.. |
TSK-Chats
|
…
|
|
TSK-Web-Bookmark
|
…
|
|
TSK-Web-Cookie
|
…
|
|
TSK-Web-Downloads
|
chg: [tsk-web-downloads] including link versus url (we assume it's malicious link by default)
|
2018-10-25 17:45:58 +02:00 |
TSK-Web-History
|
…
|
|
TSK-Web-Search-Query
|
…
|
|
ail-leak
|
…
|
|
ais-info
|
…
|
|
android-permission
|
…
|
|
annotation
|
chg: [annotation] 'full report' type added
|
2019-12-26 18:29:57 +01:00 |
anonymisation
|
chg: [anonymisation] add level-of-knowledge to request for more information if needed
|
2019-02-01 10:19:25 +01:00 |
asn
|
…
|
|
attack-pattern
|
fix: JQed all the things
|
2019-08-01 15:50:29 +02:00 |
authenticode-signerinfo
|
chg: [authenticode-signerinfo] first version
|
2019-05-06 07:10:33 +02:00 |
av-signature
|
…
|
|
bank-account
|
fix: added iban as an alternative to bank account for the requirements
|
2020-02-04 11:46:24 +01:00 |
bgp-hijack
|
…
|
|
blog
|
chg: [object fields] allow additional requiredOneOf fields in blog, microblog, meme-image objects. add attachment field to blog object. add username to news-media.
|
2020-02-02 20:08:44 -05:00 |
btc-transaction
|
disable correlation on the text field
|
2019-07-11 16:01:06 +02:00 |
btc-wallet
|
bumped version
|
2019-07-11 15:18:55 +02:00 |
cap-alert
|
…
|
|
cap-info
|
…
|
|
cap-resource
|
…
|
|
coin-address
|
fix: duplicate in coin-address
|
2019-10-01 13:21:28 -07:00 |
command
|
Better wording
|
2019-09-11 21:59:37 +02:00 |
command-line
|
Better wording
|
2019-09-11 22:02:48 +02:00 |
cookie
|
…
|
|
cortex
|
chg: [cortex] description updated as TheHive/Cortex observables will be attributes with
|
2018-11-18 10:29:42 +01:00 |
cortex-taxonomy
|
chg: [cortex-taxonomy] aka mini-report
|
2018-11-18 10:11:25 +01:00 |
course-of-action
|
added option "Further Analysis Required" to attribute stage
|
2019-04-15 17:41:39 +05:30 |
cowrie
|
chg: [cowrie] to add HASSH of the client SSH session following Salesforce algorithm
|
2019-10-05 10:05:26 +02:00 |
credential
|
chg: [credential] adding disable correlation when required
|
2019-09-11 10:27:27 +02:00 |
credit-card
|
Adding IIN and bank_name
|
2019-06-18 21:45:42 +02:00 |
crypto-material
|
chg: Update crypto-material and url
|
2019-11-18 18:03:01 +01:00 |
dark-pattern
|
chg: [dark-pattern] typos
|
2019-12-04 16:17:45 +01:00 |
ddos
|
…
|
|
device
|
chg: [device] name of an object must be lowercase
|
2019-04-21 15:57:07 +02:00 |
diameter-attack
|
…
|
|
dns-record
|
…
|
|
domain-ip
|
chg: [domain-ip] port added (required by AIL crawling)
|
2020-01-24 15:46:06 +01:00 |
elf
|
chg: [elf] disable correlation on file type
|
2019-02-20 10:43:38 +01:00 |
elf-section
|
…
|
|
email
|
chg: [email] IP and hostname fields from extracted headers
|
2019-02-14 14:33:39 +01:00 |
employee
|
…
|
|
exploit-poc
|
…
|
|
facial-composite
|
add: [facial-composite] new facial composite object
|
2018-12-21 20:41:45 +01:00 |
fail2ban
|
…
|
|
file
|
Update definition.json
|
2020-01-10 15:00:19 +01:00 |
forensic-case
|
…
|
|
forensic-evidence
|
…
|
|
forged-document
|
chg: [object fields] add forged-document types, add microblog state
|
2020-01-30 21:31:06 -05:00 |
geolocation
|
change definition.json for vehicle and geolocation
|
2020-01-24 10:30:22 +01:00 |
gtp-attack
|
…
|
|
http-request
|
chg: [http-request] IP as allowed type
|
2019-01-03 15:07:08 +01:00 |
ilr-impact
|
remove accent from ilrobjects
|
2019-02-26 15:57:58 +01:00 |
ilr-notification-incident
|
remove accent from ilr objects - bis
|
2019-02-26 16:00:23 +01:00 |
impersonation
|
chg: [new object templates] various updates
|
2019-09-11 09:11:28 +02:00 |
imsi-catcher
|
new: [imsi-catcher] object based on the output format of IMSI-catcher open source tools
|
2019-07-02 10:19:54 +02:00 |
intelmq_event
|
fix: Type asn -> AS
