From 2ff9272756464622cf8aaeff8d2861e873b783a0 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Thu, 18 Jan 2018 15:10:39 +0100
Subject: [PATCH] fix: objects updated
---
objects.html | 4554 +-
objects.pdf | 169101 ++++++++++++++++++++++++------------------------
2 files changed, 87753 insertions(+), 85902 deletions(-)
diff --git a/objects.html b/objects.html
index 9582cf2..cc39caf 100755
--- a/objects.html
+++ b/objects.html
@@ -564,20 +564,20 @@ ail-leak is a MISP object available in JSON format at origin
text
last-seen
datetime
The link where the leak is (or was) accessible at first-seen.
+When the leak has been accessible or seen for the last time.
+
duplicate
type
text
Duplicate of the existing leaks.
+Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
@@ -594,50 +594,10 @@ ail-leak is a MISP object available in JSON format at
sensor
text
raw-data
attachment
The AIL sensor uuid where the leak was processed and analysed.
--
type
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
--
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
--
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
--
last-seen
datetime
When the leak has been accessible or seen for the last time.
+Raw data as received by the AIL sensor compressed and encoded in Base64.
@@ -654,15 +614,55 @@ ail-leak is a MISP object available in JSON format at
raw-data
attachment
sensor
text
Raw data as received by the AIL sensor compressed and encoded in Base64.
+The AIL sensor uuid where the leak was processed and analysed.
++
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
duplicate
text
Duplicate of the existing leaks.
++
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
++
origin
text
The link where the leak is (or was) accessible at first-seen.
++
comment
-comment
permission
text
Comment about the set of android permission(s)
+Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
permission
text
comment
comment
Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
+Comment about the set of android permission(s)
@@ -760,10 +760,10 @@ annotation is a MISP object available in JSON format at
format
type
text
Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
+Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
@@ -780,20 +780,10 @@ annotation is a MISP object available in JSON format at
modification-date
datetime
Last update of the annotation
--
type
format
text
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
+Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
modification-date
datetime
Last update of the annotation
++
last-seen
-datetime
Last time the ASN was seen
--
description
text
Description of the autonomous system
--
first-seen
datetime
First time the ASN was seen
--
import
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
export
text
last-seen
datetime
Last time the ASN was seen
++
subnet-announced
ip-src
country
first-seen
datetime
First time the ASN was seen
++
asn
AS
Autonomous System Number
++
import
text
Country code of the main location of the autonomous system
+The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
@@ -948,10 +938,20 @@ asn is a MISP object available in JSON format at
asn
AS
country
text
Autonomous System Number
+Country code of the main location of the autonomous system
++
description
text
Description of the autonomous system
@@ -1016,20 +1016,20 @@ av-signature is a MISP object available in JSON format at
datetime
datetime
text
text
Datetime
+Free text value to attach to the file
text
text
datetime
datetime
Free text value to attach to the file
+Datetime
@@ -1094,16 +1094,6 @@ coin-address is a MISP object available in JSON format at
first-seen
datetime
First time this payment destination address has been seen
--
address
btc
first-seen
datetime
First time this payment destination address has been seen
++
text
text
text
text
A description of the cookie.
--
cookie-name
text
Name of the cookie (if splitted)
--
type
text
text
text
A description of the cookie.
++
cookie-name
text
Name of the cookie (if splitted)
++
type
+text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
++
username
text
origin
password
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
+Password
@@ -1280,16 +1290,6 @@ credential is a MISP object available in JSON format at
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
--
text
text
password
notification
text
Password
+Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
notification
origin
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
+Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
@@ -1358,26 +1358,6 @@ credit-card is a MISP object available in JSON format at
expiration
datetime
Maximum date of validity
--
version
text
Version of the card.
--
card-security-code
text
cc-number
cc-number
credit-card number as encoded on the card.
--
name
text
issued
datetime
Initial date of validity or issued date.
++
comment
comment
issued
version
text
Version of the card.
++
cc-number
cc-number
credit-card number as encoded on the card.
