misp-objects/objects
Alexandre Dulaunoy d2606f6688
chg: [ja3s] updated
2021-11-14 22:38:47 +01:00
..
ail-leak
ais-info
android-app
android-permission
annotation
anonymisation
asn
attack-pattern
authentication-failure-report
authenticode-signerinfo chg: Update objects to match lief output for authenticode 2021-01-19 15:38:31 +01:00
av-signature
bank-account
bgp-hijack
bgp-ranking
blog
boleto
btc-transaction
btc-wallet
cap-alert
cap-info chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
cap-resource
coin-address
command
command-line
cookie
cortex
cortex-taxonomy chg: [cortex-taxonomy] sort attributes 2020-07-02 13:29:32 +02:00
course-of-action
covid19-csse-daily-report chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
covid19-dxy-live-city chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
covid19-dxy-live-province
cowrie
cpe-asset chg: Using the actual attribute type for cpe and weakness instead of text 2020-10-22 22:11:50 +02:00
credential
credit-card
crypto-material chg: [crypto-material] add a public field for public cryptographic materials 2020-12-30 14:21:37 +01:00
cytomic-orion-file
cytomic-orion-machine
dark-pattern-item
ddos chg: [ddos] fix newline 2021-05-27 16:25:52 +02:00
device chg: [device] ui-priority added 2021-10-25 16:05:04 +02:00
diameter-attack
dkim fix: [dkim] clean-up 2021-02-25 07:25:09 +01:00
dns-record
domain-crawled
domain-ip chg: [domain-ip] newline fix 2021-09-11 07:53:21 +02:00
edr-report Ran jq_all_the_things.sh 2021-10-06 20:13:39 +02:00
elf
elf-section
email add: [email] Added display name attribute for CC and BCC 2021-10-25 12:00:25 +02:00
employee
exploit-poc chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
facebook-account
facebook-group
facebook-page
facebook-post
facial-composite
fail2ban
favicon chg: [favicon] jq all the things 2020-12-27 16:21:09 +01:00
file chg: can have mutliple text attributes 2020-11-25 16:17:54 +01:00
forensic-case chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
forensic-evidence
forged-document
ftm-Airplane new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-Assessment new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-Asset
ftm-Associate
ftm-Audio
ftm-BankAccount
ftm-Call
ftm-Company
ftm-Contract
ftm-ContractAward new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-CourtCase new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-CourtCaseParty
ftm-Debt
ftm-Directorship
ftm-Document
ftm-Documentation
ftm-EconomicActivity new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-Email
ftm-Event
ftm-Family
ftm-Folder
ftm-HyperText
ftm-Image
ftm-Land
ftm-LegalEntity
ftm-License
ftm-Membership new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-Message
ftm-Organization
ftm-Ownership
ftm-Package
ftm-Page
ftm-Pages
ftm-Passport
ftm-Payment
ftm-Person
ftm-PlainText new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-PublicBody
ftm-RealEstate
ftm-Representation
ftm-Row
ftm-Sanction
ftm-Succession
ftm-Table
ftm-TaxRoll
ftm-UnknownLink
ftm-UserAccount new: Objects and relations for FollowTheMoney 2020-05-05 11:02:53 +02:00
ftm-Vehicle
ftm-Vessel
ftm-Video
ftm-Workbook
geolocation chg: [geolocation] countrycode added as requested for the VarIOT. 2021-10-25 15:35:23 +02:00
git-vuln-finder new: Preliminary version of git-vuln-finder object template 2020-05-26 12:31:45 +02:00
github-user
gitlab-user chg: [gitlab-user] because -r is important 2020-10-07 09:20:54 +02:00
gtp-attack
hashlookup chg: [hashlookup] add KnownMalicious field in hashlookup record 2021-09-24 15:33:53 +02:00
http-request
ilr-impact
ilr-notification-incident
image
impersonation
imsi-catcher chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
instant-message
instant-message-group
intel471-vulnerability-intelligence Addition of Intel 471 vulnerability intelligence object 2020-09-23 13:20:33 +01:00
intelmq_event
intelmq_report
internal-reference
interpol-notice
iot-device chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
iot-firmware
ip-api-address
ip-port
irc
ja3
ja3s chg: [ja3s] updated 2021-11-14 22:38:47 +01:00
jarm chg: [jarm] jq all the things 2021-01-05 14:49:34 +01:00
keybase-account
leaked-document
legal-entity
lnk
macho
macho-section
mactime-timeline-analysis
malware-config
meme-image
microblog
mutex
narrative
netflow
network-connection
network-profile chg: [network-element] jq 2021-02-24 06:48:10 +01:00
network-socket fix: [network-socket] Typo 2021-05-06 15:42:03 +02:00
news-agency
news-media chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
open-data-security new: [open-data-security] new object template based on open data 2021-05-17 15:55:23 +02:00
organization
original-imported-file
paloalto-threat-event chg: [paloalto-threat-event] fix newline 2021-05-28 23:07:49 +02:00
parler-account
parler-comment
