From 0660d5af3603938fe33f792bfc3000d109c13673 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Fri, 15 Sep 2017 17:28:25 +0200
Subject: [PATCH] New version of objects
---
objects.html | 2915 +-
objects.pdf | 95216 +++++++++++++++++++++++++------------------------
2 files changed, 50535 insertions(+), 47596 deletions(-)
diff --git a/objects.html b/objects.html
index 9468100..42374a4 100755
--- a/objects.html
+++ b/objects.html
@@ -449,6 +449,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
sensor
text
The AIL sensor uuid where the leak was processed and analysed.
--
first-seen
datetime
When the leak has been accessible or seen for the first time.
--
last-seen
datetime
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
--
text
text
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
++
sensor
text
The AIL sensor uuid where the leak was processed and analysed.
++
origin
url
first-seen
datetime
When the leak has been accessible or seen for the first time.
++
cookie-name
-text
cookie
cookie
Name of the cookie (if splitted)
+Full cookie
@@ -661,10 +662,10 @@ cookie is a MISP object available in JSON format at
cookie
cookie
cookie-name
text
Full cookie
+Name of the cookie (if splitted)
@@ -709,26 +710,6 @@ credit-card is a MISP object available in JSON format at
issued
datetime
Initial date of validity or issued date.
--
expiration
datetime
Maximum date of validity
--
comment
comment
cc-number
cc-number
credit-card number as encoded on the card.
--
version
comment
card-security-code
name
text
Card security code as embossed or printed on the card.
+Name of the card owner.
name
expiration
datetime
Maximum date of validity
++
cc-number
cc-number
credit-card number as encoded on the card.
++
issued
datetime
Initial date of validity or issued date.
++
card-security-code
text
Name of the card owner.
+Card security code as embossed or printed on the card.
@@ -817,26 +818,6 @@ ddos is a MISP object available in JSON format at
protocol
text
Protocol used for the attack
--
first-seen
datetime
Beginning of the attack
--
total-pps
counter
total-bps
counter
protocol
text
Bits per second
+Protocol used for the attack
++
last-seen
datetime
End of the attack
++
src-port
port
Port originating the attack
++
text
text
Description of the DDoS
++
dst-port
port
Destination port of the attack
@@ -877,40 +898,20 @@ ddos is a MISP object available in JSON format at
last-seen
first-seen
datetime
End of the attack
+Beginning of the attack
dst-port
port
total-bps
counter
Destination port of the attack
--
text
text
Description of the DDoS
--
src-port
port
Port originating the attack
+Bits per second
@@ -955,16 +956,6 @@ domain|ip is a MISP object available in JSON format at
ip
ip-dst
IP Address
--
domain
domain
first-seen
last-seen
datetime
First time the tuple has been seen
+Last time the tuple has been seen
++
ip
ip-dst
IP Address
@@ -995,10 +996,10 @@ domain|ip is a MISP object available in JSON format at
last-seen
first-seen
datetime
Last time the tuple has been seen
+First time the tuple has been seen
@@ -1043,36 +1044,6 @@ elf is a MISP object available in JSON format at
arch
text
Architecture of the ELF file
--
entrypoint-address
text
Address of the entry point
--
os_abi
text
Header operating system application binary interface (ABI)
--
type
text
os_abi
text
Header operating system application binary interface (ABI)
++
arch
text
Architecture of the ELF file
++
number-sections
counter
entrypoint-address
text
Address of the entry point
++
sha512/256
-sha512/256
sha1
sha1
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -1171,56 +1162,16 @@ elf-section is a MISP object available in JSON format at
sha512
sha512
sha512/256
sha512/256
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (256 bits)
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole section
--
type
text
Type of the section
--
ssdeep
ssdeep
name
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
flag
text
Name of the section
+Flag of the section
@@ -1251,36 +1212,76 @@ elf-section is a MISP object available in JSON format at
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
flag
type
text
Flag of the section
+Type of the section
name
text
Name of the section
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
entropy
float
Entropy of the whole section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
text
text
subject
email-subject
mime-boundary
email-mime-boundary
Subject
+MIME Boundary
header
email-header
x-mailer