++
expiration
datetime
Initial date of validity or issued date.
+Maximum date of validity
@@ -1466,20 +1466,10 @@ ddos is a MISP object available in JSON format at
ip-dst
ip-dst
src-port
port
Destination IP (victim)
--
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
+Port originating the attack
@@ -1496,20 +1486,20 @@ ddos is a MISP object available in JSON format at
src-port
port
ip-dst
ip-dst
Port originating the attack
+Destination IP (victim)
text
text
first-seen
datetime
Description of the DDoS
+Beginning of the attack
@@ -1526,10 +1516,10 @@ ddos is a MISP object available in JSON format at
first-seen
datetime
text
text
Beginning of the attack
+Description of the DDoS
@@ -1556,10 +1546,10 @@ ddos is a MISP object available in JSON format at
dst-port
port
protocol
text
Destination port of the attack
+Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
dst-port
port
Destination port of the attack
++
CmdCode
-text
A decimal representation of the diameter Command Code.
--
SessionId
text
Session-ID.
--
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
--
Username
text
Username (in this case, usually the IMSI).
--
Destination-Realm
text
Destination-Realm.
--
Origin-Host
text
category
Username
text
Category. ['Cat0', 'Cat1', 'Cat2', 'Cat3', 'CatSMS']
+Username (in this case, usually the IMSI).
++
CmdCode
text
A decimal representation of the diameter Command Code.
@@ -1704,6 +1664,36 @@ diameter-attack is a MISP object available in JSON format at
Destination-Host
text
Destination-Host.
++
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
++
Destination-Realm
text
Destination-Realm.
++
IdrFlags
text
Destination-Host
SessionId
text
Destination-Host.
+Session-ID.
category
text
Category. ['Cat0', 'Cat1', 'Cat2', 'Cat3', 'CatSMS']
++
ip
+ip-dst
IP Address
++
domain
domain
text
text
A description of the tuple
++
last-seen
datetime
ip
ip-dst
IP Address
--
text
text
A description of the tuple
--
arch
+text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
++
type
text
text
text
Free text value to attach to the ELF
--
entrypoint-address
text
Address of the entry point
--
number-sections
counter
arch
entrypoint-address
text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
+Address of the entry point
++
text
text
Free text value to attach to the ELF
@@ -1958,30 +1958,10 @@ elf-section is a MISP object available in JSON format at
sha256
sha256
sha1
sha1
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -1998,40 +1978,10 @@ elf-section is a MISP object available in JSON format at
flag
text
sha512/256
sha512/256
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
--
name
text
Name of the section
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -2048,13 +1998,13 @@ elf-section is a MISP object available in JSON format at
size-in-bytes
size-in-bytes
sha256
sha256
Size of the section, in bytes
+Secure Hash Algorithm 2 (256 bits)
+
text
-text
Free text value to attach to the section
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha512
sha512
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
name
text
Name of the section
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
flag
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
++
text
text
Free text value to attach to the section
++
from-display-name
-email-src-display-name
thread-index
email-thread-index
Display name of the sender
--
attachment
email-attachment
Attachment
--
to
email-dst
Destination email address
--
return-path
text
Message return path
--
message-id
email-message-id
Message ID
--
mime-boundary
email-mime-boundary
MIME Boundary
--
cc
email-dst
Carbon copy
--
reply-to
email-reply-to
Email address the reply will be sent to
--
from
email-src
Sender email address
+Identifies a particular conversation thread
@@ -2246,10 +2166,30 @@ email is a MISP object available in JSON format at
thread-index
email-thread-index
to
email-dst
Identifies a particular conversation thread
+Destination email address
++
mime-boundary
email-mime-boundary
MIME Boundary
++
return-path
text
Message return path
@@ -2266,10 +2206,50 @@ email is a MISP object available in JSON format at
header
email-header
screenshot
attachment
Full headers
+Screenshot of email
++
from-display-name
email-src-display-name
Display name of the sender
++
message-id
email-message-id
Message ID
++
cc
email-dst
Carbon copy
++
subject
email-subject
Subject
@@ -2286,20 +2266,40 @@ email is a MISP object available in JSON format at
screenshot
attachment
reply-to
email-reply-to
Screenshot of email
