diff --git a/objects.html b/objects.html index 02d1efc..6964069 100755 --- a/objects.html +++ b/objects.html @@ -457,6 +457,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
original-date
+sensor
text
+
+
last-seen
datetime
@@ -526,6 +537,16 @@ ail-leak is a MISP object available in JSON format at
type
text
+
+
text
text
last-seen
original-date
datetime
sensor
text
-
-
type
text
-
-
cookie-value
+cookie-name
text
@@ -644,7 +645,7 @@ cookie is a MISP object available in JSON format at
cookie-name
cookie-value
text
@@ -654,16 +655,6 @@ cookie is a MISP object available in JSON format at
cookie
cookie
-
-
type
text
cookie
cookie
+
+
version
-text
expiration
datetime
cc-number
+cc-number
+
+
card-security-code
text
expiration
datetime
comment
comment
cc-number
-cc-number
-
-
comment
comment
version
text
ip-src
+ip-src
+
+
total-bps
counter
src-port
last-seen
datetime
+
+
dst-port
port
@@ -840,8 +861,18 @@ ddos is a MISP object available in JSON format at
last-seen
datetime
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
src-port
port
dst-port
-port
-
-
ip-dst
ip-dst
-
-
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
--
ip-src
ip-src
-
-
first-seen
datetime
ip-dst
ip-dst
+
+
ip
-ip-dst
-
-
domain
domain
ip
ip-dst
+
+
type
+text
+
+
text
text
+
+
entrypoint-address
text
text
text
-
-
type
text
-
-
sha1
-sha1
-
-
name
text
-
-
text
text
sha384
sha384
-
-
sha512/224
sha512/224
-
-
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
-
-
sha512
sha512
-
-
sha256
sha256
-
-
flag
text
-
-
sha512/256
sha512/256
-
-
sha224
sha224
-
-
entropy
float
-
-
type
text
sha512
sha512
+
+
sha256
sha256
+
+
sha512/224
sha512/224
+
+
sha512/256
sha512/256
+
+
entropy
float
+
+
sha1
sha1
+
+
sha384
sha384
+
+
md5
md5
sha224
sha224
+
+
flag
text
+
+
name
text
+
+
size-in-bytes
size-in-bytes
+
+
ssdeep
ssdeep
+
+
x-mailer
-email-x-mailer
-
-
subject
email-subject
from-display-name
email-src-display-name
-
-
from
email-src
to-display-name
email-dst-display-name
+
+
thread-index
email-thread-index
from-display-name
email-src-display-name
+
+
send-date
datetime
reply-to
email-reply-to
mime-boundary
email-mime-boundary
reply-to
+email-reply-to
+
+
message-id
email-message-id
to-display-name
email-dst-display-name
-
-
mime-boundary
email-mime-boundary
x-mailer
email-x-mailer
sha1
-sha1
-
-
text
text
-
-
sha384
sha384
malware-sample
malware-sample
mimetype
+text
text
@@ -1550,46 +1531,6 @@ file is a MISP object available in JSON format at
sha512/224
sha512/224
-
-
authentihash
authentihash
-
-
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
-
-
sha512
sha512
malware-sample
malware-sample
sha512/224
sha512/224
sha224
-sha224
-
-
filename
filename
mimetype
text
+
+
sha1
sha1
+
+
sha384
sha384
+
+
md5
md5
sha224
sha224
+
+
authentihash
authentihash
+
+
size-in-bytes
size-in-bytes
+
+
ssdeep
ssdeep
+
+
city
+text
+
+
last-seen
datetime
+
+
region
text
+
+
altitude
float
longitude
float
-
-
latitude
float
city
text
-
-
region
text
-
-
last-seen
datetime
longitude
float
text
-text
-
-
basicauth-user
text
-
-
proxy-user
text
-
-
method
http-method
-
-
host
hostname
uri
uri
+
+
text
text
+
+
basicauth-password
text
+
+
cookie
text
referer
referer
url
url
uri
-uri
-
-
url
url
user-agent
user-agent
basicauth-password
+method
http-method
+
+
proxy-user
text
@@ -1966,8 +1957,18 @@ http-request is a MISP object available in JSON format at
user-agent
user-agent
basicauth-user
text
+
+
referer
referer
last-seen
+datetime
+
+
dst-port
port
+
+
ip
ip-dst
last-seen
datetime
-
-
first-seen
