fd1
chg: [script] requiredOneOf for script or filename
Malicious scripts can be received without having a filename.
2019-05-23 11:24:05 +02:00
Alexandre Dulaunoy be7e37200a
add: [ssh-authorized-keys] object to add elements from SSH authorized
keys (and do correlation for fun-and-profit(tm))
2019-05-19 17:47:51 +02:00
Alexandre Dulaunoy d922d3eaa5
chg: [person] Gender unknown added
This has been added when investigation is ongoing and
alias is know but gender is unknown discovered during
Enforce training.

topic:enforce
2019-05-16 15:08:43 +02:00
Alexandre Dulaunoy e066df4e6d
chg: [microblog] state field added to describe if the tweet is malicious
or just OSINT.
2019-05-09 17:35:14 +02:00
Alexandre Dulaunoy 230122493c
chg: [authenticode-signerinfo] first version 2019-05-06 07:10:33 +02:00
Alexandre Dulaunoy 8f951e8450
chg: [jq] jq all the things(tm) 2019-05-05 12:33:59 +02:00
Alexandre Dulaunoy cce77727d6
chg: [x509] improve X.509 certificate description to match required ones
from LIEF (as discussed in #180).
2019-05-05 12:31:41 +02:00
Alexandre Dulaunoy 79ab435903
Merge pull request #181 from ater49/master
Adding registration-date in domain-ip
2019-05-04 09:35:11 +02:00
ater49 a2bec8571b Correcting "_" to "-" in fields name 2019-05-03 22:12:08 +02:00
ater49 424900b02d Adding registration-date to domain-ip 2019-05-03 22:08:44 +02:00
Raphaël Vinot f2e8195d50 new: Add offset, virtual_address and virtual_size to the pe section object
Related to https://github.com/MISP/PyMISP/issues/388
2019-05-03 11:19:42 +02:00
Alexandre Dulaunoy e76e492894
chg: [regripper] version updated 2019-05-01 21:32:14 +02:00
mday 71b4e71ab1 update the misp-attribute to specify a valid value instead of an empty string 2019-05-01 14:11:30 -05:00
mday baae683771 update the definition files of various object types so that the `required` and `requiredOneOf` lists no longer specify attributes that do not exist in the objects. 2019-04-30 12:32:22 -05:00
Alexandre Dulaunoy 0f6fdee7f3
chg: [irc] add nickname used for associated IRC server and channel(s) 2019-04-27 10:32:10 +02:00
Alexandre Dulaunoy 1966d4d5f0
add: [irc] IRC object to describe an IRC server with associated IRC channels 2019-04-27 10:28:50 +02:00
Alexandre Dulaunoy b656cc532d
chg: [device] name of an object must be lowercase 2019-04-21 15:57:07 +02:00
Alexandre Dulaunoy 3dcb1725ae
chg: [phishing-kit] small typo fixed in the description 2019-04-21 15:52:57 +02:00
Raphaël Vinot a6ed6df86a Merge branch 'master' of github.com:MISP/misp-objects 2019-04-18 11:15:56 +02:00
Raphaël Vinot 371ffe77fb chg: Allow to create a file object with a non-malicious file.
Fix #175 #176
2019-04-18 11:14:22 +02:00
Andras Iklody 92d15c5efe
Merge pull request #177 from haxpak/haxpak/update-device
Haxpak/update device
2019-04-16 07:43:01 +02:00
Andras Iklody ed271a3b7d
Merge pull request #173 from haxpak/master
added option "Further Analysis Required" to attribute stage of object course-of-action
2019-04-16 07:42:32 +02:00
haxpak 4066da31e4 changed device type drop down from category to sane_default 2019-04-16 08:31:43 +05:30
haxpak 89b8e10fbe added option "Further Analysis Required" to attribute stage 2019-04-15 17:41:39 +05:30
Andras Iklody a8e89e3eaa
Merge branch 'master' into haxpak/#24 2019-04-15 10:52:48 +02:00
haxpak 9f4e7737a1 added attribute DNS name to device object
changed MAC address misp attribute to mac-address
2019-04-15 10:33:08 +05:30
haxpak 3cef676f34 added OS, version, dns-name attribute to device
changed misp-attribute of mac-address from text to mac-address
2019-04-15 10:29:09 +05:30
haxpak 836bd04a75 meta category for organization changed back to misc since schema_objects.json does not recognize organization as a meta category 2019-04-14 11:32:55 +05:30
haxpak 2053c17fa4 corrected typo 2019-04-14 11:27:29 +05:30
haxpak 4f1745a095 added meta category organization 2019-04-14 11:26:12 +05:30
haxpak b24336499a modified: objects/device/definition.json
modified:   objects/phishing-kit/definition.json
2019-04-14 11:04:57 +05:30
haxpak bb9ff86b2f added MAC address to device
meta category of organization changed to organization
meta category of person object changed to organization
new object phishing-kit
2019-04-14 10:53:57 +05:30
haxpak 9f3fb14ed5 changed organization meta category to misc 2019-04-13 14:57:55 +05:30
haxpak 6917beee5f reverted device to misc category 2019-04-13 14:02:26 +05:30
haxpak 63fff149f0 added requiredOneOf to device definition 2019-04-13 13:49:16 +05:30
haxpak df91c999e6 fixed typos and ran jq_all_things 2019-04-13 13:45:05 +05:30
haxpak 23ab735119 - added : attachment attribute to annotation
- added : new object type device
2019-04-13 13:32:56 +05:30
haxpak 161f72678a modified : person object "changed UI priority of the attributes"
modified : report object "added attachment to report"
2019-04-13 12:05:51 +05:30
haxpak 71419a999a new-object : Organization "Defines an organization" 2019-04-13 11:55:38 +05:30
Alexandre Dulaunoy c5532621b6
chg: [ip-port] ip-src added to fix #149 2019-04-07 22:28:36 +02:00
Alexandre Dulaunoy 006aa1d1a2
chg: [script] filename added to fix #149 2019-04-07 22:24:58 +02:00
Alexandre Dulaunoy b4478a6c2b
add: [tor-hiddenservice] a simple object template to describe Tor Onion Service 2019-04-05 11:22:22 +02:00
Alexandre Dulaunoy aca06cec1f
chg: [lnk] new LNK object (Windows Shortcut) 2019-04-03 14:05:39 +02:00
Alexandre Dulaunoy 4793bf33ae
chg: [process] fix the type - fix #160 2019-04-02 19:56:59 +02:00
Alexandre Dulaunoy ba31488e5a
Merge pull request #161 from geekscrapy/geekscrapy-patch-1
Username is often utilised alongside a credential
2019-04-02 19:55:59 +02:00
Alexandre Dulaunoy 302182e594
Merge pull request #159 from geekscrapy/patch-1
Added current-directory to required field
2019-04-02 19:55:03 +02:00
molley a50986361f
Username is often utilised alongside a credential
Username can often identify malicious behavior, and is usually part of the credential tuple - it can also be used to highlight common user accounts without password/api key
2019-04-02 18:26:00 +01:00
molley 490d760a4b
Added current-directory to required field
This field will often indicate where a malicious binary is started from, therefore a good candidate for solo use
2019-04-02 17:41:07 +01:00
molley a85178255c
Added issuer as one of the required fields
This is often a field used on it's own to identify a malicious cert
2019-04-02 17:28:49 +01:00
Raphaël Vinot 0c6b7b4302 chg: Bump vehicle object 2019-04-02 17:09:02 +02:00
Alexandre Dulaunoy 047595ddeb
chg: [person] Spanish IDs added (NIE, NIF and DNI) 2019-03-15 14:36:12 +01:00
kx1499 e61344c981 Merge remote-tracking branch 'upstream/master' 2019-03-14 21:42:12 -04:00
Deborah Servili 55f5716b5d
remove accent from ilr objects - bis 2019-02-26 16:00:23 +01:00
Deborah Servili 96751b2af7
remove accent from ilrobjects 2019-02-26 15:57:58 +01:00
Deborah Servili 41dd469869
add ilr-notification-incident object 2019-02-26 15:51:20 +01:00
Deborah Servili bd9970b1c9
fix lr-impact attributes names 2019-02-26 14:26:29 +01:00
Deborah Servili bc05eca2b6
disable correlations on ilr-impact attributes 2019-02-26 14:05:01 +01:00
Deborah Servili ec2851d4eb
add ilr-impact object 2019-02-26 13:57:31 +01:00
Sascha Rommelfangen 45f6aec0f5
corrected order 2019-02-25 09:29:15 +01:00
marcnil815 03870031db
jq'ed definition.json 2019-02-21 19:36:07 +01:00
marcnil815 e26e54b54a
Create splunk object definition.json
Adding misp-object for basic splunk search/correlation search values.