+Email address the reply will be sent to
subject
email-subject
attachment
email-attachment
Subject
+Attachment
++
header
email-header
Full headers
++
from
email-src
Sender email address
@@ -2344,6 +2344,36 @@ file is a MISP object available in JSON format at
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
entropy
float
Entropy of the whole file
++
sha256
sha256
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
certificate
x509-fingerprint-sha1
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
text
text
Free text value to attach to the file
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
entropy
float
Entropy of the whole file
--
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
authentihash
authentihash
pattern-in-file
pattern-in-file
sha384
sha384
Pattern that can be found in the file
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (384 bits)
@@ -2524,10 +2454,60 @@ file is a MISP object available in JSON format at
sha384
sha384
sha512/224
sha512/224
Secure Hash Algorithm 2 (384 bits)
+Secure Hash Algorithm 2 (224 bits)
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
++
size-in-bytes
size-in-bytes
Size of the file, in bytes
++
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
text
text
Free text value to attach to the file
++
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
longitude
+float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
++
region
text
Region.
++
last-seen
datetime
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
text
text
A generic description of the location.
++
city
text
City.
++
country
text
Country.
++
altitude
float
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
--
text
text
A generic description of the location.
--
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
region
text
Region.
--
country
text
Country.
--
city
text
City.
--
GtpMsisdn
+GtpVersion
text
GTP MSISDN.
--
GtpServingNetwork
text
GTP Serving Network.
--
ipDest
ip-dst
IP destination address.
--
GtpImsi
text
GTP IMSI (International mobile subscriber identity).
--
PortDest
text
Destination port.
--
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
+GTP version ['0', '1', '2']
@@ -2790,40 +2740,30 @@ gtp-attack is a MISP object available in JSON format at
text
PortDest
text
A description of the GTP attack.
+Destination port.
ipSrc
ip-src
GtpMsisdn
text
IP source address.
+GTP MSISDN.
GtpVersion
GtpServingNetwork
text
GTP version ['0', '1', '2']
--
GtpMessageType
text
GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
+GTP Serving Network.
ipDest
ip-dst
IP destination address.
++
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
++
GtpImsi
text
GTP IMSI (International mobile subscriber identity).
++
ipSrc
ip-src
IP source address.
++
text
text
A description of the GTP attack.
++
GtpMessageType
text
GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
++
host
-hostname
The domain name of the server
--
proxy-user
text
HTTP Proxy Username
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
--
uri
uri
proxy-password
text
HTTP Proxy Password
++
host
hostname
The domain name of the server
++
url
url
method
http-method
text
text
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
+HTTP Request comment
proxy-password
text
user-agent
user-agent
HTTP Proxy Password
+The user agent string of the user agent
++
content-type
other
The MIME type of the body of the request
@@ -2968,16 +2968,6 @@ http-request is a MISP object available in JSON format at
text
text
HTTP Request comment
--
basicauth-password
text
user-agent
user-agent
cookie
text
The user agent string of the user agent
+An HTTP cookie previously sent by the server with Set-Cookie
content-type
other
method
http-method
The MIME type of the body of the request
+HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
++
proxy-user
text
HTTP Proxy Username
@@ -3046,6 +3046,16 @@ ip-port is a MISP object available in JSON format at
src-port
port
Source port
++
last-seen
datetime
src-port
port
ip
ip-dst
Source port
+IP Address
@@ -3086,16 +3096,6 @@ ip-port is a MISP object available in JSON format at
ip
ip-dst
IP Address
--
dst-port
port
ip-dst
ip-dst
Destination IP address
--
last-seen
datetime
first-seen
datetime
ip-dst
ip-dst
First seen of the SSL/TLS handshake
--
ja3-fingerprint-md5
md5
Hash identifying source
+Destination IP address
@@ -3194,6 +3174,16 @@ ja3 is a MISP object available in JSON format at
ja3-fingerprint-md5
md5
Hash identifying source
++
ip-src
ip-src
first-seen
datetime
First seen of the SSL/TLS handshake
++
entrypoint-address
+text
