Other+
Public website
+Credential
Pastie-like website
+Credit card
Electronic forum
+Mailing-list
+Phone number
Source code repository
+API key
Automatic collection including honeypots, spamtramps or equivalent technologies
+Google API key
Manual analysis or investigation where detection took place
+AWS key
Unknown
+Private key at large
Other source not specified in this list
+Encrypted private key at large
+Private SSH key
+Private state key
+VPN static key
+PGP message
+PGP private key
+Certificate
+RSA private key
+DSA private key
+EC private key
+Base64
+Bitcoin address
+Bitcoin private key
+CVE
+Onion link
+SQL injection
Credential
+False positive
Credit card
+False negative
True positive
Phone number
+True negative
+Public website
API key
+Pastie-like website
Google API key
+Electronic forum
AWS key
+Mailing-list
Private key at large
+Source code repository
Encrypted private key at large
+Automatic collection including honeypots, spamtramps or equivalent technologies
Private SSH key
+Manual analysis or investigation where detection took place
Private state key
+Unknown
VPN static key
-PGP message
-PGP private key
-Certificate
-RSA private key
-DSA private key
-EC private key
-Base64
-Bitcoin address
-Bitcoin private key
-CVE
-Onion link
-SQL injection
+Other source not specified in this list
False positive
-False negative
-True positive
-True negative
-No confidence
+Low confidence
Low confidence
+No confidence
+Difficult and expensive
+Simple and cheap
+Something in-between
+Unknown
+External - disclosed by threat agent (e.g., public brag, private blackmail)
+External - security audit or scan
+External - reported by customer or partner affected by the incident
+External - Emergency response team
+External - Found documents
+External - fraud detection (e.g., CPP)
+External - Notified while investigating another incident
+Internal - notified by law enforcement or government agency
+External - managed security event monitoring service
+Discovery method was external and known but not listed
+External - Report of suspicious traffic
+External - unknown
+Discovered by person unaffiliated with victim or threat actor
+Internal - host IDS or file integrity monitoring
+Any routine maintenance, testing or review of it assets. (Includes inspect of assets, vulnerability scans, etc.)
+Internal - All network-based security tool detection (including IPS, IDS, firewalls and other network-based security tools)
+Internal - antivirus alert
+Internal - employee discovered evidence of a break in
+Internal - Data loss prevention software
+Internal - financial audit and reconciliation process
+Internal - fraud detection mechanism
+Internal - discovered while responding to another (separate) incident
+Internal - Health and welfare monitoring of assets such as utilization, uptime, and SNMP alerts
+Internal - log review process or SIEM
+Discovery method was internal and known but not listed
+Internal - reported by employee who saw something odd
+Internal - physical security system alarm
+Internal - unknown
+Other
+Partner - Notified by antivirus company but not through AV product
+Partner - Audit performed by a partner organization
+Partner - notified while investigating another incident
+Partner - Reported by a monitoring service
+Discovery method was partner and known but not listed
+Partner - Unknown
+Unknown
+Yes - Confirmed
+False positive (response triggered, but no incident)
+Near miss (actions did not compromise asset)
+Suspected
Targeted: victim chosen as target then actor determined what weaknesses could be exploited
-Not applicable
@@ -16830,6 +17097,12 @@ veris namespace available in JSON format at +Targeted: victim chosen as target then actor determined what weaknesses could be exploited
+Simple and cheap
-Unknown
-Something in-between
-Difficult and expensive
-Suspected
-Yes - Confirmed
-Near miss (actions did not compromise asset)
-False positive (response triggered, but no incident)
-DZD - Algerian Dinar
-NAD - Namibia Dollar
-GHS - Ghana Cedi
-EGP - Egyptian Pound
-BGN - Bulgarian Lev
-PAB - Balboa
-BOB - Boliviano
-DKK - Danish Krone
-BWP - Pula
-LBP - Lebanese Pound
-TZS - Tanzanian Shilling
-VND - Dong
-AOA - Kwanza
-KHR - Riel
-MYR - Malaysian Ringgit
-KYD - Cayman Islands Dollar
-LYD - Libyan Dinar
-UAH - Hryvnia
-JOD - Jordanian Dinar
-AWG - Aruban Florin
-SAR - Saudi Riyal
-EUR - Euro
-HKD - Hong Kong Dollar
-CHF - Swiss Franc
-GIP - Gibraltar Pound
-BYR - Belarussian Ruble
-ALL - Lek
-MRO - Ouguiya
-HRK - Croatian Kuna
-DJF - Djibouti Franc
-SZL - Lilangeni
-THB - Baht
-XAF - CFA Franc BEAC
-BND - Brunei Dollar
-ISK - Iceland Krona
-UYU - Peso Uruguayo
-NIO - Cordoba Oro
-LAK - Kip
-SYP - Syrian Pound
-MAD - Moroccan Dirham
-MZN - Mozambique Metical
-PHP - Philippine Peso
-ZAR - South African Rand
-NPR - Nepalese Rupee
-NGN - Naira
-ZWD - Zimbabwean Dollar A/06
-CRC - Costa Rican Colon
-AED - UAE Dirham
-GBP - Pound Sterling
-MWK - Kwacha
-LKR - Sri Lanka Rupee
-PKR - Pakistan Rupee
-HUF - Forint
-BMD - Bermudian Dollar
-LSL - Loti
-MNT - Tugrik
-AMD - Armenian Dram
-UGX - Uganda Shilling
-QAR - Qatari Rial
-XDR - SDR (Special Drawing Right)
-JMD - Jamaican Dollar
-GEL - Lari
-SHP - Saint Helena Pound
-AFN - Afghani
-SBD - Solomon Islands Dollar
-KPW - North Korean Won
-TRY - Turkish Lira
-BDT - Taka
-YER - Yemeni Rial
-HTG - Gourde
-XOF - CFA Franc BCEAO
-MGA - Malagasy Ariary
-ANG - Netherlands Antillean Guilder
-LRD - Liberian Dollar
-RWF - Rwanda Franc
-NOK - Norwegian Krone
-MOP - Pataca
-INR - Indian Rupee
-MXN - Mexican Peso
-CZK - Czech Koruna
-TJS - Somoni
-TWD - New Taiwan Dollar
-BTN - Ngultrum
-COP - Colombian Peso
-TMT - Turkmenistan New Manat
-MUR - Mauritius Rupee
-IDR - Rupiah
-HNL - Lempira
-XPF - CFP Franc
-FJD - Fiji Dollar
-ETB - Ethiopian Birr
-PEN - Nuevo Sol
-BZD - Belize Dollar
-ILS - New Israeli Sheqel
-DOP - Dominican Peso
-GGP - Guernsey pound
-MDL - Moldovan Leu
-BSD - Bahamian Dollar
-SPL - Seborga Luigino
-SEK - Swedish Krona
-ZMK - Zambian Kwacha
-JEP - Jersey pound
-AUD - Australian Dollar
-SRD - Surinam Dollar
-CUP - Cuban Peso
-BBD - Barbados Dollar
-KMF - Comoro Franc
-KRW - South Korean Won
-GMD - Dalasi
-VEF - Bolivar
-IMP - Isle of Man Pound
-CUC - Peso Convertible
-TVD - Tuvalu Dollar
-CLP - Chilean Peso
-LTL - Lithuanian Litas
-CDF - Congolese Franc
-XCD - East Caribbean Dollar
-KZT - Tenge
-RUB - Russian Ruble
-TTD - Trinidad and Tobago Dollar
-OMR - Rial Omani
-BRL - Brazilian Real
-MMK - Kyat
-PLN - Zloty
-PYG - Guarani
-KES - Kenyan Shilling
-SVC - El Salvador Colon
-MKD - Denar
-AZN - Azerbaijanian Manat
-TOP - Pa’anga
-MVR - Rufiyaa
-VUV - Vatu
-GNF - Guinea Franc
-WST - Tala
-IQD - Iraqi Dinar
-ERN - Nakfa
-BAM - Convertible Mark
-SCR - Seychelles Rupee
-CAD - Canadian Dollar
-CVE - Cape Verde Escudo
-KWD - Kuwaiti Dinar
-BIF - Burundi Franc
-PGK - Kina
-SOS - Somali Shilling
-SGD - Singapore Dollar
-UZS - Uzbekistan Sum
-STD - Dobra
-IRR - Iranian Rial
-CNY - Yuan Renminbi
-SLL - Leone
-TND - Tunisian Dinar
-GYD - Guyana Dollar
-NZD - New Zealand Dollar
-FKP - Falkland Islands Pound
-LVL - Latvian Lats
-USD - US Dollar
-KGS - Som
-ARS - Argentine Peso
-RON - New Romanian Leu
-GTQ - Quetzal
-RSD - Serbian Dinar
-BHD - Bahraini Dinar
-JPY - Yen
-SDG - Sudanese Pound
-Insignificant: Impact absorbed by normal activities
-Catastrophic: A business-ending event (don’t choose this if the victim will continue operations)
-Distracting: Limited "hard costs", but impact felt through having to deal with the incident rather than conducting normal duties
-Damaging: Real and serious effect on the "bottom line" and/or long-term ability to generate revenue
-Unknown
-Painful: Moderate "hard costs", and impact felt through having to deal with the incident rather than conducting normal duties has quantifiable indirect costs
-Not applicable
Internally managed
+Accessibility known but not listed
Ownership known but not listed
-Externally managed
-Unknown
Penetration of another web site on shared device
+Misconfiguration or error by hosting provider
+Lack of security process or procedure by hosting provider
+Hypervisor break-out attack
+It is known no cloud assets were involved
+It is known that a cloud asset was involved and it being a cloud asset did not affect the outcome
+Cloud hosting known but not listed
+Application vulnerability in partner-developed application
+The involvement of cloud assets was not measured
+Elevation of privilege by another customer in shared environment
+Andorra
+United Arab Emirates
+Afghanistan
+Antigua and Barbuda
+Anguilla
+Albania
+Armenia
+Angola
+Antarctica
+Argentina
+American Samoa
+Austria
+Australia
+Aruba
+Aland Islands
+Azerbaijan
+Bosnia and Herzegovina
+Barbados
+Bangladesh
@@ -18195,48 +17346,6 @@ veris namespace available in JSON format at -Bosnia and Herzegovina