2019-02-21 16:12:54 +01:00
Alexandre Dulaunoy b0f07156ae
Merge pull request #147 from Delta-Sierra/master
Person object - Add a (or several) role to a person
2019-02-21 07:20:40 +01:00
Alexandre Dulaunoy 18042c0749
chg: [elf] disable correlation on file type 2019-02-20 10:43:38 +01:00
Deborah Servili 0173504050
Person object - Add a (several) role to a person 2019-02-15 09:46:29 +01:00
Alexandre Dulaunoy 08798f1262
chg: [email] IP and hostname fields from extracted headers 2019-02-14 14:33:39 +01:00
Alexandre Dulaunoy 8a4f2c96b8
chg: [file] preferred charset used by the file (if decoded from mime-type parsing) 2019-02-14 14:16:01 +01:00
Alexandre Dulaunoy f9bb8bfa9b
chg: [phishing] removed the IDS flag on the email used for takedown - and change attribute type 2019-02-11 06:45:18 +01:00
Sascha Rommelfangen f09a392d49
added hostname attribute to the phishing object 2019-02-07 14:58:40 +01:00
Alexandre Dulaunoy 75ae30f44d
Merge pull request #143 from rommelfs/master
added values valuable to operators
2019-02-02 09:27:38 +01:00
Alexandre Dulaunoy 36dc6efab3
chg: [anonymisation] add level-of-knowledge to request for more information if needed 2019-02-01 10:19:25 +01:00
Sascha Rommelfangen 732476d7ca
added values valuable to operators 2019-02-01 09:37:31 +01:00
Alexandre Dulaunoy f5c7530e0b
chg: [anonymisation] algo list fixed 2019-01-31 23:01:08 +01:00
Andras Iklody 86a116770b
Update definition.json 2019-01-31 22:57:49 +01:00
Alexandre Dulaunoy b141dce581
add: [anonymisation] Anonymisation object describing an anonymisation technique which is used in MISP anonymised attributes. 2019-01-31 22:41:23 +01:00
Deborah Servili db6297131f Merge https://github.com/MISP/misp-objects 2019-01-28 15:44:31 +01:00
Deborah Servili 0f6f7de384
fix required field for interpol notice 2019-01-28 15:40:07 +01:00
Deborah Servili 1533703894
add interpol notice object 2019-01-28 15:26:49 +01:00
Alexandre Dulaunoy beb0ec8bb7
chg: [script] added PHP in the most used programming language (at least when looking at malicious WebShells on the Internet)
- I sense a new stackoverflow survey category

Signed-off: 5c45721d-de08-4fff-b9b0-168a02de0b81
2019-01-24 13:36:09 +01:00
kx1499 a5ca2e1189 Merge remote-tracking branch 'upstream/master' 2019-01-15 21:19:19 -05:00
Alexandre Dulaunoy b25388c406
Merge pull request #139 from Delta-Sierra/master
Person object - add alias as a requiredOneof attribute
2019-01-11 20:31:03 +01:00
chrisr3d b94abc9182 Merge branch 'master' of github.com:MISP/misp-objects 2019-01-11 16:51:18 +01:00
chrisr3d cf8c50b72e
fix: Disabled correlation for original imported samples 2019-01-11 16:50:29 +01:00
Deborah Servili d6299e6542
update person object version 2019-01-11 15:03:11 +01:00
Deborah Servili b0d8e91f0f
add alias as a requiredOneof attribute 2019-01-11 15:02:06 +01:00
Christophe Vandeplas ae32e23fbf chg: [http-request] IP as allowed type 2019-01-03 15:07:08 +01:00
Stefan Kelm d98cfd6d16 New object: Information related to known scanning activity (e.g. from research projects) 2019-01-02 16:19:08 +01:00
eCrimeLabs 68ca8b0a92 Updated JA3 to have own data type ja3-fingerprint-md5 and bumped the version 2018-12-30 12:31:17 +01:00
Alexandre Dulaunoy 9b84576442
add: [facial-composite] new facial composite object 2018-12-21 20:41:45 +01:00
Alexandre Dulaunoy 5a9800ab6a
chg: [person] portrait added #133 2018-12-21 20:28:24 +01:00
Deborah Servili 7dfa69a743
Object Victim - Extended requiredOneof 2018-12-21 12:27:11 +01:00
Alexandre Dulaunoy 11a462e79b
chg: [person] OFAC fields - Office of Foreign Assets Control 2018-12-04 15:39:51 +01:00
Alexandre Dulaunoy 6cc29aad3d
chg: [microblog] a small clarification about the username to avoid the @ 2018-11-26 22:21:51 +01:00
Alexander J e44dd16b18
new misp object for a timesketch message
to be able to push timesketch messages (timesketch.org) to a misp event it is handy to have a specific type of object for it.
2018-11-23 15:40:57 +01:00
Alexandre Dulaunoy 7808850ce2
chg: [cortex] description updated as TheHive/Cortex observables will be attributes with
relationships from this object
2018-11-18 10:29:42 +01:00
Alexandre Dulaunoy 39dd150e2a
add: [cortex] new object based on a discussion with Jerome L. from TheHive (thanks to SNCF) 2018-11-18 10:28:18 +01:00
Alexandre Dulaunoy 3ec98a8a65
chg: [cortex-taxonomy] aka mini-report 2018-11-18 10:11:25 +01:00
Alexandre Dulaunoy 0f1f23fbb5
fix: [cortex-taxonomy] jq all the things(tm) 2018-11-09 14:21:10 +01:00
Hendrik d61a1f3390 Added cortex taxonomy object definition 2018-11-09 12:37:34 +01:00
Alexandre Dulaunoy 78bfd806e7
Merge pull request #127 from thomaspatzke/process-extension
Extension of process object
2018-11-02 08:56:14 +01:00
Thomas Patzke e12f15d5da Fixed misp-attribute in link attribute of paste object 2018-11-02 00:40:55 +01:00
Thomas Patzke d41b642bc4 Extension of process object 2018-11-02 00:35:28 +01:00
Steve Clement e132ea8e03 fix: [definition] Fixed current balance type, is float. 2018-10-30 22:58:54 +09:00
Steve Clement 6560a53b80 chg: [definition] Extended crypto coin object to be able to enrich with interesting data 2018-10-30 21:30:09 +09:00
Alexandre Dulaunoy a4207d1f36
chg: [mactime-timeline-analysis] disable some correlations 2018-10-29 20:43:36 +01:00
Alexandre Dulaunoy ccab94e1b7
chg: [ip-api-adress] updated to ensure correlation disabled 2018-10-28 15:07:35 +01:00
Raphaël Vinot decd49b6fc fix: JQ things 2018-10-25 17:45:47 -04:00
Raphaël Vinot e3d5d636e4 chg: Add type of internal reference 2018-10-25 15:47:04 -04:00
Raphaël Vinot 1a0d055caa new: Internal reference object 2018-10-25 13:47:20 -04:00
Alexandre Dulaunoy 2f1ed1ee0c
chg: [regripper-sam-hive-single-user] uuid fixed 2018-10-25 17:49:20 +02:00
Alexandre Dulaunoy 5e952a4bf7
chg: [tsk-web-downloads] including link versus url (we assume it's malicious link by default) 2018-10-25 17:45:58 +02:00
Alexandre Dulaunoy 38a3718693
typo fixed 2018-10-25 17:42:57 +02:00
Alexandre Dulaunoy 7a70a1ece3
fix: various typos 2018-10-25 17:38:26 +02:00
Alexandre Dulaunoy 26fcbcd3bf
fix typo 2018-10-25 17:35:50 +02:00
Alexandre Dulaunoy 172b5551ba
Merge branch 'master' of github.com:MISP/misp-objects 2018-10-25 17:32:47 +02:00
Alexandre Dulaunoy b93ad7969f
fix: jq all the things(tm) 2018-10-25 17:31:36 +02:00
Alexandre Dulaunoy 38a006b05b
Merge branch 'master' of https://github.com/Aks6193/misp-objects 2018-10-25 17:30:30 +02:00
aksha bb119724ba fix: Changed TSK object names to lower case 2018-10-25 13:21:08 +01:00