text
Address of the entry point
--
number-sections
counter
Number of sections
+Free text value to attach to the Mach-O file
@@ -3282,10 +3272,20 @@ macho is a MISP object available in JSON format at
text
number-sections
counter
Number of sections
++
entrypoint-address
text
Free text value to attach to the Mach-O file
+Address of the entry point
@@ -3330,56 +3330,6 @@ macho-section is a MISP object available in JSON format at
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
name
text
Name of the section
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha1
sha1
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
entropy
float
size-in-bytes
size-in-bytes
sha256
sha256
Size of the section, in bytes
+Secure Hash Algorithm 2 (256 bits)
+
text
-text
Free text value to attach to the section
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha512
sha512
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
name
text
Name of the section
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
text
text
Free text value to attach to the section
++
username
-text
Username who posted the microblog post
--
modification-date
datetime
Last update of the microblog post
--
type
text
username-quoted
text
url
url
Username who are quoted into the microblog post
+Original URL location of the microblog post
url
url
username
text
Original URL location of the microblog post
+Username who posted the microblog post
@@ -3558,16 +3538,6 @@ microblog is a MISP object available in JSON format at
creation-date
datetime
Initial creation of the microblog post
--
removal-date
datetime
creation-date
datetime
Initial creation of the microblog post
++
username-quoted
text
Username who are quoted into the microblog post
++
post
text
modification-date
datetime
Last update of the microblog post
++
ip-dst
-ip-dst
byte-count
counter
IP address destination of the netflow
+Bytes counted in this flow
-
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
-+
flow-count
-counter
icmp-type
text
Flows counted in this flow
+ICMP type of the flow (if the traffic is ICMP)
ip-src
ip-src
ip-dst
ip-dst
IP address source of the netflow
+IP address destination of the netflow
ip-protocol-number
size-in-bytes
ip_version
counter
IP protocol number of this flow
+IP version of this flow
@@ -3696,16 +3686,96 @@ netflow is a MISP object available in JSON format at
ip_version
packet-count
counter
IP version of this flow
+Packets counted in this flow
ip-src
ip-src
IP address source of the netflow
++
dst-port
port
Destination port of the netflow
++
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
++
direction
text
Direction of this flow ['Ingress', 'Egress']
++
first-packet-seen
datetime
First packet seen in this flow
++
ip-protocol-number
size-in-bytes
IP protocol number of this flow
++
flow-count
counter
Flows counted in this flow
++
last-packet-seen
datetime
Last packet seen in this flow
++
dst-as
AS
packet-count
counter
Packets counted in this flow
--
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
--
direction
text
Direction of this flow ['Ingress', 'Egress']
--
last-packet-seen
datetime
Last packet seen in this flow
--
first-packet-seen
datetime
First packet seen in this flow
--
dst-port
port
Destination port of the netflow
--
byte-count
counter
Bytes counted in this flow
--
count
-counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
--
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
--
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
bailiwick
sensor_id
text
Best estimate of the apex of the zone where this data is authoritative
--
rdata
text
Resource records of the queried resource
--
origin
text
Origin of the Passive DNS response
--
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
--
text
text
+
Sensor information where the record was seen
@@ -3934,6 +3854,86 @@ passive-dns is a MISP object available in JSON format at
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
++
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
++
bailiwick
text
Best estimate of the apex of the zone where this data is authoritative
++
text
text
+
+
rdata
text
Resource records of the queried resource
++
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
++
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
++
rrname
text
sensor_id
origin
text
Sensor information where the record was seen
+Origin of the Passive DNS response
@@ -3992,6 +3992,16 @@ paste is a MISP object available in JSON format at
last-seen
datetime
When the paste has been accessible or seen for the last time.
