From 2c29e65367f6534c7d08b0afd4a4ad84cb9686e0 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Sun, 24 Sep 2017 21:37:48 +0200
Subject: [PATCH] Objects updated
---
objects.html | 2850 +-
objects.pdf | 78312 ++++++++++++++++++++++++++-----------------------
2 files changed, 42594 insertions(+), 38568 deletions(-)
diff --git a/objects.html b/objects.html
index 6964069..2483a01 100755
--- a/objects.html
+++ b/objects.html
@@ -540,20 +540,20 @@ ail-leak is a MISP object available in JSON format at type
text
+
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
text
text
origin
url
+
origin
-url
text
text
+
cookie-value
+text
+
+
cookie-name
text
cookie-value
text
cookie
cookie
type
text
-
-
cookie
cookie
+
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
@@ -723,18 +723,8 @@ credit-card is a MISP object available in JSON format at
name
text
-
-
cc-number
cc-number
issued
datetime
comment
-comment
-
-
version
text
issued
datetime
cc-number
cc-number
+
+
name
text
+
+
comment
comment
total-bps
+total-pps
counter
@@ -851,6 +851,16 @@ ddos is a MISP object available in JSON format at
total-bps
counter
+
+
dst-port
port
first-seen
datetime
+
+
src-port
port
total-pps
counter
-
-
first-seen
datetime
-
-
ip-dst
ip-dst
domain
domain
-
-
text
text
-
-
last-seen
datetime
ip
ip-dst
ip
-ip-dst
last-seen
datetime
+
+
text
text
+
+
domain
domain
number-sections
-counter
-
-
arch
text
-
-
type
text
-
-
text
text
-
-
entrypoint-address
text
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
+
number-sections
counter
+
+
type
text
Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
++
text
text
+
+
arch
text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
+
text
-text
md5
md5
+
+
sha224
sha224
+
+
size-in-bytes
size-in-bytes
type
+text
text
@@ -1165,46 +1185,6 @@ elf-section is a MISP object available in JSON format at
sha512
sha512
-
-
sha256
sha256
-
-
sha512/224
sha512/224
-
-
sha512/256
sha512/256
-
-
entropy
float
sha1
sha1
-
-
sha384
sha384
-
-
md5
md5
-
-
sha224
sha224
-
-
flag
text
+
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
sha512
sha512
+
+
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
++
sha384
sha384
+
+
sha1
sha1
+
+
sha512/224
sha512/224
+
+
sha512/256
sha512/256
+
+
ssdeep
ssdeep
+
+
name
text
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
sha256
sha256
attachment
+email-attachment
+
+
message-id
email-message-id
+
+
thread-index
email-thread-index
+
+
from
email-src
+
+
from-display-name
email-src-display-name
+
+
to
email-dst
+
+
x-mailer
email-x-mailer
+
+
send-date
datetime
+
+
subject
email-subject
from
email-src
mime-boundary
email-mime-boundary
thread-index
-email-thread-index
-
-
from-display-name
email-src-display-name
-
-
send-date
datetime
-
-
to
email-dst
-
-
mime-boundary
email-mime-boundary
-
-
attachment
email-attachment
-
-
reply-to
email-reply-to
message-id
email-message-id
-
-
x-mailer
email-x-mailer
-
-
malware-sample
-malware-sample
filename
filename
tlsh
-tlsh
pattern-in-file
pattern-in-file
text
+md5
md5
+
+
sha224
sha224
+
+
sha1
sha1
+
+
sha512/256
sha512/256
+
+
sha512
sha512
+
+
mimetype
text
@@ -1531,8 +1581,8 @@ file is a MISP object available in JSON format at
sha512
sha512
sha384
sha384
pattern-in-file
-pattern-in-file
size-in-bytes
size-in-bytes
+
sha256
sha256
authentihash
authentihash
sha512/256
-sha512/256
-
-
filename
filename
-
-
entropy
float
mimetype
ssdeep
ssdeep
+
+
malware-sample
malware-sample
+
+
text
text
@@ -1611,8 +1661,8 @@ file is a MISP object available in JSON format at
sha1
sha1
tlsh
tlsh
sha384
-sha384
-
-
md5
md5
-
-
sha224
sha224
-
-
authentihash
authentihash
-
-
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
sha256
sha256
city
-text
-
-
last-seen
datetime
longitude
float
altitude
-float
-
-
text
text
-
-
first-seen
datetime
-
-
latitude
float
longitude
float
city
text
+
+
first-seen
datetime
last-seen
datetime
+
+
text
text
+
+
altitude
float
+
+
uri
+uri
+
+
url
url
+
+
proxy-password
text
+
+
proxy-user
text
+
+
user-agent
user-agent
+
+
basicauth-user
text
+
+
host
hostname
uri
uri
referer
referer
text
-text
-
-
basicauth-password
text
proxy-password
text
-
-
url
