diff --git a/objects.html b/objects.html
index 42cee29..82d3366 100755
--- a/objects.html
+++ b/objects.html
@@ -577,6 +577,36 @@ ail-leak is a MISP object available in JSON format at first-seen
datetime
When the leak has been accessible or seen for the first time.
++
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
++
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
++
duplicate_number
counter
duplicate
text
Duplicate of the existing leaks.
++
raw-data
attachment
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
--
sensor
text
The AIL sensor uuid where the leak was processed and analysed.
--
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
--
origin
text
first-seen
datetime
When the leak has been accessible or seen for the first time.
--
duplicate
sensor
text
Duplicate of the existing leaks.
+The AIL sensor uuid where the leak was processed and analysed.
@@ -705,20 +705,20 @@ android-permission is a MISP object available in JSON format at
comment
comment
permission
text
Comment about the set of android permission(s)
+Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
permission
text
comment
comment
Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
+Comment about the set of android permission(s)
@@ -763,6 +763,16 @@ annotation is a MISP object available in JSON format at
type
text
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
++
text
text
ref
link
Reference(s) to the annotation
++
modification-date
datetime
type
text
creation-date
datetime
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
+Initial creation of the annotation
+
ref
link
Reference(s) to the annotation
--
creation-date
datetime
Initial creation of the annotation
--
asn
-AS
country
text
Autonomous System Number
+Country code of the main location of the autonomous system
++
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
@@ -891,40 +901,10 @@ asn is a MISP object available in JSON format at
export
import
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
country
text
Country code of the main location of the autonomous system
--
description
text
Description of the autonomous system
--
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
@@ -941,10 +921,10 @@ asn is a MISP object available in JSON format at
import
export
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
+The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
description
text
Description of the autonomous system
++
asn
AS
Autonomous System Number
++
text
-text
Free text value to attach to the file
--
datetime
datetime
text
text
Free text value to attach to the file
++
software
text
branch
currency-code
text
Branch code or name
+Currency of the account. ['USD', 'EUR']
text
text
swift
bic
A description of the bank account.
+SWIFT or BIC as defined in ISO 9362.
@@ -1107,10 +1107,60 @@ bank-account is a MISP object available in JSON format at
iban
iban
report-code
text
IBAN of the bank account.
+Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic']
++
non-banking-institution
boolean
A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation.
++
date-balance
datetime
When the balance was reported.
++
branch
text
Branch code or name
++
opened
datetime
When the account was opened.
++
account
bank-account-nr
Account number
@@ -1127,20 +1177,10 @@ bank-account is a MISP object available in JSON format at
date-balance
datetime
When the balance was reported.
--
personal-account-type
text
text
Account type. ['A - Business', 'B - Personal Current', 'C - Savings', 'D - Trust Account', 'E - Trading Account', 'O - Other']
+A description of the bank account.
@@ -1167,13 +1207,13 @@ bank-account is a MISP object available in JSON format at
account
bank-account-nr
closed
datetime
Account number
+When the account was closed.
+
report-code
-text
Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic']
--
swift
bic
SWIFT or BIC as defined in ISO 9362.
--
currency-code
text
Currency of the account. ['USD', 'EUR']
--
balance
text
The balance of the account after the suspicious transaction was processed.
--
opened
datetime
When the account was opened.
--
beneficiary-comment
text
Comment about the final beneficiary.
--
closed
datetime
When the account was closed.
--
client-_number
text
non-banking-institution
boolean
balance
text
A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation.
+The balance of the account after the suspicious transaction was processed.
++
beneficiary-comment
text
Comment about the final beneficiary.
++
iban
iban
IBAN of the bank account.
++
personal-account-type
text
Account type. ['A - Business', 'B - Personal Current', 'C - Savings', 'D - Trust Account', 'E - Trading Account', 'O - Other']
@@ -1315,6 +1315,36 @@ coin-address is a MISP object available in JSON format at
symbol
text
The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
++
first-seen
datetime
First time this payment destination address has been seen
++
last-seen
datetime
Last time this payment destination address has been seen
++
text
text
first-seen
datetime
First time this payment destination address has been seen
--
symbol
text
The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
--
last-seen
datetime
Last time this payment destination address has been seen
--
cookie-name
+type
text
Name of the cookie (if splitted)
+Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
text
text
A description of the cookie.