-Barbados
-Wallis and Futuna Islands
-Saint-Barthelemy
-Unknown
-Brunei Darussalam
-Bolivia
-Bahrain
@@ -18255,33 +17364,27 @@ veris namespace available in JSON format at -Bhutan
+Saint-Barthelemy
Jamaica
+Bermuda
Bouvet Island
+Brunei Darussalam
Botswana
-Samoa
+Bolivia
Jersey
+Bhutan
+Bouvet Island
+Botswana
Russian Federation
+Canada
Rwanda
+Cocos (Keeling) Islands
Serbia
+Congo, Democratic Republic of the
Timor-Leste
+Central African Republic
Reunion
+Congo
Turkmenistan
+Switzerland
Bermuda
+Cote d’Ivoire
Tajikistan
+Cook Islands
Romania
+Chile
Tokelau
+Cameroon
Guinea-Bissau
+China
Guam
+Colombia
Guatemala
+Costa Rica
South Georgia and the South Sandwich Islands
+Cuba
Greece
+Cape Verde
Equatorial Guinea
+Curacao
Guadeloupe
+Christmas Island
Japan
+Cyprus
Guyana
+Czech Republic
Guernsey
+Germany
French Guiana
+Djibouti
Georgia
+Denmark
Grenada
+Dominica
United Kingdom
+Dominican Republic
Gabon
+Algeria
El Salvador
-Guinea
-Gambia
-Greenland
-Gibraltar
-Ghana
-Oman
-Tunisia
-Jordan
-Croatia
-Haiti
-Hungary
-Hong Kong
-Honduras
-Heard Island and McDonal Islands
-Venezuela (Bolivarian Republic of)
-Puerto Rico
-Palestinian Territory, Occupied
-Palau
-Portugal
-Svalbard and Jan Mayen Islands
-Paraguay
-Iraq
-Panama
-French Polynesia
-Papua New Guinea
-Peru
-Pakistan
-Philippines
-Pitcairn
-Poland
-Saint Pierre and Miquelon
-Zambia
-Western Sahara
+Ecuador
South Africa
-Ecuador
-Italy
-Viet Nam
-Solomon Islands
-Ethiopia
-Somalia
-Zimbabwe
-Saudi Arabia
-Spain
+Western Sahara
Montenegro
+Spain
Moldova, Republic of
-Madagascar
-Saint Martin (French part)
-Morocco
-Monaco
-Uzbekistan
-Myanmar
-Mali
-Macao
-Mongolia
-Marshall Islands
-Macedonia, The former Yugoslav Republic of
-Mauritius
-Malta
-Malawi
-Maldives
-Martinique
-Northern Mariana Islands
-Montserrat
-Mauritania
-Isle of Man
-Uganda
-Tanzania, United Republic of
-Malaysia
-Mexico
-Israel
-France
-British Virgin Islands
-Saint Helena
+Ethiopia
Nicaragua
+France
Netherlands
+Gabon
Norway
+United Kingdom
+Grenada
+Georgia
+French Guiana
+Guernsey
+Ghana
+Gibraltar
+Greenland
+Gambia
+Guinea
+Guadeloupe
+Equatorial Guinea
+Greece
+South Georgia and the South Sandwich Islands
+Guatemala
+Guam
+Guinea-Bissau
+Guyana
+Hong Kong
+Heard Island and McDonal Islands
+Honduras
+Croatia
+Haiti
+Hungary
+Indonesia
+Ireland
+Israel
+Isle of Man
+India
+British Virgin Islands
+Iraq
+Iran (Islamic Republic of)
+Iceland
+Italy
+Jersey
+Jamaica
+Jordan
+Japan
+Kenya
+Kyrgyzstan
+Cambodia
+Kiribati
+Comoros
+Saint Kitts and Nevis
+Korea, Democratic People’s Republic of
+Korea, Republic of
+Kuwait
+Cayman Islands
+Kazakhstan
+Lao People’s Democratic Republic
+Lebanon
+Saint Lucia
+Liechtenstein
+Sri Lanka
+Liberia
+Lesotho
+Lithuania
+Luxembourg
+Latvia
+Libya
+Morocco
+Monaco
+Moldova, Republic of
+Montenegro
+Saint Martin (French part)
+Madagascar
+Marshall Islands
+Macedonia, The former Yugoslav Republic of
+Mali
+Myanmar
+Mongolia
+Macao
+Northern Mariana Islands
+Martinique
+Mauritania
+Montserrat
+Malta
+Mauritius
+Maldives
+Malawi
+Mexico
+Malaysia
+Mozambique
Vanuatu
-New Caledonia
@@ -19017,9 +18198,21 @@ veris namespace available in JSON format at -New Zealand
+Nicaragua
+Netherlands
+Norway
Cook Islands
+New Zealand
Cote d’Ivoire
-Switzerland
-Colombia
-China
-Cameroon
-Chile
-Cocos (Keeling) Islands
-Canada
-Congo
-Central African Republic
-Congo, Democratic Republic of the
-Czech Republic
-Cyprus
-Christmas Island
-Costa Rica
-Curacao
-Cape Verde
-Cuba
-Swaziland
-Syrian Arab Republic
-Sint Maarten (Dutch part)
-Kyrgyzstan
-Kenya
-South Sudan
-Suriname
-Kiribati
-Cambodia
-Saint Kitts and Nevis
-Comoros
-Sao Tome and Principe
-Slovakia
-Korea, Republic of
-Slovenia
-Korea, Democratic People’s Republic of
-Kuwait
-Senegal
-San Marino
-Sierra Leone
-Seychelles
-Kazakhstan
-Cayman Islands
-Singapore
-Sweden
-Sudan
-Dominican Republic
-Dominica
-Djibouti
-Denmark
-British Virgin Islands
-Germany
-Yemen
+Oman
Algeria
+Panama
United States of America
+Peru
Uruguay
+French Polynesia
Mayotte
+Papua New Guinea
United States Minor Outlying Islands
+Philippines
Lebanon
+Pakistan
Saint Lucia
+Poland
Lao People’s Democratic Republic
+Saint Pierre and Miquelon
Tuvalu
+Pitcairn
Taiwan, Province of China
+Puerto Rico
Trinidad and Tobago
+Palestinian Territory, Occupied
Turkey
+Portugal
Sri Lanka
+Palau
Liechtenstein
+Paraguay
Latvia
+Qatar
Tonga
+Reunion
Lithuania
+Romania
Luxembourg
+Serbia
Liberia
+Russian Federation
Lesotho
+Rwanda
Thailand
+Saudi Arabia
+Solomon Islands
+Seychelles
+Sudan
+Sweden
+Singapore
+Saint Helena
+Slovenia
+Svalbard and Jan Mayen Islands
+Slovakia
+Sierra Leone
+San Marino
+Senegal
+Somalia
+Suriname
+South Sudan
+Sao Tome and Principe
+El Salvador
+Sint Maarten (Dutch part)
+Syrian Arab Republic
+Swaziland
+Turks and Caicos Islands
+Chad
Chad
+Thailand
Turks and Caicos Islands
+Tajikistan
Libya
+Tokelau
+Timor-Leste
+Turkmenistan
+Tunisia
+Tonga
+Turkey
+Trinidad and Tobago
+Tuvalu
+Taiwan, Province of China
+Tanzania, United Republic of
+Ukraine
+Uganda
+United States Minor Outlying Islands
+United States of America
+Uruguay
+Uzbekistan
+Unknown
United Arab Emirates
+Venezuela (Bolivarian Republic of)
Andorra
-Antigua and Barbuda
-Afghanistan
-Anguilla
+British Virgin Islands
Iceland
+Viet Nam
Iran (Islamic Republic of)
+Vanuatu
Armenia
+Wallis and Futuna Islands
Albania
+Samoa
Angola
+Yemen
Antarctica
+Mayotte
American Samoa
+South Africa
Argentina
+Zambia
Australia
-Austria
-Aruba
-India
-Aland Islands
-Azerbaijan
-Ireland
-Indonesia
-Ukraine
-Qatar
-Mozambique
-Externally hosted in a shared environment
-Externally hosted in a dedicated environment
-Not applicable
-Internally hosted
-Externally hosted (unsure if dedicated or shared)
-Unknown
-Hosting known but not listed
+Zimbabwe
Unknown
-Managed by 3rd party
@@ -19749,15 +18741,15 @@ veris namespace available in JSON format at -Governance known but not listed
+Isolated internal asset
The victim owns and controls the asset
+Governance known but not listed
Isolated internal asset
-Not applicable
-Internally isolated or restricted environment
-Internally accessible
-Publicly accessible
-Unknown
Accessibility known but not listed
+The victim owns and controls the asset
+Externally hosted (unsure if dedicated or shared)
+Externally hosted in a dedicated environment
+Externally hosted in a shared environment
+Internally hosted
+Not applicable
+Hosting known but not listed
+Unknown
+Externally managed
+Internally managed
+Not applicable
+Ownership known but not listed
+Unknown
Unknown
-Owner known but not listed
-Victim owned
+Employee owned
Employee owned
+Owner known but not listed
Unknown
+Victim owned
+It is known no cloud assets were involved
+AED - UAE Dirham
It is known that a cloud asset was involved and it being a cloud asset did not affect the outcome
+AFN - Afghani
Misconfiguration or error by hosting provider
+ALL - Lek
Elevation of privilege by another customer in shared environment
+AMD - Armenian Dram
The involvement of cloud assets was not measured
+ANG - Netherlands Antillean Guilder
Penetration of another web site on shared device
+AOA - Kwanza
Lack of security process or procedure by hosting provider
+ARS - Argentine Peso
Hypervisor break-out attack
+AUD - Australian Dollar
Cloud hosting known but not listed
+AWG - Aruban Florin
Application vulnerability in partner-developed application
+AZN - Azerbaijanian Manat
+BAM - Convertible Mark
+BBD - Barbados Dollar
+BDT - Taka
+BGN - Bulgarian Lev
+BHD - Bahraini Dinar
+BIF - Burundi Franc
+BMD - Bermudian Dollar
+BND - Brunei Dollar
+BOB - Boliviano
+BRL - Brazilian Real
+BSD - Bahamian Dollar
+BTN - Ngultrum
+BWP - Pula
+BYR - Belarussian Ruble
+BZD - Belize Dollar
+CAD - Canadian Dollar
+CDF - Congolese Franc
+CHF - Swiss Franc
+CLP - Chilean Peso
+CNY - Yuan Renminbi
+COP - Colombian Peso
+CRC - Costa Rican Colon
+CUC - Peso Convertible
+CUP - Cuban Peso
+CVE - Cape Verde Escudo
+CZK - Czech Koruna
+DJF - Djibouti Franc
+DKK - Danish Krone
+DOP - Dominican Peso
+DZD - Algerian Dinar
+EGP - Egyptian Pound
+ERN - Nakfa
+ETB - Ethiopian Birr
+EUR - Euro
+FJD - Fiji Dollar
+FKP - Falkland Islands Pound
+GBP - Pound Sterling
+GEL - Lari
+GGP - Guernsey pound
+GHS - Ghana Cedi
+GIP - Gibraltar Pound
+GMD - Dalasi
+GNF - Guinea Franc
+GTQ - Quetzal
+GYD - Guyana Dollar
+HKD - Hong Kong Dollar
+HNL - Lempira
+HRK - Croatian Kuna
+HTG - Gourde
+HUF - Forint
+IDR - Rupiah
+ILS - New Israeli Sheqel
+IMP - Isle of Man Pound
+INR - Indian Rupee
+IQD - Iraqi Dinar
+IRR - Iranian Rial
+ISK - Iceland Krona
+JEP - Jersey pound
+JMD - Jamaican Dollar
+JOD - Jordanian Dinar
+JPY - Yen
+KES - Kenyan Shilling
+KGS - Som
+KHR - Riel
+KMF - Comoro Franc
+KPW - North Korean Won
+KRW - South Korean Won
+KWD - Kuwaiti Dinar
+KYD - Cayman Islands Dollar
