|Raphaël Vinot a3f7cf8561 fix: Reorder predicates||1 day ago|
|CERT-XLM||2 years ago|
|DFRLab-dichotomies-of-disinformation||1 day ago|
|DML||2 years ago|
|PAP||3 months ago|
|access-method||1 year ago|
|accessnow||1 year ago|
|action-taken||1 year ago|
|admiralty-scale||3 months ago|
|adversary||2 years ago|
|ais-marking||3 months ago|
|analyst-assessment||3 months ago|
|approved-category-of-action||1 year ago|
|binary-class||3 months ago|
|cccs||1 year ago|
|circl||9 months ago|
|coa||3 months ago|
|collaborative-intelligence||5 months ago|
|common-taxonomy||10 months ago|
|copine-scale||3 months ago|
|course-of-action||5 months ago|
|cryptocurrency-threat||1 year ago|
|csirt-americas||7 months ago|
|csirt_case_classification||3 years ago|
|cssa||2 months ago|
|cyber-threat-framework||3 months ago|
|dark-web||6 months ago|
|data-classification||1 year ago|
|dcso-sharing||11 months ago|
|ddos||1 year ago|
|de-vs||4 years ago|
|dhs-ciip-sectors||3 years ago|
|diamond-model||3 months ago|
|dni-ism||2 years ago|
|domain-abuse||2 years ago|
|drugs||10 months ago|
|economical-impact||3 months ago|
|ecsirt||2 years ago|
|enisa||2 years ago|
|estimative-language||3 months ago|
|eu-marketop-and-publicadmin||3 years ago|
|eu-nis-sector-and-subsectors||1 year ago|
|euci||3 months ago|
|europol-event||3 years ago|
|europol-incident||3 years ago|
|event-assessment||1 year ago|
|event-classification||1 year ago|
|exercise||2 months ago|
|failure-mode-in-machine-learning||1 day ago|
|false-positive||3 months ago|
|file-type||1 year ago|
|flesch-reading-ease||3 months ago|
|fpf||1 year ago|
|fr-classif||3 months ago|
|gdpr||1 year ago|
|gea-nz-activities||3 months ago|
|gea-nz-entities||3 months ago|
|gea-nz-motivators||2 months ago|
|gsma-attack-category||1 year ago|
|gsma-fraud||1 year ago|
|gsma-network-technology||1 year ago|
|honeypot-basic||1 year ago|
|ics||5 months ago|
|iep||2 years ago|
|iep2-policy||1 month ago|
|iep2-reference||1 month ago|
|ifx-vetting||3 months ago|
|incident-disposition||3 months ago|
|infoleak||3 months ago|
|information-security-data-source||1 year ago|
|information-security-indicators||3 years ago|
|interception-method||1 year ago|
|iot||3 months ago|
|kill-chain||3 years ago|
|maec-delivery-vectors||1 year ago|
|maec-malware-behavior||1 year ago|
|maec-malware-capabilities||8 months ago|
|maec-malware-obfuscation-methods||1 year ago|
|malware_classification||3 years ago|
|mapping||9 months ago|
|misp||2 months ago|
|monarc-threat||1 year ago|
|ms-caro-malware||3 years ago|
|ms-caro-malware-full||2 years ago|
|mwdb||2 months ago|
|nato||3 months ago|
|nis||1 year ago|
|open_threat||3 years ago|
|osint||3 months ago|
|passivetotal||1 year ago|
|pentest||1 year ago|
|phishing||3 months ago|
|priority-level||3 months ago|
|ransomware||9 months ago|
|retention||3 months ago|
|rsit||7 months ago|
|rt_event_status||3 months ago|
|runtime-packer||2 years ago|
|scrippsco2-fgc||7 months ago|
|scrippsco2-fgi||7 months ago|
|scrippsco2-sampling-stations||7 months ago|
|smart-airports-threats||1 year ago|
|stealth_malware||3 years ago|
|stix-ttp||3 years ago|
|targeted-threat-index||3 months ago|
|threats-to-dns||8 months ago|
|tlp||2 years ago|
|tools||2 months ago|
|tor||2 years ago|
|type||1 year ago|
|use-case-applicability||1 year ago|
|veris||1 year ago|
|vocabulaire-des-probabilites-estimatives||3 months ago|
|workflow||3 months ago|
|.travis.yml||1 month ago|
|LICENSE.md||1 year ago|
|MANIFEST.json||1 week ago|
|README.md||3 months ago|
|jq_all_the_things.sh||1 year ago|
|schema.json||1 year ago|
|schema_mapping.json||2 years ago|
|summary.md||1 month ago|
|validate_all.sh||2 years ago|
MISP Taxonomies is a set of common classification libraries to tag, classify and organise information. Taxonomy allows to express the same vocabulary among a distributed set of users and organisations.
Taxonomies that can be used in MISP (2.4) and other information sharing tool and expressed in Machine Tags (Triple Tags). A machine tag is composed of a namespace (MUST), a predicate (MUST) and an (OPTIONAL) value. Machine tags are often called triple tag due to their format.
The following taxonomies can be used in MISP (as local or distributed tags) or in other tools and software willing to share common taxonomies among security information sharing tools.
The following taxonomies are described:
The Admiralty Scale (also called the NATO System) is used to rank the reliability of a source and the credibility of an information.
An overview and description of the adversary infrastructure.