email-x-mailer
Full headers
--
reply-to
email-reply-to
Email address the reply will be sent to
--
thread-index
email-thread-index
Identifies a particular conversation thread
--
from-display-name
email-src-display-name
Display name of the sender
--
to-display-name
email-dst-display-name
Display name of the receiver
--
send-date
datetime
Date the email has been sent
--
attachment
email-attachment
Attachment
--
message-id
email-message-id
Message ID
--
to
email-dst
Destination email address
+X-Mailer generally tells the program that was used to draft and send the original email
@@ -1439,20 +1360,100 @@ email is a MISP object available in JSON format at
mime-boundary
email-mime-boundary
attachment
email-attachment
MIME Boundary
+Attachment
x-mailer
email-x-mailer
header
email-header
X-Mailer generally tells the program that was used to draft and send the original email
+Full headers
++
message-id
email-message-id
Message ID
++
thread-index
email-thread-index
Identifies a particular conversation thread
++
send-date
datetime
Date the email has been sent
++
reply-to
email-reply-to
Email address the reply will be sent to
++
subject
email-subject
Subject
++
to-display-name
email-dst-display-name
Display name of the receiver
++
from-display-name
email-src-display-name
Display name of the sender
++
to
email-dst
Destination email address
@@ -1497,40 +1498,10 @@ file is a MISP object available in JSON format at
sha512/256
sha512/256
filename
filename
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
+Filename on disk
@@ -1547,66 +1518,6 @@ file is a MISP object available in JSON format at
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole file
--
malware-sample
malware-sample
The file itself (binary)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
authentihash
authentihash
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
mimetype
text
malware-sample
malware-sample
The file itself (binary)
++
size-in-bytes
size-in-bytes
Size of the file, in bytes
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
entropy
float
Entropy of the whole file
++
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
text
text
filename
filename
sha384
sha384
Filename on disk
+Secure Hash Algorithm 2 (384 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
@@ -1715,56 +1716,6 @@ geolocation is a MISP object available in JSON format at
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
first-seen
datetime
When the location was seen for the first time.
--
region
text
Region.
--
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
--
city
text
City.
--
country
text
longitude
float
last-seen
datetime
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
+When the location was seen for the last time.
@@ -1795,10 +1746,60 @@ geolocation is a MISP object available in JSON format at
last-seen
city
text
City.
++
region
text
Region.
++
first-seen
datetime
When the location was seen for the last time.
+When the location was seen for the first time.
++
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
++
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
@@ -1843,6 +1844,26 @@ http-request is a MISP object available in JSON format at
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
++
uri
uri
Request URI
++
basicauth-password
text
basicauth-user
text
user-agent
user-agent
HTTP Basic Authentication Username
--
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
--
url
url
Full HTTP Request URL
--
proxy-user
text
HTTP Proxy Username
+The user agent string of the user agent
@@ -1913,40 +1904,10 @@ http-request is a MISP object available in JSON format at
uri
uri
Request URI
--
host
hostname
The domain name of the server
--
user-agent
user-agent
The user agent string of the user agent
--
cookie
basicauth-user
text
An HTTP cookie previously sent by the server with Set-Cookie
+HTTP Basic Authentication Username
@@ -1963,6 +1924,16 @@ http-request is a MISP object available in JSON format at
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
++
text
text
proxy-user
text
HTTP Proxy Username
++
host
hostname
The domain name of the server
++
url
url
Full HTTP Request URL
++
ip
-ip-dst
IP Address
--
first-seen
datetime
First time the tuple has been seen
--
last-seen
datetime
dst-port
src-port
port
Destination port
+Source port
@@ -2061,10 +2042,30 @@ ip|port is a MISP object available in JSON format at
src-port
dst-port
port
Source port
+Destination port
++
first-seen
datetime
First time the tuple has been seen