++
paste
text
origin
text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
--
first-seen
datetime
last-seen
datetime
When the paste has been accessible or seen for the last time.
--
title
text
origin
text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
++
impfuzzy
-impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
--
product-name
text
file-description
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
++
internal-filename
filename
InternalFilename in the resources
++
number-sections
counter
Number of sections
++
imphash
imphash
Hash (md5) calculated from the import table
++
entrypoint-address
text
FileDescription in the resources
+Address of the entry point
@@ -4130,6 +4160,46 @@ pe is a MISP object available in JSON format at
text
text
Free text value to attach to the PE
++
legal-copyright
text
LegalCopyright in the resources
++
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
++
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
type
text
file-version
text
FileVersion in the resources
--
number-sections
counter
Number of sections
--
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
--
original-filename
filename
internal-filename
filename
file-version
text
InternalFilename in the resources
+FileVersion in the resources
imphash
imphash
Hash (md5) calculated from the import table
--
text
text
Free text value to attach to the PE
--
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
--
product-version
text
entrypoint-address
file-description
text
Address of the entry point
+FileDescription in the resources
legal-copyright
text
LegalCopyright in the resources
--
sha256
-sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha1
sha1
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
entropy
float
characteristic
text
sha256
sha256
Characteristic of the section ['read', 'write', 'executable']
+Secure Hash Algorithm 2 (256 bits)
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
ssdeep
ssdeep
text
text
Free text value to attach to the section
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha512
sha512
characteristic
text
Characteristic of the section ['read', 'write', 'executable']
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
text
text
Free text value to attach to the section
++
first-name
-first-name
First name of a natural person.
--
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
--
gender
gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
--
place-of-birth
place-of-birth
Place of birth of a natural person.
--
passport-expiration
passport-expiration
The expiration date of a passport.
--
middle-name
middle-name
Middle name of a natural person
--
passport-country
passport-country
date-of-birth
date-of-birth
gender
gender
Date of birth of a natural person (in YYYY-MM-DD format).
--
last-name
last-name
Last name of a natural person.
+The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
@@ -4596,6 +4526,46 @@ person is a MISP object available in JSON format at
last-name
last-name
Last name of a natural person.
++
passport-expiration
passport-expiration
The expiration date of a passport.
++
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
++
middle-name
middle-name
Middle name of a natural person
++
nationality
nationality
place-of-birth
place-of-birth
Place of birth of a natural person.
++
first-name
first-name
First name of a natural person.
++
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
++
serial-number
+text
Serial Number.
++
msisdn
text
tmsi
first-seen
datetime
When the phone has been accessible or seen for the first time.
++
gummei
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
+Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
++
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
@@ -4694,20 +4724,10 @@ phone is a MISP object available in JSON format at
gummei
tmsi
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
--
serial-number
text
Serial Number.
+Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
--
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
callbacks
+local-references
counter
Amount of callbacks (functions started as thread)
+Amount of API calls inside a code section
local-references
r2-commit-version
text
Radare2 commit ID used to generate this object
++
memory-allocations
counter
Amount of API calls inside a code section
+Amount of memory allocations
++
gml
attachment
Graph export in G>raph Modelling Language format
@@ -4822,10 +4842,10 @@ r2graphity is a MISP object available in JSON format at
memory-allocations
not-referenced-strings
counter
Amount of memory allocations
+Amount of not referenced strings
@@ -4842,40 +4862,50 @@ r2graphity is a MISP object available in JSON format at
r2-commit-version
text
Radare2 commit ID used to generate this object
--
gml
attachment
Graph export in G>raph Modelling Language format
--
text
text
Description of the r2graphity object
--
dangling-strings
shortest-path-to-create-thread
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
+Shortest path to the first time the binary calls CreateThread
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
total-functions
counter
Total amount of functions in the file.