--
cookie-value
text
type
cookie-name
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
+Name of the cookie (if splitted)
text
text
A description of the cookie.
++
type
+text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
++
username
text
notification
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
++
origin
text
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
--
format
text
notification
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
--
comment
-comment
cc-number
cc-number
A description of the card.
--
version
text
Version of the card.
+credit-card number as encoded on the card.
@@ -1659,10 +1649,20 @@ credit-card is a MISP object available in JSON format at
cc-number
cc-number
version
text
credit-card number as encoded on the card.
+Version of the card.
++
comment
comment
A description of the card.
@@ -1707,6 +1707,36 @@ ddos is a MISP object available in JSON format at
src-port
port
Port originating the attack
++
total-bps
counter
Bits per second
++
domain-dst
domain
Destination domain (victim)
++
text
text
ip-dst
ip-dst
first-seen
datetime
Destination IP (victim)
+Beginning of the attack
++
last-seen
datetime
End of the attack
++
dst-port
port
Destination port of the attack
@@ -1747,26 +1797,6 @@ ddos is a MISP object available in JSON format at
dst-port
port
Destination port of the attack
--
first-seen
datetime
Beginning of the attack
--
total-pps
counter
last-seen
datetime
ip-dst
ip-dst
End of the attack
--
src-port
port
Port originating the attack
--
domain-dst
domain
Destination domain (victim)
--
total-bps
counter
Bits per second
+Destination IP (victim)
@@ -1855,56 +1855,6 @@ diameter-attack is a MISP object available in JSON format at
text
text
A description of the attack seen.
--
Destination-Realm
text
Destination-Realm.
--
Destination-Host
text
Destination-Host.
--
Origin-Realm
text
Origin-Realm.
--
IdrFlags
text
IDR-Flags.
--
first-seen
datetime
CmdCode
Username
text
A decimal representation of the diameter Command Code.
--
Origin-Host
text
Origin-Host.
--
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
+Username (in this case, usually the IMSI).
@@ -1965,10 +1895,80 @@ diameter-attack is a MISP object available in JSON format at
Username
IdrFlags
text
Username (in this case, usually the IMSI).
+IDR-Flags.
++
Origin-Host
text
Origin-Host.
++
Destination-Host
text
Destination-Host.
++
CmdCode
text
A decimal representation of the diameter Command Code.
++
text
text
A description of the attack seen.
++
Destination-Realm
text
Destination-Realm.
++
Origin-Realm
text
Origin-Realm.
++
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
@@ -2013,26 +2013,6 @@ domain-ip is a MISP object available in JSON format at
ip
ip-dst
IP Address
--
text
text
A description of the tuple
--
first-seen
datetime
text
text
A description of the tuple
++
ip
ip-dst
IP Address
++
arch
+entrypoint-address
text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
--
number-sections
counter
Number of sections
--
text
text
Free text value to attach to the ELF
--
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
+Address of the entry point
@@ -2151,10 +2121,40 @@ elf is a MISP object available in JSON format at
entrypoint-address
os_abi
text
Address of the entry point
+Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
++
text
text
Free text value to attach to the ELF
++
number-sections
counter
Number of sections
++
arch
text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
@@ -2199,13 +2199,23 @@ elf-section is a MISP object available in JSON format at
type
text
ssdeep
ssdeep
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
+Fuzzy hash using context triggered piecewise hashes (CTPH)
+
+
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+
sha1
-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
name
text
Name of the section
--
flag
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
--
entropy
float
sha384
sha384
sha512/256
sha512/256
Secure Hash Algorithm 2 (384 bits)
+Secure Hash Algorithm 2 (256 bits)
flag
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
++
name
text
Name of the section
++
md5
md5
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
size-in-bytes
size-in-bytes
sha512/256
sha512/256
sha512/224
sha512/224
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (224 bits)