+KZT - Tenge
+LAK - Kip
+LBP - Lebanese Pound
+LKR - Sri Lanka Rupee
+LRD - Liberian Dollar
+LSL - Loti
+LTL - Lithuanian Litas
+LVL - Latvian Lats
+LYD - Libyan Dinar
+MAD - Moroccan Dirham
+MDL - Moldovan Leu
+MGA - Malagasy Ariary
+MKD - Denar
+MMK - Kyat
+MNT - Tugrik
+MOP - Pataca
+MRO - Ouguiya
+MUR - Mauritius Rupee
+MVR - Rufiyaa
+MWK - Kwacha
+MXN - Mexican Peso
+MYR - Malaysian Ringgit
+MZN - Mozambique Metical
+NAD - Namibia Dollar
+NGN - Naira
+NIO - Cordoba Oro
+NOK - Norwegian Krone
+NPR - Nepalese Rupee
+NZD - New Zealand Dollar
+OMR - Rial Omani
+PAB - Balboa
+PEN - Nuevo Sol
+PGK - Kina
+PHP - Philippine Peso
+PKR - Pakistan Rupee
+PLN - Zloty
+PYG - Guarani
+QAR - Qatari Rial
+RON - New Romanian Leu
+RSD - Serbian Dinar
+RUB - Russian Ruble
+RWF - Rwanda Franc
+SAR - Saudi Riyal
+SBD - Solomon Islands Dollar
+SCR - Seychelles Rupee
+SDG - Sudanese Pound
+SEK - Swedish Krona
+SGD - Singapore Dollar
+SHP - Saint Helena Pound
+SLL - Leone
+SOS - Somali Shilling
+SPL - Seborga Luigino
+SRD - Surinam Dollar
+STD - Dobra
+SVC - El Salvador Colon
+SYP - Syrian Pound
+SZL - Lilangeni
+THB - Baht
+TJS - Somoni
+TMT - Turkmenistan New Manat
+TND - Tunisian Dinar
+TOP - Pa’anga
+TRY - Turkish Lira
+TTD - Trinidad and Tobago Dollar
+TVD - Tuvalu Dollar
+TWD - New Taiwan Dollar
+TZS - Tanzanian Shilling
+UAH - Hryvnia
+UGX - Uganda Shilling
+USD - US Dollar
+UYU - Peso Uruguayo
+UZS - Uzbekistan Sum
+VEF - Bolivar
+VND - Dong
+VUV - Vatu
+WST - Tala
+XAF - CFA Franc BEAC
+XCD - East Caribbean Dollar
+XDR - SDR (Special Drawing Right)
+XOF - CFA Franc BCEAO
+XPF - CFP Franc
+YER - Yemeni Rial
+ZAR - South African Rand
+ZMK - Zambian Kwacha
+ZWD - Zimbabwean Dollar A/06
+Catastrophic: A business-ending event (don’t choose this if the victim will continue operations)
+Damaging: Real and serious effect on the "bottom line" and/or long-term ability to generate revenue
+Distracting: Limited "hard costs", but impact felt through having to deal with the incident rather than conducting normal duties
+Insignificant: Impact absorbed by normal activities
+Painful: Moderate "hard costs", and impact felt through having to deal with the incident rather than conducting normal duties has quantifiable indirect costs
+Unknown
Andorra
+United Arab Emirates
+Afghanistan
+Antigua and Barbuda
+Anguilla
+Albania
+Armenia
+Angola
+Antarctica
+Argentina
+American Samoa
+Austria
+Australia
+Aruba
+Aland Islands
+Azerbaijan
+Bosnia and Herzegovina
+Barbados
+Bangladesh
@@ -19947,48 +20055,6 @@ veris namespace available in JSON format at -Bosnia and Herzegovina
-Barbados
-Wallis and Futuna Islands
-Saint-Barthelemy
-Unknown
-Brunei Darussalam
-Bolivia
-Bahrain
@@ -20007,33 +20073,27 @@ veris namespace available in JSON format at -Bhutan
+Saint-Barthelemy
Jamaica
+Bermuda
Bouvet Island
+Brunei Darussalam
Botswana
-Samoa
+Bolivia
Jersey
+Bhutan
+Bouvet Island
+Botswana
Russian Federation
+Canada
Rwanda
+Cocos (Keeling) Islands
Serbia
+Congo, Democratic Republic of the
Timor-Leste
+Central African Republic
Reunion
+Congo
Turkmenistan
+Switzerland
Bermuda
+Cote d’Ivoire
Tajikistan
+Cook Islands
Romania
+Chile
Tokelau
+Cameroon
Guinea-Bissau
+China
Guam
+Colombia
Guatemala
+Costa Rica
South Georgia and the South Sandwich Islands
+Cuba
Greece
+Cape Verde
Equatorial Guinea
+Curacao
Guadeloupe
+Christmas Island
Japan
+Cyprus
Guyana
+Czech Republic
Guernsey
+Germany
French Guiana
+Djibouti
Georgia
+Denmark
Grenada
+Dominica
United Kingdom
+Dominican Republic
Gabon
+Algeria
El Salvador
-Guinea
-Gambia
-Greenland
-Gibraltar
-Ghana
-Oman
-Tunisia
-Jordan
-Croatia
-Haiti
-Hungary
-Hong Kong
-Honduras
-Heard Island and McDonal Islands
-Venezuela (Bolivarian Republic of)
-Puerto Rico
-Palestinian Territory, Occupied
-Palau
-Portugal
-Svalbard and Jan Mayen Islands
-Paraguay
-Iraq
-Panama
-French Polynesia
-Papua New Guinea
-Peru
-Pakistan
-Philippines
-Pitcairn
-Poland
-Saint Pierre and Miquelon
-Zambia
-Western Sahara
+Ecuador
South Africa
-Ecuador
-Italy
-Viet Nam
-Solomon Islands
-Ethiopia
-Somalia
-Zimbabwe
-Saudi Arabia
-Spain
+Western Sahara
Montenegro
+Spain
Moldova, Republic of
-Madagascar
-Saint Martin (French part)
-Morocco
-Monaco
-Uzbekistan
-Myanmar
-Mali
-Macao
-Mongolia
-Marshall Islands
-Macedonia, The former Yugoslav Republic of
-Mauritius
-Malta
-Malawi
-Maldives
-Martinique
-Northern Mariana Islands
-Montserrat
-Mauritania
-Isle of Man
-Uganda
-Tanzania, United Republic of
-Malaysia
-Mexico
-Israel
-France
-British Virgin Islands
-Saint Helena
+Ethiopia
Nicaragua
+France
Netherlands
+Gabon
Norway
+United Kingdom
+Grenada
+Georgia
+French Guiana
+Guernsey
+Ghana
+Gibraltar
+Greenland
+Gambia
+Guinea
+Guadeloupe
+Equatorial Guinea
+Greece
+South Georgia and the South Sandwich Islands
+Guatemala
+Guam
+Guinea-Bissau
+Guyana
+Hong Kong
+Heard Island and McDonal Islands
+Honduras
+Croatia
+Haiti
+Hungary
+Indonesia
+Ireland
+Israel
+Isle of Man
+India
+British Virgin Islands
+Iraq
+Iran (Islamic Republic of)
+Iceland
+Italy
+Jersey
+Jamaica
+Jordan
+Japan
+Kenya
+Kyrgyzstan
+Cambodia
+Kiribati
+Comoros
+Saint Kitts and Nevis
+Korea, Democratic People’s Republic of
+Korea, Republic of
+Kuwait
+Cayman Islands
+Kazakhstan
+Lao People’s Democratic Republic
+Lebanon
+Saint Lucia
+Liechtenstein
+Sri Lanka
+Liberia
+Lesotho
+Lithuania
+Luxembourg
+Latvia
+Libya
+Morocco
+Monaco
+Moldova, Republic of
+Montenegro
+Saint Martin (French part)
+Madagascar
+Marshall Islands
+Macedonia, The former Yugoslav Republic of
+Mali
+Myanmar
+Mongolia
+Macao
+Northern Mariana Islands
+Martinique
+Mauritania
+Montserrat
+Malta
+Mauritius
+Maldives
+Malawi
+Mexico
+Malaysia
+Mozambique
Vanuatu
-New Caledonia
@@ -20769,9 +20907,21 @@ veris namespace available in JSON format at -New Zealand
+Nicaragua
+Netherlands
+Norway
Cook Islands
+New Zealand
Cote d’Ivoire
-Switzerland
-Colombia
-China
-Cameroon
-Chile
-Cocos (Keeling) Islands
-Canada
-Congo
-Central African Republic
-Congo, Democratic Republic of the
-Czech Republic
-Cyprus
-Christmas Island
-Costa Rica
-Curacao
-Cape Verde
-Cuba
-Swaziland
-Syrian Arab Republic
-Sint Maarten (Dutch part)
-Kyrgyzstan
-Kenya
-South Sudan
-Suriname
-Kiribati
-Cambodia
-Saint Kitts and Nevis
-Comoros
-Sao Tome and Principe
-Slovakia
-Korea, Republic of
-Slovenia
-Korea, Democratic People’s Republic of
-Kuwait
-Senegal
-San Marino
-Sierra Leone
-Seychelles
-Kazakhstan
-Cayman Islands
-Singapore
-Sweden
-Sudan
-Dominican Republic
-Dominica
-Djibouti
-Denmark
-British Virgin Islands
-Germany
-Yemen
+Oman
Algeria
+Panama
United States of America
+Peru
Uruguay
+French Polynesia
Mayotte
+Papua New Guinea
United States Minor Outlying Islands
+Philippines
Lebanon
+Pakistan
Saint Lucia
+Poland
Lao People’s Democratic Republic
+Saint Pierre and Miquelon
Tuvalu
+Pitcairn
Taiwan, Province of China
+Puerto Rico
Trinidad and Tobago
+Palestinian Territory, Occupied
Turkey
+Portugal
Sri Lanka
+Palau
Liechtenstein
+Paraguay
Latvia
+Qatar
Tonga
+Reunion
Lithuania
+Romania
Luxembourg
+Serbia
Liberia
+Russian Federation
Lesotho
+Rwanda
Thailand
+Saudi Arabia
+Solomon Islands
+Seychelles
+Sudan
+Sweden
+Singapore
+Saint Helena
+Slovenia
+Svalbard and Jan Mayen Islands
+Slovakia
+Sierra Leone
+San Marino
+Senegal
+Somalia
+Suriname
+South Sudan
+Sao Tome and Principe
+El Salvador
+Sint Maarten (Dutch part)
+Syrian Arab Republic
+Swaziland
+Turks and Caicos Islands
+Chad
Chad
+Thailand
Turks and Caicos Islands
+Tajikistan
Libya
+Tokelau
+Timor-Leste
+Turkmenistan
+Tunisia
+Tonga
+Turkey
+Trinidad and Tobago
+Tuvalu
+Taiwan, Province of China
+Tanzania, United Republic of
+Ukraine
+Uganda
+United States Minor Outlying Islands
+United States of America
+Uruguay
+Uzbekistan
+Unknown
United Arab Emirates
+Venezuela (Bolivarian Republic of)
Andorra
-Antigua and Barbuda
-Afghanistan
-Anguilla
+British Virgin Islands
Iceland
+Viet Nam
Iran (Islamic Republic of)
+Vanuatu
Armenia
+Wallis and Futuna Islands
Albania
+Samoa
Angola
+Yemen
Antarctica
+Mayotte
American Samoa
+South Africa
Argentina
+Zambia
Australia
-Austria
-Aruba
-India
-Aland Islands
-Azerbaijan
-Ireland
-Indonesia
-Ukraine
-Qatar
-Mozambique
+Zimbabwe
1,001 to 10,000 employees
-Over 100,0001 employees
-Unknown number of employees
-50,001 to 100,000 employees
-25,001 to 50,000 employees
-101 to 1,000 employees
-Large organizations (over 1,000 employees)
+1 to 10 employees
Small organizations (1,000 employees or less)
+1,001 to 10,000 employees
1 to 10 employees
+101 to 1,000 employees
Legal and regulatory costs
+Deterioration and degradation
Asset and fraud-related losses
+Electromagnetic interference (EMI)
Business disruption
+Electrostatic discharge (ESD)
Response and recovery costs
+Earthquake
Loss of competitive advantage
+Fire
Increased operating costs
+Flood
Impact variety known but not listed.
