From 3da59c78a936ae60ac4fe050438aa776d4009a5d Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Fri, 5 Jan 2018 14:37:56 +0100
Subject: [PATCH] objects updated
---
objects.html | 3940 +-
objects.pdf | 132556 ++++++++++++++++++++++++------------------------
2 files changed, 68648 insertions(+), 67848 deletions(-)
diff --git a/objects.html b/objects.html
index b0cae4a..20dad42 100755
--- a/objects.html
+++ b/objects.html
@@ -561,10 +561,10 @@ ail-leak is a MISP object available in JSON format at origin
duplicate
text
The link where the leak is (or was) accessible at first-seen.
+Duplicate of the existing leaks.
@@ -581,30 +581,40 @@ ail-leak is a MISP object available in JSON format at
text
text
duplicate_number
counter
A description of the leak which could include the potential victim(s) or description of the leak.
--
type
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
+Number of known duplicates.
duplicate
first-seen
datetime
When the leak has been accessible or seen for the first time.
++
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
++
origin
text
Duplicate of the existing leaks.
+The link where the leak is (or was) accessible at first-seen.
@@ -621,6 +631,16 @@ ail-leak is a MISP object available in JSON format at
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
++
last-seen
datetime
duplicate_number
counter
type
text
Number of known duplicates.
+Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
--
first-seen
datetime
When the leak has been accessible or seen for the first time.
--
import
-text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
description
text
Description of the autonomous system
--
subnet-announced
ip-src
Subnet announced
--
country
text
export
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
last-seen
datetime
Last time the ASN was seen
--
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
--
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
--
asn
AS
subnet-announced
ip-src
Subnet announced
++
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
last-seen
datetime
Last time the ASN was seen
++
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
import
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
++
export
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
++
description
text
Description of the autonomous system
++
datetime
-datetime
Datetime
--
software
text
text
Name of antivirus software
+Free text value to attach to the file
@@ -925,10 +915,20 @@ av-signature is a MISP object available in JSON format at
text
datetime
datetime
Datetime
++
software
text
Free text value to attach to the file
+Name of antivirus software
@@ -973,36 +973,6 @@ coin-address is a MISP object available in JSON format at
address
btc
Address used as a payment destination in a cryptocurrency
--
symbol
text
The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
--
last-seen
datetime
Last time this payment destination address has been seen
--
text
text
symbol
text
The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
++
address
btc
Address used as a payment destination in a cryptocurrency
++
last-seen
datetime
Last time this payment destination address has been seen
++
cookie-value
+text
Value of the cookie (if splitted)
++
text
text
type
cookie-name
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
--
cookie-value
text
Value of the cookie (if splitted)
+Name of the cookie (if splitted)
@@ -1101,10 +1101,10 @@ cookie is a MISP object available in JSON format at
cookie-name
type
text
Name of the cookie (if splitted)
+Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
@@ -1149,6 +1149,16 @@ credential is a MISP object available in JSON format at
origin
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
++
password
text
origin
format
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
+Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
@@ -1179,20 +1189,10 @@ credential is a MISP object available in JSON format at
format
notification
text
Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
--
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
+Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
@@ -1209,10 +1209,10 @@ credential is a MISP object available in JSON format at
notification
type
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
+Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
@@ -1257,16 +1257,6 @@ credit-card is a MISP object available in JSON format at
card-security-code
text
Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
--
cc-number
cc-number
comment
comment
A description of the card.
--
name
text
issued
datetime
comment
comment
Initial date of validity or issued date.
+A description of the card.
++
card-security-code
text
Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
++
version
text
Version of the card.
@@ -1317,10 +1317,10 @@ credit-card is a MISP object available in JSON format at
version
text
issued
datetime
Version of the card.
+Initial date of validity or issued date.
@@ -1365,86 +1365,6 @@ ddos is a MISP object available in JSON format at
total-pps
counter
Packets per second
--
dst-port
port
Destination port of the attack
--
domain-dst
domain
Destination domain (victim)
--
first-seen
datetime
Beginning of the attack
--
text
text
Description of the DDoS
--
src-port
port
Port originating the attack
--
last-seen
datetime
End of the attack
--
ip-dst
ip-dst
Destination IP (victim)
--
ip-src
ip-src
first-seen
datetime
Beginning of the attack
++
dst-port
port
Destination port of the attack
++
last-seen
datetime
End of the attack
++
src-port
port
Port originating the attack
++
text
text
Description of the DDoS
++
total-pps
counter
Packets per second
++
total-bps
counter
domain-dst
domain
Destination domain (victim)
++
ip-dst
ip-dst
Destination IP (victim)
++
ApplicationId
+Destination-Realm
text
Application-ID is used to identify for which Diameter application the message is applicable.