|
2019-11-25 16:23:42 +01:00 |
intelmq_report
|
fix: Type asn -> AS
|
2019-11-25 16:23:42 +01:00 |
internal-reference
|
fix: JQ things
|
2018-10-25 17:45:47 -04:00 |
interpol-notice
|
fix required field for interpol notice
|
2019-01-28 15:40:07 +01:00 |
ip-api-address
|
chg: [ip-api-adress] updated to ensure correlation disabled
|
2018-10-28 15:07:35 +01:00 |
ip-port
|
add: [ip-port] Added ip-dst as one of the required attributes
|
2019-07-05 16:11:31 +02:00 |
irc
|
chg: [irc] add nickname used for associated IRC server and channel(s)
|
2019-04-27 10:32:10 +02:00 |
ja3
|
Updated JA3 to have own data type ja3-fingerprint-md5 and bumped the version
|
2018-12-30 12:31:17 +01:00 |
leaked-document
|
chg: [misinfosec objects] add archive (Internet Archive, Archive.is, etc) fields, change blog post title description
|
2020-01-30 14:08:19 -05:00 |
legal-entity
|
…
|
|
lnk
|
chg: [lnk] new LNK object (Windows Shortcut)
|
2019-04-03 14:05:39 +02:00 |
macho
|
…
|
|
macho-section
|
…
|
|
mactime-timeline-analysis
|
update the definition files of various object types so that the `required` and `requiredOneOf` lists no longer specify attributes that do not exist in the objects.
|
2019-04-30 12:32:22 -05:00 |
malware-config
|
…
|
|
meme-image
|
chg: [object fields] allow additional requiredOneOf fields in blog, microblog, meme-image objects. add attachment field to blog object. add username to news-media.
|
2020-02-02 20:08:44 -05:00 |
microblog
|
chg: [object fields] allow additional requiredOneOf fields in blog, microblog, meme-image objects. add attachment field to blog object. add username to news-media.
|
2020-02-02 20:08:44 -05:00 |
mutex
|
…
|
|
netflow
|
chg: [netflow] attribute community-id added in netflow object template
|
2019-07-13 10:02:15 +02:00 |
network-connection
|
chg: [network-connection] community-id added
|
2019-07-13 10:22:18 +02:00 |
network-socket
|
…
|
|
news-agency
|
chg: [object fields] allow additional requiredOneOf fields in blog, microblog, meme-image objects. add attachment field to blog object. add username to news-media.
|
2020-02-02 20:08:44 -05:00 |
news-media
|
chg: [object fields] allow additional requiredOneOf fields in blog, microblog, meme-image objects. add attachment field to blog object. add username to news-media.
|
2020-02-02 20:08:44 -05:00 |
organization
|
chg: [organization] typo fixed + description added
|
2020-02-05 15:06:37 +01:00 |
original-imported-file
|
update the definition files of various object types so that the `required` and `requiredOneOf` lists no longer specify attributes that do not exist in the objects.
|
2019-04-30 12:32:22 -05:00 |
passive-dns
|
…
|
|
paste
|
Update version of paste object
|
2019-09-23 09:54:41 +02:00 |
pcap-metadata
|
…
|
|
pe
|
updated "version" to 4
|
2019-11-29 09:09:30 +01:00 |
pe-section
|
new: Add offset, virtual_address and virtual_size to the pe section object
|
2019-05-03 11:19:42 +02:00 |
person
|
chg: [person] Gender unknown added
|
2019-05-16 15:08:43 +02:00 |
pgp-meta
|
fix: [new object pgp-meta] remove first seen/last seen + fix description
|
2020-02-03 16:45:28 +01:00 |
phishing
|
corrected order
|
2019-02-25 09:29:15 +01:00 |
phishing-kit
|
update the definition files of various object types so that the `required` and `requiredOneOf` lists no longer specify attributes that do not exist in the objects.
|
2019-04-30 12:32:22 -05:00 |
phone
|
chg: [phone] add brand and model
|
2020-02-05 15:04:10 +01:00 |
process
|
fix: [process] change undefined attributes
|
2019-08-06 10:39:43 +02:00 |
python-etvx-event-log
|
update the definition files of various object types so that the `required` and `requiredOneOf` lists no longer specify attributes that do not exist in the objects.