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
header
-email-header
mime-boundary
email-mime-boundary
Full headers
+MIME Boundary
@@ -2407,56 +2407,6 @@ email is a MISP object available in JSON format at
mime-boundary
email-mime-boundary
MIME Boundary
--
message-id
email-message-id
Message ID
--
from-display-name
email-src-display-name
Display name of the sender
--
attachment
email-attachment
Attachment
--
send-date
datetime
Date the email has been sent
--
x-mailer
email-x-mailer
subject
email-subject
Subject
--
screenshot
attachment
Screenshot of email
--
to-display-name
email-dst-display-name
Display name of the receiver
--
cc
email-dst
return-path
text
reply-to
email-reply-to
Message return path
+Email address the reply will be sent to
reply-to
email-reply-to
to-display-name
email-dst-display-name
Email address the reply will be sent to
+Display name of the receiver
++
email-body
email-body
Body of the email
++
subject
email-subject
Subject
@@ -2537,6 +2477,46 @@ email is a MISP object available in JSON format at
attachment
email-attachment
Attachment
++
message-id
email-message-id
Message ID
++
screenshot
attachment
Screenshot of email
++
from-display-name
email-src-display-name
Display name of the sender
++
thread-index
email-thread-index
header
email-header
Full headers
++
send-date
datetime
Date the email has been sent
++
return-path
text
Message return path
++
certificate
-x509-fingerprint-sha1
ssdeep
ssdeep
Certificate value if the binary is signed with another authentication scheme than authenticode
--
text
text
Free text value to attach to the file
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
mimetype
text
Mime type
--
entropy
float
Entropy of the whole file
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
+Fuzzy hash using context triggered piecewise hashes (CTPH)
@@ -2665,20 +2615,30 @@ file is a MISP object available in JSON format at
md5
md5
text
text
[Insecure] MD5 hash (128 bits)
+Free text value to attach to the file
+
size-in-bytes
size-in-bytes
entropy
float
Size of the file, in bytes
+Entropy of the whole file
++
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
@@ -2695,6 +2655,56 @@ file is a MISP object available in JSON format at
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
mimetype
text
Mime type
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
tlsh
tlsh
sha512/256
sha512/256
md5
md5
Secure Hash Algorithm 2 (256 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
+[Insecure] MD5 hash (128 bits)
@@ -2735,13 +2735,13 @@ file is a MISP object available in JSON format at
sha512/224
sha512/224
size-in-bytes
size-in-bytes
Secure Hash Algorithm 2 (224 bits)
+Size of the file, in bytes
+
sha224
-sha224
pattern-in-file
pattern-in-file
Secure Hash Algorithm 2 (224 bits)
+Pattern that can be found in the file
@@ -2775,10 +2775,20 @@ file is a MISP object available in JSON format at
ssdeep
ssdeep
sha512/224
sha512/224
Fuzzy hash using context triggered piecewise hashes (CTPH)
+Secure Hash Algorithm 2 (224 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
@@ -2823,6 +2833,46 @@ geolocation is a MISP object available in JSON format at
first-seen
datetime
When the location was seen for the first time.
++
city
text
City.
++
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
++
text
text
country
text
Country.
++
altitude
float
city
text
City.
--
region
text
country
text
Country.
--
first-seen
datetime
When the location was seen for the first time.
--
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
--
GtpImsi
+GtpMsisdn
text
GTP IMSI (International mobile subscriber identity).
+GTP MSISDN.
text
text
ipDest
ip-dst
A description of the GTP attack.
+IP destination address.
+
GtpMsisdn
+PortDest
text
GTP MSISDN.
+Destination port.
++
text
text
A description of the GTP attack.
++
GtpVersion
text
GTP version ['0', '1', '2']
++
GtpImsi
text
GTP IMSI (International mobile subscriber identity).
@@ -3001,13 +3041,33 @@ gtp-attack is a MISP object available in JSON format at
ipDest
ip-dst
GtpMessageType
text
IP destination address.
+GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
+
+
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
++
PortSrc
port
Source port.
+
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
--
GtpVersion
text
GTP version ['0', '1', '2']
--
PortSrc
port
Source port.