++
ip
ip-dst
IP Address
@@ -2109,16 +2110,6 @@ macho is a MISP object available in JSON format at
name
text
Binary’s name
--
number-sections
counter
entrypoint-address
text
Address of the entry point
++
type
text
name
text
Binary’s name
++
text
text
entrypoint-address
text
Address of the entry point
--
sha512/256
-sha512/256
sha1
sha1
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -2227,46 +2218,16 @@ macho-section is a MISP object available in JSON format at
sha512
sha512
sha512/256
sha512/256
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (256 bits)
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole section
--
ssdeep
ssdeep
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
name
text
sha256
sha256
sha384
sha384
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (384 bits)
sha512/224
sha512/224
md5
md5
Secure Hash Algorithm 2 (224 bits)
+[Insecure] MD5 hash (128 bits)
@@ -2317,6 +2298,26 @@ macho-section is a MISP object available in JSON format at
entropy
float
Entropy of the whole section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
text
text
sensor_id
text
Sensor information where the record was seen
--
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
bailiwick
text
Best estimate of the apex of the zone where this data is authoritative
--
rdata
text
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
zone_time_last
datetime
rrtype
rrname
text
Resource Record type as seen by the passive DNS
+Resource Record name of the queried resource
rrname
sensor_id
text
Resource Record name of the queried resource
+Sensor information where the record was seen
@@ -2465,6 +2426,16 @@ passive-dns is a MISP object available in JSON format at
rrtype
text
Resource Record type as seen by the passive DNS
++
text
text
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
++
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
origin
text
bailiwick
text
Best estimate of the apex of the zone where this data is authoritative
++
impfuzzy
-impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
--
original-filename
filename
OriginalFilename in the resources
--
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
lang-id
text
Lang ID in the resources
--
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
--
file-version
text
imphash
imphash
Hash (md5) calculated from the import table
--
type
text
company-name
text
CompanyName in the resources
--
entrypoint-address
text
Address of the entry point
--
file-description
text
FileDescription in the resources
--
internal-filename
filename
legal-copyright
text
LegalCopyright in the resources
--
product-name
text
ProductName in the resources
--
entrypoint-section-at-position
text
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
++
number-sections
counter
Number of sections
++
product-version
text
file-description
text
FileDescription in the resources
++
imphash
imphash
Hash (md5) calculated from the import table
++
lang-id
text
Lang ID in the resources
++
company-name
text
CompanyName in the resources
++
text
text
number-sections
counter
legal-copyright
text
Number of sections
+LegalCopyright in the resources
original-filename
filename
OriginalFilename in the resources
++
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
++
product-name
text
ProductName in the resources
++
entrypoint-address
text
Address of the entry point
++
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
sha512/256
-sha512/256
sha1
sha1
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -2771,46 +2762,26 @@ pe-section is a MISP object available in JSON format at
sha512
sha512
characteristic
text
Secure Hash Algorithm 2 (512 bits)
+Characteristic of the section
sha1
sha1
sha512/256
sha512/256
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (256 bits)
md5
md5
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole section
--
ssdeep
ssdeep
name
text
sha512/224
sha512/224
Name of the section
--
characteristic
text
Characteristic of the section
+Secure Hash Algorithm 2 (224 bits)
@@ -2851,10 +2812,30 @@ pe-section is a MISP object available in JSON format at
sha512/224
sha512/224
name
text
Secure Hash Algorithm 2 (224 bits)
+Name of the section
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
@@ -2871,6 +2852,26 @@ pe-section is a MISP object available in JSON format at
entropy
float
Entropy of the whole section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
text
text
An person which describes a person or an identity..