|
2019-04-30 12:32:22 -05:00 |
r2graphity
|
…
|
|
regexp
|
…
|
|
registry-key
|
…
|
|
regripper-NTUser
|
…
|
|
regripper-sam-hive-single-user
|
chg: [regripper-sam-hive-single-user] uuid fixed
|
2018-10-25 17:49:20 +02:00 |
regripper-sam-hive-user-group
|
…
|
|
regripper-software-hive-BHO
|
…
|
|
regripper-software-hive-appInit-DLLS
|
…
|
|
regripper-software-hive-application-paths
|
…
|
|
regripper-software-hive-applications-installed
|
…
|
|
regripper-software-hive-command-shell
|
…
|
|
regripper-software-hive-general-windows-info
|
…
|
|
regripper-software-hive-software-run
|
…
|
|
regripper-software-hive-userprofile-winlogon
|
…
|
|
regripper-system-hive-firewall-configuration
|
…
|
|
regripper-system-hive-general-configuration
|
chg: [regripper] version updated
|
2019-05-01 21:32:14 +02:00 |
regripper-system-hive-network-information
|
…
|
|
regripper-system-hive-service-drivers
|
chg: [regripper] version updated
|
2019-05-01 21:32:14 +02:00 |
report
|
fixed typos and ran jq_all_things
|
2019-04-13 13:45:05 +05:30 |
research-scanner
|
New object: Information related to known scanning activity (e.g. from research projects)
|
2019-01-02 16:19:08 +01:00 |
rogue-dns
|
chg: [rogue-dns] new object template expressing rogue dns
|
2019-06-18 17:39:47 +02:00 |
rtir
|
…
|
|
sandbox-report
|
…
|
|
sb-signature
|
Change undefined category to "External analysis"
|
2019-08-02 14:37:08 +02:00 |
scrippsco2-c13-daily
|
chg: Rename category environment -> climate
|
2019-07-24 09:31:15 +02:00 |
scrippsco2-c13-monthly
|
chg: Rename category environment -> climate
|
2019-07-24 09:31:15 +02:00 |
scrippsco2-co2-daily
|
chg: Rename category environment -> climate
|
2019-07-24 09:31:15 +02:00 |
scrippsco2-co2-monthly
|
chg: Rename category environment -> climate
|
2019-07-24 09:31:15 +02:00 |
scrippsco2-o18-daily
|
chg: Rename category environment -> climate
|
2019-07-24 09:31:15 +02:00 |
scrippsco2-o18-monthly
|
chg: Rename category environment -> climate
|
2019-07-24 09:31:15 +02:00 |
script
|
fix: Wrong name in requiredOneOf
|
2020-01-28 10:47:18 +01:00 |
shell-commands
|
switch requiredOneOf list to required since it contains only one element
|
2019-11-08 15:35:14 +01:00 |
shodan-report
|
…
|
|
short-message-service
|
…
|
|
shortened-link
|
…
|
|
splunk
|
jq'ed definition.json
|
2019-02-21 19:36:07 +01:00 |
ss7-attack
|
…
|
|
ssh-authorized-keys
|
add: [ssh-authorized-keys] object to add elements from SSH authorized
|
2019-05-19 17:47:51 +02:00 |
stix2-pattern
|
…
|
|
suricata
|
…
|
|
target-system
|
…
|
|
threatgrid-report
|
…
|
|
timecode
|
…
|
|
timesketch-timeline
|
fix: [timesketch] fix incorrect attribute type
|
2019-08-08 12:11:13 +02:00 |
timesketch_message
|
new misp object for a timesketch message
|
2018-11-23 15:40:57 +01:00 |
timestamp
|
…
|
|
tor-hiddenservice
|
add: [tor-hiddenservice] a simple object template to describe Tor Onion Service
|
2019-04-05 11:22:22 +02:00 |
tor-node
|
…
|
|
tracking-id
|
…
|
|
transaction
|
…
|
|
translation
|
chg: [translation] double entry fixed in requiredOneOf
|
2019-09-20 09:05:49 +02:00 |
trustar_report
|
new: TruStar report object
|
2020-01-24 12:58:28 +01:00 |
url
|
chg: Update crypto-material and url
|
2019-11-18 18:03:01 +01:00 |
user-account
|
chg: [object field] add profile picture to user-account
|
2020-01-31 18:27:42 -05:00 |
vehicle
|
chg: [vehicule] image + type of vehicle added
|
2020-02-05 15:15:23 +01:00 |
victim
|
Object Victim - Extended requiredOneof
|
2018-12-21 12:27:11 +01:00 |
virustotal-graph
|
new: [virustotal-graph] VirusTotal graph object added
|
2019-12-03 07:39:28 +01:00 |
virustotal-report
|
fix: [virustotal] corrected typo in category
|
2019-08-08 14:01:09 +02:00 |
vulnerability
|
…
|
|
weakness
|
fix: JQed all the things
|
2019-08-01 15:50:29 +02:00 |
whois
|
…
|
|
x509
|
chg: [x509, crypto-material] several changes:
|
2019-10-31 10:09:40 +01:00 |
yabin
|
…
|
|
yara
|
chg: [yara] add a yara-rule-name field which can be optional or the only field
|
2019-07-11 22:59:05 +02:00 |