+Hazardous material
Brand and market damage
+Humidity
Never
+Hurricane
Seconds
+Ice and snow
Exfiltration does not apply in the context of the security event.
+Landslide
Months
+Water leak
Days
+Lightning
Years
+Meteorite
Hours
-Unknown
-Weeks
-Minutes
-Never
-Seconds
-Containment does not apply in the context of the security event.
-Months
-Days
-Years
-Hours
-Unknown
-Weeks
-Minutes
-Never
-Seconds
-Compromise does not apply in the context of the security event.
-Months
-Days
-Years
-Hours
-Unknown
-Weeks
-Minutes
-Never
-Seconds
-Discovery does not apply in the context of the security event.
-Months
-Days
-Years
-Hours
-Unknown
-Weeks
-Minutes
-Grudge or personal offense
-Financial or personal gain
-Not Applicable (unintentional action)
-Ideology or protest
-Convenience of expediency
-Other
Particulate matter (e.g., dust, smoke)
+Pathogen
+Power failure or fluctuation
+Extreme temperature
+Tornado
+Tsunami
+Unknown
Fun, curiosity, or pride
+Vermin
Fear or duress
+Volcanic eruption
Espionage or competitive advantage
-Aid in a different attack
+Wind
Bangladesh
+Poor capacity planning
Belgium
+Classification or labeling error
Burkina Faso
+Data entry error
Bulgaria
+Disposal error
Bosnia and Herzegovina
+Gaffe (social or verbal slip)
Barbados
+Loss or misplacement
Wallis and Futuna Islands
+Maintenance error
Saint-Barthelemy
+Technical malfunction or glitch
Unknown
+Misconfiguration
Brunei Darussalam
+Misdelivery (send wrong info or to wrong recipient)
Bolivia
+Misinformation (unintentionally giving false info)
Bahrain
+Omission (something intended, but not done)
Burundi
-Benin
-Bhutan
-Jamaica
-Bouvet Island
-Botswana
-Samoa
-Bonaire, Saint Eustatius and Saba
-Brazil
-Bahamas
-Jersey
-Belarus
-Belize
-Russian Federation
-Rwanda
-Serbia
-Timor-Leste
-Reunion
-Turkmenistan
-Bermuda
-Tajikistan
-Romania
-Tokelau
-Guinea-Bissau
-Guam
-Guatemala
-South Georgia and the South Sandwich Islands
-Greece
-Equatorial Guinea
-Guadeloupe
-Japan
-Guyana
-Guernsey
-French Guiana
-Georgia
-Grenada
-United Kingdom
-Gabon
-El Salvador
-Guinea
-Gambia
-Greenland
-Gibraltar
-Ghana
-Oman
-Tunisia
-Jordan
-Croatia
-Haiti
-Hungary
-Hong Kong
-Honduras
-Heard Island and McDonal Islands
-Venezuela (Bolivarian Republic of)
-Puerto Rico
-Palestinian Territory, Occupied
-Palau
-Portugal
-Svalbard and Jan Mayen Islands
-Paraguay
-Iraq
-Panama
-French Polynesia
-Papua New Guinea
-Peru
-Pakistan
-Philippines
-Pitcairn
-Poland
-Saint Pierre and Miquelon
-Zambia
-Western Sahara
-Estonia
-Egypt
-South Africa
-Ecuador
-Italy
-Viet Nam
-Solomon Islands
-Ethiopia
-Somalia
-Zimbabwe
-Saudi Arabia
-Spain
-Eritrea
-Montenegro
-Moldova, Republic of
-Madagascar
-Saint Martin (French part)
-Morocco
-Monaco
-Uzbekistan
-Myanmar
-Mali
-Macao
-Mongolia
-Marshall Islands
-Macedonia, The former Yugoslav Republic of
-Mauritius
-Malta
-Malawi
-Maldives
-Martinique
-Northern Mariana Islands
-Montserrat
-Mauritania
-Isle of Man
-Uganda
-Tanzania, United Republic of
-Malaysia
-Mexico
-Israel
-France
-British Virgin Islands
-Saint Helena
-Finland
-Fiji
-Faeroe Islands
-Micronesia (Federated States of)
-Falkland Islands (Malvinas)
-Nicaragua
-Netherlands
-Norway
-Namibia
-Vanuatu
-New Caledonia
-Niger
-Norfolk Island
-Nigeria
-New Zealand
-Nepal
-Nauru
-Niue
-Cook Islands
-Cote d’Ivoire
-Switzerland
-Colombia
-China
-Cameroon
-Chile
-Cocos (Keeling) Islands
-Canada
-Congo
-Central African Republic
-Congo, Democratic Republic of the
-Czech Republic
-Cyprus
-Christmas Island
-Costa Rica
-Curacao
-Cape Verde
-Cuba
-Swaziland
-Syrian Arab Republic
-Sint Maarten (Dutch part)
-Kyrgyzstan
-Kenya
-South Sudan
-Suriname
-Kiribati
-Cambodia
-Saint Kitts and Nevis
-Comoros
-Sao Tome and Principe
-Slovakia
-Korea, Republic of
-Slovenia
-Korea, Democratic People’s Republic of
-Kuwait
-Senegal
-San Marino
-Sierra Leone
-Seychelles
-Kazakhstan
-Cayman Islands
-Singapore
-Sweden
-Sudan
-Dominican Republic
-Dominica
-Djibouti
-Denmark
-British Virgin Islands
-Germany
-Yemen
-Other
Algeria
+Physical accidents (e.g., drops, bumps, spills)
United States of America
+Programming error (flaws or bugs in custom code)
Uruguay
+Publishing error (private info to public doc or site)
Mayotte
-United States Minor Outlying Islands
-Lebanon
-Saint Lucia
-Lao People’s Democratic Republic
-Tuvalu
-Taiwan, Province of China
-Trinidad and Tobago
-Turkey
-Sri Lanka
-Liechtenstein
-Latvia
-Tonga
-Lithuania
-Luxembourg
-Liberia
-Lesotho
-Thailand
-French Southern Territories
-Togo
-Chad
-Turks and Caicos Islands
-Libya
-Holy See
-Saint Vincent and the Grenadines
-United Arab Emirates
-Andorra
-Antigua and Barbuda
-Afghanistan
-Anguilla
-United States Virgin Islands
-Iceland
-Iran (Islamic Republic of)
-Armenia
-Albania
-Angola
-Antarctica
-American Samoa
-Argentina
-Australia
-Austria
-Aruba
-India
-Aland Islands
-Azerbaijan
-Ireland
-Indonesia
-Ukraine
-Qatar
-Mozambique
+Unknown
Grudge or personal offense
+Carelessness
Financial or personal gain
+Inadequate or insufficient personnel
Not Applicable (unintentional action)
+Inadequate or insufficient processes
Ideology or protest
+Inadequate or insufficient technology resources
Convenience of expediency
-Other
Random error (no reason, no fault)
+Unknown
Fun, curiosity, or pride
-Fear or duress
-Espionage or competitive advantage
-Aid in a different attack
-Lateral move
+The hacking action resulted in additional permissions
Fired, laid off, or let go
+The hacking action exfiltrated data from the victim
Unknown
-Personal issues
-Recent poor job evaluation
-Recently reprimanded
-Recently hired
-Recently passed over for promotion
-Recently demoted or hours reduced
-Recently promoted
-Preparing to resign or recently resigned
-Other
+The hacking action infiltrated the victim
End-user or regular employee
+Abuse of functionality
Human resources staff
+Brute force or password guessing attacks
Finance or accounting staff
+Buffer overflow
Unknown
+Cross-site request forgery
Helpdesk staff
+Cache poisoning
Executive or upper management
+Cryptanalysis
Cashier, teller, or waiter
+Denial of service
Manager or supervisor
+Footprinting and fingerprinting
A doctor or a nurse
+Forced browsing or predictable resource location
Security guard
+Format string attack
Fuzz testing
+HTTP Response Splitting
+HTTP request smuggling
+HTTP request splitting
+HTTP response smuggling
+Integer overflows
+LDAP injection
+Mail command injection
+Man-in-the-middle attack
+Null byte injection
+OS commanding
+Offline password or key cracking (e.g., rainbow tables, Hashcat, JtR)
+Other
Pass-the-hash
+Path traversal
+Remote file inclusion
+Reverse engineering
+Routing detour
+SQL injection
+SSI injection
+Session fixation
+Credential or session prediction
+Session replay
+Soap array abuse
+Special element injection
+URL redirector abuse
+Unknown
+Use of Backdoor or C2 channel
+Use of stolen authentication credentials
+Virtual machine escape
+XML attribute blowup
+XML entity expansion
+XML external entities
+XML injection
+XPath injection
+XQuery injection
+Cross-site scripting
+3rd party online desktop sharing (LogMeIn, Go2Assist)
+Backdoor or command and control channel
+Remote shell
+Graphical desktop sharing (RDP, VNC, PCAnywhere, Citrix)
+Superset of 'Desktop sharing' and '3rd party desktop'. Please use in place of the other two
+Other
+Partner connection or credential
+Physical access or connection (i.e., at keyboard or via cable)
+Unknown
+VPN
+Web application
+The malware action resulted in additional permissions
+The malware action exfiltrated data from the victim
+The malware action infiltrated the victim
+System or network utilities (e.g., PsTools, Netcat)
+Adware
+Backdoor (enable remote access)
+Brute force attack
+Command and control (C2)
+Capture data from application or system process
+Capture data stored on system disk
+Click fraud or Bitcoin mining
+Client-side or browser attack (e.g., redirection, XSS, MitB)
+Destroy or corrupt stored data
+Disable or interfere with security controls
+DoS attack
+Downloader (pull updates or other malware)
+Exploit vulnerability in code (vs misconfig or weakness)
+Export data to another site or system
+Malware which compromises a legitimate file rather than creating new filess
+Other
+Packet sniffer (capture data from network)
+Password dumper (extract credential hashes)
+Ram scraper or memory parser (capture data from volatile memory)
+Ransomware (encrypt or seize stored data)
+Rootkit (maintain local privileges and stealth)
+SQL injection attack
+Scan or footprint network
+Send spam
+Spyware, keylogger or form-grabber (capture user input or activity)
+Unknown
+Worm (propagate to other systems or devices)
+Directly installed or inserted by threat agent (after system access)
+Downloaded and installed by local malware
+Email via user-executed attachment
+Email via automatic execution
+Email via embedded link
+Email but sub-variety (attachment, autoexecute, link, etc) not known
+Instant Messaging
+Network propagation
+Other
+Remotely injected by agent (i.e. via SQLi)
+Removable storage media or devices
+Included in automated software update
+Unknown
+Web via user-executed or downloaded content
+Web via auto-executed or "drive-by" infection
+The misuse action resulted in additional permissions
+The misuse action exfiltrated data from the victim
+The misuse action infiltrated the victim
+Handling of data in an unapproved manner
+Inappropriate use of email or IM
+Storage or distribution of illicit content
