Commit Graph

640 Commits (e0cd87bdc37910dcb079275347fe371309de0bb3)

Author SHA1 Message Date
gallypette f91a15bcec removes parts that belong to the analysis, adds predicates relating to reversing 2017-05-02 16:54:17 +02:00
Alexandre Dulaunoy f9d423643e Fix the asciidoctor admonition reference to have a proper output 2017-04-30 11:32:11 +02:00
Alexandre Dulaunoy d0029b49af machinetag list is now sorted by default 2017-04-30 11:03:19 +02:00
Alexandre Dulaunoy 081be4fcdd A first version of A series of assessment predicates describing the
analyst capabilities to perform analysis or making judgments under a
certain level of uncertainty. These assessment can be assigned by the
analyst him/herself or by another party evaluating the analyst or
the analysis.

This is based on various documents but especially those two documents:

- Psychology of Intelligence Analysis (Richards J. Heuer, Jr.)
- Judgment under Uncertainty: Heuristics and Biases (Amos Tversky; Daniel Kahneman)

The challenge when doing such taxonomy is to describes a human process
into a machine-readable taxonomy. So feedback (via PR or issues)
is more than welcome.
2017-04-19 21:19:32 +02:00
Alexandre Dulaunoy 3ea0aedc16 Merge pull request #61 from FloatingGhost/master
Basic binary taxonomy
2017-04-06 07:48:15 +02:00
Hannah Ward 311f30487c
fix: Typo in readme 2017-04-05 12:09:51 +01:00
Hannah Ward 6ae728cc3d
chg: Added binary-class to README 2017-04-05 12:08:16 +01:00
Hannah Ward ec73ce3ad4
new: Added basic binary file taxonomy.
Fixes #59
2017-04-05 12:00:00 +01:00
Alexandre Dulaunoy 6b783ef9ec Vocabulaire des probabilités estimatives added to index 2017-04-03 19:13:23 +02:00
Alexandre Dulaunoy 7f2c310d37 Merge branch 'master' of github.com:MISP/misp-taxonomies 2017-04-03 19:08:22 +02:00
Alexandre Dulaunoy 6a7d498b10 Vocabulaire des probabilités estimatives added based on the document
from "Service canadien de renseignements criminels".
2017-04-03 19:07:39 +02:00
Raphaël Vinot dbcc46cd0f Merge branch 'master' of github.com:MISP/misp-taxonomies 2017-04-02 22:07:23 +02:00
Raphaël Vinot 8930ad0a2e Make pep8 happy 2017-04-02 22:06:32 +02:00
Andras Iklody 0b02703c40 Typo corrected 2017-03-28 13:35:50 +02:00
Alexandre Dulaunoy 853939605e A first taxonomy covering DDoS attack 2017-03-05 17:02:49 +01:00
Raphaël Vinot 3ae38176b4 Merge pull request #60 from MISP/access
[WIP] Add assessnow taxonomy
2017-03-02 23:17:37 +01:00
Alexandre Dulaunoy dec71fc0cc Clean-up 2017-03-02 22:01:44 +01:00
Alexandre Dulaunoy 4bc5cbaab7 Proposal for blocking module expansion 2017-03-02 22:00:56 +01:00
Raphaël Vinot 136697abcc Add assessnow taxonomy 2017-02-23 15:46:02 +01:00
Raphaël Vinot 1c6ece2ae6 Update schema, fix taxonomies accordingly. 2017-02-13 16:39:06 +01:00
Raphaël Vinot fcde7e1af8 Merge branch 'master' of github.com:MISP/misp-taxonomies 2017-02-13 12:03:15 +01:00
Raphaël Vinot 3099290e4c JQ all the things 2017-02-13 12:02:51 +01:00
Raphaël Vinot 94290cfaa9 Add schema 2017-02-13 12:01:05 +01:00
Alexandre Dulaunoy 14cf779bf3 Diamond model added to the README and MANIFEST 2017-01-29 14:34:42 +01:00
Alexandre Dulaunoy a3e31c92c2 Merge pull request #58 from FloatingGhost/master
Update machinetag to allow running from any directory
2017-01-20 10:45:59 +01:00
Hannah Ward 2ef7392555
