mirror of https://github.com/MISP/misp-objects
Alexandre Dulaunoy
0c98a925f3
The idea is to separate the evidences from the case itself as you can have multiple acquisitions for a specific case. Another object template is required such as [forensic-evidence] to be able to link between the forensic-case object and one or more evidences. |
||
---|---|---|
.. | ||
ail-leak | ||
ais-info | ||
android-permission | ||
annotation | ||
asn | ||
av-signature | ||
bank-account | ||
cap-alert | ||
cap-info | ||
cap-resource | ||
coin-address | ||
cookie | ||
course-of-action | ||
cowrie | ||
credential | ||
credit-card | ||
ddos | ||
diameter-attack | ||
domain-ip | ||
elf | ||
elf-section | ||
exploit-poc | ||
fail2ban | ||
file | ||
forensic-case | ||
geolocation | ||
gtp-attack | ||
http-request | ||
ip-port | ||
ja3 | ||
legal-entity | ||
macho | ||
macho-section | ||
microblog | ||
mutex | ||
netflow | ||
network-connection | ||
network-socket | ||
passive-dns | ||
paste | ||
pe | ||
pe-section | ||
person | ||
phone | ||
process | ||
r2graphity | ||
regexp | ||
registry-key | ||
report | ||
rtir | ||
sandbox-report | ||
sb-signature | ||
script | ||
short-message-service | ||
shortened-link | ||
ss7-attack | ||
stix2-pattern | ||
suricata | ||
target-system | ||
threatgrid-report | ||
timecode | ||
timesketch-timeline | ||
timestamp | ||
tor-node | ||
transaction | ||
url | ||
vehicle | ||
victim | ||
virustotal-report | ||
vulnerability | ||
whois | ||
x509 | ||
yabin | ||
yara |