+Abuse of private or entrusted knowledge
+Inappropriate use of network or Web access
+Other+
Abuse of physical access to asset
+Abuse of system access privileges
+Use of unapproved hardware or devices
+Use of unapproved software or services
+Unapproved workaround or shortcut
+Unknown
+Local network access within corporate facility
+Non-corporate facilities or networks
+Other
+Physical access within corporate facility
+Remote access connection to corporate network (i.e. VPN)
+Unknown
+The physical action resulted in additional permissions
+The physical action exfiltrated data from the victim
+The physical action infiltrated the victim
+Assault (threats or acts of physical violence)
+Bypassed physical barriers or controls
+Connection
+Destruction (deliberate damaging or disabling)
+Disabled physical barriers or controls
+Other
+Installing card skimming device
+Snooping (sneak about to gain info or access)
+Surveillance (monitoring and observation)
+Tampering (alter physical form or function)
+Theft (taking assets without permission)
+Unknown
+Wiretapping (Physical tap to comms line)
+Other
+Partner facility or area
+Partner vehicle (e.g., delivery truck)
+Personal residence
+Personal vehicle
+Held privileged access to location
+Public facility or area
+Public vehicle (e.g., plane, taxi)
+The location was uncontrolled (public)
+Unknown
+Victim outdoor grounds
+Victim public or customer area (e.g., lobby, storefront)
+Victim high security area (e.g., server room, R&D labs)
+Victim private or work area (e.g., office space)
+Given temporary visitor access
+The social action resulted in additional permissions
+The social action exfiltrated data from the victim
+The social action infiltrated the victim
+Auditor
Maintenance or janitorial staff
-Call center staff
System or network administrator
+Cashier, teller or waiter
Customer (B2C)
+Software developer
Grudge or personal offense
+End-user or regular employee
Financial or personal gain
+Executive or upper management
Not Applicable (unintentional action)
+Finance or accounting staff
Ideology or protest
+Former employee
Convenience of expediency
+Security guard
Helpdesk staff
+Human resources staff
+Maintenance or janitorial staff
+Manager or supervisor
+Other
Partner (B2B)
+System or network administrator
+Unknown
+Baiting (planting infected media)
+Bribery or solicitation
+Elicitation (subtle extraction of info through conversation)
+Extortion or blackmail
+Forgery or counterfeiting (fake hardware, software, documents, etc)
+Influence tactics (Leveraging authority or obligation, framing, etc)
+Other
+Phishing (or any type of *ishing)
+Pretexting (dialogue leveraging invented scenario)
+Propaganda or disinformation
+Online scam or hoax (e.g., scareware, 419 scam, auction fraud)
+Spam (unsolicited or undesired email and advertisements)
+Unknown
+Documents
+Instant messaging
+In-person
+Other
+Phone
+Removable storage media
+SMS or texting
+Social media or networking
+Software
+Unknown
Fun, curiosity, or pride
+Website
+The hacking action resulted in additional permissions
Fear or duress
+The hacking action exfiltrated data from the victim
Espionage or competitive advantage
-Aid in a different attack
+The hacking action infiltrated the victim
Andorra
+United Arab Emirates
+Afghanistan
+Antigua and Barbuda
+Anguilla
+Albania
+Armenia
+Angola
+Antarctica
+Argentina
+American Samoa
+Austria
+Australia
+Aruba
+Aland Islands
+Azerbaijan
+Bosnia and Herzegovina
+Barbados
+Bangladesh
@@ -23751,48 +23237,6 @@ veris namespace available in JSON format at -Bosnia and Herzegovina
-Barbados
-Wallis and Futuna Islands
-Saint-Barthelemy
-Unknown
-Brunei Darussalam
-Bolivia
-Bahrain
@@ -23811,33 +23255,27 @@ veris namespace available in JSON format at -Bhutan
+Saint-Barthelemy
Jamaica
+Bermuda
Bouvet Island
+Brunei Darussalam
Botswana
-Samoa
+Bolivia
Jersey
+Bhutan
+Bouvet Island
+Botswana
Russian Federation
+Canada
Rwanda
+Cocos (Keeling) Islands
Serbia
+Congo, Democratic Republic of the
Timor-Leste
+Central African Republic
Reunion
+Congo
Turkmenistan
+Switzerland
Bermuda
+Cote d’Ivoire
Tajikistan
+Cook Islands
Romania
+Chile
Tokelau
+Cameroon
Guinea-Bissau
+China
Guam
+Colombia
Guatemala
+Costa Rica
South Georgia and the South Sandwich Islands
+Cuba
Greece
+Cape Verde
Equatorial Guinea
+Curacao
Guadeloupe
+Christmas Island
Japan
+Cyprus
Guyana
+Czech Republic
Guernsey
+Germany
French Guiana
+Djibouti
Georgia
+Denmark
Grenada
+Dominica
United Kingdom
+Dominican Republic
Gabon
+Algeria
El Salvador
-Guinea
-Gambia
-Greenland
-Gibraltar
-Ghana
-Oman
-Tunisia
-Jordan
-Croatia
-Haiti
-Hungary
-Hong Kong
-Honduras
-Heard Island and McDonal Islands
-Venezuela (Bolivarian Republic of)
-Puerto Rico
-Palestinian Territory, Occupied
-Palau
-Portugal
-Svalbard and Jan Mayen Islands
-Paraguay
-Iraq
-Panama
-French Polynesia
-Papua New Guinea
-Peru
-Pakistan
-Philippines
-Pitcairn
-Poland
-Saint Pierre and Miquelon
-Zambia
-Western Sahara
+Ecuador
South Africa
-Ecuador
-Italy
-Viet Nam
-Solomon Islands
-Ethiopia
-Somalia
-Zimbabwe
-Saudi Arabia
-Spain
+Western Sahara
Montenegro
+Spain
Moldova, Republic of
-Madagascar
-Saint Martin (French part)
-Morocco
-Monaco
-Uzbekistan
-Myanmar
-Mali
-Macao
-Mongolia
-Marshall Islands
-Macedonia, The former Yugoslav Republic of
-Mauritius
-Malta
-Malawi
-Maldives
-Martinique
-Northern Mariana Islands
-Montserrat
-Mauritania
-Isle of Man
-Uganda
-Tanzania, United Republic of
-Malaysia
-Mexico
-Israel
-France
-British Virgin Islands
-Saint Helena
+Ethiopia
Nicaragua
+France
Netherlands
+Gabon
Norway
+United Kingdom
+Grenada
+Georgia
+French Guiana
+Guernsey
+Ghana
+Gibraltar
+Greenland
+Gambia
+Guinea
+Guadeloupe
+Equatorial Guinea
+Greece
+South Georgia and the South Sandwich Islands
+Guatemala
+Guam
+Guinea-Bissau
+Guyana
+Hong Kong
+Heard Island and McDonal Islands
+Honduras
+Croatia
+Haiti
+Hungary
+Indonesia
+Ireland
+Israel
+Isle of Man
+India
+British Virgin Islands
+Iraq
+Iran (Islamic Republic of)
+Iceland
+Italy
+Jersey
+Jamaica
+Jordan
+Japan
+Kenya
+Kyrgyzstan
+Cambodia
+Kiribati
+Comoros
+Saint Kitts and Nevis
+Korea, Democratic People’s Republic of
+Korea, Republic of
+Kuwait
+Cayman Islands
+Kazakhstan
+Lao People’s Democratic Republic
+Lebanon
+Saint Lucia
+Liechtenstein
+Sri Lanka
+Liberia
+Lesotho
+Lithuania
+Luxembourg
+Latvia
+Libya
+Morocco
+Monaco
+Moldova, Republic of
+Montenegro
+Saint Martin (French part)
+Madagascar
+Marshall Islands
+Macedonia, The former Yugoslav Republic of
+Mali
+Myanmar
+Mongolia
+Macao
+Northern Mariana Islands
+Martinique
+Mauritania
+Montserrat
+Malta
+Mauritius
+Maldives
+Malawi
+Mexico
+Malaysia
+Mozambique
Vanuatu
-New Caledonia
@@ -24573,9 +24089,21 @@ veris namespace available in JSON format at -New Zealand
+Nicaragua
+Netherlands
+Norway
Cook Islands
+New Zealand
Cote d’Ivoire
-Switzerland
-Colombia
-China
-Cameroon
-Chile
-Cocos (Keeling) Islands
-Canada
-Congo
-Central African Republic
-Congo, Democratic Republic of the
-Czech Republic
-Cyprus
-Christmas Island
-Costa Rica
-Curacao
-Cape Verde
-Cuba
-Swaziland
-Syrian Arab Republic
-Sint Maarten (Dutch part)
-Kyrgyzstan
-Kenya
-South Sudan
-Suriname
-Kiribati
-Cambodia
-Saint Kitts and Nevis
-Comoros
-Sao Tome and Principe
-Slovakia
-Korea, Republic of
-Slovenia
-Korea, Democratic People’s Republic of
-Kuwait
-Senegal
-San Marino
-Sierra Leone
-Seychelles
-Kazakhstan
-Cayman Islands
-Singapore
-Sweden
-Sudan
-Dominican Republic
-Dominica
-Djibouti
-Denmark
-British Virgin Islands
-Germany
-Yemen
+Oman
Algeria
+Panama
United States of America
+Peru
Uruguay
+French Polynesia
Mayotte
+Papua New Guinea
United States Minor Outlying Islands
+Philippines
Lebanon
+Pakistan
Saint Lucia
+Poland
Lao People’s Democratic Republic
+Saint Pierre and Miquelon
Tuvalu
+Pitcairn
Taiwan, Province of China
+Puerto Rico
Trinidad and Tobago
+Palestinian Territory, Occupied
Turkey
+Portugal
Sri Lanka
+Palau
Liechtenstein
+Paraguay
Latvia
+Qatar
Tonga
+Reunion
Lithuania
+Romania
Luxembourg
+Serbia
Liberia
+Russian Federation
Lesotho
+Rwanda
Thailand
+Saudi Arabia
+Solomon Islands
+Seychelles
+Sudan
+Sweden
+Singapore
+Saint Helena
+Slovenia
+Svalbard and Jan Mayen Islands
+Slovakia
+Sierra Leone
+San Marino
+Senegal
+Somalia
+Suriname
+South Sudan
+Sao Tome and Principe
+El Salvador
+Sint Maarten (Dutch part)
+Syrian Arab Republic
+Swaziland
+Turks and Caicos Islands
+Chad
Chad
+Thailand
Turks and Caicos Islands
+Tajikistan
Libya
+Tokelau
+Timor-Leste
+Turkmenistan
+Tunisia
+Tonga
+Turkey
+Trinidad and Tobago
+Tuvalu
+Taiwan, Province of China
+Tanzania, United Republic of
+Ukraine
+Uganda
+United States Minor Outlying Islands
+United States of America
+Uruguay
+Uzbekistan
+Unknown
United Arab Emirates
+Venezuela (Bolivarian Republic of)
Andorra
-Antigua and Barbuda
-Afghanistan
-Anguilla
+British Virgin Islands
Iceland
+Viet Nam
Iran (Islamic Republic of)
+Vanuatu
Armenia
+Wallis and Futuna Islands
Albania
+Samoa
Angola
+Yemen
Antarctica
+Mayotte
American Samoa
+South Africa
Argentina
+Zambia
Australia
+Zimbabwe
+Convenience of expediency
Austria
+Espionage or competitive advantage
Aruba
+Fear or duress
India
+Financial or personal gain
Aland Islands
+Fun, curiosity, or pride
Azerbaijan
+Grudge or personal offense
Ireland
+Ideology or protest
Indonesia
+Not Applicable (unintentional action)
Ukraine
+Other
Qatar
+Aid in a different attack
Mozambique
+Unknown
Customer (B2C)
-Organized or professional criminal group