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
@@ -4892,6 +4922,56 @@ r2graphity is a MISP object available in JSON format at
get-proc-address
counter
Amount of calls to GetProcAddress
++
create-thread
counter
Amount of calls to CreateThread
++
callbacks
counter
Amount of callbacks (functions started as thread)
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
++
callback-largest
counter
miss-api
counter
text
text
Amount of API call reference that does not resolve to a function offset
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
not-referenced-strings
counter
Amount of not referenced strings
--
total-functions
counter
Total amount of functions in the file.
--
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
create-thread
counter
Amount of calls to CreateThread
+Description of the r2graphity object
@@ -5040,20 +5040,10 @@ regexp is a MISP object available in JSON format at
regexp-type
type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
--
comment
comment
A description of the regular expression.
+Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
@@ -5070,15 +5060,25 @@ regexp is a MISP object available in JSON format at
type
text
comment
comment
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
+A description of the regular expression.
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
++
data
+text
Data stored in the registry key
++
root-keys
text
Root key of the Windows registry (extracted from the key) ['HKCC', 'HKCR', 'HKCU', 'HKDD', 'HKEY_CLASSES_ROOT', 'HKEY_CURRENT_CONFIG', 'HKEY_CURRENT_USER', 'HKEY_DYN_DATA', 'HKEY_LOCAL_MACHINE', 'HKEY_PERFORMANCE_DATA', 'HKEY_USERS', 'HKLM', 'HKPD', 'HKU']
++
name
text
Name of the registry key
++
key
regkey
name
data-type
text
Name of the registry key
+Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
-
data
text
Data stored in the registry key
-+
data-type
text
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
--
case-number
+summary
text
Case number
+Free text summary of the report
summary
case-number
text
Free text summary of the report
+Case number
@@ -5274,26 +5284,6 @@ rtir is a MISP object available in JSON format at
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
--
classification
text
Classification of the RTIR ticket
--
constituency
text
ticket-number
text
ticket-number of the RTIR ticket
--
ip
ip-dst
IPs automatically extracted from the RTIR ticket
--
status
text
ip
ip-dst
IPs automatically extracted from the RTIR ticket
++
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
++
classification
text
Classification of the RTIR ticket
++
ticket-number
text
ticket-number of the RTIR ticket
++
permalink
-link
Permalink reference
--
score
on-premise-sandbox
text
Score
--
saas-sandbox
text
A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud']
+The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
@@ -5422,10 +5412,10 @@ sandbox-report is a MISP object available in JSON format at
on-premise-sandbox
raw-report
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
+Raw report from sandbox
@@ -5442,16 +5432,36 @@ sandbox-report is a MISP object available in JSON format at
raw-report
saas-sandbox
text
Raw report from sandbox
+A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud']
score
text
Score
++
permalink
link
Permalink reference
++
web-sandbox
text
MapSmsTypeNumber
MapVlrGT
text
MAP SMS TypeNumber.
--
MapSmscGT
text
MAP SMSC. Phone number.
--
MapSmsTP-DCS
text
MAP SMS TP-DCS.
--
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
+MAP VLR GT. Phone number.
@@ -5550,56 +5530,6 @@ ss7-attack is a MISP object available in JSON format at
MapVersion
text
Map version. ['1', '2', '3']
--
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
--
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
--
text
text
A description of the attack seen via SS7 logging.
--
SccpCdPC
text
Signaling Connection Control Part (SCCP) CdPC - Phone number.
--
MapMscGT
text
MapVlrGT
MapSmsText
text
MAP VLR GT. Phone number.
--
MapGmlc
text
MAP GMLC. Phone number.
+MAP SMS Text. Important indicators in SMS text.
@@ -5640,77 +5560,7 @@ ss7-attack is a MISP object available in JSON format at
MapGsmscfGT
text
MAP GSMSCF GT. Phone number.
--
MapSmsTP-PID
text
MAP SMS TP-PID.
--
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
--
MapApplicationContext
text
MAP application context in OID format.
--
MapMsisdn
text
MAP MSISDN. Phone number.
--
first-seen
datetime
When the attack has been seen for the first time.
--
MapUssdContent
text
MAP USSD Content.