aksha 1cedea6506 Chg: Jq'ed all the objects 2018-10-25 12:39:48 +01:00
Alexandre Dulaunoy 15539c5e25
Merge pull request #123 from neok0/sandbox-file-attribute
added sandbox-file type as attribute for storing e.g. sandbox results…
2018-10-24 14:39:25 +02:00
Alexandre Dulaunoy 7bffd599ab
Merge pull request #122 from neok0/master
enable multiple summary attribute in report object
2018-10-24 14:37:33 +02:00
Tobias Mainka 8b861df876 fix failing check via running .jq_all_the_things.sh 2018-10-24 14:14:32 +02:00
Tobias Mainka 675b60703b added sandbox-file type as attribute for storing e.g. sandbox results file in sandbox-report object 2018-10-24 13:58:38 +02:00
Alexandre Dulaunoy a2ce46ecad
chg: [pcap-metadata] linktype added in the sane default 2018-10-24 07:35:31 +02:00
Alexandre Dulaunoy 3bf8c938aa
fix the required part of the url 2018-10-23 20:03:58 +02:00
Alexandre Dulaunoy 1a1972003d
add: [pcap-metadata] new object template for pcap file metadata (WiP) 2018-10-23 16:35:08 +02:00
Alexandre Dulaunoy ae103f6080
chg: [person] add attributes to whois-related information which can be associated to a person 2018-10-23 08:43:35 +02:00
Tobias Mainka 332cf5475c enable multiple summary attribute in report object 2018-10-22 14:55:27 +02:00
aksha 478dc899f2 Add: Web artefacts objects 2018-10-22 09:35:21 +01:00
chrisr3d de3acf865d
fix: Disabled correlation of imported files format attribute 2018-10-22 10:13:48 +02:00
aksha 711abb094a Add: python-etvx object 2018-10-15 11:08:09 +01:00
chrisr3d 141a0c8d41
fix: JQed ip-api-address template 2018-10-11 09:14:08 +02:00
chrisr3d 8137a58f48 fix: Fixed ip-api-address object template filename 2018-10-11 07:11:28 +02:00
Alexandre Dulaunoy 09495c3f2a
chg: [network-connection] disable correlation 2018-10-06 20:27:51 +02:00
Alexandre Dulaunoy 6ea337654a
Merge branch 'master' of github.com:MISP/misp-objects 2018-10-06 09:35:58 +02:00
Alexandre Dulaunoy 9735995ba1
chg: [process] disable correlation where it's not required 2018-10-06 07:42:34 +02:00
DigitalLeukocyte afb1d28b2b
Added ip-api-address object
Object useful for IP data from http://ip-api.com.
2018-10-04 13:45:22 -07:00
DigitalLeukocyte 237b5a364b
Delete IP_API_IP_Address.json 2018-10-04 13:42:07 -07:00
DigitalLeukocyte c39ff94f41
Deleted IP_API single file 2018-10-04 13:15:55 -07:00
DigitalLeukocyte 04aea7b596
Uploaded IP_API Object in folder 2018-10-04 13:14:42 -07:00
DigitalLeukocyte 59b1dda754
Updated to match more of ip-api.com 2018-10-04 12:41:52 -07:00
DigitalLeukocyte ec75268f5c
Created for data from ip-api.com 2018-10-02 13:02:49 -07:00
DigitalLeukocyte 60f559f6da
Create IP_API.JSON 2018-10-02 13:01:29 -07:00
aksha f8226fc200 Fix: Regripper object templates fixed 2018-10-02 10:14:19 +01:00
aksha 44d92e95be Add: Regripper objects (System + Software Hive) 2018-10-01 12:18:55 +01:00
aksha 58f39ff62d Add: regripper objects for system hive 2018-09-30 21:35:38 +01:00
Alexandre Dulaunoy 25e9f5d51a
chg: [phishing] new template object (first draft) based on the phishtank format 2018-09-28 15:14:51 +02:00
aksha 58ab539825 Fix: NTUser template 2018-09-28 12:15:21 +01:00
aksha 98459432a2 Add: Regripper 3 object templates including SAM hive and NTUSer.dat. 2018-09-28 12:13:31 +01:00
Alexandre Dulaunoy 5acaa3498f
chg: jq all the things ;-) 2018-09-27 13:19:33 +02:00
Alexandre Dulaunoy 96f234884a
Merge branch 'master' of https://github.com/Aks6193/misp-objects into Aks6193-master 2018-09-27 13:19:04 +02:00
aksha 10acf6289e add: Misp object for Mactime-timeline-analysis 2018-09-27 11:46:32 +01:00
Alexandre Dulaunoy 01ea4c3097
chg: [malware-config] new object to describe malware configuration in clear-text or encrypted/encoded
ref: fix https://github.com/MISP/MISP/issues/3679
2018-09-21 07:11:38 +02:00
Alexandre Dulaunoy 4d6e0d7580
chg: [file] fullpath can be part of a single file object 2018-09-16 17:13:30 +02:00
Stefan Kelm 00184b6fc0 bgp-hijack 2018-09-13 14:13:33 +02:00
Stefan Kelm 8b5b5df77c bgp-hijack 2018-09-13 14:05:45 +02:00
Alexandre Dulaunoy 243396a34d
chg: [ail] version of the template updated 2018-09-12 22:11:46 +02:00
Terrtia 76b3086356
fix: [ail-leak] disable correlation 2018-09-12 16:49:28 +02:00
Alexandre Dulaunoy bb2b8d810f
chg: [tracking-id] add the tracker origin such as the vendor or software 2018-09-09 12:39:22 +02:00
Alexandre Dulaunoy 37a4a93326
chg: [original-import-file] list of "sane" default format. 2018-09-09 12:34:06 +02:00
Alexandre Dulaunoy 755dbe5837
Merge branch 'master' of github.com:MISP/misp-objects 2018-09-09 12:30:26 +02:00
Alexandre Dulaunoy c8ecf75fdc
new: [tracking-id] Analytics and tracking ID such as used in Google Analytics or other analytic platform. 2018-09-09 12:29:58 +02:00
chrisr3d 5f74fe8fa8 Merge branch 'master' of github.com:MISP/misp-objects into chrisr3d_patch 2018-09-07 11:33:45 +02:00
chrisr3d 344b8f002e
fix: Changed 'type' attribute that is more relevant as being called 'format' 2018-09-07 11:32:47 +02:00
Alexandre Dulaunoy 767b461429
chg: [file] following some CyBOX import adding a fullpath field which includes filename and path request 2018-09-07 11:26:37 +02:00
kx1499 46c244ad08 Merge branch 'master' of https://github.com/kx499/misp-objects 2018-09-06 13:20:52 -04:00
kx1499 4ffac9da5e updated disabling correlation for userid 2018-09-06 13:20:20 -04:00
chrisr3d 1a02c6879e
chg: Deleted filename attribute since it is already contained in attachment 2018-09-06 14:54:39 +02:00
chrisr3d 0890420856
new: New Object describing original files usedd to import data in MISP 2018-09-06 11:20:26 +02:00
Alexandre Dulaunoy 38071f4bd9
chg: [forensic-evidence] updated to include other tools and correlation disabled for some fields 2018-09-04 20:48:51 +02:00
Alexandre Dulaunoy 3a81765d8f
jq all the things (tm) 2018-09-04 20:40:16 +02:00
aksha d2550dffb6 update: Forensic-evidence object 2018-09-04 14:18:30 +01:00
aksha 4e66e692d4 fixed intendation 2018-09-04 12:46:00 +01:00
aksha 7ee2ff1901 Add: Object template for digital evidence 2018-09-04 12:31:13 +01:00
Aks6193 d92e482a96
Merge pull request #1 from MISP/master
chg: [forensic-case] object added based on the original one from @Aks…
2018-09-03 20:01:41 +01:00
Alexandre Dulaunoy 0c98a925f3
chg: [forensic-case] object added based on the original one from @Aks6193
The idea is to separate the evidences from the case itself as you can
have multiple acquisitions for a specific case. Another object template
is required such as [forensic-evidence] to be able to link between the
forensic-case object and one or more evidences.