-Relative or acquaintance of employee
Activist group
+Auditor
+Competitor
Unaffiliated person(s)
+Customer (B2C)
Activist group
+Organized or professional criminal group
Terrorist group
-Auditor
-Unknown
+Other
Terrorist group
+Unaffiliated person(s)
+Unknown
+Recently demoted or hours reduced
+Recently hired
+Recent poor job evaluation
+Lateral move
+Fired, laid off, or let go
+Other
Recently passed over for promotion
+Personal issues
+Recently promoted
+Recently reprimanded
+Preparing to resign or recently resigned
+Unknown
+Convenience of expediency
+Espionage or competitive advantage
+Fear or duress
+Financial or personal gain
+Fun, curiosity, or pride
+Grudge or personal offense
+Ideology or protest
+Not Applicable (unintentional action)
+Other
+Aid in a different attack
+Unknown
+Auditor
+Call center staff
+Cashier, teller, or waiter
+Software developer
+A doctor or a nurse
+End-user or regular employee
+Executive or upper management
+Finance or accounting staff
+Security guard
+Helpdesk staff
+Human resources staff
+Maintenance or janitorial staff
+Manager or supervisor
+Other
+System or network administrator
+Unknown
+Andorra
+United Arab Emirates
+Afghanistan
+Antigua and Barbuda
+Anguilla
+Albania
+Armenia
+Angola
+Antarctica
+Argentina
+American Samoa
+Austria
+Australia
+Aruba
+Aland Islands
+Azerbaijan
+Bosnia and Herzegovina
+Barbados
+Bangladesh
+Belgium
+Burkina Faso
+Bulgaria
+Bahrain
+Burundi
+Benin
+Saint-Barthelemy
+Bermuda
+Brunei Darussalam
+Bolivia
+Bonaire, Saint Eustatius and Saba
+Brazil
+Bahamas
+Bhutan
+Bouvet Island
+Botswana
+Belarus
+Belize
+Canada
+Cocos (Keeling) Islands
+Congo, Democratic Republic of the
+Central African Republic
+Congo
+Switzerland
+Cote d’Ivoire
+Cook Islands
+Chile
+Cameroon
+China
+Colombia
+Costa Rica
+Cuba
+Cape Verde
+Curacao
+Christmas Island
+Cyprus
+Czech Republic
+Germany
+Djibouti
+Denmark
+Dominica
+Dominican Republic
+Algeria
+Ecuador
+Estonia
+Egypt
+Western Sahara
+Eritrea
+Spain
+Ethiopia
+Finland
+Fiji
+Faeroe Islands
+Micronesia (Federated States of)
+Falkland Islands (Malvinas)
+France
+Gabon
+United Kingdom
+Grenada
+Georgia
+French Guiana
+Guernsey
+Ghana
+Gibraltar
+Greenland
+Gambia
+Guinea
+Guadeloupe
+Equatorial Guinea
+Greece
+South Georgia and the South Sandwich Islands
+Guatemala
+Guam
+Guinea-Bissau
+Guyana
+Hong Kong
+Heard Island and McDonal Islands
+Honduras
+Croatia
+Haiti
+Hungary
+Indonesia
+Ireland
+Israel
+Isle of Man
+India
+British Virgin Islands
+Iraq
+Iran (Islamic Republic of)
+Iceland
+Italy
+Jersey
+Jamaica
+Jordan
+Japan
+Kenya
+Kyrgyzstan
+Cambodia
+Kiribati
+Comoros
+Saint Kitts and Nevis
+Korea, Democratic People’s Republic of
+Korea, Republic of
+Kuwait
+Cayman Islands
+Kazakhstan
+Lao People’s Democratic Republic
+Lebanon
+Saint Lucia
+Liechtenstein
+Sri Lanka
+Liberia
+Lesotho
+Lithuania
+Luxembourg
+Latvia
+Libya
+Morocco
+Monaco
+Moldova, Republic of
+Montenegro
+Saint Martin (French part)
+Madagascar
+Marshall Islands
+Macedonia, The former Yugoslav Republic of
+Mali
+Myanmar
+Mongolia
+Macao
+Northern Mariana Islands
+Martinique
+Mauritania
+Montserrat
+Malta
+Mauritius
+Maldives
+Malawi
+Mexico
+Malaysia
+Mozambique
+Namibia
+New Caledonia
+Niger
+Norfolk Island
+Nigeria
+Nicaragua
+Netherlands
+Norway
+Nepal
+Nauru
+Niue
+New Zealand
+Oman
+Other
+Panama
+Peru
+French Polynesia
+Papua New Guinea
+Philippines
+Pakistan
+Poland
+Saint Pierre and Miquelon
+Pitcairn
+Puerto Rico
+Palestinian Territory, Occupied
+Portugal
+Palau
+Paraguay
+Qatar
+Reunion
+Romania
+Serbia
+Russian Federation
+Rwanda
+Saudi Arabia
+Solomon Islands
+Seychelles
+Sudan
+Sweden
+Singapore
+Saint Helena
+Slovenia
+Svalbard and Jan Mayen Islands
+Slovakia
+Sierra Leone
+San Marino
+Senegal
+Somalia
+Suriname
+South Sudan
+Sao Tome and Principe
+El Salvador
+Sint Maarten (Dutch part)
+Syrian Arab Republic
+Swaziland
+Turks and Caicos Islands
+Chad
+French Southern Territories
+Togo
+Thailand
+Tajikistan
+Tokelau
+Timor-Leste
+Turkmenistan
+Tunisia
+Tonga
+Turkey
+Trinidad and Tobago
+Tuvalu
+Taiwan, Province of China
+Tanzania, United Republic of
+Ukraine
+Uganda
+United States Minor Outlying Islands
+United States of America
+Uruguay
+Uzbekistan
+Unknown
+Holy See
+Saint Vincent and the Grenadines
+Venezuela (Bolivarian Republic of)
+British Virgin Islands
+United States Virgin Islands
+Viet Nam
+Vanuatu
+Wallis and Futuna Islands
+Samoa
+Yemen
+Mayotte
+South Africa
+Zambia
+Zimbabwe
+Convenience of expediency
+Espionage or competitive advantage
+Fear or duress
+Financial or personal gain
+Fun, curiosity, or pride
+Grudge or personal offense
+Ideology or protest
+Not Applicable (unintentional action)
+Other
+Aid in a different attack
+Unknown
+Embedded - A dedicated device that collects data about the physical world
-Unknown type of asset
-Media - The output of a fax machine
-Media - Disk media (e.g., CDs, DVDs)
-Media - Payment card (e.g., magstripe, EMV)
-User Device - Mobile phone or smartphone
-Public Terminal - Self-service kiosk
-People - Former employee
-User Device - POS terminal
-Network - Mobile broadband network
-User Device - Variety not known
-Network - Telephone
-People - Finance
-Network - VoIP adapter
-Server - Payment switch or gateway
-User Device - Authentication token or device
-User Device - Variety known but not listed
-Server - Remote access
-Media - Documents
-Public Terminal - Variety known but not listed
-Server - Distributed control system (DCS)
-Network - Private branch exchange (PBX)
-Server - DHCP
-Network - Wired LAN
-Public Terminal - Automated Teller Machine (ATM)
-Network - Public WAN
-Embedded - Variety not known
-People - End-user
-Network - IDS or IPs
-User Device - Desktop or workstation
-Network - Variety known but not listed
-User Device - Tablet
-Network - Firewall
-Media - Hard disk drive
-Servers maintaining or deploying configurations or patches to other assets
-Server - Industrial Control System (ICS). Includes Supervisory Control And Data Acquisition (SCADA) systems.
-People - Human resources
-Server - File
-Network - Wireless LAN
-Server - Database
-Network - Camera or surveillance system
-Network - Variety not known
-User Device - Media player or recorder
-Public Terminal - Detached PIN pad or card reader
-Network - Remote terminal unit (RTU)
-Server - Authentication
-Network - Router or switch
-Network - Hardware security module (HSM)
-Server - Mail
-Network - Storage area network (SAN)
-Network - Programmable logic controller (PLC)
-People - Cashier
-Public Terminal - Gas "pay-at-the-pump" terminal
-People - Variety not known
-Server - Mainframe
-User Device - Laptop
-People - Auditor
-User Device - VoIP phone
+Embedded - Variety known but not listed
Server - DNS
+Embedded - A dedicated device that collects data about the physical world
Server - Log or event management
+Embedded - Variety not known
People - Variety known but not listed
+Media - Hard disk drive
Server - Proxy
+Media - Disk media (e.g., CDs, DVDs)
Public Terminal - Variety not known
+Media - Documents
Network - Access control reader (e.g., badge, biometric)
-Server - Web application
-Server - POS controller
-People - Manager
+Media - The output of a fax machine
Server - Print
-People - Guard
-Media - Variety known but not listed
Server - Variety known but not listed
-People - Administrator
-Server - Variety not known
-Asset type known but not User Device, Server, Public Terminal, Server, People, Network, or Media
-People - Call center
-Network - Network area storage (NAS)
-Embedded - Variety known but not listed
-Server - Code repository
-People - Developer
+Media - Payment card (e.g., magstripe, EMV)
People - Executive
-People - Customer
-Server - Directory (LDAP, AD)
-Network - Private WAN
-People - Helpdesk
-User Device - Peripheral (e.g., printer, copier, fax)
-People - Partner
-People - Maintenance
-Server - Virtual Host
+Media - Backup tapes
Media - Backup tapes
+Network - Access control reader (e.g., badge, biometric)
+Network - Mobile broadband network
+Network - Camera or surveillance system
+Network - Firewall
+Network - Hardware security module (HSM)
+Network - IDS or IPs
+Network - Wired LAN
+Network - Network area storage (NAS)
+Network - Variety known but not listed
+Network - Private branch exchange (PBX)
+Network - Programmable logic controller (PLC)
+Network - Private WAN
+Network - Public WAN
+Network - Remote terminal unit (RTU)
+Network - Router or switch
+Network - Storage area network (SAN)
+Network - Telephone
+Network - Variety not known
+Network - VoIP adapter
+Network - Wireless LAN
+Asset type known but not User Device, Server, Public Terminal, Server, People, Network, or Media
+People - Auditor
+People - Call center
+People - Cashier
+People - Customer
+People - Developer
+People - End-user
+People - Executive
+People - Finance
+People - Former employee
+People - Guard
+People - Helpdesk
+People - Human resources
+People - Maintenance
+People - Manager
+People - Variety known but not listed
+People - Partner
+People - Administrator
+People - Variety not known
+Server - Authentication
+Server - Backup
+Server - Code repository
+Servers maintaining or deploying configurations or patches to other assets
+Server - Distributed control system (DCS)
+Server - DHCP
+Server - DNS
+Server - Database
+Server - Directory (LDAP, AD)
+Server - File
+Server - Industrial Control System (ICS). Includes Supervisory Control And Data Acquisition (SCADA) systems.
