diff --git a/MANIFEST.json b/MANIFEST.json index 7b66e9b..6f4b4c4 100644 --- a/MANIFEST.json +++ b/MANIFEST.json @@ -164,6 +164,11 @@ "description": "Representation of the behavior or modus operandi of cyber adversaries (a.k.a TTP) as normalized in STIX", "name": "stix-ttp", "version": 1 + }, + { + "description" : "Tags for RiskIQ's passivetotal service", + "name" : "passivetotal", + "version" : 1 } ] } diff --git a/passivetotal/machinetag.json b/passivetotal/machinetag.json new file mode 100644 index 0000000..a718f0d --- /dev/null +++ b/passivetotal/machinetag.json @@ -0,0 +1,86 @@ +{ + "namespace" : "passivetotal", + "expanded" : "PassiveTotal", + "description": "Tags from RiskIQ's PassiveTotal service", + "version" : 1, + "predicates": [ + { + "value" : "sinkholed", + "expanded": "Sinkhole Status" + }, + { + "value" : "ever-comprimised", + "expanded" : "Ever Comprimised?" + }, + { + "value" : "class", + "expanded" : "Classification" + }, + { + "value" : "dynamic-dns", + "expanded": "Dynamic DNS" + } + ], + "values" : [ + { + "predicate" : "sinkholed", + "entry" : [ + { + "value" : "yes", + "expanded": "Yes" + }, + { + "value" : "no", + "expanded" : "No" + } + ] + }, + { + "predicate" : "ever-comprimised", + "entry" : [ + { + "value" : "yes", + "expanded": "Yes" + }, + { + "value" : "no", + "expanded" : "No" + } + ] + }, + { + "predicate" : "dynamic-dns", + "entry" : [ + { + "value" : "yes", + "expanded": "Yes" + }, + { + "value" : "no", + "expanded" : "No" + } + ] + }, + { + "predicate" : "class", + "entry" : [ + { + "value" : "malicious", + "expanded" : "Malicious" + }, + { + "value" : "suspicious", + "expanded": "Malicious" + }, + { + "value": "non-malicious", + "expanded": "Non Malicious" + }, + { + "value" : "unknown", + "expanded" : "Unknown" + } + ] + } + ] +}