url
-
-
user-agent
user-agent
-
-
content-type
other
method
http-method
text
text
proxy-user
-text
method
http-method
-
basicauth-user
text
-
-
referer
referer
-
+
last-seen
-datetime
ip
ip-dst
ip
-ip-dst
-
-
text
text
-
-
first-seen
datetime
last-seen
datetime
+
+
text
text
+
+
description
+text
+
+
ip-src
ip-src
first-seen
datetime
+
+
last-seen
datetime
description
text
-
-
first-seen
datetime
-
-
ip-dst
ip-dst
type
text
-
-
text
entrypoint-address
text
@@ -2231,7 +2221,17 @@ macho is a MISP object available in JSON format at
entrypoint-address
name
text
+
+
text
text
@@ -2251,10 +2251,10 @@ macho is a MISP object available in JSON format at
name
type
text
+
Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
@@ -2299,8 +2299,28 @@ macho-section is a MISP object available in JSON format at
text
text
md5
md5
+
+
sha224
sha224
+
+
size-in-bytes
size-in-bytes
sha512
-sha512
text
text
-
sha256
sha256
-
-
sha512/224
sha512/224
-
-
sha512/256
sha512/256
-
+
sha1
-sha1
sha512
sha512
md5
-md5
sha1
sha1
sha224
-sha224
sha512/224
sha512/224
+
+
sha512/256
sha512/256
+
+
ssdeep
ssdeep
size-in-bytes
-size-in-bytes
-
-
ssdeep
ssdeep
sha256
sha256
rrname
-text
count
counter
time_first
+zone_time_first
datetime
@@ -2497,7 +2497,27 @@ passive-dns is a MISP object available in JSON format at
rdata
time_first
datetime
+
+
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
++
rrname
text
@@ -2507,8 +2527,8 @@ passive-dns is a MISP object available in JSON format at
zone_time_first
datetime
rdata
text
sensor_id
-text
-
-
text
text
count
counter
-
-
zone_time_last
datetime
rrtype
sensor_id
text
@@ -2625,136 +2625,6 @@ pe is a MISP object available in JSON format at
lang-id
text
-
-
number-sections
counter
-
-
product-version
text
-
-
internal-filename
filename
-
-
impfuzzy
impfuzzy
-
-
type
text
-
-
entrypoint-address
text
-
-
company-name
text
-
-
legal-copyright
text
-
-
pehash
pehash
-
-
entrypoint-section-at-position
text
-
-
file-version
text
-
-
file-description
text
-
-
original-filename
filename
imphash
imphash
-
-
product-name
text
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
++
entrypoint-section-at-position
text
+
+
internal-filename
filename
+
+
imphash
imphash
+
+
file-description
text
+
+
lang-id
text
+
+
entrypoint-address
text
+
+
file-version
text
+
+
number-sections
counter
+
+
legal-copyright
text
+
+
pehash
pehash
+
+
product-version
text
+
+
text
text
+
+
impfuzzy
impfuzzy
+
+
company-name
text
@@ -2843,8 +2843,38 @@ pe-section is a MISP object available in JSON format at
characteristic
text
text
Characteristic of the section ['read', 'write', 'executable']
++
md5
md5
+
+
sha224
sha224
+
+
size-in-bytes
size-in-bytes
sha512
-sha512
-
-
sha256
sha256
-
-
sha512/224
sha512/224
-
-
sha512/256
sha512/256
-
-
characteristic
text
text
+
sha1
-sha1
sha512
sha512
md5
-md5
sha1
sha1
sha224
-sha224
sha512/224
sha512/224
+
+
sha512/256
sha512/256
+
+
ssdeep
ssdeep
name
text
+
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
sha256
sha256
passport-country
-passport-country
-
-
last-name
last-name
-
-
passport-number
passport-number
first-name
first-name
-
-
place-of-birth
place-of-birth
-
-
redress-number
redress-number
middle-name
middle-name
+
+
nationality
nationality
last-name
last-name
+
+
first-name
first-name
+
+
date-of-birth
date-of-birth
+
+
passport-country
passport-country
+
+
place-of-birth
place-of-birth
+
+
text
text
middle-name
middle-name
-
-
date-of-birth
date-of-birth
-
-
serial-number
+msisdn
text
@@ -3189,6 +3189,46 @@ phone is a MISP object available in JSON format at
tmsi
text
+
+
guti
text
+
+
gummei
text
+
+
first-seen
datetime
+
+
last-seen
datetime
imei
text
-
-
gummei
text
-
-
tmsi
text
-
-
msisdn
text
-
-
first-seen
datetime
-
-
imsi
text
guti
serial-number
text
+
+
imei
text
@@ -3317,56 +3317,6 @@ r2graphity is a MISP object available in JSON format at
gml
attachment
-
-
total-functions
counter
-
-
total-api
counter
-
-
ratio-string
float
-
-
unknown-references
counter
-
-
callback-largest
counter
referenced-strings
counter
-
-
ratio-functions
float
-
-
r2-commit-version
text
-
-
text
text
-
-
miss-api
counter
-
-
not-referenced-strings