++ + | ++person is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +
---|---|---|---|
place-of-birth |
+place-of-birth |
+
+ Place of birth of a natural person. + |
+
+ + |
+
last-name |
+last-name |
+
+ Last name of a natural person. + |
+
+ + |
+
date-of-birth |
+date-of-birth |
+
+ Date of birth of a natural person (in YYYY-MM-DD format). + |
+
+ + |
+
first-name |
+first-name |
+
+ First name of a natural person. + |
+
+ + |
+
redress-number |
+redress-number |
+
+ The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems. + |
+
+ + |
+
gender |
+gender |
+
+ The gender of a natural person. + |
+
+ + |
+
passport-expiration |
+passport-expiration |
+
+ The expiration date of a passport. + |
+
+ + |
+
text |
+text |
+
+ A description of the person or identity. + |
+
+ + |
+
passport-country |
+passport-country |
+
+ The country in which the passport was issued. + |
+
+ + |
+
nationality |
+nationality |
+
+ The nationality of a natural person. + |
+
+ + |
+
passport-number |
+passport-number |
+
+ The passport number of a natural person. + |
+
+ + |
+
middle-name |
+middle-name |
+
+ Middle name of a natural person + |
+
+ + |
+
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
--
msisdn
text
serial-number
gummei
text
Serial Number.
+Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
text
text
A description of the phone.
++
imsi
text
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
--
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
guti
text
text
text
first-seen
datetime
A description of the phone.
+When the phone has been accessible or seen for the first time.
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
++
serial-number
text
Serial Number.
++
create-thread
+refsglobalvar
counter
Amount of calls to CreateThread
+Amount of API calls outside of code section (glob var, dynamic API)
@@ -3077,10 +3236,10 @@ r2graphity is a MISP object available in JSON format at
referenced-strings
counter
ratio-functions
float
Amount of referenced strings
+Ratio: amount of functions per kilobyte of code section
@@ -3097,120 +3256,10 @@ r2graphity is a MISP object available in JSON format at
miss-api
counter
gml
attachment
Amount of API call reference that does not resolve to a function offset
--
r2-commit-version
text
Radare2 commit ID used to generate this object
--
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
--
text
text
Description of the r2graphity object
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
callback-average
counter
Average size of a callback
--
local-references
counter
Amount of API calls inside a code section
--
not-referenced-strings
counter
Amount of not referenced strings
--
callbacks
counter
Amount of callbacks (functions started as thread)
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
callback-largest
counter
Largest callback
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Graph export in G>raph Modelling Language format
@@ -3227,30 +3276,20 @@ r2graphity is a MISP object available in JSON format at
gml
attachment
r2-commit-version
text
Graph export in G>raph Modelling Language format
+Radare2 commit ID used to generate this object
refsglobalvar
local-references
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
+Amount of API calls inside a code section
@@ -3267,6 +3306,46 @@ r2graphity is a MISP object available in JSON format at
get-proc-address
counter
Amount of calls to GetProcAddress
++
callbacks
counter
Amount of callbacks (functions started as thread)
++
callback-average
counter
Average size of a callback
++
callback-largest
counter
Largest callback
++
total-api
counter
referenced-strings
counter
Amount of referenced strings
++
create-thread
counter
Amount of calls to CreateThread
++
text
text
Description of the r2graphity object
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
++
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
not-referenced-strings
counter
Amount of not referenced strings
++
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
++
hive
-reg-hive
name
reg-name
Hive used to store the registry key (file on disk)
+Name of the registry key
++
last-modified
datetime
Last time the registry key has been modified
@@ -3335,6 +3504,16 @@ registry-key is a MISP object available in JSON format at
hive
reg-hive
Hive used to store the registry key (file on disk)
++
data
reg-data
last-modified
datetime
Last time the registry key has been modified
--
name
reg-name
Name of the registry key
--
nickname
-text
router’s nickname.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
document
text
fingerprint
nickname
text
router’s fingerprint.
--
flags
text
list of flag associated with the node.
+router’s nickname.
@@ -3473,10 +3602,20 @@ tor-node is a MISP object available in JSON format at
version_line
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
++
flags
text
versioning information reported by the node.
+list of flag associated with the node.
@@ -3493,20 +3632,10 @@ tor-node is a MISP object available in JSON format at
published
datetime
version
text
router’s publication time. This can be different from first-seen and last-seen.
--
address
ip-src
IP address of the Tor node seen.
+parsed version of tor, this is None if the relay’s using a new versioning scheme.