+Destination-Realm.
CmdCode
category
text
A decimal representation of the diameter Command Code.
+Category. ['Cat0', 'Cat1', 'Cat2', 'Cat3', 'CatSMS']
@@ -1543,10 +1543,50 @@ diameter-attack is a MISP object available in JSON format at
category
Origin-Realm
text
Category. ['Cat0', 'Cat1', 'Cat2', 'Cat3', 'CatSMS']
+Origin-Realm.
++
Destination-Host
text
Destination-Host.
++
Origin-Host
text
Origin-Host.
++
Username
text
Username (in this case, usually the IMSI).
++
IdrFlags
text
IDR-Flags.
SessionId
text
Session-ID.
++
CmdCode
text
A decimal representation of the diameter Command Code.
++
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
++
last-seen
+text
text
A description of the tuple
++
domain
domain
Domain name
++
first-seen
datetime
Last time the tuple has been seen
+First time the tuple has been seen
@@ -1621,30 +1711,10 @@ domain-ip is a MISP object available in JSON format at
domain
domain
Domain name
--
text
text
A description of the tuple
--
first-seen
last-seen
datetime
First time the tuple has been seen
+Last time the tuple has been seen
@@ -1689,10 +1759,10 @@ elf is a MISP object available in JSON format at
entrypoint-address
text
number-sections
counter
Address of the entry point
+Number of sections
@@ -1709,6 +1779,26 @@ elf is a MISP object available in JSON format at
entrypoint-address
text
Address of the entry point
++
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
++
text
text
number-sections
counter
Number of sections
--
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
--
entropy
-float
Entropy of the whole section
--
md5
md5
name
text
Name of the section
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
size-in-bytes
size-in-bytes
flag
name
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
+Name of the section
@@ -1857,16 +1897,26 @@ elf-section is a MISP object available in JSON format at
sha512/224
sha512/224
ssdeep
ssdeep
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
text
text
Free text value to attach to the section
++
sha1
sha1
sha512
sha512
sha256
sha256
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -1897,20 +1947,30 @@ elf-section is a MISP object available in JSON format at
type
flag
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
+Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
sha256
sha256
sha512
sha512
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (512 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
@@ -1927,10 +1987,20 @@ elf-section is a MISP object available in JSON format at
text
entropy
float
Entropy of the whole section
++
type
text
Free text value to attach to the section
+Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
@@ -1975,10 +2045,10 @@ email is a MISP object available in JSON format at
message-id
email-message-id
return-path
text
Message ID
+Message return path
@@ -1995,36 +2065,6 @@ email is a MISP object available in JSON format at
reply-to
email-reply-to
Email address the reply will be sent to
--
return-path
text
Message return path
--
thread-index
email-thread-index
Identifies a particular conversation thread
--
mime-boundary
email-mime-boundary
subject
email-subject
Subject
++
send-date
datetime
to
email-dst
message-id
email-message-id
Destination email address
+Message ID
@@ -2065,6 +2115,76 @@ email is a MISP object available in JSON format at
header
email-header
Full headers
++
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
++
to-display-name
email-dst-display-name
Display name of the receiver
++
screenshot
attachment
Screenshot of email
++
reply-to
email-reply-to
Email address the reply will be sent to
++
to
email-dst
Destination email address
++
thread-index
email-thread-index
Identifies a particular conversation thread
++
from-display-name
email-src-display-name
screenshot
attachment
Screenshot of email
--
subject
email-subject
Subject
--
to-display-name
email-dst-display-name
Display name of the receiver
--
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
--
header
email-header
Full headers
--
entropy
-float
Entropy of the whole file
--
md5
md5
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
mimetype
text
Mime type
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
malware-sample
malware-sample
sha512
sha512
size-in-bytes
size-in-bytes
Secure Hash Algorithm 2 (512 bits)
+Size of the file, in bytes
++
mimetype
text
Mime type
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
@@ -2313,10 +2313,30 @@ file is a MISP object available in JSON format at
authentihash
authentihash
text
text
Authenticode executable signature hash
+Free text value to attach to the file
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
@@ -2343,16 +2363,66 @@ file is a MISP object available in JSON format at
sha256
sha256
sha512
sha512
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (512 bits)
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
authentihash
authentihash
Authenticode executable signature hash
++
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
++
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
++
sha224
sha224
text
text
entropy
float
Free text value to attach to the file
+Entropy of the whole file
@@ -2411,16 +2481,6 @@ geolocation is a MISP object available in JSON format at
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
--
country
text
city
text
City.