--
GtpMessageType
text
GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
--
PortDest
text
Destination port.
--
text
-text
HTTP Request comment
--
uri
uri
Request URI
--
basicauth-user
text
HTTP Basic Authentication Username
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
--
basicauth-password
text
HTTP Basic Authentication Password
--
host
hostname
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
--
proxy-password
proxy-user
text
HTTP Proxy Password
+HTTP Proxy Username
@@ -3229,6 +3179,56 @@ http-request is a MISP object available in JSON format at
uri
uri
Request URI
++
text
text
HTTP Request comment
++
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
++
basicauth-user
text
HTTP Basic Authentication Username
++
basicauth-password
text
HTTP Basic Authentication Password
++
url
url
proxy-user
cookie
text
HTTP Proxy Username
+An HTTP cookie previously sent by the server with Set-Cookie
++
proxy-password
text
HTTP Proxy Password
@@ -3287,10 +3297,10 @@ ip-port is a MISP object available in JSON format at
text
text
first-seen
datetime
Description of the tuple
+First time the tuple has been seen
@@ -3307,6 +3317,26 @@ ip-port is a MISP object available in JSON format at
text
text
Description of the tuple
++
src-port
port
Source port
++
dst-port
port
first-seen
datetime
First time the tuple has been seen
--
src-port
port
Source port
--
ip-dst
-ip-dst
Destination IP address
--
ip-src
ip-src
Source IP Address
--
description
text
Type of detected software ie software, malware
--
first-seen
datetime
last-seen
datetime
Last seen of the SSL/TLS handshake
++
ja3-fingerprint-md5
md5
last-seen
datetime
description
text
Last seen of the SSL/TLS handshake
+Type of detected software ie software, malware
+
+
ip-src
ip-src
Source IP Address
++
ip-dst
ip-dst
Destination IP address
+
entrypoint-address
+text
Address of the entry point
++
type
text
name
text
Binary’s name
++
text
text
entrypoint-address
text
Address of the entry point
--
name
text
Binary’s name
--
number-sections
counter
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
text
text
entropy
float
Entropy of the whole section
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha1
sha1
entropy
float
md5
md5
Entropy of the whole section
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+[Insecure] MD5 hash (128 bits)
md5
md5
sha256
sha256
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -3641,10 +3691,10 @@ macho-section is a MISP object available in JSON format at
sha512/256
sha512/256
sha512/224
sha512/224
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (224 bits)
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
removal-date
-datetime
When the microblog post was removed
--
modification-date
datetime
Last update of the microblog post
--
link
url
Link into the microblog post
--
post
text
username-quoted
text
Username who are quoted into the microblog post
--
username
text
username-quoted
text
Username who are quoted into the microblog post
++
url
url
link
url
Link into the microblog post
++
modification-date
datetime
Last update of the microblog post
++
creation-date
datetime
removal-date
datetime
When the microblog post was removed
++
ip_version
+flow-count
counter
IP version of this flow
--
dst-port
port
Destination port of the netflow
--
ip-protocol-number
size-in-bytes
IP protocol number of this flow
--
ip-dst
ip-dst
IP address destination of the netflow
--
ip-src
ip-src
IP address source of the netflow
--
tcp-flags
text
TCP flags of the flow
--
first-packet-seen
datetime
First packet seen in this flow
--
packet-count
counter
Packets counted in this flow
+Flows counted in this flow
@@ -4025,16 +3965,6 @@ netflow is a MISP object available in JSON format at
direction
text
Direction of this flow ['Ingress', 'Egress']
--
dst-as
AS
flow-count
src-as
AS
Source AS number for this flow
++
ip-src
ip-src
IP address source of the netflow
++
packet-count
counter
Flows counted in this flow
+Packets counted in this flow
++
ip-protocol-number
size-in-bytes
IP protocol number of this flow
@@ -4065,13 +4025,23 @@ netflow is a MISP object available in JSON format at
src-as
AS
byte-count
counter
Source AS number for this flow
+Bytes counted in this flow
+
+
direction
text
Direction of this flow ['Ingress', 'Egress']
+
byte-count
+ip-dst
ip-dst
IP address destination of the netflow
++
ip_version
counter
Bytes counted in this flow
+IP version of this flow
++
first-packet-seen
datetime
First packet seen in this flow
++
dst-port
port
Destination port of the netflow
++
tcp-flags
text
TCP flags of the flow
@@ -4153,10 +4163,30 @@ passive-dns is a MISP object available in JSON format at
count
counter
zone_time_first
datetime
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers.