+Server - Log or event management
+Server - Mail
+Server - Mainframe
+Server - Variety known but not listed
+Server - POS controller
+Server - Payment switch or gateway
+Server - Print
+Server - Proxy
+Server - Remote access
+Server - Variety not known
+Server - Virtual Host
+Server - Web application
+Public Terminal - Automated Teller Machine (ATM)
+Public Terminal - Gas "pay-at-the-pump" terminal
+Public Terminal - Self-service kiosk
+Public Terminal - Variety known but not listed
+Public Terminal - Detached PIN pad or card reader
+Public Terminal - Variety not known
+User Device - Authentication token or device
+User Device - Desktop or workstation
+User Device - Laptop
+User Device - Media player or recorder
+User Device - Mobile phone or smartphone
+User Device - Variety known but not listed
+User Device - POS terminal
+User Device - Peripheral (e.g., printer, copier, fax)
+User Device - Tablet
Server - Backup
-DZD - Algerian Dinar
-NAD - Namibia Dollar
-GHS - Ghana Cedi
-EGP - Egyptian Pound
-BGN - Bulgarian Lev
-PAB - Balboa
-BOB - Boliviano
-DKK - Danish Krone
-BWP - Pula
-LBP - Lebanese Pound
-TZS - Tanzanian Shilling
-VND - Dong
-AOA - Kwanza
-KHR - Riel
-MYR - Malaysian Ringgit
-KYD - Cayman Islands Dollar
-LYD - Libyan Dinar
-UAH - Hryvnia
-JOD - Jordanian Dinar
-AWG - Aruban Florin
-SAR - Saudi Riyal
-EUR - Euro
-HKD - Hong Kong Dollar
-CHF - Swiss Franc
-GIP - Gibraltar Pound
-BYR - Belarussian Ruble
-ALL - Lek
-MRO - Ouguiya
-HRK - Croatian Kuna
-DJF - Djibouti Franc
-SZL - Lilangeni
-THB - Baht
-XAF - CFA Franc BEAC
-BND - Brunei Dollar
-ISK - Iceland Krona
-UYU - Peso Uruguayo
-NIO - Cordoba Oro
-LAK - Kip
-SYP - Syrian Pound
-MAD - Moroccan Dirham
-MZN - Mozambique Metical
-PHP - Philippine Peso
-ZAR - South African Rand
-NPR - Nepalese Rupee
-NGN - Naira
-ZWD - Zimbabwean Dollar A/06
-CRC - Costa Rican Colon
-AED - UAE Dirham
-GBP - Pound Sterling
-MWK - Kwacha
-LKR - Sri Lanka Rupee
-PKR - Pakistan Rupee
-HUF - Forint
-BMD - Bermudian Dollar
-LSL - Loti
-MNT - Tugrik
-AMD - Armenian Dram
-UGX - Uganda Shilling
-QAR - Qatari Rial
-XDR - SDR (Special Drawing Right)
-JMD - Jamaican Dollar
-GEL - Lari
-SHP - Saint Helena Pound
-AFN - Afghani
-SBD - Solomon Islands Dollar
-KPW - North Korean Won
-TRY - Turkish Lira
-BDT - Taka
-YER - Yemeni Rial
-HTG - Gourde
-XOF - CFA Franc BCEAO
-MGA - Malagasy Ariary
-ANG - Netherlands Antillean Guilder
-LRD - Liberian Dollar
-RWF - Rwanda Franc
-NOK - Norwegian Krone
-MOP - Pataca
-INR - Indian Rupee
-MXN - Mexican Peso
-CZK - Czech Koruna
-TJS - Somoni
-TWD - New Taiwan Dollar
-BTN - Ngultrum
-COP - Colombian Peso
-TMT - Turkmenistan New Manat
-MUR - Mauritius Rupee
-IDR - Rupiah
-HNL - Lempira
-XPF - CFP Franc
-FJD - Fiji Dollar
-ETB - Ethiopian Birr
-PEN - Nuevo Sol
-BZD - Belize Dollar
-ILS - New Israeli Sheqel
-DOP - Dominican Peso
-GGP - Guernsey pound
-MDL - Moldovan Leu
-BSD - Bahamian Dollar
-SPL - Seborga Luigino
-SEK - Swedish Krona
-ZMK - Zambian Kwacha
-JEP - Jersey pound
-AUD - Australian Dollar
-SRD - Surinam Dollar
-CUP - Cuban Peso
-BBD - Barbados Dollar
-KMF - Comoro Franc
-KRW - South Korean Won
-GMD - Dalasi
-VEF - Bolivar
-IMP - Isle of Man Pound
-CUC - Peso Convertible
-TVD - Tuvalu Dollar
-CLP - Chilean Peso
-LTL - Lithuanian Litas
-CDF - Congolese Franc
-XCD - East Caribbean Dollar
-KZT - Tenge
-RUB - Russian Ruble
-TTD - Trinidad and Tobago Dollar
-OMR - Rial Omani
-BRL - Brazilian Real
-MMK - Kyat
-PLN - Zloty
-PYG - Guarani
-KES - Kenyan Shilling
-SVC - El Salvador Colon
-MKD - Denar
-AZN - Azerbaijanian Manat
-TOP - Pa’anga
-MVR - Rufiyaa
-VUV - Vatu
-GNF - Guinea Franc
-WST - Tala
-IQD - Iraqi Dinar
-ERN - Nakfa
-BAM - Convertible Mark
-SCR - Seychelles Rupee
-CAD - Canadian Dollar
-CVE - Cape Verde Escudo
-KWD - Kuwaiti Dinar
-BIF - Burundi Franc
-PGK - Kina
-SOS - Somali Shilling
-SGD - Singapore Dollar
-UZS - Uzbekistan Sum
-STD - Dobra
-IRR - Iranian Rial
-CNY - Yuan Renminbi
-SLL - Leone
-TND - Tunisian Dinar
-GYD - Guyana Dollar
-NZD - New Zealand Dollar
-FKP - Falkland Islands Pound
-LVL - Latvian Lats
-USD - US Dollar
-KGS - Som
-ARS - Argentine Peso
-RON - New Romanian Leu
-GTQ - Quetzal
-RSD - Serbian Dinar
-BHD - Bahraini Dinar
-JPY - Yen
-SDG - Sudanese Pound
-Misrepresentation
-Modified stored data or content
-Unknown
-Created new user account
-Deface content
-Log tampering or modification
-Modified privileges or permissions
-Software installation or code modification
-Other
-Initiate fraudulent transaction
-Influence or alter human behavior
-Hardware tampering or physical alteration
-Modified configuration or services
-Repurposed asset for unauthorized function
-Customer
-Patient
-Unknown
-Other
-Student
-Employee
-Partner
-Data stat not known
-Transmitted encrypted
-Transmitted unencrypted
-Stored
-Transmitted
-Processed
-Stored encrypted
-Data state known but not listed.
-Stored unencrypted
-Data printed in human-readable format
-Unknown
-Yes (confirmed)
+User Device - Variety not known
Potentially (at risk)
+User Device - VoIP phone
No
+Unknown type of asset
Performance degradation
+Destruction
+Interruption
@@ -27123,15 +27194,9 @@ veris namespace available in JSON format at -Unknown
-Performance degradation
+Conversion or obscuration
Conversion or obscuration
-Destruction
+Unknown
Remotely injected by agent (i.e. via SQLi)
+No
Included in automated software update
+Potentially (at risk)
Instant Messaging
-Email via user-executed attachment
-Directly installed or inserted by threat agent (after system access)
-Downloaded and installed by local malware
-Web via auto-executed or "drive-by" infection
-Email via embedded link
-Network propagation
-Unknown
Email via automatic execution
+Yes (confirmed)
+Customer
Employee
+Other
Web via user-executed or downloaded content
+Partner
Email but sub-variety (attachment, autoexecute, link, etc) not known
+Patient
Removable storage media or devices
-The malware action resulted in additional permissions
+Student
The malware action exfiltrated data from the victim
-The malware action infiltrated the victim
-Malware which compromises a legitimate file rather than creating new filess
-Send spam
-Unknown
Packet sniffer (capture data from network)
+Data state known but not listed.
Backdoor (enable remote access)
+Data printed in human-readable format
Exploit vulnerability in code (vs misconfig or weakness)
+Processed
Stored
+Stored encrypted
+Stored unencrypted
+Transmitted
+Transmitted encrypted
+Transmitted unencrypted
+Data stat not known
+Influence or alter human behavior
+Created new user account
+Deface content
+Initiate fraudulent transaction
+Hardware tampering or physical alteration
+Log tampering or modification
+Misrepresentation
+Modified configuration or services
+Modified stored data or content
+Modified privileges or permissions
+Other
Password dumper (extract credential hashes)
+Repurposed asset for unauthorized function
Scan or footprint network
+Software installation or code modification
Downloader (pull updates or other malware)
-System or network utilities (e.g., PsTools, Netcat)
-Click fraud or Bitcoin mining
-Adware
-Command and control (C2)
-Worm (propagate to other systems or devices)
-Spyware, keylogger or form-grabber (capture user input or activity)
-Brute force attack
-Capture data from application or system process
-Ram scraper or memory parser (capture data from volatile memory)
-Disable or interfere with security controls
-Capture data stored on system disk
-Ransomware (encrypt or seize stored data)
-Export data to another site or system
-Client-side or browser attack (e.g., redirection, XSS, MitB)
-SQL injection attack
-Rootkit (maintain local privileges and stealth)
-Destroy or corrupt stored data
-DoS attack
+Unknown
The hacking action resulted in additional permissions
+Major
The hacking action exfiltrated data from the victim
+Minor
The hacking action infiltrated the victim
+Moderate
+None
+Unknown
The social action resulted in additional permissions
+Asset and fraud-related losses
The social action exfiltrated data from the victim
+Brand and market damage
The social action infiltrated the victim
+Business disruption
+Loss of competitive advantage
+Legal and regulatory costs
+Increased operating costs
+Impact variety known but not listed.
+Response and recovery costs
In-person
+Days
Social media or networking
+Hours
Documents
+Minutes
Months
+Compromise does not apply in the context of the security event.
+Never
+Seconds
+Unknown
SMS or texting
+Weeks
Phone
-Website
-Other
-Instant messaging
-Removable storage media
-Software
+Years
Customer (B2C)
+Days
End-user or regular employee
+Hours
Human resources staff
+Minutes
Finance or accounting staff
+Months
Containment does not apply in the context of the security event.
+Never
+Seconds
+Unknown
Helpdesk staff
+Weeks
Executive or upper management
-Cashier, teller or waiter
-Manager or supervisor
-Former employee
-Security guard
-Other
-Auditor
-Maintenance or janitorial staff
-Call center staff
-Partner (B2B)
-System or network administrator
-Software developer
+Years
Online scam or hoax (e.g., scareware, 419 scam, auction fraud)
+Days
Phishing (or any type of *ishing)
+Hours
Elicitation (subtle extraction of info through conversation)
+Minutes
Months
+Discovery does not apply in the context of the security event.