--
SccpCdSSN
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
@@ -5720,7 +5570,17 @@ ss7-attack is a MISP object available in JSON format atSccpCgSSN
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
++
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
@@ -5740,6 +5600,76 @@ ss7-attack is a MISP object available in JSON format atMapMsisdn
text
MAP MSISDN. Phone number.
++
SccpCdPC
text
Signaling Connection Control Part (SCCP) CdPC - Phone number.
++
MapUssdContent
text
MAP USSD Content.
++
MapGmlc
text
MAP GMLC. Phone number.
++
MapGsmscfGT
text
MAP GSMSCF GT. Phone number.
++
MapVersion
text
Map version. ['1', '2', '3']
++
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
++
MapOpCode
text
first-seen
datetime
When the attack has been seen for the first time.
++
MapSmsTP-DCS
text
MAP SMS TP-DCS.
++
text
text
A description of the attack seen via SS7 logging.
++
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
++
MapSmscGT
text
MAP SMSC. Phone number.
++
MapApplicationContext
text
MAP application context in OID format.
++
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
++
MapSmsTypeNumber
text
MAP SMS TypeNumber.
++
MapSmsTP-PID
text
MAP SMS TP-PID.
++
stix2-pattern
-stix2-pattern
comment
comment
STIX 2 pattern
+A description of the stix2-pattern.
comment
comment
stix2-pattern
stix2-pattern
A description of the stix2-pattern.
+STIX 2 pattern
@@ -5846,26 +5866,56 @@ tor-node is a MISP object available in JSON format at
document
version
text
Raw document from the consensus.
+parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
address
ip-src
IP address of the Tor node seen.
++
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
fingerprint
version_line
text
router’s fingerprint.
+versioning information reported by the node.
text
text
Tor node comment.
++
description
text
version_line
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
++
nickname
text
versioning information reported by the node.
+router’s nickname.
++
fingerprint
text
router’s fingerprint.
@@ -5906,65 +5976,15 @@ tor-node is a MISP object available in JSON format at
nickname
document
text
router’s nickname.
--
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
+Raw document from the consensus.
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
text
text
Tor node comment.
--
address
ip-src
IP address of the Tor node seen.
--
tld
+text
Top-Level Domain
++
query_string
text
Query (after path, preceded by '?')
++
first-seen
datetime
First time this URL has been seen
++
url
url
Full URL
++
credential
text
subdomain
text
Subdomain
++
text
text
Description of the URL
++
port
port
Port number
++
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
++
domain
domain
Full domain
++
last-seen
datetime
Last time this URL has been seen
++
host
hostname
resource_path
text
Path (between hostname:port and query)
--
url
url
Full URL
--
subdomain
text
Subdomain
--
query_string
text
Query (after path, preceded by '?')
--
last-seen
datetime
Last time this URL has been seen
--
port
port
Port number
--
first-seen
datetime
First time this URL has been seen
--
domain_without_tld
text
tld
resource_path
text
Top-Level Domain
--
text
text
Description of the URL
+Path (between hostname:port and query)
domain
domain
Full domain
--
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
--
user
-target-user
node
target-machine
The username(s) of the user targeted.
--
external
target-external
External target organisations affected by this attack.
--
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
--
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
+Name(s) of node that was targeted.
@@ -6252,20 +6242,50 @@ victim is a MISP object available in JSON format at
description
text
regions
target-location
Description of the victim
+The list of regions or locations from the victim targeted. ISO 3166 should be used.
node
target-machine
classification
text
Name(s) of node that was targeted.
+The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
++
target-email
The email address(es) of the user targeted.
++
user
target-user
The username(s) of the user targeted.
++
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
@@ -6282,20 +6302,20 @@ victim is a MISP object available in JSON format at
target-email
description
text
The email address(es) of the user targeted.
+Description of the victim
regions
target-location
external
target-external
The list of regions or locations from the victim targeted. ISO 3166 should be used.
+External target organisations affected by this attack.
