Commit Graph

1243 Commits (ea4892144468cc5a61776d05157d3f09b4010f92)

Author SHA1 Message Date
Alexandre Dulaunoy ea48921444
chg: [cert-pl-phishing] fixed 2024-04-04 16:48:33 +02:00
Alexandre Dulaunoy 4c661b7747
new: [cert-pl-phishing] first draft of a template for the CERT.PL
phishing system
2024-04-04 16:45:33 +02:00
Christian Studer 5b95994bdd
fix: [pe] Removing the `disable_correlation` flag for a `size-in-bytes` attribute type 2024-04-03 17:33:30 +02:00
Christian Studer 980ab615ec
add: [pe-optional-header] New object template for PE optional headers 2024-04-03 17:32:47 +02:00
Christian Studer f247f04548
Merge branch 'main' of github.com:MISP/misp-objects 2024-04-03 14:38:38 +02:00
Christian Studer fba223520a
fix: [pe] Sizes in the PE format should be in bytes 2024-04-03 14:37:55 +02:00
Alexandre Dulaunoy d905c08031
fix: [pe] typo fixed 2024-04-03 14:29:36 +02:00
Christian Studer 2afdb6104b
fix: [pe] `counter` makes more sense here 2024-04-03 14:08:17 +02:00
Christian Studer e042ac127a
chg: [pe] Using the new `integer` attribute type 2024-04-03 13:31:32 +02:00
Christian Studer eb1536f505
chg: [pe] Added `characteristics` & `machine-type` enumerations
- Characteristics are usually in a list, so we
  have now both the list of characteristics with
  their name, and the hex value of the addition
  of all the characteristics numeric values
- We represent the machine type with its name
2024-04-03 11:19:16 +02:00
Christian Studer ad952beb60
add: [pe] Added some PE fields as available with `lief` API 2024-04-02 21:21:38 +02:00
Alexandre Dulaunoy b023d0a3de
chg: [ddos] object type alone authorized if the source/target cannot be
disclosed
2024-03-29 16:22:07 +01:00
Sebastien Larinier d6af105b45 Add software impacted by exploit 2024-03-18 14:19:35 +00:00
Alexandre Dulaunoy ab963cdb5b
chg: [command-line] added sane_default 2024-03-16 09:48:29 +01:00
Alexandre Dulaunoy 322e451c3c
Merge branch 'main' of https://github.com/sebdraven/misp-objects into sebdraven-main 2024-03-16 09:46:59 +01:00
goodlandsecurity fac453a247
fixed parse error 2024-03-15 14:04:07 -05:00
goodlandsecurity 11bf472d8e
forgot multiple flag on two attributes 2024-03-15 13:52:09 -05:00
goodlandsecurity c3f17d6060
adding stairwell object 2024-03-15 12:05:03 -05:00
Sebastien Larinier acfef2f5e8 change type of ans name 2024-03-07 12:02:23 +00:00
Sebastien Larinier 53572fe294 fix typo of description 2024-03-07 10:12:21 +00:00
Sebastien Larinier 9c03f6ab9d add software for cmd line and change type 2024-03-07 10:10:36 +00:00
Alexandre Dulaunoy c72ec74070
fix: [cs-beacon-config] Partial info from CS beacon are possible
Fix #417 - Thanks to @sebdraven
2024-03-06 07:24:37 +01:00
Christos Arvanitis a367c43eb9 Disable correlation for IntelMQ time fields 2024-03-05 11:22:17 +01:00
Alexandre Dulaunoy 173af552aa
chg: [person/organization] `impersonated` added to the role of person
and organization templates

Thanks to NRC Cyber Security for the idea.
2024-03-05 08:59:45 +01:00
Christian Studer 3ac509965f
add: [process] Environment variables attribute 2024-01-30 15:19:54 +01:00
Christian Studer 7c565093df
chg: [artifact] Changed the `payload_bin` attribute to attachment type 2024-01-19 23:15:41 +01:00
David Cruciani 401c34f6f3
chg: [flowintel-task] add case-uuid 2024-01-15 09:11:00 +01:00
David Cruciani 248e7a95dc
chg: [validation] jq all 2024-01-10 12:07:32 +01:00
David Cruciani 55917fe94c
chg: [version] v2 2024-01-10 11:52:10 +01:00
David Cruciani b407a9d046
chg: [url] to_ids 2024-01-10 11:49:54 +01:00
David Cruciani 156fa7a07e
chg: [flowintel] typo + uuid+origin-url 2023-12-14 16:14:44 +01:00
David Cruciani b657128758
new: [object] flowintel-cm 2023-12-14 15:58:46 +01:00
Alexandre Dulaunoy 587b298e1e
chg: [shadowserver-malware-url-report] resource path added to improve
correlation aspects
2023-12-08 15:18:32 +01:00
Alexandre Dulaunoy fcd2cf2445
chg: [cs-beacon-config] updated to add details requested by ShadowServer 2023-12-07 10:54:40 +01:00
Alexandre Dulaunoy 7f77dbe685
chg: [shadowserver-malware-url-report] sane default added for severity
Ref: https://github.com/The-Shadowserver-Foundation/report_schema/blob/main/severity.md
2023-12-07 08:50:15 +01:00
Alexandre Dulaunoy f02af50725
chg: [shadowserver-malware-url-report] sane_default added 2023-12-06 09:50:54 +01:00
Alexandre Dulaunoy 23e41b2262
chg: [shadowserver-malware-url-report] severity added 2023-12-06 09:46:08 +01:00
Alexandre Dulaunoy 047d442311
fix: [report] typo fixed 2023-12-06 09:32:13 +01:00
Alexandre Dulaunoy 08db16c162
chg: [report] `title` field added to the report object template 2023-12-06 09:05:16 +01:00
Alexandre Dulaunoy c536f2f318
fix: [shadowserver-malware-url-report] `port` field added 2023-12-06 08:45:51 +01:00
Alexandre Dulaunoy a240e70334
fix: [victim] object updated 2023-12-05 20:58:22 +01:00
Matthieu Faou 5a19c46498
Changed academic research to academia - university to align with the sector cluster 2023-12-05 12:25:32 -05:00
Matthieu Faou d7007fe456
Added 5 sectors to the victim object 2023-12-05 11:50:38 -05:00
Alexandre Dulaunoy c18a240153
new: [shadowserver-malware-url-report] first version
Transposition of the `malware_url` from Shadowserver
2023-11-22 09:20:56 +01:00
Matthijs van P fd90274503
Merge branch 'MISP:main' into main 2023-11-21 14:03:33 +01:00
Alexandre Dulaunoy d4b6596a9d
fix: [crowdstrike-report] jq all the things 2023-11-21 08:20:35 +01:00
akshayjain-1 516d5ac668
Update definition.json
Changed the file hash attribute type to sha256 from text
2023-11-20 13:54:12 -05:00
akshayjain-1 feeaa600b7
Create definition.json for Crowdstrike report 2023-11-20 12:09:18 -05:00
Matthijs van Polen f90ff8c3c0 [attack-step] Fixed typo, added multiples. 2023-11-10 15:18:48 +01:00
Christian Studer 8fb566fc60
add: [intrusion-set] Added `first_seen` & `last_seen` attributes 2023-11-09 12:10:52 +01:00