parler-post chg: [dev] add Parler app objects 2020-07-05 22:03:16 -04:00
passive-dns chg: [passive-dns] jq 2021-05-03 07:20:51 +02:00
passive-dns-dnsdbflex fix: [passive-dns-dnsdbflex] newline 2021-05-26 14:12:10 +02:00
passive-ssh chg: [passive-ssh] newlines disaster 2021-10-26 14:03:24 +02:00
paste Typo and version number correction + adding a field in twitter-post 2020-12-14 23:01:12 +01:00
pcap-metadata
pe chg: Update objects to match lief output for authenticode 2021-01-19 15:38:31 +01:00
pe-section chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
person chg: [person] full-name attribute type added + expanding object person with full-name 2021-03-03 07:41:16 +01:00
pgp-meta chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
phishing chg: [phishing] newline 2021-05-11 15:44:35 +02:00
phishing-kit fix: Normalised object relations of the phishing objects 2020-09-03 14:12:05 +02:00
phone
postal-address new: postal address object 2021-11-03 22:00:49 +01:00
process chg: [process] remove ambiguity between user-creator and current user running the process 2021-09-14 08:35:02 +02:00
publication
python-etvx-event-log
r2graphity
reddit-account
reddit-comment
reddit-post
reddit-subreddit
regexp chg: [regexp] fixed 2021-02-19 21:56:35 +01:00
registry-key chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-NTUser
regripper-sam-hive-single-user chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-sam-hive-user-group
regripper-software-hive-BHO
regripper-software-hive-appInit-DLLS
regripper-software-hive-application-paths chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-software-hive-applications-installed
regripper-software-hive-command-shell
regripper-software-hive-software-run chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-software-hive-userprofile-winlogon chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-software-hive-windows-general-info
regripper-system-hive-firewall-configuration chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-system-hive-general-configuration chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-system-hive-network-information chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
regripper-system-hive-services-drivers chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
report chg: [report] disable correlation on report type 2021-11-02 09:06:18 +01:00
research-scanner
rogue-dns
rtir
sandbox-report
sb-signature
scheduled-event
scrippsco2-c13-daily
scrippsco2-c13-monthly
scrippsco2-co2-daily
scrippsco2-co2-monthly
scrippsco2-o18-daily
scrippsco2-o18-monthly
script
security-playbook chg: [security-playbook] updated 2021-10-05 15:28:26 +02:00
shell-commands chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
shodan-report chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
short-message-service
shortened-link chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
social-media-group
splunk fix: [splunk] fixed 2021-02-15 15:10:20 +01:00
ss7-attack chg: [ss7-attack] order and newline 2021-09-04 10:19:25 +02:00
ssh-authorized-keys
stix2-pattern fix: [stix2-pattern] disable correlation on version 2021-04-27 05:57:52 +02:00
submarine chg: [submarine] fixes and list of types added 2021-11-12 08:39:35 +01:00
suricata
target-system chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
telegram-account chg: [telegram-account] required attributes 2021-01-26 11:39:22 +01:00
threatgrid-report
timecode
timesketch-timeline
timesketch_message
timestamp
tor-hiddenservice
tor-node
tracking-id chg: [dev] update tracking-id to disable correlation on id description. minor changes to attribute descriptions. 2020-05-28 15:19:27 -04:00
transaction
translation
trustar_report chg: [trustar_report] Updated to add "THREAT_ACTOR" 2021-01-05 09:30:28 +01:00
tsk-chats
tsk-web-bookmark
tsk-web-cookie
tsk-web-downloads
tsk-web-history
tsk-web-search-query chg: [tsk-web-search-query] jq all the things 2021-07-25 09:11:42 +02:00
twitter-account
twitter-list
twitter-post chg: [twitter-post] jq 2020-12-20 10:52:40 +01:00
url chg: [url] jq all the things 2021-02-02 11:57:41 +01:00
user-account fix: [user-account] replace the unclear text in description 2021-09-14 08:31:01 +02:00
vehicle
victim
virustotal-graph chg: Sort all the entries in the templates by default 2020-04-26 02:13:18 +02:00
virustotal-report fix: keys order in VT object 2021-02-02 15:31:00 +01:00
vulnerability chg: [vulnerability] fixed 2020-10-15 22:49:29 +02:00
weakness chg: Using the actual attribute type for cpe and weakness instead of text 2020-10-22 22:11:50 +02:00
whois
windows-service new: [windows-service] windows-service object added 2021-02-13 17:01:44 +01:00
x509
yabin
yara chg: [yara] disable correlations on some fields 2020-12-30 14:46:04 +01:00
youtube-channel
youtube-comment
youtube-playlist
youtube-video