--
region
text
Region.
--
last-seen
datetime
When the location was seen for the last time.
--
first-seen
datetime
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
++
text
text
last-seen
datetime
When the location was seen for the last time.
++
region
text
Region.
++
city
text
City.
++
GtpImei
-text
GTP IMEI (International Mobile Equipment Identity).
--
ipDest
ip-dst
GtpVersion
text
GTP version ['0', '1', '2']
--
GtpServingNetwork
text
GTP Serving Network.
--
GtpMsisdn
text
GTP MSISDN.
--
PortSrc
port
Source port.
--
first-seen
datetime
When the attack has been seen for the first time.
--
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8']
--
GtpMessageType
text
GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
--
text
text
A description of the GTP attack.
--
GtpImsi
text
GTP IMSI (International mobile subscriber identity).
--
PortDest
text
GtpImsi
text
GTP IMSI (International mobile subscriber identity).
++
GtpMsisdn
text
GTP MSISDN.
++
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
++
PortSrc
port
Source port.
++
GtpMessageType
text
GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
++
first-seen
datetime
When the attack has been seen for the first time.
++
GtpVersion
text
GTP version ['0', '1', '2']
++
ipSrc
ip-src
text
text
A description of the GTP attack.
++
GtpImei
text
GTP IMEI (International Mobile Equipment Identity).
++
GtpServingNetwork
text
GTP Serving Network.
++
basicauth-password
-text
HTTP Basic Authentication Password
--
host
hostname
The domain name of the server
--
content-type
other
basicauth-user
basicauth-password
text
HTTP Basic Authentication Username
+HTTP Basic Authentication Password
proxy-user
text
method
http-method
HTTP Proxy Username
+HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
-
user-agent
user-agent
The user agent string of the user agent
-+
method
-http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
--
referer
referer
proxy-user
text
HTTP Proxy Username
++
proxy-password
text
user-agent
user-agent
The user agent string of the user agent
++
basicauth-user
text
HTTP Basic Authentication Username
++
url
url
host
hostname
The domain name of the server
++
dst-port
-port
first-seen
datetime
Destination port
--
text
text
Description of the tuple
+First time the tuple has been seen
src-port
dst-port
port
Source port
+Destination port
@@ -2915,6 +2975,16 @@ ip-port is a MISP object available in JSON format at
text
text
Description of the tuple
++
ip
ip-dst
first-seen
datetime
src-port
port
First time the tuple has been seen
+Source port
+
description
-text
Type of detected software ie software, malware
--
last-seen
datetime
Last seen of the SSL/TLS handshake
--
ja3-fingerprint-md5
md5
Hash identifying source
--
ip-dst
ip-dst
Destination IP address
--
ip-src
ip-src
ja3-fingerprint-md5
md5
Hash identifying source
++
last-seen
datetime
Last seen of the SSL/TLS handshake
++
ip-dst
ip-dst
Destination IP address
++
description
text
Type of detected software ie software, malware
++
text
+text
Free text value to attach to the Mach-O file
++
entrypoint-address
text
text
text
Free text value to attach to the Mach-O file
--
name
text
entropy
float
Entropy of the whole section
--
md5
md5
name
text
Name of the section
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
size-in-bytes
size-in-bytes
name
text
Name of the section
++
sha512/256
sha512/256
sha512/224
sha512/224
ssdeep
ssdeep
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
text
text
Free text value to attach to the section
++
sha1
sha1
sha512
sha512
sha256
sha256
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -3259,10 +3319,20 @@ macho-section is a MISP object available in JSON format at
sha256
sha256
sha512
sha512
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (512 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
@@ -3279,10 +3349,10 @@ macho-section is a MISP object available in JSON format at
text
text
entropy
float
Free text value to attach to the section
+Entropy of the whole section
@@ -3327,50 +3397,10 @@ microblog is a MISP object available in JSON format at
post
username-quoted
text
Raw post
--
removal-date
datetime
When the microblog post was removed
--
url
url
Original URL location of the microblog post
--
type
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
--
creation-date
datetime
Initial creation of the microblog post
+Username who are quoted into the microblog post
@@ -3387,20 +3417,20 @@ microblog is a MISP object available in JSON format at
username
text
removal-date
datetime
Username who posted the microblog post
+When the microblog post was removed
username-quoted
post
text
Username who are quoted into the microblog post
+Raw post
type
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
++
url
url
Original URL location of the microblog post
++
creation-date
datetime
Initial creation of the microblog post
++
username
text
Username who posted the microblog post
++
dst-port
-port
Destination port of the netflow
--
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