+First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
sensor_id
text
Sensor information where the record was seen
++
origin
text
Origin of the Passive DNS response
@@ -4173,13 +4203,13 @@ passive-dns is a MISP object available in JSON format at
rrtype
rdata
text
Resource Record type as seen by the passive DNS. ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
+Resource records of the queried resource
+
sensor_id
-text
time_first
datetime
Sensor information where the record was seen
--
rdata
text
Resource records of the queried resource
--
origin
text
Origin of the Passive DNS response
+First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
@@ -4243,20 +4253,20 @@ passive-dns is a MISP object available in JSON format at
zone_time_first
datetime
count
counter
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
+How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers.
time_first
datetime
rrtype
text
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
+Resource Record type as seen by the passive DNS. ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
@@ -4301,36 +4311,6 @@ paste is a MISP object available in JSON format at
last-seen
datetime
When the paste has been accessible or seen for the last time.
--
paste
text
Raw text of the paste or post
--
origin
text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
--
first-seen
datetime
last-seen
datetime
When the paste has been accessible or seen for the last time.
++
paste
text
Raw text of the paste or post
++
url
url
origin
text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
++
internal-filename
-filename
entrypoint-address
text
InternalFilename in the resources
+Address of the entry point
number-sections
counter
file-version
text
Number of sections
+FileVersion in the resources
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
--
company-name
text
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
imphash
imphash
text
text
compilation-timestamp
datetime
Free text value to attach to the PE
+Compilation timestamp defined in the PE header
+
product-version
text
number-sections
counter
ProductVersion in the resources
+Number of sections
@@ -4499,40 +4489,20 @@ pe is a MISP object available in JSON format at
entrypoint-section-at-position
text
pehash
pehash
Name of the section and position of the section in the PE
+Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
+
legal-copyright
product-version
text
LegalCopyright in the resources
--
file-version
text
FileVersion in the resources
--
product-name
text
ProductName in the resources
+ProductVersion in the resources
@@ -4559,10 +4529,30 @@ pe is a MISP object available in JSON format at
entrypoint-address
entrypoint-section-at-position
text
Address of the entry point
+Name of the section and position of the section in the PE
++
product-name
text
ProductName in the resources
++
text
text
Free text value to attach to the PE
legal-copyright
text
LegalCopyright in the resources
++
internal-filename
filename
InternalFilename in the resources
++
ssdeep
+ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
text
text
entropy
float
Entropy of the whole section
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha1
sha1
entropy
float
characteristic
text
Entropy of the whole section
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+Characteristic of the section ['read', 'write', 'executable']
@@ -4677,6 +4727,16 @@ pe-section is a MISP object available in JSON format at
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
size-in-bytes
size-in-bytes
sha512/256
sha512/256
sha512/224
sha512/224
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (224 bits)
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
characteristic
text
Characteristic of the section ['read', 'write', 'executable']
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
last-name
-last-name
passport-expiration
passport-expiration
Last name of a natural person.
--
text
text
A description of the person or identity.
+The expiration date of a passport.
@@ -4825,20 +4825,30 @@ person is a MISP object available in JSON format at
mothers-name
social-security-number
text
Mother name, father, second name or other names following country’s regulation.
+Social security number
social-security-number
text
nationality
nationality
Social security number
+The nationality of a natural person.
++
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
@@ -4865,10 +4875,10 @@ person is a MISP object available in JSON format at
gender
gender
first-name
first-name
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
+First name of a natural person.
@@ -4885,6 +4895,36 @@ person is a MISP object available in JSON format at
text
text
A description of the person or identity.
++
mothers-name
text
Mother name, father, second name or other names following country’s regulation.