2018-09-03 13:54:59 +02:00
aksha b83e98bbd4 Add: Misp object for Digital Forensic - Case metadata 2018-09-03 11:28:40 +01:00
Alexandre Dulaunoy e90b1ce457
chg: [ja3] categories removed (default attributes categories will be used)
Fix MISP/MISP/issues/3593
2018-08-28 14:30:29 +02:00
Alexandre Dulaunoy ab58f01666
chg: [geolocation] disable correlation on specific attributes 2018-08-15 18:34:35 +02:00
Alexandre Dulaunoy 487ff53afe
fix: [geolocation] to include accuracy-radius as described by maxmind geoip2 API 2018-08-15 18:26:10 +02:00
Alexandre Dulaunoy 0b164141af
chg: [vehicle] Vehicle object template to describe a vehicle information and registration 2018-08-04 15:39:38 +02:00
Deborah Servili 60010ce556
fix file object version 2018-07-27 15:19:15 +02:00
Deborah Servili 4e23159cb0
fix RequiredOneOf list in fle object 2018-07-27 15:15:47 +02:00
Deborah Servili c1f5e7342b
url is not a field of email object, then not one of the requiredOneOf 2018-07-26 15:49:44 +02:00
Alexandre Dulaunoy 3aa3247b09
chg: [paste object] add a link attribute when the paste reference is not malicious 2018-07-26 14:06:39 +02:00
Alexandre Dulaunoy 51d8e83b1f
Merge branch 'master' of github.com:MISP/misp-objects 2018-07-20 10:18:33 +02:00
Alexandre Dulaunoy 9a72b53923
chg: allow multiple domains too fix #108 2018-07-20 10:12:09 +02:00
Andras Iklody 5af0d31c49
Allow multiple "pattern-in-file" in file object, fixes #109 2018-07-20 07:03:22 +02:00
kx1499 bf64122d32 Merge remote-tracking branch 'upstream/master' 2018-07-18 15:57:56 -04:00
Alexandre Dulaunoy 6bfa279701
new: [short-message-service] Short Message Service (SMS) object template describing one or more SMS message added 2018-07-18 09:52:31 +02:00
Raphaël Vinot 0244bce6ef new: threatgrid-report object template 2018-07-16 13:48:56 +02:00
Alexandre Dulaunoy 9918cc393d
chg: [coin-address] ETN symbol added 2018-07-13 17:07:35 +02:00
Alexandre Dulaunoy 88819d6fa3
chg: [exploit-poc] a same context can contains multiple PoC samples 2018-07-10 09:32:12 +02:00
Alexandre Dulaunoy 021b06bacd
new: exploit-poc object describing a proof of concept or exploit of a vulnerability. This object has often a relationship with a vulnerability object. 2018-07-10 07:41:09 +02:00
Alexandre Dulaunoy 856cec8d09
chg: [vulnerability] is now in its own vulnerability meta-category 2018-07-10 07:38:28 +02:00
Alexandre Dulaunoy 9eb578d747
chg: [vulnerability] updated following NATO and CIRCL feedback
- CVSS score added
- CVSS string added
- credit attribute added
- text -> description
- vulnerability attribute can now be any format (not only the CVE
format)
2018-07-10 07:21:36 +02:00
Alexandre Dulaunoy 2b5592cfa6
fix: [suricata] allow multiple Suricata rules in the object (similar context) and fix the rule to be in Snort format
Fix #106
2018-07-09 21:50:44 +02:00
Alexandre Dulaunoy 6c36a1df69
chg: [coin-address] XMR type address added in addition to the default Bitcoin address format 2018-07-04 11:10:50 +02:00
Alexandre Dulaunoy 3b21125acd
add: missing timesketch-timeline object template 2018-06-22 07:44:20 +02:00
Alexandre Dulaunoy d9a616095a
Chg: jq all the things 2018-06-19 21:11:24 +02:00
AH 7d1e3747d0 STIX AIS Information source 2018-06-18 19:24:31 -04:00
Thirion Aurélien d2c9ae007a
modify ail-leak object for the tagging system 2018-06-12 11:47:44 +02:00
Alexandre Dulaunoy b6f12a9f46
chg: new script template object
Object describing a computer program written to be run in a special run-time environment. The script or shell
script can be used for malicious activities but also as support tools for threat analysts.

Fix #101
2018-06-09 11:36:58 +02:00
Alexandre Dulaunoy 1ca25a39ad
fix: missing ui-priority 2018-06-09 10:59:01 +02:00
Alexandre Dulaunoy 07f41b0444
chg: EPSG and spacial-reference add fix #102
Following feedback during the last ENISA Cyber Europe 2018, we updated
the geolocation object to the following:

 - Fixing ui-priority to ensure lat,long in order
 - Adding the ability to specify an EPSG value instead of coordinates
 (handy if you want to quickly express a known location/area)
 - Set a default spacial-reference to avoid confusion between reported
 value from GPS versus values projected into a specific spacial
 projection. default is WGS-84.
2018-06-09 10:46:12 +02:00
Corsin Camichel 85901f995a
renamed url attributed, versioning date based 2018-06-05 14:39:12 +02:00
Corsin Camichel 69ed89cef0
updated definition, removed some attributes 2018-06-05 14:35:42 +02:00
Corsin Camichel 19f7c90d1a
Shortened link and its redirect target 2018-06-05 11:04:15 +02:00
Alexandre Dulaunoy d17d11df1a
chg: username of the author added + disable correlation for origin 2018-06-04 19:46:58 +02:00
Alexandre Dulaunoy fe3a91b8d9
chg: change version of the SS7 template object 2018-05-29 16:07:50 +02:00
chrisr3d 00bf1999fc Merge branch 'master' of github.com:MISP/misp-objects 2018-05-25 09:13:44 +02:00
chrisr3d e754719c00
Attribute typo 2018-05-25 09:13:14 +02:00
Alexandre Dulaunoy 52e1316717
chg: Timecode object to describe a start of video sequence (e.g. CCTV evidence) and the end of the video sequence. 2018-05-21 10:19:54 +02:00
kx499 b5da300852 Merge remote-tracking branch 'upstream/master' 2018-05-08 14:42:00 -04:00
chrisr3d b5f352e8c2
add: Added protocol attribute in the network socket object 2018-05-08 09:26:24 +02:00
chrisr3d 536f647135
add: Added hostname (src & dst) attributes 2018-05-08 09:03:57 +02:00
Alexandre Dulaunoy 4d47c41f5e
Network socket connection template object added 2018-05-08 07:53:58 +02:00
Alexandre De Oliveira 13ec601820
Update definition.json
To avoid having multiple object for each similar attacks coming from the same source, we allow multiple attack source in the same attack.