counter
-
-
create-thread
counter
-
-
callbacks
counter
-
-
callback-average
counter
-
-
local-references
counter
dangling-strings
ratio-api
float
+
+
callbacks
counter
+
+
get-proc-address
counter
+
+
r2-commit-version
text
+
+
create-thread
counter
+
+
text
text
+
+
shortest-path-to-create-thread
counter
@@ -3497,7 +3417,27 @@ r2graphity is a MISP object available in JSON format at
ratio-api
gml
attachment
+
+
miss-api
counter
+
+
ratio-string
float
@@ -3507,7 +3447,67 @@ r2graphity is a MISP object available in JSON format at
get-proc-address
not-referenced-strings
counter
+
+
total-functions
counter
+
+
unknown-references
counter
+
+
callback-average
counter
+
+
ratio-functions
float
+
+
total-api
counter
+
+
dangling-strings
counter
@@ -3527,7 +3527,7 @@ r2graphity is a MISP object available in JSON format at
shortest-path-to-create-thread
referenced-strings
counter
@@ -3575,6 +3575,16 @@ regexp is a MISP object available in JSON format at
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
++
comment
comment
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
--
key
-reg-key
data
reg-data
name
-reg-name
key
reg-key
data-type
reg-datatype
+
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
data
reg-data
hive
reg-hive
hive
-reg-hive
name
reg-name
published
+datetime
+
+
version
text
+
+
nickname
text
+
+
version_line
text
+
+
description
text
+
+
fingerprint
text
+
+
flags
text
published
first-seen
datetime
@@ -3761,6 +3821,36 @@ tor-node is a MISP object available in JSON format at
last-seen
datetime
+
+
text
text
+
+
document
text
+
+
address
ip-src
last-seen
datetime
-
-
nickname
text
-
-
document
text
-
-
version_line
text
-
-
fingerprint
text
-
-
version
text
-
-
text
text
-
-
description
text
-
-
first-seen
datetime
-
-
port
-port
-
-
last-seen
datetime
host
hostname
-
-
scheme
text
-
-
fragment
text
-
-
url
url
-
-
subdomain
text
-
-
tld
text
-
-
credential
text
-
-
resource_path
text
-
-
text
text
-
-
domain_without_tld
text
first-seen
datetime
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
++
fragment
text
+
+
tld
text
+
+
host
hostname
credential
text
+
+
subdomain
text
+
+
resource_path
text
+
+
first-seen
datetime
+
+
url
url
+
+
text
text
+
+
port
port
+
+
classification
-text
-
-
name
text
-
-
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial\xadservices', 'government\xadnational', 'government\xadregional', 'government\xadlocal', 'government\xadpublic\xadservices', 'healthcare', 'hospitality\xadleisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non\xadprofit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
++
regions
text
regions
roles
text
@@ -4137,7 +4127,17 @@ victim is a MISP object available in JSON format at
roles
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
++
name
text
@@ -4185,8 +4185,8 @@ vulnerability is a MISP object available in JSON format at
summary
text
id
vulnerability
vulnerable_configuration
-text
published
datetime
id
-vulnerability
vulnerable_configuration
text
published
-datetime
summary
text
domain
-domain
expiration-date
datetime
+
+
creation-date
datetime
expiration-date
+modification-date
datetime
@@ -4323,18 +4333,8 @@ whois is a MISP object available in JSON format at
registrant-email
whois-registrant-email
-
-
creation-date
datetime
domain
domain
modification-date
-datetime
registar
whois-registrar
registar
-whois-registrar
registrant-email
whois-registrant-email
subject
+x509-fingerprint-md5
md5
+
+
pubkey-info-algorithm
text
@@ -4431,7 +4441,7 @@ x509 is a MISP object available in JSON format at
serial-number
version
text
@@ -4451,26 +4461,6 @@ x509 is a MISP object available in JSON format at
x509-fingerprint-md5
md5
-
-
version
text
-
-
validity-not-after
datetime
issuer
text
+
+
pubkey-info-exponent
text
raw-base64
text
+
+
x509-fingerprint-sha256
sha256
subject
text
+
+
pubkey-info-modulus
text
raw-base64
text
text
@@ -4531,7 +4551,7 @@ x509 is a MISP object available in JSON format at
issuer
serial-number
text
text
text
-
-
pubkey-info-algorithm
text
-
-
comment
-comment
-
-
version
comment
yara
yara
-
-
whitelist
comment
comment
comment
+
+
yara-hunt
yara
yara
yara
+
+