datetime
dst-port
port
-
-
ip-src
+ip-src
+
+
last-seen
datetime
+
+
ja3-fingerprint-md5
md5
+
+
description
text
ja3-fingerprint-md5
md5
-
-
ip-src
ip-src
-
-
last-seen
datetime
-
-
name
+type
text
@@ -2220,16 +2221,6 @@ macho is a MISP object available in JSON format at
number-sections
counter
-
-
text
text
type
number-sections
counter
+
+
name
text
@@ -2298,26 +2299,6 @@ macho-section is a MISP object available in JSON format at
sha1
sha1
-
-
name
text
-
-
text
text
sha384
sha384
-
-
sha512/224
sha512/224
-
-
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
-
-
sha512
sha512
sha512/256
sha512/256
sha512/224
sha512/224
sha224
-sha224
sha512/256
sha512/256
sha1
+sha1
+
+
sha384
sha384
+
+
md5
md5
sha224
sha224
+
+
name
text
+
+
size-in-bytes
size-in-bytes
+
+
ssdeep
ssdeep
+
+
text
-text
-
-
sensor_id
text
-
-
rdata
text
-
-
time_first
datetime
zone_time_last
datetime
-
-
rrtype
text
-
-
origin
rdata
text
@@ -2566,7 +2517,27 @@ passive-dns is a MISP object available in JSON format at
bailiwick
origin
text
+
+
sensor_id
text
+
+
text
text
zone_time_last
datetime
+
+
bailiwick
text
+
+
rrtype
text
+
+
legal-copyright
-text
-
-
product-version
lang-id
text
@@ -2654,7 +2645,7 @@ pe is a MISP object available in JSON format at
text
product-version
text
@@ -2664,7 +2655,27 @@ pe is a MISP object available in JSON format at
file-description
internal-filename
filename
+
+
impfuzzy
impfuzzy
+
+
type
text
@@ -2674,7 +2685,7 @@ pe is a MISP object available in JSON format at
product-name
entrypoint-address
text
@@ -2694,6 +2705,16 @@ pe is a MISP object available in JSON format at
legal-copyright
text
+
+
pehash
pehash
file-version
text
+
+
file-description
text
+
+
original-filename
filename
type
product-name
text
@@ -2754,7 +2795,7 @@ pe is a MISP object available in JSON format at
entrypoint-address
text
text
file-version
text
-
-
impfuzzy
impfuzzy
-
-
lang-id
text
-
-
internal-filename
filename
-
-
sha1
-sha1
-
-
name
text
-
-
text
text
sha384
sha384
-
-
sha512/224
sha512/224
-
-
size-in-bytes
size-in-bytes
-
-
ssdeep
ssdeep
-
-
sha512
sha512
sha512/256
sha512/256
sha512/224
sha512/224
sha224
-sha224
sha512/256
sha512/256
sha1
+sha1
+
+
sha384
sha384
+
+
md5
md5
sha224
sha224
+
+
name
text
+
+
size-in-bytes
size-in-bytes
+
+
ssdeep
ssdeep
+
+
text
-text
passport-expiration
passport-expiration
+
+
passport-country
passport-country
+
place-of-birth
-place-of-birth
-
-
first-name
first-name
passport-number
passport-number
middle-name
-middle-name
first-name
first-name
passport-expiration
-passport-expiration
-
-
date-of-birth
date-of-birth
-
-
passport-number
passport-number
-
-
nationality
nationality
place-of-birth
place-of-birth
passport-country
-passport-country
nationality
nationality
+
+
text
text
+
+
middle-name
middle-name
+
+
date-of-birth
date-of-birth
gummei
+serial-number
text
@@ -3188,13 +3189,23 @@ phone is a MISP object available in JSON format at
guti
last-seen
datetime
+
+
text
text
+
gummei
+text
+
+
tmsi
text
serial-number
msisdn
text
@@ -3248,17 +3269,7 @@ phone is a MISP object available in JSON format at
text
text
-
-
msisdn
guti
text
last-seen
datetime
-
-
ratio-api
-float
-
-
callback-average
counter
-
-
callbacks
counter
-
-
memory-allocations
counter
-
-
not-referenced-strings
counter
-
-
r2-commit-version
text
-
-
referenced-strings
counter
-
-
miss-api
counter
-
-
get-proc-address
counter
-
-
dangling-strings
counter
-
-
local-references
counter
-
-
text
text
-
-
ratio-functions
float
-
-
shortest-path-to-create-thread
counter
-
-