2018-05-04 19:09:54 +02:00
chrisr3d 6faf42cbd2
First version of process object
- Potentially more attributes to come
2018-05-04 16:34:35 +02:00
Raphaël Vinot 956e649315 chg: Update email template 2018-05-03 20:49:48 +02:00
chrisr3d 4cdfd7b0a0
fix: RequiredOneOf field
Sorry, ate too much ananas in my pizza
2018-05-03 14:28:46 +02:00
chrisr3d 3a78d64644 Merge branch 'master' of github.com:MISP/misp-objects 2018-05-03 14:21:56 +02:00
chrisr3d 554cfe29fe
Added definition 2018-05-03 14:21:36 +02:00
Alexandre Dulaunoy 453fd31797
fix: jq all 2018-05-03 14:18:15 +02:00
chrisr3d d221a5e68e Merge branch 'master' of github.com:MISP/misp-objects 2018-05-03 14:11:39 +02:00
chrisr3d e07f2d5c62
Network connection object 2018-05-03 14:11:14 +02:00
Alexandre Dulaunoy e9e1bdd56c
add: Context where the YARA rule can be applied 2018-05-01 11:21:05 +02:00
Alexandre Dulaunoy 3382e18393
add: new timestamp object 2018-04-30 16:27:17 +02:00
Raphaël Vinot 2da5eabbd0 Merge branch 'master' of github.com:MISP/misp-objects 2018-04-27 14:21:23 +02:00
Raphaël Vinot 1fe1f12026 new: Add EML to the email template 2018-04-27 14:20:39 +02:00
StefanKelm f7b17ab62a
Update definition.json 2018-04-26 16:53:24 +02:00
StefanKelm ef1bcc7067
Allow multiple domains and/or IP addresses per object 2018-04-26 16:50:25 +02:00
Raphaël Vinot 196991c73f fix: Bump email template version 2018-04-26 15:07:12 +02:00
Raphaël Vinot 3d75d48051 chg: [email] add email-body in requiredOneOf 2018-04-26 15:05:19 +02:00
ater49 2991d58b0b Adding ui-priority fields 2018-04-23 11:22:39 +02:00
ater49 df38573a3e Correction for multiple parameter 2018-04-23 11:17:41 +02:00
ater49 24c4a68acd Modifying version number 2018-04-23 11:11:29 +02:00
ater49 da216650d7 dding comment fields in VT report objects 2018-04-23 11:09:43 +02:00
Deborah Servili a3f8b1a0ba regexp object - change version 2018-04-13 10:56:56 +02:00
Deborah Servili 55a5508a76 regexp object - disable correlation on type 2018-04-13 10:54:28 +02:00
chrisr3d 05873aefaf
Course of Action object 2018-04-11 16:48:05 +02:00
Dennis Rand 8744ff50a3 moved object into internal 2018-04-10 16:08:04 +00:00
Dennis Rand c8e7cea45b Added target-system as object 2018-04-10 16:03:05 +00:00
Alexandre Dulaunoy c8e9155a3e
fix: add hostname to ip-port template and make attributes multiple 2018-04-10 14:46:36 +02:00
Alexandre Dulaunoy bd89d1cd01
fix: file path added in file object 2018-04-09 15:56:39 +02:00
Alexandre Dulaunoy 1ff6cbf67a
fix: Feedback from @sheidan 2018-03-28 15:26:35 +02:00
Alexandre Dulaunoy 62e782b589
add: Suricata object added with context 2018-03-28 14:32:53 +02:00
Alexandre Dulaunoy 405d4e6bff
fix: name of the object template was incorrect 2018-03-28 14:31:32 +02:00
Raphaël Vinot 7c9e0420e1 Merge branch 'master' of github.com:MISP/misp-objects 2018-03-27 10:26:21 +02:00
Raphaël Vinot 206da3b100 new: Attach logfile to fail2ban 2018-03-27 10:25:54 +02:00
Alexandre Dulaunoy d87336b5c9
version fixed for X509 object 2018-03-27 08:55:02 +02:00
Sheidan b3c348f4ab x509-add-required-one-of-serial-number 2018-03-26 18:16:29 +02:00
Raphaël Vinot 4708caffb5 Merge branch 'master' of github.com:MISP/misp-objects 2018-03-26 17:28:03 +02:00
Raphaël Vinot 3d0540a671 chg: disable correlations in fail2ban 2018-03-26 17:27:55 +02:00
Alexandre Dulaunoy 0a0778bb86
add: new yara object added with a version number 2018-03-26 14:26:15 +02:00
Raphaël Vinot 7c2e07a50b fix: wrong attribute name 2018-03-26 12:05:17 +02:00
Raphaël Vinot d51c3712b9 Merge branch 'master' of github.com:MISP/misp-objects 2018-03-26 11:41:12 +02:00
Raphaël Vinot 1f8fd57d69 chg: Fix&update fail2ban def 2018-03-26 11:41:00 +02:00
Alexandre Dulaunoy b0755e3ca8
jq all 2018-03-26 11:37:38 +02:00
Alexandre Dulaunoy aa30a49796
fix: attribute type fixed 2018-03-26 11:28:32 +02:00
Raphaël Vinot 61fd6728d9 Merge branch 'master' of github.com:MISP/misp-objects 2018-03-26 10:54:52 +02:00
Raphaël Vinot 1f8a26fa3e new: Fail2ban object 2018-03-26 10:54:44 +02:00
Alexandre Dulaunoy c92ee2e461
fix: version field added if stix2-pattern has multiple version in the future 2018-03-19 17:33:45 +01:00
Alexandre Dulaunoy e7e3878042
fix: whois record object updated to cover both cases: domain or IP address 2018-03-16 13:29:39 +01:00
Alexandre Dulaunoy 982e2d8b75
fix: raw whois is also accepted as single attribute in whois object
Required for importing STIX CybOX 1.1 object where just a raw whois
entry is added in remarks.
2018-03-16 13:13:35 +01:00
Alexandre Dulaunoy f7f0a88838
fix: some parts of the URL can be repeated such as resource path, anchor...
multiple flag added to the potential part to be repeated.

following a discussion in Gitter with @makflwana
2018-03-15 09:38:53 +01:00
Alexandre Dulaunoy 4ed961f5e6
fix: disable correlation for compression algorithms 2018-03-01 21:09:04 +01:00
Alexandre Dulaunoy a93a285132
fix: Cowrie object - SSH attributes added 2018-03-01 21:08:16 +01:00
Sami Mokaddem 73aa339ddd typo: passsword -> password 2018-03-01 16:20:58 +01:00
Alexandre Dulaunoy 1fe3e79a05
fix: add missing destination and source port 2018-02-28 17:47:02 +01:00
Alexandre Dulaunoy bdaee9e1c7
add: Cowrie honeypot object template 2018-02-28 17:41:29 +01:00
Alexandre Dulaunoy 73a2b41103
fix: jq all the things 2018-02-23 08:25:35 +01:00
zoomequipd 0d31f27efc
correct rbn --> rtn 2018-02-22 16:37:12 -06:00
zoomequipd 8b1aff8135
add aba-rtn to bank-account object 2018-02-22 16:36:19 -06:00
chrisr3d 271c789f97
fix: Fixed somme bank-account fields 2018-02-22 01:18:15 +01:00
chrisr3d 4cccea8828
Fixed the bank-account meta-category
... which is actually "financial"
2018-02-20 15:44:02 +01:00
chrisr3d 71fa0f66fa
Added default values of funds code 2018-02-14 14:11:42 +01:00
chrisr3d 0367068f92
Added attributes to describe some origin and target fields of a transaction 2018-02-14 11:33:37 +01:00
chrisr3d 594bf5dcc0
Added attributes for the teller and the authorizer of a transaction 2018-02-13 17:53:37 +01:00
Andras Iklody eef4aab989
Changed http request object template
require either uri or url, http method is no longer required.
2018-02-09 09:43:39 +01:00
Alexandre Dulaunoy 3d2091b33c
fix: use new attribute type mime-type instead of text 2018-02-09 07:34:58 +01:00
Alexandre Dulaunoy 1c8a5031f7
Merge branch 'master' of github.com:MISP/misp-objects 2018-02-08 11:55:19 +01:00
Alexandre Dulaunoy b4d433a845
add: Common Alerting Protocol Version (CAP) resource object 2018-02-08 11:53:05 +01:00
Alexandre Dulaunoy 64f9c60ae6
Merge pull request #78 from chrisr3d/master
Transaction Object definition and readme file updated
2018-02-08 08:06:35 +01:00
Alexandre Dulaunoy 857065e0e8
Merge branch 'master' of github.com:MISP/misp-objects 2018-02-08 08:05:53 +01:00
Alexandre Dulaunoy 49f78f067d
add: Common Alerting Protocol Version (CAP) info object 2018-02-08 07:45:41 +01:00
chrisr3d 9ad2b50895
Updated description and readme 2018-02-07 17:26:09 +01:00
chrisr3d 416c91fd5d Merge branch 'master' of github.com:MISP/misp-objects 2018-02-07 15:43:40 +01:00
chrisr3d ad8e01d4c5
Transaction object 2018-02-07 15:36:37 +01:00
Alexandre Dulaunoy 3161533692
fix: trailing dot removed 2018-02-07 14:54:15 +01:00
Alexandre Dulaunoy e1258cd2f7
Common Alerting Protocol Version (CAP) alert object 2018-02-07 14:46:09 +01:00
chrisr3d fd74fac62b
Fixed disable_correlation variable type 2018-02-06 15:36:57 +01:00
chrisr3d 7966c58db9
typo 2018-02-06 15:06:20 +01:00
chrisr3d d250e62546
Added additional attributes 2018-02-06 14:19:04 +01:00
chrisr3d 573873db3b
First version of the legal-entity object 2018-02-05 17:20:39 +01:00
chrisr3d b92d92764b
description typo 2018-02-05 16:10:23 +01:00
chrisr3d c11c4a28ab
chg: Added address and zip code attributes 2018-02-05 14:19:58 +01:00
chrisr3d f169fbee36
chg: updated name of the new attribute 2018-02-05 14:18:21 +01:00
chrisr3d b09f0453ab
chg: Added identity card number 2018-02-05 09:26:50 +01:00
Alexandre Dulaunoy 41b0d33ab3
fix: improve ip-port object to add domain instead of IP address 2018-01-31 15:05:55 +01:00
Alexandre Dulaunoy c57b9b867c
fix: increment version of the MISP email object 2018-01-30 08:59:41 +01:00
David Lord 8d7e3b34a7
Add email-body to the email object definition 2018-01-30 10:12:53 +10:00
Alexandre Dulaunoy f91929738b
add: an object describing bank account information based on account description from goAML 4.0.