++
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
++
passport-number
passport-number
passport-expiration
passport-expiration
last-name
last-name
The expiration date of a passport.
--
nationality
nationality
The nationality of a natural person.
--
first-name
first-name
First name of a natural person.
--
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
+Last name of a natural person.
@@ -4945,13 +4955,13 @@ person is a MISP object available in JSON format at
redress-number
redress-number
gender
gender
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
+The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
+
text
-text
A description of the phone.
--
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
--
imsi
text
gummei
text
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+A description of the phone.
+
imei
+text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
++
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
++
msisdn
text
tmsi
gummei
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
+Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
@@ -5131,90 +5141,10 @@ r2graphity is a MISP object available in JSON format at
local-references
get-proc-address
counter
Amount of API calls inside a code section
--
callbacks
counter
Amount of callbacks (functions started as thread)
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
memory-allocations
counter
Amount of memory allocations
--
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
create-thread
counter
Amount of calls to CreateThread
--
referenced-strings
counter
Amount of referenced strings
+Amount of calls to GetProcAddress
@@ -5231,20 +5161,40 @@ r2graphity is a MISP object available in JSON format at
text
text
dangling-strings
counter
Description of the r2graphity object
+Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
gml
attachment
ratio-string
float
Graph export in G>raph Modelling Language format
+Ratio: amount of referenced strings per kilobyte of code section
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
++
callbacks
counter
Amount of callbacks (functions started as thread)
@@ -5261,6 +5211,46 @@ r2graphity is a MISP object available in JSON format at
callback-largest
counter
Largest callback
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
text
text
Description of the r2graphity object
++
local-references
counter
Amount of API calls inside a code section
++
ratio-api
float
not-referenced-strings
miss-api
counter
Amount of not referenced strings
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
--
callback-largest
counter
Largest callback
+Amount of API call reference that does not resolve to a function offset
@@ -5341,10 +5291,70 @@ r2graphity is a MISP object available in JSON format at
get-proc-address
referenced-strings
counter
Amount of calls to GetProcAddress
+Amount of referenced strings
++
memory-allocations
counter
Amount of memory allocations
++
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
++
not-referenced-strings
counter
Amount of not referenced strings
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
gml
attachment
Graph export in G>raph Modelling Language format
++
create-thread
counter
Amount of calls to CreateThread
@@ -5399,16 +5409,6 @@ regexp is a MISP object available in JSON format at
regexp
text
regexp
--
regexp-type
text
regexp
text
regexp
++
comment
comment
hive
text
Hive used to store the registry key (file on disk)
++
data-type
text
name
text
Name of the registry key
--
last-modified
datetime
root-keys
text
Root key of the Windows registry (extracted from the key) ['HKCC', 'HKCR', 'HKCU', 'HKDD', 'HKEY_CLASSES_ROOT', 'HKEY_CURRENT_CONFIG', 'HKEY_CURRENT_USER', 'HKEY_DYN_DATA', 'HKEY_LOCAL_MACHINE', 'HKEY_PERFORMANCE_DATA', 'HKEY_USERS', 'HKLM', 'HKPD', 'HKU']
--
hive
text
Hive used to store the registry key (file on disk)
--
data
text
name
text
Name of the registry key
++
key
regkey
root-keys
text
Root key of the Windows registry (extracted from the key) ['HKCC', 'HKCR', 'HKCU', 'HKDD', 'HKEY_CLASSES_ROOT', 'HKEY_CURRENT_CONFIG', 'HKEY_CURRENT_USER', 'HKEY_DYN_DATA', 'HKEY_LOCAL_MACHINE', 'HKEY_PERFORMANCE_DATA', 'HKEY_USERS', 'HKLM', 'HKPD', 'HKU']
++
constituency
-text
Constituency of the RTIR ticket
--
subject
text
Subject of the RTIR ticket
--
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
--
ticket-number
text
ip
ip-dst
IPs automatically extracted from the RTIR ticket
--
classification
text
subject
text
Subject of the RTIR ticket
++
constituency
text
Constituency of the RTIR ticket
++
status
text
ip
ip-dst
IPs automatically extracted from the RTIR ticket
++
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
++
score
-text
Score
--
web-sandbox
text
A web sandbox where results are publicly available via an URL ['malwr', 'hybrid-analysis']
--
results
text
Freetext result values
--
on-premise-sandbox
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
--
sandbox-type
text
raw-report
text
Raw report from sandbox
--
permalink
link
score
text
Score
++
saas-sandbox
text
raw-report
text
Raw report from sandbox
++
on-premise-sandbox
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
++
results
text
Freetext result values
++
web-sandbox
text
A web sandbox where results are publicly available via an URL ['malwr', 'hybrid-analysis']
++
text
-text
Additional signature description
--
datetime
datetime
text
text
Additional signature description
++
software
text
MapVersion
MapMscGT
text
Map version. ['1', '2', '3']
+MAP MSC GT. Phone number.