--
packet-count
counter
Packets counted in this flow
--
src-port
port
Source port of the netflow
--
direction
text
Direction of this flow ['Ingress', 'Egress']
--
dst-as
AS
Destination AS number for this flow
--
flow-count
counter
Flows counted in this flow
--
byte-count
counter
Bytes counted in this flow
--
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
--
ip_version
counter
IP version of this flow
--
first-packet-seen
datetime
ip-protocol-number
size-in-bytes
packet-count
counter
IP protocol number of this flow
+Packets counted in this flow
@@ -3585,6 +3555,36 @@ netflow is a MISP object available in JSON format at
ip-protocol-number
size-in-bytes
IP protocol number of this flow
++
dst-as
AS
Destination AS number for this flow
++
byte-count
counter
Bytes counted in this flow
++
last-packet-seen
datetime
ip-dst
ip-dst
src-port
port
IP address destination of the netflow
+Source port of the netflow
@@ -3615,6 +3615,36 @@ netflow is a MISP object available in JSON format at
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
++
dst-port
port
Destination port of the netflow
++
direction
text
Direction of this flow ['Ingress', 'Egress']
++
src-as
AS
flow-count
counter
Flows counted in this flow
++
ip_version
counter
IP version of this flow
++
ip-dst
ip-dst
IP address destination of the netflow
++
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
++
origin
-text
Origin of the Passive DNS response
--
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
--
count
counter
rdata
text
Resource records of the queried resource
--
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
--
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
rrname
text
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
++
bailiwick
text
origin
text
Origin of the Passive DNS response
++
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
rdata
text
Resource records of the queried resource
++
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
++
sensor_id
text
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
++
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
paste
+first-seen
datetime
When the paste has been accessible or seen for the first time.
++
last-seen
datetime
When the paste has been accessible or seen for the last time.
++
title
text
Raw text of the paste or post
+Title of the paste or post.
@@ -3851,35 +3941,15 @@ paste is a MISP object available in JSON format at
title
paste
text
Title of the paste or post.
+Raw text of the paste or post
last-seen
datetime
When the paste has been accessible or seen for the last time.
--
first-seen
datetime
When the paste has been accessible or seen for the first time.
--
entrypoint-address
+legal-copyright
text
Address of the entry point
+LegalCopyright in the resources
++
number-sections
counter
Number of sections
@@ -3939,6 +4019,16 @@ pe is a MISP object available in JSON format at
imphash
imphash
Hash (md5) calculated from the import table
++
lang-id
text
imphash
imphash
Hash (md5) calculated from the import table
--
type
text
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
file-description
text
FileDescription in the resources
--
product-version
text
ProductVersion in the resources
+Free text value to attach to the PE
@@ -4009,10 +4069,20 @@ pe is a MISP object available in JSON format at
company-name
product-version
text
CompanyName in the resources
+ProductVersion in the resources
++
file-version
text
FileVersion in the resources
@@ -4029,16 +4099,6 @@ pe is a MISP object available in JSON format at
text
text
Free text value to attach to the PE
--
original-filename
filename
file-version
text
FileVersion in the resources
--
number-sections
counter
Number of sections
--
legal-copyright
text
LegalCopyright in the resources
--
compilation-timestamp
datetime
file-description
text
FileDescription in the resources
++
entrypoint-address
text
Address of the entry point
++
company-name
text
CompanyName in the resources
++
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
++
entropy
-float
Entropy of the whole section
--
md5
md5
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
size-in-bytes
size-in-bytes
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
++
sha512/256
sha512/256
sha512/224
sha512/224
ssdeep
ssdeep
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
text
text
Free text value to attach to the section
++
sha1
sha1
sha512
sha512
sha256
sha256
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -4237,10 +4297,20 @@ pe-section is a MISP object available in JSON format at
sha256
sha256
sha512
sha512
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (512 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
@@ -4267,10 +4337,10 @@ pe-section is a MISP object available in JSON format at
text
text
entropy
float
Free text value to attach to the section
+Entropy of the whole section
@@ -4315,26 +4385,6 @@ person is a MISP object available in JSON format at
passport-expiration
passport-expiration
The expiration date of a passport.
