.. |
TSK-Chats
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
TSK-Web-Bookmark
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
TSK-Web-Cookie
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
TSK-Web-Downloads
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
TSK-Web-History
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
TSK-Web-Search-Query
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
ail-leak
|
chg: [ail] version of the template updated
|
2018-09-12 22:11:46 +02:00 |
ais-info
|
Chg: jq all the things
|
2018-06-19 21:11:24 +02:00 |
android-permission
|
…
|
|
annotation
|
…
|
|
asn
|
…
|
|
av-signature
|
…
|
|
bank-account
|
…
|
|
bgp-hijack
|
bgp-hijack
|
2018-09-13 14:13:33 +02:00 |
cap-alert
|
…
|
|
cap-info
|
…
|
|
cap-resource
|
…
|
|
coin-address
|
chg: [coin-address] ETN symbol added
|
2018-07-13 17:07:35 +02:00 |
cookie
|
…
|
|
course-of-action
|
…
|
|
cowrie
|
…
|
|
credential
|
…
|
|
credit-card
|
…
|
|
ddos
|
…
|
|
diameter-attack
|
…
|
|
domain-ip
|
chg: allow multiple domains too fix #108
|
2018-07-20 10:12:09 +02:00 |
elf
|
…
|
|
elf-section
|
…
|
|
email
|
url is not a field of email object, then not one of the requiredOneOf
|
2018-07-26 15:49:44 +02:00 |
exploit-poc
|
chg: [exploit-poc] a same context can contains multiple PoC samples
|
2018-07-10 09:32:12 +02:00 |
fail2ban
|
…
|
|
file
|
chg: [file] fullpath can be part of a single file object
|
2018-09-16 17:13:30 +02:00 |
forensic-case
|
chg: [forensic-case] object added based on the original one from @Aks6193
|
2018-09-03 13:54:59 +02:00 |
forensic-evidence
|
chg: [forensic-evidence] updated to include other tools and correlation disabled for some fields
|
2018-09-04 20:48:51 +02:00 |
geolocation
|
chg: [geolocation] disable correlation on specific attributes
|
2018-08-15 18:34:35 +02:00 |
gtp-attack
|
…
|
|
http-request
|
…
|
|
ip-api-address
|
fix: JQed ip-api-address template
|
2018-10-11 09:14:08 +02:00 |
ip-port
|
…
|
|
ja3
|
chg: [ja3] categories removed (default attributes categories will be used)
|
2018-08-28 14:30:29 +02:00 |
legal-entity
|
…
|
|
macho
|
…
|
|
macho-section
|
…
|
|
mactime-timeline-analysis
|
chg: jq all the things ;-)
|
2018-09-27 13:19:33 +02:00 |
malware-config
|
chg: [malware-config] new object to describe malware configuration in clear-text or encrypted/encoded
|
2018-09-21 07:11:38 +02:00 |
microblog
|
…
|
|
mutex
|
…
|
|
netflow
|
…
|
|
network-connection
|
chg: [network-connection] disable correlation
|
2018-10-06 20:27:51 +02:00 |
network-socket
|
…
|
|
original-imported-file
|
fix: Disabled correlation of imported files format attribute
|
2018-10-22 10:13:48 +02:00 |
passive-dns
|
…
|
|
paste
|
chg: [paste object] add a link attribute when the paste reference is not malicious
|
2018-07-26 14:06:39 +02:00 |
pcap-metadata
|
chg: [pcap-metadata] linktype added in the sane default
|
2018-10-24 07:35:31 +02:00 |
pe
|
…
|
|
pe-section
|
…
|
|
person
|
chg: [person] add attributes to whois-related information which can be associated to a person
|
2018-10-23 08:43:35 +02:00 |
phishing
|
chg: [phishing] new template object (first draft) based on the phishtank format
|
2018-09-28 15:14:51 +02:00 |
phone
|
…
|
|
process
|
chg: [process] disable correlation where it's not required
|
2018-10-06 07:42:34 +02:00 |
python-etvx-event-log
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
r2graphity
|
…
|
|
regexp
|
…
|
|
registry-key
|
…
|
|
regripper-NTUser
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-sam-hive-single-user
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-sam-hive-user-group
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-BHO
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-appInit-DLLS
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-application-paths
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-applications-installed
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-command-shell
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-general-windows-info
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-software-run
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-software-hive-userprofile-winlogon
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-system-hive-firewall-configuration
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-system-hive-general-configuration
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-system-hive-network-information
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
regripper-system-hive-service-drivers
|
fix: jq all the things(tm)
|
2018-10-25 17:31:36 +02:00 |
report
|
enable multiple summary attribute in report object
|
2018-10-22 14:55:27 +02:00 |
rtir
|
…
|
|
sandbox-report
|
fix failing check via running .jq_all_the_things.sh
|
2018-10-24 14:14:32 +02:00 |
sb-signature
|
…
|
|
script
|
chg: new script template object
|
2018-06-09 11:36:58 +02:00 |
short-message-service
|
new: [short-message-service] Short Message Service (SMS) object template describing one or more SMS message added
|
2018-07-18 09:52:31 +02:00 |
shortened-link
|
renamed url attributed, versioning date based
|
2018-06-05 14:39:12 +02:00 |
ss7-attack
|
…
|
|
stix2-pattern
|
…
|
|
suricata
|
fix: [suricata] allow multiple Suricata rules in the object (similar context) and fix the rule to be in Snort format
|
2018-07-09 21:50:44 +02:00 |
target-system
|
…
|
|
threatgrid-report
|
new: threatgrid-report object template
|
2018-07-16 13:48:56 +02:00 |
timecode
|
…
|
|
timesketch-timeline
|
add: missing timesketch-timeline object template
|
2018-06-22 07:44:20 +02:00 |
timestamp
|
…
|
|
tor-node
|
…
|
|
tracking-id
|
chg: [tracking-id] add the tracker origin such as the vendor or software
|
2018-09-09 12:39:22 +02:00 |
transaction
|
…
|
|
url
|
fix the required part of the url
|
2018-10-23 20:03:58 +02:00 |
vehicle
|
chg: [vehicle] Vehicle object template to describe a vehicle information and registration
|
2018-08-04 15:39:38 +02:00 |
victim
|
…
|
|
virustotal-report
|
…
|
|
vulnerability
|
chg: [vulnerability] is now in its own vulnerability meta-category
|
2018-07-10 07:38:28 +02:00 |
whois
|
…
|
|
x509
|
…
|
|
yabin
|
…
|
|
yara
|
…
|
|