+
SccpCdSSN
-text
first-seen
datetime
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
--
MapApplicationContext
text
MAP application context in OID format.
--
MapVlrGT
text
MAP VLR GT. Phone number.
--
MapUssdContent
text
MAP USSD Content.
--
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
--
MapSmsTypeNumber
text
MAP SMS TypeNumber.
+When the attack has been seen for the first time.
@@ -6037,16 +5987,116 @@ ss7-attack is a MISP object available in JSON format at
MapMscGT
SccpCdGT
text
MAP MSC GT. Phone number.
+Signaling Connection Control Part (SCCP) CdGT - Phone number.
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
++
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
++
MapSmscGT
text
MAP SMSC. Phone number.
++
MapVersion
text
Map version. ['1', '2', '3']
++
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
++
text
text
A description of the attack seen via SS7 logging.
++
MapUssdCoding
text
MAP USSD Content.
++
MapVlrGT
text
MAP VLR GT. Phone number.
++
MapSmsTP-PID
text
MAP SMS TP-PID.
++
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
MapMsisdn
text
text
text
A description of the attack seen via SS7 logging.
--
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
--
MapSmscGT
text
MAP SMSC. Phone number.
--
MapUssdCoding
text
MAP USSD Content.
--
first-seen
datetime
When the attack has been seen for the first time.
--
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
--
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
--
MapImsi
text
MAP IMSI. Phone number starting with MCC/MNC.
--
MapGmlc
text
MAP GMLC. Phone number.
--
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
--
MapSmsTP-PID
text
MAP SMS TP-PID.
--
SccpCdPC
text
MapSmsTypeNumber
text
MAP SMS TypeNumber.
++
MapApplicationContext
text
MAP application context in OID format.
++
MapImsi
text
MAP IMSI. Phone number starting with MCC/MNC.
++
MapUssdContent
text
MAP USSD Content.
++
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
++
MapGmlc
text
MAP GMLC. Phone number.
++
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
++
text
-text
first-seen
datetime
Tor node comment.
+When the Tor node designed by the IP address has been seen for the first time.
nickname
text
router’s nickname.
++
published
datetime
flags
text
list of flag associated with the node.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
description
text
Tor node description.
--
version_line
text
nickname
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
++
version
text
router’s nickname.
+parsed version of tor, this is None if the relay’s using a new versioning scheme.
flags
text
list of flag associated with the node.
++
text
text
Tor node comment.
++
address
ip-src
IP address of the Tor node seen.
++
description
text
Tor node description.
++
fingerprint
text
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
--
address
ip-src
IP address of the Tor node seen.
--
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
--
host
+hostname
Full hostname
++
first-seen
datetime
First time this URL has been seen
++
text
text
tld
resource_path
text
Top-Level Domain
+Path (between hostname:port and query)
++
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
++
domain
domain
Full domain
++
last-seen
datetime
port
port
tld
text
Port number
+Top-Level Domain
domain_without_tld
text
port
port
Domain without Top-Level Domain
--
first-seen
datetime
First time this URL has been seen
+Port number
@@ -6531,36 +6581,6 @@ url is a MISP object available in JSON format at
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
--
resource_path
text
Path (between hostname:port and query)
--
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
--
credential
text
domain_without_tld
text
Domain without Top-Level Domain
++
url
url
domain
domain
Full domain
--
host
hostname
Full hostname
--
external
-target-external
target-email
External target organisations affected by this attack.