A generic bank account partially based on the goAML 4.0 standard.
The bank account alone can convey information regarding the type
of transactions seen or suspected which allow to use the object alone
without the need to describe the full list of transactions.

Additional objects could be created like report, transactions and like
to fully support AML.

The existing person in MISP objects was previously updated to include
the field missing from AML.

A potential evolution is based on the transaction status which can
be described as a simple relationship between MISP objects like:

Bought, Sold, Let, Hired, Exchanged, Donated, Destroyed and Other
2018-01-29 07:42:30 +01:00
Alexandre Dulaunoy bd508a3455
fix: Passive DNS records especially on the disabled_correlation fields 2018-01-25 15:07:19 +01:00
kx499 9eaf4f15fe updated employee object to disable correlation on specific fields 2018-01-24 14:16:28 -05:00
Raphaël Vinot 333f9a46e4 fix: Make the schema happy. 2018-01-23 10:46:15 +01:00
Raphaël Vinot 8c178fd837 fix: Make JQ happy. 2018-01-23 10:43:36 +01:00
garanews 0f3b8195f5 sandbox-signature
Added object sb-signature
2018-01-23 10:12:07 +01:00
Alexandre Dulaunoy 90e72d5895
fix: person object updated to match AML client record + various fixes 2018-01-22 14:16:46 +01:00
Alexandre Dulaunoy cd528865bb
add: Object to describe mutual exclusion locks (mutex) as seen in memory or computer program 2018-01-22 13:34:33 +01:00
kx499 1f061ce2ed Merge remote-tracking branch 'upstream/master' 2018-01-18 10:49:57 -05:00
Alexandre Dulaunoy c75015e1a6
fix: registry-key updated 2018-01-18 13:49:03 +01:00
Alexandre Dulaunoy c04d56d7cd
remove registry hive because registry-key is enough 2018-01-18 13:47:57 +01:00
Alexandre Dulaunoy 94cfc57e16
add: registry-hive object describing a Windows registry hive including key, subkey and
value (and associated data if any)
2018-01-18 12:54:01 +01:00
Alexandre De Oliveira 1b42b02c99
Update definition.json
Adding the multiple possibility for SMSC GT to cover SMS Spaming case. Also text field for multiple details if needed.
Adding "MapSmsText" attribute to help matching malicious URL, keywords or MSISDN inside SMS.
2018-01-11 11:52:11 +01:00
c-goes f92eb6e1b7 added sandbox-report object 2018-01-08 17:28:21 +01:00
Alexandre Dulaunoy 735ebf26bc
fix: annotation object 2018-01-08 11:47:19 +01:00
Alexandre Dulaunoy eafb54fd07
add: An annotation object allowing analysts to add annotations,
comments, executive summary to a MISP event, objects or attributes.
2018-01-08 11:28:11 +01:00
Alexandre Dulaunoy 1008428476
fix: add missing attribute type for the state 2018-01-08 08:15:43 +01:00
Alexandre Dulaunoy 71c0ae1e6c
fix: Vulnerability object improved to include the case of unpublished
security vulnerability
2018-01-08 07:48:32 +01:00
Alexandre Dulaunoy 60279184dd
add: ss7-attack object for the attack against GSM/UMTS networks seen in
SS7 logging.
2018-01-05 16:17:23 +01:00
Alexandre Dulaunoy 8f9c7b1ae1
add: Diameter attack object targeting GSM, UMTS and 4G networks. 2018-01-05 14:34:20 +01:00
Alexandre Dulaunoy 17373f6130
fix: GTPInterface updated 2018-01-05 14:26:28 +01:00
Alexandre Dulaunoy 93f8c7e9d3
fix: GTP attack - multiple on GTP interface 2018-01-05 14:10:05 +01:00
Alexandre Dulaunoy 60d5767e8b
add: first version of a MISP object to describe GTP attack on
GSM/UTMS/3G network.
2018-01-05 13:37:54 +01:00
Alexandre Dulaunoy 7ebda41b4a
fix: disable correlation on fields where is not needed 2017-12-30 19:39:55 +01:00
Alexandre Dulaunoy b4d30b1419
fix: disable correlation on microblog type (Twitter or alike) 2017-12-30 19:26:48 +01:00
Alexandre Dulaunoy 5cd069acdd
fix: disable correlation on all filename-* 2017-12-24 15:05:12 +01:00
Alexandre Dulaunoy 3aea2f2950
fix: Disable correlation on filename by default 2017-12-24 15:02:47 +01:00
Alexandre Dulaunoy 1460d055a0
add: new stix2-pattern object to include STIX 2 patterning 2017-12-21 16:16:33 +01:00
Christophe Vandeplas 9de7423501 whois - adds nameserver attributes
adding nameserver attributes as a whois response contains those
2017-12-20 15:22:45 +01:00
Alexandre Dulaunoy 871b86e35f
fix: Update registry-key to match correct MISP attributes 2017-12-18 14:16:36 +01:00
Alexandre Dulaunoy cf7aa00f98
chg: whois object now includes registrant-org matching new MISP
attributes type - whois-registrant-org
2017-12-18 14:04:53 +01:00
Alexandre Dulaunoy b85438fc45
Fix: x509 object now uses the new and proper fp type 2017-12-13 17:39:59 +01:00
Alexandre Dulaunoy de36d3b735
jq all the things! 2017-12-12 21:57:45 +01:00
Alexandre Dulaunoy 75f9af5464
Merge pull request #41 from truckydev/patch-1
regex addon
2017-12-12 21:42:13 +01:00
Raphaël Vinot 4a7bb59354 chg: Allow malware-sample as only attribute in file. 2017-12-12 17:16:47 +01:00
c-goes fbccdfef24 disable correlation for last-seen/first-seen/text 2017-12-05 11:05:56 +01:00
Alexandre Dulaunoy f5d1742bae
Merge pull request #57 from c-goes/coin-address
Coin address object
2017-12-04 16:00:22 +01:00
c-goes bc01c0c4b8 added coin-address object(2) 2017-12-04 15:43:49 +01:00
c-goes bb0788e267 added coin-address object 2017-12-04 15:37:39 +01:00
Alexandre Dulaunoy b4cae64392
Never trust standards using Google docs to store list of machine parsable information.
Another good reason, why all open vocabularies in OASIS should be
in parsable and validated JSON files. And not *bloody* list of words
in a Google doc.
2017-12-04 15:28:29 +01:00
Alexandre Dulaunoy c3f88d6901
State of the file is no more correlated - and default state value is Malicious. 2017-12-04 11:01:56 +01:00
c-goes 3fc7ce2f7d victim object: changed attributes, added object relations(2) 2017-12-04 10:49:44 +01:00
c-goes 7fadc89ed8 victim object: changed attributes, added object relations 2017-12-04 10:48:01 +01:00
kx499 01df8c715e Added employee-type 2017-12-03 21:39:23 -05:00
Alexandre Dulaunoy 82f440931c
Disable correlation on classification on the victim object 2017-12-03 12:07:54 +01:00
Alexandre Dulaunoy a258d79fef
Typo fixed 2017-12-03 11:42:56 +01:00
Alexandre Dulaunoy e11e95415a
add: x509-fingerprint-sha1 added to file object description (e.g signed APK but not PE) 2017-12-03 11:36:22 +01:00
Alexandre Dulaunoy 04d38118d1
registar->registrar 2017-12-02 23:08:56 +01:00
kx499 8b8ffaea17 added employee object 2017-11-30 15:53:59 -05:00
Alexandre Dulaunoy 465251bf43
fix: update android permissions based on Google latest list 2017-11-28 15:59:01 +01:00
Alexandre Dulaunoy 2baad824b0
add: first version of an android permission(s) object 2017-11-28 15:24:47 +01:00
Deborah Servili 0051ad8167 ddos v5 - add destination domain attribute 2017-11-23 14:43:04 +01:00
c-goes 39319e1cd6 allow multiple filenames 2017-11-23 09:57:49 +01:00
Alexandre Dulaunoy 59edaa978f
raw data is now an attachment 2017-11-22 20:52:26 +01:00
Alexandre Dulaunoy b915869ab2
being lax on origin to avoid rebuilding url path for unknown services 2017-11-22 17:08:56 +01:00
Alexandre Dulaunoy 51e873760e
AIL leak template updated to include duplicate of leaks 2017-11-22 16:38:25 +01:00
Alexandre Dulaunoy dd4e2d1977
fix: MISP type are case-sensitive - fixing AS number type 2017-11-19 10:22:32 +01:00
Alexandre Dulaunoy b046eb4ba7
fix: AIL leak object to include raw-data 2017-11-15 07:32:49 +01:00
kx499 59a78eef24 dns record and shodan report objects 2017-11-14 15:38:54 -05:00
Alexandre Dulaunoy 1fd5d4f6a7
fix: subnets announced is an ip-src type 2017-11-14 15:02:49 +01:00
Alexandre Dulaunoy 666c7a6916
added: Autonomous system object describing an autonomous system which can include one or more network operators management an entity (e.g. ISP) along with their routing policy, routing prefixes o
r alike.

