From 0afc6088aba7bbed3d977c43fb88a90c5f329ae0 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Fri, 1 Dec 2017 14:29:41 +0100
Subject: [PATCH] taxonomies updated
---
taxonomies.html | 261 +-
taxonomies.pdf | 95374 +++++++++++++++++++++++-----------------------
2 files changed, 48436 insertions(+), 47199 deletions(-)
diff --git a/taxonomies.html b/taxonomies.html
index d3e1631..005eabd 100755
--- a/taxonomies.html
+++ b/taxonomies.html
@@ -1209,24 +1209,36 @@ admiralty-scale namespace available in JSON format at
Completely reliable Associated numerical value="100" Usually reliable Associated numerical value="75" Fairly reliable Associated numerical value="50" Not usually reliable Associated numerical value="25" Confirmed by other sources Associated numerical value="100" Probably true Associated numerical value="75" Possibly true Associated numerical value="50" Doubtful Associated numerical value="25" Less than 1 year Associated numerical value="1" Between 1 and 5 years Associated numerical value="2" Between 5 and 10 years Associated numerical value="3" Between 10 and 20 years Associated numerical value="4" More than 20 years Associated numerical value="5" Less than 1 year Associated numerical value="1" Between 1 and 5 years Associated numerical value="2" Between 5 and 10 years Associated numerical value="3" Between 10 and 20 years Associated numerical value="4" More than 20 years Associated numerical value="5" Less than 1 year Associated numerical value="1" Between 1 and 5 years Associated numerical value="2" Between 5 and 10 years Associated numerical value="3" Between 10 and 20 years Associated numerical value="4" More than 20 years Associated numerical value="5" Less than 1 year Associated numerical value="1" Between 1 and 5 years Associated numerical value="2" Between 5 and 10 years Associated numerical value="3" Between 10 and 20 years Associated numerical value="4" More than 20 years Associated numerical value="5" Very unlikely - highly improbable - 05-20% Associated numerical value="5" Unlikely - improbable (improbably) - 20-45% Associated numerical value="20" Roughly even change - roughly even odds - 45-55% Associated numerical value="45" Likely - probable (probably) - 55-80% Associated numerical value="55" Very likely - highly probable - 80-95% Associated numerical value="80" Almost certain(ly) - nearly certain - 95-99% Associated numerical value="95" French gov information classification system Completely confident Associated numerical value="100" Usually confident Associated numerical value="75" Fairly confident Associated numerical value="50" Rarely confident Associated numerical value="25" Low risk which can include mass-malware. (CEUS threat level) Associated numerical value="25" Medium risk which can include targeted attacks (e.g. APT). (CEUS threat level) Associated numerical value="50" High risk which can include highly sophisticated attacks or 0-day attack. (CEUS threat level) Associated numerical value="100" 100% Certainty Certainty (probability equals 1 - 100%) 100% Certainty Certainty Associated numerical value="100" 93% Almost certain Almost certain (probability equals 0.93 - 93%) 93% Almost certain Almost certain Associated numerical value="93" 75% Probable Probable (probability equals 0.75 - 75%) 75% Probable Probable Associated numerical value="75" 50% Chances about even Chances about even (probability equals 0.50 - 50%) 50% Chances about even Chances about even Associated numerical value="50" 30% Probably not Probably not (probability equals 0.30 - 30%) 30% Probably not Probably not Associated numerical value="30" 7% Almost certainly not Almost certainly not (probability equals 0.07 - 7%) 7% Almost certainly not Almost certainly not Associated numerical value="7" 0% Impossibility Impossibility (probability equals 0 - 0%) 0% Impossibility Impossibility Targeted but not customized. Sent with a message that is obviously false with little to no validation required. Associated numerical value="1" Targeted and poorly customized. Content is generally relevant to the target. May look questionable. Associated numerical value="2" Targeted and customized. May use a real person/organization or content to convince the target the message is legitimate. Content is specifically relevant to the target and looks legitimate. Associated numerical value="3" Targeted and well-customized. Uses a real person/organization and content to convince the target the message is legitimate. Probably directly addressing the recipient. Content is specifically relevant to the target, looks legitimate, and can be externally referenced (e.g. by a website). May be sent from a hacked account. Associated numerical value="4" Targeted and highly customized using sensitive data. Individually targeted and customized, likely using inside/sensitive information that is directly relevant to the target. Associated numerical value="5" The sample contains no code protection such as packing, obfuscation (e.g. simple rotation of C2 names or other