--
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
--
first-name
first-name
middle-name
middle-name
date-of-birth
date-of-birth
Middle name of a natural person
--
gender
gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
--
last-name
last-name
Last name of a natural person.
--
passport-number
passport-number
The passport number of a natural person.
+Date of birth of a natural person (in YYYY-MM-DD format).
@@ -4405,6 +4425,16 @@ person is a MISP object available in JSON format at
middle-name
middle-name
Middle name of a natural person
++
passport-country
passport-country
gender
gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
++
place-of-birth
place-of-birth
last-name
last-name
Last name of a natural person.
++
passport-expiration
passport-expiration
The expiration date of a passport.
++
passport-number
passport-number
The passport number of a natural person.
++
nationality
nationality
gummei
guti
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
--
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
+Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
@@ -4503,30 +4563,10 @@ phone is a MISP object available in JSON format at
text
imei
text
A description of the phone.
--
serial-number
text
Serial Number.
--
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
+International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
@@ -4553,6 +4593,26 @@ phone is a MISP object available in JSON format at
text
text
A description of the phone.
++
serial-number
text
Serial Number.
++
msisdn
text
gummei
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
++
imsi
text
memory-allocations
unknown-references
counter
Amount of memory allocations
--
callback-largest
counter
Largest callback
--
referenced-strings
counter
Amount of referenced strings
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
total-functions
counter
Total amount of functions in the file.
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
not-referenced-strings
counter
Amount of not referenced strings
--
total-api
counter
Total amount of API calls
+Amount of API calls not ending in a function (Radare2 bug, probalby)
@@ -4721,50 +4701,10 @@ r2graphity is a MISP object available in JSON format at
gml
attachment
Graph export in G>raph Modelling Language format
--
create-thread
local-references
counter
Amount of calls to CreateThread
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
--
text
text
Description of the r2graphity object
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
+Amount of API calls inside a code section
@@ -4781,26 +4721,6 @@ r2graphity is a MISP object available in JSON format at
callback-average
counter
Average size of a callback
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
get-proc-address
counter
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
++
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
r2-commit-version
text
local-references
not-referenced-strings
counter
Amount of API calls inside a code section
+Amount of not referenced strings
++
callback-largest
counter
Largest callback
++
create-thread
counter
Amount of calls to CreateThread
++
gml
attachment
Graph export in G>raph Modelling Language format
++
total-api
counter
Total amount of API calls
++
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
++
memory-allocations
counter
Amount of memory allocations
++
total-functions
counter
Total amount of functions in the file.
++
referenced-strings
counter
Amount of referenced strings
++
callback-average
counter
Average size of a callback
++
text
text
Description of the r2graphity object
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
@@ -4879,16 +4949,6 @@ regexp is a MISP object available in JSON format at
comment
comment
A description of the regular expression.
--
regexp-type
text
comment
comment
A description of the regular expression.
++
regexp
text
name
text
Name of the registry key
--
last-modified
datetime
Last time the registry key has been modified
--
data
text
name
text
Name of the registry key
++
data-type
text
last-modified
datetime
Last time the registry key has been modified
++
summary
+case-number
text
Free text summary of the report
+Case number
case-number
summary
text
Case number
+Free text summary of the report
@@ -5103,26 +5173,6 @@ rtir is a MISP object available in JSON format at
constituency
text
Constituency of the RTIR ticket
--
status
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
--
ticket-number
text
classification
text
Classification of the RTIR ticket
--
subject
text
Subject of the RTIR ticket
--
queue
text
subject
text
Subject of the RTIR ticket
++
classification
text
Classification of the RTIR ticket
++
ip
ip-dst
status
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
++
constituency
text
Constituency of the RTIR ticket
++
published
-datetime
router’s publication time. This can be different from first-seen and last-seen.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
document
text
Raw document from the consensus.
--
nickname
text
router’s nickname.
--
description
text
flags
text
list of flag associated with the node.
++
text
text
last-seen
published
datetime
When the Tor node designed by the IP address has been seen for the last time.
+router’s publication time. This can be different from first-seen and last-seen.
version_line
text
versioning information reported by the node.
--
flags
text
list of flag associated with the node.
--
first-seen
datetime
document
text
Raw document from the consensus.
++
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
++
nickname
text
router’s nickname.
++
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
version_line
text
versioning information reported by the node.