Fix #50
2017-11-13 20:36:16 +01:00
Raphaël Vinot f9b2bdf22c chg: Fix logic in URL
Fix #21
2017-11-10 15:05:22 -08:00
Raphaël Vinot 805ed85bbe chg: Disable some correlations by default in URL
Fix #47
2017-11-10 15:02:37 -08:00
Raphaël Vinot dade532c1f Merge branch 'master' of github.com:MISP/misp-objects 2017-11-10 13:29:03 -08:00
Raphaël Vinot b4b3e685ea fix: requiredOneOf list of r2graphity was wrong
Fix #20
2017-11-10 13:28:05 -08:00
c-goes 8e47b33787 Added file attribute screenshot to email object 2017-11-09 16:07:54 +01:00
Andras Iklody 6b43b68651
Merge pull request #48 from Delta-Sierra/master
allow multiple ips in domain|ip object
2017-11-07 10:08:24 +01:00
Deborah Servili 51f79bceba allow multiple ips in domain|ip object 2017-11-07 09:34:26 +01:00
Alexandre Dulaunoy f46343b2e2
Merge pull request #46 from Delta-Sierra/master
update ail-leak object
2017-11-06 16:20:25 +01:00
Deborah Servili d171c73660 update ail-leak object 2017-11-06 14:53:58 +01:00
Alexandre Dulaunoy 2a2b48a162
fix: origin of credential as sane_default 2017-11-02 21:37:53 +01:00
Alexandre Dulaunoy dab3ad881a
add: credential object (fix #44) 2017-11-02 20:41:02 +01:00
Raphaël Vinot 28dfbb50f7 Remove the executable flag from the json files 2017-10-25 12:16:17 -04:00
truckydev fe594f98ba regex addon
Add field to specify which type correspond to this regex.
2017-10-25 10:39:39 +02:00
Raphaël Vinot 3569c70407 Add report object 2017-10-24 13:04:41 -04:00
Thomas Gardner 6e36c162a4 fixed av-signature merge conflicts with upstream 2017-10-24 10:26:24 -04:00
Thomas Gardner 1c4933c1ce disabled AV software correlation and re-ran jq-all-the-things 2017-10-24 10:23:46 -04:00
Alexandre Dulaunoy 9410aa99a5
Fix the file object 2017-10-23 20:35:07 +02:00
Alexandre Dulaunoy 0f3261077b
State added to file like signed, harmless... 2017-10-23 20:28:30 +02:00
Raphaël Vinot b801bc6603 jq all the things 2017-10-23 11:51:05 -04:00
Thomas Gardner f9204db304 added av-signature and virustotal-report 2017-10-23 10:43:12 -04:00
Alexandre Dulaunoy a5d2f71fef Merge pull request #34 from MISP/fix-31-2
Fix object name
2017-10-16 15:41:33 +02:00
Raphaël Vinot 9078fa0e73 Fix object name
Related to: https://github.com/MISP/misp-objects/issues/31
2017-10-16 11:41:22 +02:00
Raphaël Vinot 60a375f85d Fix object name.
Related to: https://github.com/MISP/misp-objects/issues/31
2017-10-16 11:40:20 +02:00
Alexandre Dulaunoy 0ab002e94c
Fix typo in the field 2017-10-13 15:08:25 +02:00
Alexandre Dulaunoy 9b55a361ec
Some updates including description of fields 2017-10-13 15:02:04 +02:00
Alexandre Dulaunoy 94b9bc9aee
First version of Netflow object based on proposal from @JanKoDFNCERT
Open questions:

  - What is a minimal Netflow records? I relax a bit the required fields.
  - How does this work with IPFIX (and variable templates)?
  - How should we express the TCP flags expressed? (S/SA/SAF)
2017-10-13 14:30:10 +02:00
Alexandre Dulaunoy 2b9ba3ac00
add: RTIR object added (as requested by CSP - Cyber Security Core Service Platform) 2017-10-12 22:08:09 +02:00
Alexandre Dulaunoy deda8abfb1
use url attribute type for link inside a post 2017-10-06 08:22:41 +02:00
Alexandre Dulaunoy c4bc232be2
Merge branch 'patch-4' of https://github.com/ater49/misp-objects into ater49-patch-4 2017-10-06 08:22:00 +02:00
ater49 a13726c138 Update definition.json
Link attribute added in case of url present into the post.

Multiple set to true for "username-quoted"
2017-10-04 13:31:25 +02:00
ater49 71860b21e9 New attributes: title
In case of paste or post has a title.

Ghostbin.com origin added
2017-10-04 13:24:29 +02:00
Alexandre Dulaunoy bc7c84ca5a
add: Paste or similar post from a website allowing to share privately or publicly posts. 2017-09-29 14:59:39 +02:00
Alexandre Dulaunoy f10f361df0
jq all and fix the space ;-) 2017-09-28 22:07:15 +02:00
ater49 4c69154ad3 Attributes username-quoted added
Added Attributes: "username-quoted"
Added types: LinkedIn, Reddit, Google+, Instagram
2017-09-28 21:36:27 +02:00
Alexandre Dulaunoy 5a80d5c4d2
add: Microblog post object like a Twitter tweet or a post on a Facebook wall. 2017-09-28 19:32:31 +02:00
Alexandre Dulaunoy 5b66865268
Carbon copy field added 2017-09-27 16:43:21 +02:00
Alexandre Dulaunoy 140b55254a
return-path added in email object 2017-09-25 20:37:02 +02:00
Alexandre Dulaunoy 9d14620739
Victim object added mainly based on the STIX 2.0 victim proposal 2017-09-24 21:21:33 +02:00
Alexandre Dulaunoy 3ecace4d12
First version of the ja3 object based on the proposal from @delbs 2017-09-24 20:10:59 +02:00
Alexandre Dulaunoy a5c0c4e192
Fixing typo in the credit-card object 2017-09-21 15:35:05 +02:00
Alexandre Dulaunoy d22ced3b82
whois template fixed 2017-09-18 09:01:57 +02:00
Alexandre Dulaunoy 3e00c3129c
Fix #22 2017-09-18 08:11:25 +02:00
iglocska 10b21c6aac fix: Fixed typo 2017-09-17 12:46:51 +02:00
iglocska 8662818177 fix: Updated the required_value field with the new name: values_list 2017-09-17 12:43:09 +02:00
iglocska 8643f0dc47 fix: Fixed an issue with the email object not having the correct requiredoneof fieldnames, fixes MISP/MISP#2481 2017-09-17 12:31:50 +02:00
Alexandre Dulaunoy 777ef97aeb
An object describing a regular expression (regex or regexp).
The object can be linked via a relationship to other attributes
or objects to describe how it can be represented as a regular expression.