interesting strings), or anti-reversing tricks. Associated numerical value="1" The sample contains a simple method of protection, such as one of the following: code protection using publicly available tools where the reverse method is available, such as UPX packing; simple anti-reversing techniques such as not using import tables, or a call to IsDebuggerPresent(); self-disabling in the presence of AV software. Associated numerical value="1.25" The sample contains multiple minor code protection techniques (anti-reversing tricks, packing, VM / reversing tools detection) that require some low-level knowledge. This level includes malware where code that contains the core functionality of the program is decrypted only in memory. Associated numerical value="1.5" The sample contains minor code protection techniques along with at least one advanced protection method such as rootkit functionality or a custom virtualized packer. Associated numerical value="1.75" The sample contains multiple advanced protection techniques, e.g. rootkit capability, virtualized packer, multiple anti-reversing techniques, and is clearly designed by a professional software engineering team. Associated numerical value="2"admiralty-scale:source-reliability="b"
admiralty-scale:source-reliability="c"
admiralty-scale:source-reliability="d"
admiralty-scale:source-reliability="e"
@@ -1248,24 +1260,36 @@ admiralty-scale namespace available in JSON format at
admiralty-scale:information-credibility="2"
admiralty-scale:information-credibility="3"
admiralty-scale:information-credibility="4"
admiralty-scale:information-credibility="5"
@@ -1536,30 +1560,45 @@ analyst-assessment namespace available in JSON format at
analyst-assessment:experience="between-1-and-5-years"
analyst-assessment:experience="between-5-and-10-years"
analyst-assessment:experience="between-10-and-20-years"
analyst-assessment:experience="more-than-20-years"
analyst-assessment:binary-reversing-experience="between-1-and-5-years"
analyst-assessment:binary-reversing-experience="between-5-and-10-years"
analyst-assessment:binary-reversing-experience="between-10-and-20-years"
analyst-assessment:binary-reversing-experience="more-than-20-years"
analyst-assessment:web-experience="between-1-and-5-years"
analyst-assessment:web-experience="between-5-and-10-years"
analyst-assessment:web-experience="between-10-and-20-years"
analyst-assessment:web-experience="more-than-20-years"
analyst-assessment:crypto-experience="between-1-and-5-years"
analyst-assessment:crypto-experience="between-5-and-10-years"
analyst-assessment:crypto-experience="between-10-and-20-years"
analyst-assessment:crypto-experience="more-than-20-years"
estimative-language:likelihood-probability="unlikely"
estimative-language:likelihood-probability="roughly-even-chance"
estimative-language:likelihood-probability="likely"
estimative-language:likelihood-probability="very-likely"
estimative-language:likelihood-probability="almost-certain"
+
+
+
+
+
+
+
+Exclusive flag set which means the values or predicate below must be set exclusively.
+
+classifiees-defense
+
+
+
+
+
+
+
+
+Exclusive flag set which means the values or predicate below must be set exclusively.
+
+fr-classif:classifiees-defense="TRES_SECRET_DEFENSE"
non-classifiees-defense
+
+
+
+
+
+
+
+
+Exclusive flag set which means the values or predicate below must be set exclusively.
+
+fr-classif:non-classifiees-defense="SECRET"
non-classifiees
+
+
+
+
+
+
+
+
+Exclusive flag set which means the values or predicate below must be set exclusively.
+
+fr-classif:non-classifiees="NON-CLASSIFIEES"
misp:confidence-level="usually-confident"
misp:confidence-level="fairly-confident"
misp:confidence-level="rarely-confident"
misp:confidence-level="unconfident"
@@ -8194,6 +8356,9 @@ misp namespace available in JSON format at
misp:threat-level="medium-risk"
@@ -8203,6 +8368,9 @@ misp namespace available in JSON format at
misp:threat-level="high-risk"
@@ -8212,6 +8380,9 @@ misp namespace available in JSON format at
osint:certainty="100"
osint:certainty="93"
osint:certainty="75"
osint:certainty="50"
osint:certainty="30"
osint:certainty="7"
osint:certainty="0"
targeted-threat-index:targeting-sophistication-base-value="targeted-and-poorly-customized"
targeted-threat-index:targeting-sophistication-base-value="targeted-and-customized"
targeted-threat-index:targeting-sophistication-base-value="targeted-and-well-customized"
targeted-threat-index:targeting-sophistication-base-value="targeted-and-highly-customized-using-sensitive-data"
targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-a-simple-method-of-protection"
targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-multiple-minor-code-protection-techniques"
targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-minor-code-protection-techniques-plus-one-advanced"
targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-multiple-advanced-protection-techniques"
+ + | ++Exclusive flag set which means the values or predicate below must be set exclusively. + | +