+Never
+Seconds
+Unknown
Spam (unsolicited or undesired email and advertisements)
+Weeks
Influence tactics (Leveraging authority or obligation, framing, etc)
-Propaganda or disinformation
-Forgery or counterfeiting (fake hardware, software, documents, etc)
-Bribery or solicitation
-Other
-Pretexting (dialogue leveraging invented scenario)
-Extortion or blackmail
-Baiting (planting infected media)
+Years
Hazardous material
+Days
Extreme temperature
+Hours
Water leak
+Minutes
Hurricane
+Months
Ice and snow
+Exfiltration does not apply in the context of the security event.
Meteorite
+Never
Other
+Seconds
Pathogen
-Landslide
-Tornado
-Unknown
Earthquake
+Weeks
Particulate matter (e.g., dust, smoke)
-Power failure or fluctuation
-Electromagnetic interference (EMI)
-Humidity
-Tsunami
-Electrostatic discharge (ESD)
-Deterioration and degradation
-Volcanic eruption
-Lightning
-Wind
-Flood
-Vermin
-Fire
+Years
Random error (no reason, no fault)
+AED - UAE Dirham
Carelessness
+AFN - Afghani
Other
+ALL - Lek
Unknown
+AMD - Armenian Dram
Inadequate or insufficient processes
+ANG - Netherlands Antillean Guilder
Inadequate or insufficient technology resources
+AOA - Kwanza
Inadequate or insufficient personnel
+ARS - Argentine Peso
AUD - Australian Dollar
+Disposal error
+AWG - Aruban Florin
Omission (something intended, but not done)
+AZN - Azerbaijanian Manat
Loss or misplacement
+BAM - Convertible Mark
Unknown
+BBD - Barbados Dollar
Maintenance error
+BDT - Taka
Misinformation (unintentionally giving false info)
+BGN - Bulgarian Lev
Physical accidents (e.g., drops, bumps, spills)
+BHD - Bahraini Dinar
Publishing error (private info to public doc or site)
+BIF - Burundi Franc
Technical malfunction or glitch
+BMD - Bermudian Dollar
Poor capacity planning
+BND - Brunei Dollar
Other
+BOB - Boliviano
Programming error (flaws or bugs in custom code)
+BRL - Brazilian Real
Data entry error
+BSD - Bahamian Dollar
Gaffe (social or verbal slip)
+BTN - Ngultrum
Misconfiguration
+BWP - Pula
Misdelivery (send wrong info or to wrong recipient)
+BYR - Belarussian Ruble
Classification or labeling error
+BZD - Belize Dollar
CAD - Canadian Dollar
+Physical access within corporate facility
+CDF - Congolese Franc
Remote access connection to corporate network (i.e. VPN)
+CHF - Swiss Franc
Local network access within corporate facility
+CLP - Chilean Peso
Unknown
+CNY - Yuan Renminbi
Non-corporate facilities or networks
+COP - Colombian Peso
Other
+CRC - Costa Rican Colon
CUC - Peso Convertible
+The misuse action resulted in additional permissions
+CUP - Cuban Peso
The misuse action exfiltrated data from the victim
+CVE - Cape Verde Escudo
The misuse action infiltrated the victim
+CZK - Czech Koruna
DJF - Djibouti Franc
+Use of unapproved software or services
+DKK - Danish Krone
Storage or distribution of illicit content
+DOP - Dominican Peso
Unapproved workaround or shortcut
+DZD - Algerian Dinar
Use of unapproved hardware or devices
+EGP - Egyptian Pound
Unknown
+ERN - Nakfa
Inappropriate use of email or IM
+ETB - Ethiopian Birr
Abuse of physical access to asset
+EUR - Euro
Other+
FJD - Fiji Dollar
FKP - Falkland Islands Pound
+Inappropriate use of network or Web access
+GBP - Pound Sterling
Handling of data in an unapproved manner
+GEL - Lari
Abuse of system access privileges
+GGP - Guernsey pound
Abuse of private or entrusted knowledge
+GHS - Ghana Cedi
+GIP - Gibraltar Pound
Physical access or connection (i.e., at keyboard or via cable)
+GMD - Dalasi
Remote shell
+GNF - Guinea Franc
Unknown
+GTQ - Quetzal
Superset of 'Desktop sharing' and '3rd party desktop'. Please use in place of the other two
+GYD - Guyana Dollar
Backdoor or command and control channel
+HKD - Hong Kong Dollar
Web application
+HNL - Lempira
Graphical desktop sharing (RDP, VNC, PCAnywhere, Citrix)
+HRK - Croatian Kuna
3rd party online desktop sharing (LogMeIn, Go2Assist)
+HTG - Gourde
Partner connection or credential
+HUF - Forint
VPN
+IDR - Rupiah
Other
+ILS - New Israeli Sheqel
IMP - Isle of Man Pound
+The hacking action resulted in additional permissions
+INR - Indian Rupee
The hacking action exfiltrated data from the victim
+IQD - Iraqi Dinar
The hacking action infiltrated the victim
+IRR - Iranian Rial
ISK - Iceland Krona
+Cross-site scripting
+JEP - Jersey pound
HTTP Response Splitting
+JMD - Jamaican Dollar
Unknown
+JOD - Jordanian Dinar
Buffer overflow
+JPY - Yen
Format string attack
+KES - Kenyan Shilling
LDAP injection
+KGS - Som
SSI injection
+KHR - Riel
Man-in-the-middle attack
+KMF - Comoro Franc
Path traversal
+KPW - North Korean Won
URL redirector abuse
+KRW - South Korean Won
Use of Backdoor or C2 channel
+KWD - Kuwaiti Dinar
Mail command injection
+KYD - Cayman Islands Dollar
Virtual machine escape
+KZT - Tenge
OS commanding
+LAK - Kip
Soap array abuse
+LBP - Lebanese Pound
Footprinting and fingerprinting
+LKR - Sri Lanka Rupee
Cryptanalysis
+LRD - Liberian Dollar
SQL injection
+LSL - Loti
XML external entities
+LTL - Lithuanian Litas
Abuse of functionality
+LVL - Latvian Lats
XML injection
+LYD - Libyan Dinar
Routing detour
+MAD - Moroccan Dirham
HTTP response smuggling
+MDL - Moldovan Leu
Forced browsing or predictable resource location
+MGA - Malagasy Ariary
Cache poisoning
+MKD - Denar
Null byte injection
+MMK - Kyat
Reverse engineering
+MNT - Tugrik
Brute force or password guessing attacks
+MOP - Pataca
Fuzz testing
+MRO - Ouguiya
Offline password or key cracking (e.g., rainbow tables, Hashcat, JtR)
+MUR - Mauritius Rupee
Cross-site request forgery
+MVR - Rufiyaa
XML entity expansion
+MWK - Kwacha
Remote file inclusion
+MXN - Mexican Peso
Session fixation
+MYR - Malaysian Ringgit
Integer overflows
+MZN - Mozambique Metical
XQuery injection
+NAD - Namibia Dollar
Pass-the-hash
+NGN - Naira
XML attribute blowup
+NIO - Cordoba Oro
Credential or session prediction
+NOK - Norwegian Krone
Use of stolen authentication credentials
+NPR - Nepalese Rupee
HTTP request smuggling
+NZD - New Zealand Dollar
XPath injection
+OMR - Rial Omani
Other
+PAB - Balboa
Denial of service
+PEN - Nuevo Sol
Special element injection
+PGK - Kina
HTTP request splitting
+PHP - Philippine Peso
Session replay
+PKR - Pakistan Rupee
+PLN - Zloty
Personal vehicle
+PYG - Guarani
Given temporary visitor access
+QAR - Qatari Rial
Public facility or area
+RON - New Romanian Leu
Victim outdoor grounds
+RSD - Serbian Dinar
The location was uncontrolled (public)
+RUB - Russian Ruble
Partner vehicle (e.g., delivery truck)
+RWF - Rwanda Franc
Victim private or work area (e.g., office space)
+SAR - Saudi Riyal
Victim high security area (e.g., server room, R&D labs)
+SBD - Solomon Islands Dollar
Partner facility or area
+SCR - Seychelles Rupee
Personal residence
+SDG - Sudanese Pound
Other
+SEK - Swedish Krona
Public vehicle (e.g., plane, taxi)
+SGD - Singapore Dollar
Unknown
+SHP - Saint Helena Pound
Victim public or customer area (e.g., lobby, storefront)
+SLL - Leone
Held privileged access to location
+SOS - Somali Shilling
SPL - Seborga Luigino
+The physical action resulted in additional permissions
+SRD - Surinam Dollar
The physical action exfiltrated data from the victim
+STD - Dobra
The physical action infiltrated the victim
+SVC - El Salvador Colon
SYP - Syrian Pound
+Installing card skimming device
+SZL - Lilangeni
Snooping (sneak about to gain info or access)
+THB - Baht
Tampering (alter physical form or function)
+TJS - Somoni
Unknown
+TMT - Turkmenistan New Manat
Theft (taking assets without permission)
+TND - Tunisian Dinar
Connection
+TOP - Pa’anga
Surveillance (monitoring and observation)
+TRY - Turkish Lira
Assault (threats or acts of physical violence)
+TTD - Trinidad and Tobago Dollar
Other
+TVD - Tuvalu Dollar
Wiretapping (Physical tap to comms line)
+TWD - New Taiwan Dollar
Bypassed physical barriers or controls
+TZS - Tanzanian Shilling
Destruction (deliberate damaging or disabling)
+UAH - Hryvnia
Disabled physical barriers or controls
+UGX - Uganda Shilling
+USD - US Dollar
Source code
+UYU - Peso Uruguayo
Personal or identifying information (e.g., addr, ID#, credit score)
+UZS - Uzbekistan Sum
Unknown
+VEF - Bolivar
Medical records
+VND - Dong
Classified information
+VUV - Vatu
System information (e.g., config info, open services)
+WST - Tala
Digital certificate
+XAF - CFA Franc BEAC
Trade secrets
+XCD - East Caribbean Dollar
Sensitive internal data (e.g., plans, reports, emails)
+XDR - SDR (Special Drawing Right)
Virtual currency
+XOF - CFA Franc BCEAO
Copyrighted material
+XPF - CFP Franc
Authentication credentials (e.g., pwds, OTPs, biometrics)
+YER - Yemeni Rial
Other
+ZAR - South African Rand
Payment card data (e.g., PAN, PIN, CVV2, Expiration)
+ZMK - Zambian Kwacha
Bank account data
+ZWD - Zimbabwean Dollar A/06
Days
+Hours
+Minutes
+Months
+NA
+Never
@@ -28865,36 +28802,6 @@ veris namespace available in JSON format at -NA
-Months
-Days
-Years
-Hours
-Unknown
@@ -28907,9 +28814,102 @@ veris namespace available in JSON format at -Minutes
+Years
+Bank account data
+Classified information
+Copyrighted material
+Authentication credentials (e.g., pwds, OTPs, biometrics)
+Digital certificate
+Sensitive internal data (e.g., plans, reports, emails)
+Medical records
+Other
+Payment card data (e.g., PAN, PIN, CVV2, Expiration)
+Personal or identifying information (e.g., addr, ID#, credit score)
+Trade secrets
+Source code
+System information (e.g., config info, open services)
+Unknown
+Virtual currency