@@ -6340,30 +6360,10 @@ virustotal-report is a MISP object available in JSON format at
community-score
text
Community Score
--
permalink
link
Permalink Reference
--
first-submission
last-submission
datetime
First Submission
+Last Submission
@@ -6380,10 +6380,30 @@ virustotal-report is a MISP object available in JSON format at
last-submission
community-score
text
Community Score
++
first-submission
datetime
Last Submission
+First Submission
++
permalink
link
Permalink Reference
@@ -6428,26 +6448,6 @@ vulnerability is a MISP object available in JSON format at
references
link
External references
--
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely). The id is not required as the object itself has an UUID and the CVE id can updated later.
--
modified
datetime
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
text
text
Description of the vulnerability
--
state
text
State of the vulnerability. A vulnerability can have multiple states depending of the current actions performed. ['Published', 'Embargo', 'Reviewed', 'Vulnerability ID Assigned', 'Reported', 'Fixed']
--
published
datetime
created
datetime
references
link
First time when the vulnerability was discovered
+External references
++
state
text
State of the vulnerability. A vulnerability can have multiple states depending of the current actions performed. ['Published', 'Embargo', 'Reviewed', 'Vulnerability ID Assigned', 'Reported', 'Fixed']
text
text
Description of the vulnerability
++
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely). The id is not required as the object itself has an UUID and the CVE id can updated later.
++
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
++
created
datetime
First time when the vulnerability was discovered
++
registrar
-whois-registrar
Registrar of the whois entry
--
registrant-name
whois-registrant-name
Registrant name
--
modification-date
expiration-date
datetime
Last update of the whois entry
+Expiration of the whois entry
registrant-phone
whois-registrant-phone
Registrant phone number
--
domain
domain
Domain of the whois entry
--
registrant-email
whois-registrant-email
registrar
whois-registrar
Registrar of the whois entry
++
creation-date
datetime
registrant-org
whois-registrant-org
Registrant organisation
++
domain
domain
Domain of the whois entry
++
registrant-phone
whois-registrant-phone
Registrant phone number
++
text
text
registrant-name
whois-registrant-name
Registrant name
++
nameserver
hostname
registrant-org
whois-registrant-org
Registrant organisation
--
expiration-date
modification-date
datetime
Expiration of the whois entry
+Last update of the whois entry
@@ -6704,26 +6724,6 @@ x509 is a MISP object available in JSON format at
pubkey-info-algorithm
text
Algorithm of the public key
--
validity-not-before
datetime
Certificate invalid before that date
--
serial-number
text
pubkey-info-algorithm
text
Algorithm of the public key
++
pubkey-info-modulus
text
pubkey-info-exponent
text
x509-fingerprint-md5
x509-fingerprint-md5
Exponent of the public key
--
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
--
pubkey-info-size
text
Length of the public key (in bits)
--
version
text
Version of the certificate
--
text
text
Free text description of hte certificate
+[Insecure] MD5 hash (128 bits)
@@ -6814,20 +6784,20 @@ x509 is a MISP object available in JSON format at
subject
text
validity-not-before
datetime
Subject of the certificate
+Certificate invalid before that date
issuer
pubkey-info-size
text
Issuer of the certificate
+Length of the public key (in bits)
@@ -6844,10 +6814,60 @@ x509 is a MISP object available in JSON format at
x509-fingerprint-md5
x509-fingerprint-md5
version
text
[Insecure] MD5 hash (128 bits)
+Version of the certificate
++
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
++
issuer
text
Issuer of the certificate
++
subject
text
Subject of the certificate
++
pubkey-info-exponent
text
Exponent of the public key
++
text
text
Free text description of hte certificate
@@ -6892,13 +6912,23 @@ yabin is a MISP object available in JSON format at
yara-hunt
yara
whitelist
comment
Wide yara rule generated from -yh.
+Whitelist name used to generate the rules.
+
+
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
+
version
-comment
yara-hunt
yara
yabin.py and regex.txt version used for the generation of the yara rules.
+Wide yara rule generated from -yh.
-
whitelist
comment
Whitelist name used to generate the rules.
-+