Update machinetag to allow running from any directory 2017-01-20 09:35:28 +00:00
Alexandre Dulaunoy f65e0a9b6e Merge pull request #57 from gbossert/killchain-weaponization
Typo fix: replaces weaponiSation by weaponiZation
2017-01-09 13:28:18 +01:00
Georges Bossert 2b47a71110 Upgrade version number from 1 to 2 in cyber killchain taxo. 2017-01-09 13:25:55 +01:00
Georges Bossert 8c5096b8d3 Typo fix: replaces weaponiSation by weaponiZation
The official term (see. http://www.lockheedmartin.com/us/what-we-do/aerospace-defense/cyber/cyber-kill-chain.html) relies on the American/Oxford
spelling.
2017-01-09 13:21:14 +01:00
Alexandre Dulaunoy 4e284c267d
MANIFEST updated 2017-01-08 15:40:38 +01:00
Alexandre Dulaunoy efd30b3e71
source-code-repository as source added 2017-01-08 15:38:49 +01:00
Alexandre Dulaunoy 178faf2adc Merge pull request #56 from FloatingGhost/master
Added passivetotal tags for #30.
2017-01-04 19:16:37 +01:00
Hannah Ward 160d223a93
Restored manifest to have the right entries 2017-01-04 17:06:28 +00:00
Alexandre Dulaunoy ebc5e2ecfe MANIFEST file version updated 2017-01-04 18:04:47 +01:00
Hannah Ward 0f1cc819b8
Added basic PassiveTotal tags, updated MANIFEST 2017-01-04 17:03:54 +00:00
Andras Iklody 0e320249de Merge pull request #55 from gbossert/stix-ttp
Registers stix-ttp taxonomy in MANIFEST.json.
2017-01-04 16:20:08 +01:00
Georges Bossert cb3d63215b Registers stix-ttp taxonomy in MANIFEST.json. 2017-01-04 16:09:44 +01:00
Andras Iklody b4dd6c0c85 Merge pull request #54 from gbossert/stix-ttp
Introducing STIX-TTP Taxonomy
2017-01-04 15:51:48 +01:00
Georges Bossert 5ca99f3505 Introducing STIX-TTP Taxonomy
The STIX-TTP taxonomy follows the STIX model to handle the classification of event TTPs.
This version covers both Victim Trageting by Sector and Victim Targeting by Information Type.
2017-01-04 15:44:44 +01:00
Alexandre Dulaunoy 40d96b6f2d OSINT updated 2016-12-19 17:14:54 +01:00
Alexandre Dulaunoy 766b5239cb microblog-post added in the type OSINT source 2016-12-19 17:14:10 +01:00
Alexandre Dulaunoy 53b0201e9c Default branch of MISP changed - so raw path images too... 2016-12-18 14:14:10 +01:00
Alexandre Dulaunoy aed7e1ea50 MANIFEST updated to add TTI 2016-12-18 13:10:42 +01:00
Alexandre Dulaunoy a286c23d98 Typo fixed 2016-12-18 13:04:52 +01:00
Alexandre Dulaunoy f79edc8c1b TTI added 2016-12-18 13:03:42 +01:00
Alexandre Dulaunoy 51379e011a targeted-threat-index taxonomy added
The Targeted Threat Index is a metric for assigning an overall threat
ranking score to email messages that deliver malware to a victim’s
computer. The TTI metric was first introduced at SecTor 2013 by Seth
Hardy as part of the talk “RATastrophe: Monitoring a Malware Menagerie”
along with Katie Kleemola and Greg Wiseman.

ref: https://citizenlab.org/2013/10/targeted-threat-index/
2016-12-18 12:55:55 +01:00
Alexandre Dulaunoy b8e1584711 Galaxy removed 2016-12-08 17:00:53 +01:00
Alexandre Dulaunoy e9ae20f312 MISP galaxy removed as included by default via galaxy
https://github.com/MISP/MISP/issues/1731#issuecomment-265766291
2016-12-08 16:59:23 +01:00
Alexandre Dulaunoy 1d957da224 Reference added to the diamond model taxonomy 2016-12-07 06:58:39 +01:00
Alexandre Dulaunoy fe78b3e4a3 Merge branch 'master' of github.com:MISP/misp-taxonomies 2016-12-07 06:57:49 +01:00