2017-09-15 21:02:11 +02:00
Alexandre Dulaunoy d781a0eb05
add: first version of a person object (partially based on the PNR types) 2017-09-14 07:49:50 +02:00
Alexandre Dulaunoy bc27dc6d42
add: first version of the credit-card object 2017-09-13 21:18:16 +02:00
Alexandre Dulaunoy 0e409294c0
fix: port is used instead of text type 2017-09-13 17:26:59 +02:00
Alexandre Dulaunoy 579e851f5e
port type instead of text 2017-09-13 16:42:15 +02:00
Raphaël Vinot 96db4ae070 Disable some correlations 2017-09-11 16:08:03 +02:00
Alexandre Dulaunoy 50fe0c2993 Updated following Andras feedback 2017-09-06 16:13:35 +02:00
Alexandre Dulaunoy 8814be9527 yabin updated following Andras feedback 2017-09-06 16:13:02 +02:00
Alexandre Dulaunoy 317fd559d6 first version of a yabin object 2017-09-06 16:04:37 +02:00
Alexandre Dulaunoy 60f6c15655
Typo fixed 2017-08-29 22:02:10 +02:00
Raphaël Vinot 0445ebd350 Add descriptions in all the objects 2017-08-29 18:36:46 +02:00
Raphaël Vinot 9a3974f383 Update definitions of binaries 2017-08-29 13:25:58 +02:00
Raphaël Vinot d34dd5fb60 Allow multiple entries of type flag in the ELFSection object 2017-08-27 17:49:53 +02:00
Alexandre Dulaunoy 66e7397397
phone defintion fixed 2017-08-27 08:30:58 +02:00
Alexandre Dulaunoy 41f3792b49
first version of a mobile phone object 2017-08-27 08:16:58 +02:00
Raphaël Vinot 7c3aaa30c2 Update ELF definitions, add MachO. 2017-08-25 15:52:32 +02:00
Raphaël Vinot 49cd96aa2b Add mimetype to file object template 2017-08-23 11:01:48 +02:00
Alexandre Dulaunoy 2fd589e151
version updated 2017-08-08 20:39:36 +02:00
truckydev ea7bdb5bd7 add X509-fingerprint
https://github.com/MISP/MISP/pull/2357
2017-08-08 15:11:47 +02:00
Thomas Gardner 8558bef481 added http-request object 2017-08-03 16:11:33 -06:00
Alexandre Dulaunoy 10ca2819a1
Fix: tld type not existing in MISP 2017-08-03 18:27:34 +02:00
Alexandre Dulaunoy 113eb9e5a0
A cookie object has been added.
An HTTP cookie (web cookie, browser cookie) is a small piece of data
that a server sends to the user's web browser. The object includes
type which can help to describe the malicious use-case of the cookie.
2017-08-03 12:15:26 +02:00
Alexandre Dulaunoy 08e5ebe995
Typo fixed in key-size - Thanks to @StefanKelm 2017-08-03 12:00:00 +02:00
Raphaël Vinot ca24684e2f Update required entries for PE objects 2017-07-21 11:33:38 +02:00
Alexandre Dulaunoy 6e88746a67 Improved Tor node object to include support of the new Tor monitoring 2017-07-06 14:57:32 +02:00
Alexandre Dulaunoy afaf0d0e19 add a comment field 2017-07-05 07:41:07 +02:00
Alexandre Dulaunoy 30976be591 Tor node object template which are part of the Tor network at a time. 2017-07-05 07:33:35 +02:00
Alexandre Dulaunoy 9a1c5511f4 ui-priority 2017-07-03 16:55:14 +02:00
Alexandre Dulaunoy e8c74fbccc ui-priority 2017-07-03 16:50:13 +02:00
Alexandre Dulaunoy ea8885f317 ui-priority 2017-07-03 16:50:00 +02:00
Alexandre Dulaunoy 17e57b4a59 ui-priority 2017-07-03 16:49:43 +02:00
Alexandre Dulaunoy cb4af3ffce ui-priority 2017-07-03 16:45:54 +02:00
Alexandre Dulaunoy d2568c922e ui-priority 2017-07-03 16:45:41 +02:00
Alexandre Dulaunoy 611c0b8f55 ui-priority 2017-07-03 16:45:25 +02:00
Alexandre Dulaunoy 60ebdfc3e7 ui-priority 2017-07-03 16:44:39 +02:00
Alexandre Dulaunoy a0a922ee61 ui-priority 2017-07-03 16:44:11 +02:00
Alexandre Dulaunoy c59ed7394a ui-priority 2017-07-03 16:43:57 +02:00
Alexandre Dulaunoy eab13ff63c ui-priority 2017-07-03 16:43:25 +02:00
Alexandre Dulaunoy 65ec7b18a7 ui-priority 2017-07-03 16:43:12 +02:00
Alexandre Dulaunoy 89858f8f72 ui-priority 2017-07-03 16:42:40 +02:00
Alexandre Dulaunoy 13c7d100d0 ui-priority 2017-07-03 16:42:26 +02:00
Alexandre Dulaunoy 5615f18767 ui-priority 2017-07-03 16:42:07 +02:00
Alexandre Dulaunoy 48b17a11ed ui-priority 2017-07-03 16:41:53 +02:00
Alexandre Dulaunoy c0a78b1b25 ui-priority 2017-07-03 16:41:16 +02:00
Alexandre Dulaunoy 7e2214f9e9 ui-priority 2017-07-03 16:40:42 +02:00
Alexandre Dulaunoy e9859c4746 ui-frequency updated 2017-07-03 12:27:16 +02:00
Alexandre Dulaunoy 4915d6688d ui-frequency is the one! 2017-07-03 12:26:40 +02:00
Alexandre Dulaunoy 17d4fab43e ui-priority is now the King! 2017-07-03 12:25:06 +02:00
Alexandre Dulaunoy fb18a4ec29 ui-priority is now the new frequency 2017-07-03 12:24:21 +02:00
Alexandre Dulaunoy ce9f50013c misp-usage-frequency updated 2017-07-03 12:19:04 +02:00
Alexandre Dulaunoy 1f0d512b7d misp-usage-frequency updated 2017-07-03 12:18:47 +02:00
Alexandre Dulaunoy 86f8ad974a misp-usage-frequency updated 2017-07-03 12:18:25 +02:00
Alexandre Dulaunoy 405a5451cc misp-usage-frequency updated 2017-07-03 12:17:46 +02:00
Alexandre Dulaunoy dc2b6524c1 misp-usage-frequency updated 2017-07-03 12:15:50 +02:00
Alexandre Dulaunoy edcf0d1a90 misp-usage-frequency updated 2017-07-03 12:14:48 +02:00
Alexandre Dulaunoy eff1b8ba39 misp-usage-frequency updated 2017-07-03 12:14:13 +02:00
Alexandre Dulaunoy 82bdbbbd4f misp-usage-frequency updated 2017-07-03 12:13:38 +02:00
Alexandre Dulaunoy 5f0755859e misp-usage-frequency updated 2017-07-03 12:11:54 +02:00
Alexandre Dulaunoy a8b1a0a512 misp-usage-frequency updated 2017-07-03 12:09:46 +02:00
Alexandre Dulaunoy 0949bd47ca misp-usage-frequency updated 2017-07-03 12:08:42 +02:00
Alexandre Dulaunoy a04174c1c1 misp-usage-frequency updated 2017-07-03 12:06:11 +02:00
Alexandre Dulaunoy b18eed04ae misp-usage-frequency 2017-07-03 12:04:56 +02:00
Alexandre Dulaunoy aed89b835d misp-usage-frequency -> ui-priority 2017-07-03 12:03:18 +02:00
Alexandre Dulaunoy 45230db220 Fix #14 2017-07-03 11:59:25 +02:00
Andras Iklody ef05cd5f06 Changed DDOS port attributes to port type 2017-07-03 06:33:53 +02:00
Raphaël Vinot 9186771eb7 Update versions 2017-06-28 11:57:36 +02:00
Raphaël Vinot 16af934386 Enforce meta-category 2017-06-28 11:21:24 +02:00
Alexandre Dulaunoy c3186cbcb2 Now meta category for ail to misc 2017-06-28 11:11:44 +02:00
Alexandre Dulaunoy 3e19326efa jq of geolocation object 2017-03-22 07:32:07 +01:00
Alexandre Dulaunoy ff8e9c0a36 geolocation - an object to describe a geographic location. 2017-03-22 07:30:42 +01:00
Alexandre Dulaunoy d413434463 jq of ail-leak 2017-03-22 06:55:15 +01:00
Alexandre Dulaunoy e6fbcf9d53 information leak object as defined by the AIL Analysis Information Leak framework. 2017-03-22 06:54:11 +01:00
Raphaël Vinot d7a1f85100 Update attributes os r2graphity object 2017-03-21 16:46:41 +01:00
Raphaël Vinot 2f74b709d4 Updade r2graphity definition 2017-03-20 14:30:45 +01:00
Raphaël Vinot 29a66cd4d6 Add initial version of the r2graphity object 2017-03-17 18:42:10 +01:00
Raphaël Vinot c0d95f58b5 Remove duplicate entries in file object 2017-03-17 18:00:37 +01:00
Raphaël Vinot 2c5208aab2 Merge branch 'master' of github.com:MISP/misp-objects 2017-03-17 17:32:21 +01:00