--
node
target-machine
Name(s) of node that was targeted.
--
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
+The email address(es) of the user targeted.
@@ -6679,36 +6669,6 @@ victim is a MISP object available in JSON format at
ip-address
ip-dst
IP address(es) of the node targeted.
--
roles
text
The list of roles targeted within the victim.
--
description
text
Description of the victim
--
classification
text
external
target-external
External target organisations affected by this attack.
++
ip-address
ip-dst
IP address(es) of the node targeted.
++
user
target-user
target-email
sectors
text
The email address(es) of the user targeted.
+The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
++
description
text
Description of the victim
++
node
target-machine
Name(s) of node that was targeted.
++
roles
text
The list of roles targeted within the victim.
@@ -6787,16 +6797,26 @@ virustotal-report is a MISP object available in JSON format at
community-score
detection-ratio
text
Community Score
+Detection Ratio
permalink
link
Permalink Reference
++
last-submission
datetime
detection-ratio
text
Detection Ratio
--
first-submission
datetime
permalink
link
community-score
text
Permalink Reference
+Community Score
+
text
+references
link
External references
++
created
datetime
First time when the vulnerability was discovered
++
summary
text
Description of the vulnerability
+Summary of the vulnerability
@@ -6895,6 +6925,26 @@ vulnerability is a MISP object available in JSON format at
text
text
Description of the vulnerability
++
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
++
id
vulnerability
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
created
datetime
First time when the vulnerability was discovered
--
summary
text
Summary of the vulnerability
--
references
link
External references
--
registrant-org
-whois-registrant-org
Registrant organisation
--
text
text
Full whois entry
--
registrar
whois-registrar
Registrar of the whois entry
--
expiration-date
datetime
registrant-name
whois-registrant-name
Registrant name
--
nameserver
hostname
Nameserver
--
modification-date
datetime
Last update of the whois entry
--
registrant-email
whois-registrant-email
registrant-phone
whois-registrant-phone
Registrant phone number
++
nameserver
hostname
Nameserver
++
text
text
Full whois entry
++
registrant-name
whois-registrant-name
Registrant name
++
registrar
whois-registrar
Registrar of the whois entry
++
domain
domain
registrant-phone
whois-registrant-phone
registrant-org
whois-registrant-org
Registrant phone number
+Registrant organisation
modification-date
datetime
Last update of the whois entry
++
creation-date
datetime
text
text
Free text description of hte certificate
--
pubkey-info-algorithm
text
Algorithm of the public key
--
validity-not-before
datetime
pubkey-info-size
text
Length of the public key (in bits)
--
validity-not-after
datetime
Certificate invalid after that date
--
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
--
pubkey-info-modulus
text
Modulus of the public key
--
pubkey-info-exponent
text
Exponent of the public key
--
serial-number
text
Serial number of the certificate
--
subject
text
x509-fingerprint-sha256
x509-fingerprint-sha256
x509-fingerprint-md5
x509-fingerprint-md5
Secure Hash Algorithm 2 (256 bits)
+[Insecure] MD5 hash (128 bits)
++
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -7281,6 +7211,46 @@ x509 is a MISP object available in JSON format at
version
text
Version of the certificate
++
pubkey-info-size
text
Length of the public key (in bits)
++
pubkey-info-modulus
text
Modulus of the public key
++
serial-number
text
Serial number of the certificate
++
issuer
text
version
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
++
text
text
Version of the certificate
+Free text description of hte certificate
++
validity-not-after
datetime
Certificate invalid after that date
++
pubkey-info-algorithm
text
Algorithm of the public key
++
pubkey-info-exponent
text
Exponent of the public key
@@ -7349,16 +7359,6 @@ yabin is a MISP object available in JSON format at
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
--
whitelist
comment
comment
comment
A description of Yara rule generated.
--
yara
yara
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
++
comment
comment
A description of Yara rule generated.
++