@@ -3523,15 +3652,45 @@ tor-node is a MISP object available in JSON format at
last-seen
published
datetime
When the Tor node designed by the IP address has been seen for the last time.
+router’s publication time. This can be different from first-seen and last-seen.
version_line
text
versioning information reported by the node.
++
fingerprint
text
router’s fingerprint.
++
address
ip-src
IP address of the Tor node seen.
++
url
+url
Full URL
++
scheme
text
Scheme
++
subdomain
text
credential
text
first-seen
datetime
Credential (username, password)
--
resource_path
text
Path (between hostname:port and query)
+First time this URL has been seen
@@ -3621,16 +3790,6 @@ url is a MISP object available in JSON format at
port
port
Port number
--
host
hostname
first-seen
datetime
First time this URL has been seen
--
domain_without_tld
text
Domain without Top-Level Domain
--
url
url
Full URL
--
domain
domain
Full domain
--
last-seen
datetime
Last time this URL has been seen
--
tld
text
port
port
Port number
++
last-seen
datetime
Last time this URL has been seen
++
text
text
scheme
domain_without_tld
text
Scheme
+Domain without Top-Level Domain
++
credential
text
Credential (username, password)
++
domain
domain
Full domain
++
resource_path
text
Path (between hostname:port and query)
@@ -3759,20 +3918,10 @@ vulnerability is a MISP object available in JSON format at
modified
datetime
text
text
Last modification date
--
published
datetime
Initial publication date
+Description of the vulnerability
@@ -3789,6 +3938,16 @@ vulnerability is a MISP object available in JSON format at
modified
datetime
Last modification date
++
references
link
summary
text
Summary of the vulnerability
++
vulnerable_configuration
text
text
text
published
datetime
Description of the vulnerability
--
summary
text
Summary of the vulnerability
+Initial publication date
@@ -3867,10 +4026,20 @@ whois is a MISP object available in JSON format at
registrant-email
whois-registrant-email
expiration-date
datetime
Registrant email address
+Expiration of the whois entry
++
modification-date
datetime
Last update of the whois entry
@@ -3887,6 +4056,16 @@ whois is a MISP object available in JSON format at
registrant-email
whois-registrant-email
Registrant email address
++
registrant-phone
whois-registrant-phone
expiration-date
datetime
Expiration of the whois entry
--
domain
domain
Domain of the whois entry
--
registar
whois-registar
Registar of the whois entry
--
modification-date
datetime
Last update of the whois entry
--
text
text
domain
domain
Domain of the whois entry
++
registar
whois-registar
Registar of the whois entry
++
subject
-text
Subject of the certificate
--
x509-fingerprint-md5
md5
[Insecure] MD5 hash (128 bits)
--
version
text
Version of the certificate
--
pubkey-info-exponent
text
pubkey-info-size
text
Length of the public key (in bits)
--
x509-fingerprint-sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
serial-number
text
Serial number of the certificate
--
issuer
text
Issuer of the certificate
--
validity-not-after
datetime
Certificate invalid after that date
--
raw-base64
text
Raw certificate base64 encoded
--
pubkey-info-algorithm
text
pubkey-info-modulus
version
text
Modulus of the public key
+Version of the certificate
++
validity-not-after
datetime
Certificate invalid after that date
@@ -4125,10 +4204,50 @@ x509 is a MISP object available in JSON format at
validity-not-before
datetime
pubkey-info-modulus
text
Certificate invalid before that date
+Modulus of the public key
++
issuer
text
Issuer of the certificate
++
x509-fingerprint-md5
md5
[Insecure] MD5 hash (128 bits)
++
serial-number
text
Serial number of the certificate
++
x509-fingerprint-sha256
sha256
Secure Hash Algorithm 2 (256 bits)
subject
text
Subject of the certificate
++
raw-base64
text
Raw certificate base64 encoded
++
pubkey-info-size
text
Length of the public key (in bits)
++
validity-not-before
datetime
Certificate invalid before that date
++
version
+comment
yabin.py and regex.txt version used for the generation of the yara rules.
++
whitelist
comment
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
--
comment
comment