CIRCL Taxonomy is a simple scheme for incident classification and area topic where the incident took place.
Cyber Kill Chain from Lockheed Martin as described in Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains.
The Cyber Threat Framework was developed by the US Government to enable consistent characterization and categorization of cyber threat events, and to identify trends or changes in the activities of cyber adversaries.
Taxonomy for the handling of protectively marked information in MISP with German (DE) Government classification markings (VS).
DHS critical sectors as described in https://www.dhs.gov/critical-infrastructure-sectors.
The Diamond Model for Intrusion Analysis, a phase-based model developed by Lockheed Martin, aims to help categorise and identify the stage of an attack as described in http://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf.
The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks. It’s designed for organizations who perform intel-driven detection and response and who put an emphasis on having a mature detection program.
Taxonomy to tag domain names used for cybercrime. We suggest to use europol-incident(./europol-incident) to tag abuse-activity.
eCSIRT incident classification Appendix C of the eCSIRT EU project including IntelMQ updates.
ENISA Threat Taxonomy - A tool for structuring threat information as published
Estimative language - including likelihood or probability of event based on the Intelligence Community Directive 203 (ICD 203) (6.2.(a)).
Market operators and public administrations that must comply to some notifications requirements under EU NIS directive.
EU classified information (EUCI) means any information or material designated by a EU security classification, the unauthorised disclosure of which could cause varying degrees of prejudice to the interests of the European Union or of one or more of the Member States as described.
EUROPOL class of incident taxonomy
EUROPOL type of events taxonomy
FIRST CSIRT Case Classification.
Information security indicators have been standardized by the ETSI Industrial Specification Group (ISG) ISI. These indicators provide the basis to switch from a qualitative to a quantitative culture in IT Security Scope of measurements: External and internal threats (attempt and success), user’s deviant behaviours, nonconformities and/or vulnerabilities (software, configuration, behavioural, general security framework).
ISM (Information Security Marking Metadata) V13 as described by DNI.gov.
Malware classification based on a SANS whitepaper about malware.
Marking of Classified and Unclassified materials as described by the North Atlantic Treaty Organization, NATO.
Open Threat Taxonomy v1.1 base on James Tarala of SANS ref.
STIX-TTP exposes a set classification tools that represents the behavior or modus operandi of cyber adversaries as normalized in STIX. TTPs consist of the specific adversary behavior (attack patterns, malware, exploits) exhibited, resources leveraged (tools, infrastructure, personas), information on the victims targeted (who, what or where), relevant ExploitTargets being targeted, intended effects, relevant kill chain phases, handling guidance, source of the TTP information, etc.
The Targeted Threat Index is a metric for assigning an overall threat ranking score to email messages that deliver malware to a victim’s computer. The TTI metric was first introduced at SecTor 2013 by Seth Hardy as part of the talk “RATastrophe: Monitoring a Malware Menagerie” along with Katie Kleemola and Greg Wiseman. More info about TTI.
The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used. It’s a protocol/taxonomy similar to TLP informing the recipients of information what they can do with the received information.
The Traffic Light Protocol - or short: TLP - was designed with the objective to create a favorable classification scheme for sharing sensitive information while keeping the control over its distribution at the same time.
Vocabulary for Event Recording and Incident Sharing is a format created by the VERIS community.
The following taxonomy namespaces are reserved and used internally to MISP.
It is quite easy. Create a JSON file describing your taxonomy as triple tags (e.g. check an existing one like Admiralty Scale), create a directory matching your name space, put your machinetag file in the directory and pull your request. That’s it. Everyone can benefit from your taxonomy and can be automatically enabled in information sharing tools like MISP.
For more information, “Information Sharing and Taxonomies Practical Classification of Threat Indicators using MISP” presentation given to the last MISP training in Luxembourg.
$ cd /var/www/MISP/app/files/taxonomies/ $ mkdir privatetaxonomy $ cd privatetaxonomy $ vi machinetag.json
Create a JSON file describing your taxonomy as triple tags.
Once you are happy with your file go to MISP Web GUI taxonomies/index and update the taxonomies, the newly created taxonomy should be visible, now you need to activate the tags within your taxonomy.
machinetag.py is a parsing tool to dump taxonomies expressed in Machine Tags (Triple Tags) and list all valid tags from a specific taxonomy.
% cd tools % python machinetag.py admiralty-scale:source-reliability="a" admiralty-scale:source-reliability="b" admiralty-scale:source-reliability="c" admiralty-scale:source-reliability="d" admiralty-scale:source-reliability="e" admiralty-scale:source-reliability="f" admiralty-scale:information-credibility="1" admiralty-scale:information-credibility="2" admiralty-scale:information-credibility="3" admiralty-scale:information-credibility="4" admiralty-scale:information-credibility="5" admiralty-scale:information-credibility="6" ...
The MISP taxonomies (JSON files) are dual-licensed under:
~~~~ Copyright © 2015-2019 Alexandre Dulaunoy - email@example.com Copyright © 2015-2019 CIRCL - Computer Incident Response Center Luxembourg Copyright © 2015-2019 Andras Iklody Copyright © 2015-2019 Raphael Vinot Copyright © 2016-2019 Various contributors to MISP Project
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. 2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS “AS IS” AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ~~~~~
If a specific author of a taxonomy wants to license it under a different license, a pull request can be requested.