++
fragment
-text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
--
tld
text
Top-Level Domain
--
credential
text
port
port
Port number
++
host
hostname
Full hostname
++
domain_without_tld
text
Domain without Top-Level Domain
++
text
text
Description of the URL
++
tld
text
Top-Level Domain
++
domain
domain
Full domain
++
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
++
first-seen
datetime
First time this URL has been seen
++
last-seen
datetime
Last time this URL has been seen
++
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
++
url
url
host
hostname
Full hostname
--
port
port
Port number
--
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
--
text
text
Description of the URL
--
domain_without_tld
text
Domain without Top-Level Domain
--
domain
domain
Full domain
--
last-seen
datetime
Last time this URL has been seen
--
query_string
text
first-seen
datetime
First time this URL has been seen
--
description
+sectors
text
Description of the victim
+The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
--
node
target-machine
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
++
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
++
user
target-user
The username(s) of the user targeted.
++
target-email
description
text
Description of the victim
++
ip-address
ip-dst
user
target-user
The username(s) of the user targeted.
--
roles
text
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
--
external
target-external
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
--
first-submission
-datetime
community-score
text
First Submission
+Community Score
+
last-submission
datetime
permalink
link
Last Submission
+Permalink Reference
@@ -5793,20 +5863,20 @@ virustotal-report is a MISP object available in JSON format at
community-score
text
first-submission
datetime
Community Score
+First Submission
+
permalink
link
last-submission
datetime
Permalink Reference
+Last Submission
@@ -5861,6 +5931,36 @@ vulnerability is a MISP object available in JSON format at
references
link
External references
++
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely)
++
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
++
text
text
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
references
link
External references
--
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely)
--
creation-date
+expiration-date
datetime
Initial creation of the whois entry
+Expiration of the whois entry
domain
domain
nameserver
hostname
Domain of the whois entry
+Nameserver
++
modification-date
datetime
Last update of the whois entry
++
registrant-email
whois-registrant-email
Registrant email address
++
registrant-name
whois-registrant-name
Registrant name
++
registrar
whois-registrar
Registrar of the whois entry
@@ -5989,46 +6099,16 @@ whois is a MISP object available in JSON format at
registrar
whois-registrar
registrant-phone
whois-registrant-phone
Registrar of the whois entry
+Registrant phone number
modification-date
datetime
Last update of the whois entry
--
registrant-name
whois-registrant-name
Registrant name
--
expiration-date
datetime
Expiration of the whois entry
--
registrant-org
whois-registrant-org
registrant-email
whois-registrant-email
creation-date
datetime
Registrant email address
--
nameserver
hostname
Nameserver
+Initial creation of the whois entry
registrant-phone
whois-registrant-phone
domain
domain
Registrant phone number
+Domain of the whois entry
@@ -6117,10 +6187,10 @@ x509 is a MISP object available in JSON format at
validity-not-before
datetime
pubkey-info-size
text
Certificate invalid before that date
+Length of the public key (in bits)
@@ -6137,40 +6207,10 @@ x509 is a MISP object available in JSON format at
pubkey-info-algorithm
text
text
Algorithm of the public key
--
validity-not-after
datetime
Certificate invalid after that date
--
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
--
version
text
Version of the certificate
+Free text description of hte certificate
@@ -6187,20 +6227,30 @@ x509 is a MISP object available in JSON format at
pubkey-info-modulus
pubkey-info-exponent
text
Modulus of the public key
+Exponent of the public key
subject
text
validity-not-after
datetime
Subject of the certificate
+Certificate invalid after that date
++
validity-not-before
datetime
Certificate invalid before that date
@@ -6217,6 +6267,36 @@ x509 is a MISP object available in JSON format at
subject
text
Subject of the certificate
++
pubkey-info-modulus
text
Modulus of the public key
++
version
text
Version of the certificate
++
x509-fingerprint-sha256
x509-fingerprint-sha256
pubkey-info-size
pubkey-info-algorithm
text
Length of the public key (in bits)
+Algorithm of the public key
pubkey-info-exponent
text
x509-fingerprint-md5
x509-fingerprint-md5
Exponent of the public key
--
text
text
Free text description of hte certificate
+[Insecure] MD5 hash (128 bits)
@@ -6305,16 +6375,6 @@ yabin is a MISP object available in JSON format at
whitelist
comment
Whitelist name used to generate the rules.
--
version
comment
comment
whitelist
comment
A description of Yara rule generated.
+Whitelist name used to generate the rules.
comment
comment
A description of Yara rule generated.
++