unknown-references
counter
-
-
ratio-string
float
-
-
gml
attachment
refsglobalvar
counter
-
-
callback-largest
total-functions
counter
@@ -3516,6 +3347,96 @@ r2graphity is a MISP object available in JSON format at
ratio-string
float
+
+
unknown-references
counter
+
+
callback-largest
counter
+
+
referenced-strings
counter
+
+
ratio-functions
float
+
+
r2-commit-version
text
+
+
text
text
+
+
miss-api
counter
+
+
not-referenced-strings
counter
+
+
create-thread
counter
total-functions
callbacks
counter
+
+
callback-average
counter
+
+
local-references
counter
+
+
dangling-strings
counter
+
+
memory-allocations
counter
+
+
ratio-api
float
+
+
get-proc-address
counter
+
+
refsglobalvar
counter
+
+
shortest-path-to-create-thread
counter
@@ -3574,16 +3575,6 @@ regexp is a MISP object available in JSON format at
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
--
comment
comment
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
++
name
-reg-name
key
reg-key
key
-reg-key
name
reg-name
hive
-reg-hive
last-modified
datetime
last-modified
-datetime
hive
reg-hive
flags
+text
+
+
published
datetime
+
+
address
ip-src
last-seen
datetime
+
+
nickname
text
+
+
document
text
@@ -3770,33 +3811,13 @@ tor-node is a MISP object available in JSON format at
first-seen
datetime
-
-
published
datetime
-
-
document
fingerprint
text
+
text
+text
+
+
description
text
fingerprint
text
-
-
nickname
text
-
-
flags
text
-
-
last-seen
first-seen
datetime
@@ -3898,18 +3899,8 @@ url is a MISP object available in JSON format at
credential
text
-
-
text
text
port
port
first-seen
-datetime
host
hostname
+
+
scheme
text
host
-hostname
url
url
resource_path
-text
-
-
tld
text
domain
domain
credential
text
url
-url
resource_path
text
port
-port
-
-
scheme
text
text
first-seen
datetime
+
+
domain
domain
+
+
Victim object describes the target of an attack or abuse..
++ + | ++victim is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +
---|---|---|---|
classification |
+text |
+
+ + |
+
+ + |
+
name |
+text |
+
+ + |
+
+ + |
+
sectors |
+text |
+
+ + |
+
+ + |
+
description |
+text |
+
+ + |
+
+ + |
+
regions |
+text |
+
+ + |
+
+ + |
+
roles |
+text |
+
+ + |
+
+ + |
+
id
-vulnerability
-
-
summary
text
text
vulnerable_configuration
text
@@ -4126,6 +4215,26 @@ vulnerability is a MISP object available in JSON format at
text
text
+
+
id
vulnerability
+
+
published
datetime
vulnerable_configuration
text
-
-
domain
+domain
+
+
registrant-phone
whois-registrant-phone
+
+
expiration-date
datetime
+
+
registrant-email
whois-registrant-email
+
+
creation-date
datetime
registar
whois-registrar
-
-
expiration-date
datetime
-
-
registrant-phone
whois-registrant-phone
-
-
registrant-email
whois-registrant-email
registrant-name
whois-registrant-name
registrant-name
-whois-registrant-name
-
-
domain
domain
registar
whois-registrar
serial-number
+text
+
+
pubkey-info-size
text
x509-fingerprint-sha256
sha256
-
-
validity-not-after
datetime
x509-fingerprint-md5
md5
x509-fingerprint-sha1
-sha1
validity-not-after
datetime
serial-number
+validity-not-before
datetime
+
+
x509-fingerprint-sha256
sha256
+
+
pubkey-info-modulus
text
@@ -4412,7 +4531,7 @@ x509 is a MISP object available in JSON format at
pubkey-info-modulus
issuer
text
@@ -4422,8 +4541,8 @@ x509 is a MISP object available in JSON format at
issuer
text
x509-fingerprint-sha1
sha1
validity-not-before
datetime
-
-
x509-fingerprint-md5
md5
-
-
comment
+comment
+
+
version
comment
yara-hunt
yara
-
-
comment
comment
-
-
whitelist
comment
yara-hunt
yara
+
+