From 46ed6e9a4f4efe0d08353606b30c19b79d04f5eb Mon Sep 17 00:00:00 2001 From: Alexandre Dulaunoy Date: Sun, 18 Dec 2016 14:27:38 +0100 Subject: [PATCH] Taxonomies updated --- taxonomies.html | 10244 ---------------------------------------------- 1 file changed, 10244 deletions(-) diff --git a/taxonomies.html b/taxonomies.html index 8ab9553..e69de29 100644 --- a/taxonomies.html +++ b/taxonomies.html @@ -1,10244 +0,0 @@ -:toc: right -:icons: font -:images-cdn: https://raw.githubusercontent.com/MISP/MISP/2.4/INSTALL/logos/ -= MISP taxonomies and classification as machine tags - -Generated from https://github.com/MISP/misp-taxonomies. - - -image::{images-cdn}misp-logo.png[MISP logo] -Taxonomies that can be used in MISP (2.4) and other information sharing tool and expressed in Machine Tags (Triple Tags). A machine tag is composed of a namespace (MUST), a predicate (MUST) and an (OPTIONAL) value. Machine tags are often called triple tag due to their format. - - - -== veris -NOTE: veris namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/veris/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Vocabulary for Event Recording and Incident Sharing (VERIS) - -=== iso_currency_code -==== veris:iso_currency_code="DZD" - -veris:DZD - Algerian Dinar - -==== veris:iso_currency_code="NAD" - -veris:NAD - Namibia Dollar - -==== veris:iso_currency_code="GHS" - -veris:GHS - Ghana Cedi - -==== veris:iso_currency_code="EGP" - -veris:EGP - Egyptian Pound - -==== veris:iso_currency_code="BGN" - -veris:BGN - Bulgarian Lev - -==== veris:iso_currency_code="PAB" - -veris:PAB - Balboa - -==== veris:iso_currency_code="BOB" - -veris:BOB - Boliviano - -==== veris:iso_currency_code="DKK" - -veris:DKK - Danish Krone - -==== veris:iso_currency_code="BWP" - -veris:BWP - Pula - -==== veris:iso_currency_code="LBP" - -veris:LBP - Lebanese Pound - -==== veris:iso_currency_code="TZS" - -veris:TZS - Tanzanian Shilling - -==== veris:iso_currency_code="VND" - -veris:VND - Dong - -==== veris:iso_currency_code="AOA" - -veris:AOA - Kwanza - -==== veris:iso_currency_code="KHR" - -veris:KHR - Riel - -==== veris:iso_currency_code="MYR" - -veris:MYR - Malaysian Ringgit - -==== veris:iso_currency_code="KYD" - -veris:KYD - Cayman Islands Dollar - -==== veris:iso_currency_code="LYD" - -veris:LYD - Libyan Dinar - -==== veris:iso_currency_code="UAH" - -veris:UAH - Hryvnia - -==== veris:iso_currency_code="JOD" - -veris:JOD - Jordanian Dinar - -==== veris:iso_currency_code="AWG" - -veris:AWG - Aruban Florin - -==== veris:iso_currency_code="SAR" - -veris:SAR - Saudi Riyal - -==== veris:iso_currency_code="EUR" - -veris:EUR - Euro - -==== veris:iso_currency_code="HKD" - -veris:HKD - Hong Kong Dollar - -==== veris:iso_currency_code="CHF" - -veris:CHF - Swiss Franc - -==== veris:iso_currency_code="GIP" - -veris:GIP - Gibraltar Pound - -==== veris:iso_currency_code="BYR" - -veris:BYR - Belarussian Ruble - -==== veris:iso_currency_code="ALL" - -veris:ALL - Lek - -==== veris:iso_currency_code="MRO" - -veris:MRO - Ouguiya - -==== veris:iso_currency_code="HRK" - -veris:HRK - Croatian Kuna - -==== veris:iso_currency_code="DJF" - -veris:DJF - Djibouti Franc - -==== veris:iso_currency_code="SZL" - -veris:SZL - Lilangeni - -==== veris:iso_currency_code="THB" - -veris:THB - Baht - -==== veris:iso_currency_code="XAF" - -veris:XAF - CFA Franc BEAC - -==== veris:iso_currency_code="BND" - -veris:BND - Brunei Dollar - -==== veris:iso_currency_code="ISK" - -veris:ISK - Iceland Krona - -==== veris:iso_currency_code="UYU" - -veris:UYU - Peso Uruguayo - -==== veris:iso_currency_code="NIO" - -veris:NIO - Cordoba Oro - -==== veris:iso_currency_code="LAK" - -veris:LAK - Kip - -==== veris:iso_currency_code="SYP" - -veris:SYP - Syrian Pound - -==== veris:iso_currency_code="MAD" - -veris:MAD - Moroccan Dirham - -==== veris:iso_currency_code="MZN" - -veris:MZN - Mozambique Metical - -==== veris:iso_currency_code="PHP" - -veris:PHP - Philippine Peso - -==== veris:iso_currency_code="ZAR" - -veris:ZAR - South African Rand - -==== veris:iso_currency_code="NPR" - -veris:NPR - Nepalese Rupee - -==== veris:iso_currency_code="NGN" - -veris:NGN - Naira - -==== veris:iso_currency_code="ZWD" - -veris:ZWD - Zimbabwean Dollar A/06 - -==== veris:iso_currency_code="CRC" - -veris:CRC - Costa Rican Colon - -==== veris:iso_currency_code="AED" - -veris:AED - UAE Dirham - -==== veris:iso_currency_code="GBP" - -veris:GBP - Pound Sterling - -==== veris:iso_currency_code="MWK" - -veris:MWK - Kwacha - -==== veris:iso_currency_code="LKR" - -veris:LKR - Sri Lanka Rupee - -==== veris:iso_currency_code="PKR" - -veris:PKR - Pakistan Rupee - -==== veris:iso_currency_code="HUF" - -veris:HUF - Forint - -==== veris:iso_currency_code="BMD" - -veris:BMD - Bermudian Dollar - -==== veris:iso_currency_code="LSL" - -veris:LSL - Loti - -==== veris:iso_currency_code="MNT" - -veris:MNT - Tugrik - -==== veris:iso_currency_code="AMD" - -veris:AMD - Armenian Dram - -==== veris:iso_currency_code="UGX" - -veris:UGX - Uganda Shilling - -==== veris:iso_currency_code="QAR" - -veris:QAR - Qatari Rial - -==== veris:iso_currency_code="XDR" - -veris:XDR - SDR (Special Drawing Right) - -==== veris:iso_currency_code="JMD" - -veris:JMD - Jamaican Dollar - -==== veris:iso_currency_code="GEL" - -veris:GEL - Lari - -==== veris:iso_currency_code="SHP" - -veris:SHP - Saint Helena Pound - -==== veris:iso_currency_code="AFN" - -veris:AFN - Afghani - -==== veris:iso_currency_code="SBD" - -veris:SBD - Solomon Islands Dollar - -==== veris:iso_currency_code="KPW" - -veris:KPW - North Korean Won - -==== veris:iso_currency_code="TRY" - -veris:TRY - Turkish Lira - -==== veris:iso_currency_code="BDT" - -veris:BDT - Taka - -==== veris:iso_currency_code="YER" - -veris:YER - Yemeni Rial - -==== veris:iso_currency_code="HTG" - -veris:HTG - Gourde - -==== veris:iso_currency_code="XOF" - -veris:XOF - CFA Franc BCEAO - -==== veris:iso_currency_code="MGA" - -veris:MGA - Malagasy Ariary - -==== veris:iso_currency_code="ANG" - -veris:ANG - Netherlands Antillean Guilder - -==== veris:iso_currency_code="LRD" - -veris:LRD - Liberian Dollar - -==== veris:iso_currency_code="RWF" - -veris:RWF - Rwanda Franc - -==== veris:iso_currency_code="NOK" - -veris:NOK - Norwegian Krone - -==== veris:iso_currency_code="MOP" - -veris:MOP - Pataca - -==== veris:iso_currency_code="INR" - -veris:INR - Indian Rupee - -==== veris:iso_currency_code="MXN" - -veris:MXN - Mexican Peso - -==== veris:iso_currency_code="CZK" - -veris:CZK - Czech Koruna - -==== veris:iso_currency_code="TJS" - -veris:TJS - Somoni - -==== veris:iso_currency_code="TWD" - -veris:TWD - New Taiwan Dollar - -==== veris:iso_currency_code="BTN" - -veris:BTN - Ngultrum - -==== veris:iso_currency_code="COP" - -veris:COP - Colombian Peso - -==== veris:iso_currency_code="TMT" - -veris:TMT - Turkmenistan New Manat - -==== veris:iso_currency_code="MUR" - -veris:MUR - Mauritius Rupee - -==== veris:iso_currency_code="IDR" - -veris:IDR - Rupiah - -==== veris:iso_currency_code="HNL" - -veris:HNL - Lempira - -==== veris:iso_currency_code="XPF" - -veris:XPF - CFP Franc - -==== veris:iso_currency_code="FJD" - -veris:FJD - Fiji Dollar - -==== veris:iso_currency_code="ETB" - -veris:ETB - Ethiopian Birr - -==== veris:iso_currency_code="PEN" - -veris:PEN - Nuevo Sol - -==== veris:iso_currency_code="BZD" - -veris:BZD - Belize Dollar - -==== veris:iso_currency_code="ILS" - -veris:ILS - New Israeli Sheqel - -==== veris:iso_currency_code="DOP" - -veris:DOP - Dominican Peso - -==== veris:iso_currency_code="GGP" - -veris:GGP - Guernsey pound - -==== veris:iso_currency_code="MDL" - -veris:MDL - Moldovan Leu - -==== veris:iso_currency_code="BSD" - -veris:BSD - Bahamian Dollar - -==== veris:iso_currency_code="SPL" - -veris:SPL - Seborga Luigino - -==== veris:iso_currency_code="SEK" - -veris:SEK - Swedish Krona - -==== veris:iso_currency_code="ZMK" - -veris:ZMK - Zambian Kwacha - -==== veris:iso_currency_code="JEP" - -veris:JEP - Jersey pound - -==== veris:iso_currency_code="AUD" - -veris:AUD - Australian Dollar - -==== veris:iso_currency_code="SRD" - -veris:SRD - Surinam Dollar - -==== veris:iso_currency_code="CUP" - -veris:CUP - Cuban Peso - -==== veris:iso_currency_code="BBD" - -veris:BBD - Barbados Dollar - -==== veris:iso_currency_code="KMF" - -veris:KMF - Comoro Franc - -==== veris:iso_currency_code="KRW" - -veris:KRW - South Korean Won - -==== veris:iso_currency_code="GMD" - -veris:GMD - Dalasi - -==== veris:iso_currency_code="VEF" - -veris:VEF - Bolivar - -==== veris:iso_currency_code="IMP" - -veris:IMP - Isle of Man Pound - -==== veris:iso_currency_code="CUC" - -veris:CUC - Peso Convertible - -==== veris:iso_currency_code="TVD" - -veris:TVD - Tuvalu Dollar - -==== veris:iso_currency_code="CLP" - -veris:CLP - Chilean Peso - -==== veris:iso_currency_code="LTL" - -veris:LTL - Lithuanian Litas - -==== veris:iso_currency_code="CDF" - -veris:CDF - Congolese Franc - -==== veris:iso_currency_code="XCD" - -veris:XCD - East Caribbean Dollar - -==== veris:iso_currency_code="KZT" - -veris:KZT - Tenge - -==== veris:iso_currency_code="RUB" - -veris:RUB - Russian Ruble - -==== veris:iso_currency_code="TTD" - -veris:TTD - Trinidad and Tobago Dollar - -==== veris:iso_currency_code="OMR" - -veris:OMR - Rial Omani - -==== veris:iso_currency_code="BRL" - -veris:BRL - Brazilian Real - -==== veris:iso_currency_code="MMK" - -veris:MMK - Kyat - -==== veris:iso_currency_code="PLN" - -veris:PLN - Zloty - -==== veris:iso_currency_code="PYG" - -veris:PYG - Guarani - -==== veris:iso_currency_code="KES" - -veris:KES - Kenyan Shilling - -==== veris:iso_currency_code="SVC" - -veris:SVC - El Salvador Colon - -==== veris:iso_currency_code="MKD" - -veris:MKD - Denar - -==== veris:iso_currency_code="AZN" - -veris:AZN - Azerbaijanian Manat - -==== veris:iso_currency_code="TOP" - -veris:TOP - Pa'anga - -==== veris:iso_currency_code="MVR" - -veris:MVR - Rufiyaa - -==== veris:iso_currency_code="VUV" - -veris:VUV - Vatu - -==== veris:iso_currency_code="GNF" - -veris:GNF - Guinea Franc - -==== veris:iso_currency_code="WST" - -veris:WST - Tala - -==== veris:iso_currency_code="IQD" - -veris:IQD - Iraqi Dinar - -==== veris:iso_currency_code="ERN" - -veris:ERN - Nakfa - -==== veris:iso_currency_code="BAM" - -veris:BAM - Convertible Mark - -==== veris:iso_currency_code="SCR" - -veris:SCR - Seychelles Rupee - -==== veris:iso_currency_code="CAD" - -veris:CAD - Canadian Dollar - -==== veris:iso_currency_code="CVE" - -veris:CVE - Cape Verde Escudo - -==== veris:iso_currency_code="KWD" - -veris:KWD - Kuwaiti Dinar - -==== veris:iso_currency_code="BIF" - -veris:BIF - Burundi Franc - -==== veris:iso_currency_code="PGK" - -veris:PGK - Kina - -==== veris:iso_currency_code="SOS" - -veris:SOS - Somali Shilling - -==== veris:iso_currency_code="SGD" - -veris:SGD - Singapore Dollar - -==== veris:iso_currency_code="UZS" - -veris:UZS - Uzbekistan Sum - -==== veris:iso_currency_code="STD" - -veris:STD - Dobra - -==== veris:iso_currency_code="IRR" - -veris:IRR - Iranian Rial - -==== veris:iso_currency_code="CNY" - -veris:CNY - Yuan Renminbi - -==== veris:iso_currency_code="SLL" - -veris:SLL - Leone - -==== veris:iso_currency_code="TND" - -veris:TND - Tunisian Dinar - -==== veris:iso_currency_code="GYD" - -veris:GYD - Guyana Dollar - -==== veris:iso_currency_code="NZD" - -veris:NZD - New Zealand Dollar - -==== veris:iso_currency_code="FKP" - -veris:FKP - Falkland Islands Pound - -==== veris:iso_currency_code="LVL" - -veris:LVL - Latvian Lats - -==== veris:iso_currency_code="USD" - -veris:USD - US Dollar - -==== veris:iso_currency_code="KGS" - -veris:KGS - Som - -==== veris:iso_currency_code="ARS" - -veris:ARS - Argentine Peso - -==== veris:iso_currency_code="RON" - -veris:RON - New Romanian Leu - -==== veris:iso_currency_code="GTQ" - -veris:GTQ - Quetzal - -==== veris:iso_currency_code="RSD" - -veris:RSD - Serbian Dinar - -==== veris:iso_currency_code="BHD" - -veris:BHD - Bahraini Dinar - -==== veris:iso_currency_code="JPY" - -veris:JPY - Yen - -==== veris:iso_currency_code="SDG" - -veris:SDG - Sudanese Pound - -=== confidence -==== veris:confidence="High" - -veris:High confidence - -==== veris:confidence="None" - -veris:No confidence - -==== veris:confidence="Medium" - -veris:Medium confidence - -==== veris:confidence="Low" - -veris:Low confidence - -=== targeted -==== veris:targeted="Targeted" - -veris:Targeted: victim chosen as target then actor determined what weaknesses could be exploited - -==== veris:targeted="NA" - -veris:Not applicable - -==== veris:targeted="Opportunistic" - -veris:Opportunistic: victim attacked because they exhibited a weakness the actor knew how to exploit - -==== veris:targeted="Unknown" - -veris:Unknown - -=== discovery_method -==== veris:discovery_method="Int - financial audit" - -veris:Internal - financial audit and reconciliation process - -==== veris:discovery_method="Ext - found documents" - -veris:External - Found documents - -==== veris:discovery_method="Unknown" - -veris:Unknown - -==== veris:discovery_method="Ext - audit" - -veris:External - security audit or scan - -==== veris:discovery_method="Ext - incident response" - -veris:External - Notified while investigating another incident - -==== veris:discovery_method="Ext - unknown" - -veris:External - unknown - -==== veris:discovery_method="Other" - -veris:Other - -==== veris:discovery_method="Int - NIDS" - -veris:Internal - network IDS or IPS alert - -==== veris:discovery_method="Ext - emergency response team" - -veris:External - Emergency response team - -==== veris:discovery_method="Ext - fraud detection" - -veris:External - fraud detection (e.g., CPP) - -==== veris:discovery_method="Int - incident response" - -veris:Internal - discovered while responding to another (separate) incident - -==== veris:discovery_method="Ext - customer" - -veris:External - reported by customer or partner affected by the incident - -==== veris:discovery_method="Prt - audit" - -veris:Partner - Audit performed by a partner organization - -==== veris:discovery_method="Int - IT review" - -veris:Internal - Informal IT review - -==== veris:discovery_method="Int - log review" - -veris:Internal - log review process or SIEM - -==== veris:discovery_method="Int - unknown" - -veris:Internal - unknown - -==== veris:discovery_method="Ext - suspicious traffic" - -veris:External - Report of suspicious traffic - -==== veris:discovery_method="Int - HIDS" - -veris:Internal - host IDS or file integrity monitoring - -==== veris:discovery_method="Prt - Other" - -veris:Partner - Other - -==== veris:discovery_method="Ext - monitoring service" - -veris:External - managed security event monitoring service - -==== veris:discovery_method="Prt - antivirus" - -veris:Partner - Notified by antivirus company but not through AV product - -==== veris:discovery_method="Prt - Unknown" - -veris:Partner - Unknown - -==== veris:discovery_method="Int - security alarm" - -veris:Internal - physical security system alarm - -==== veris:discovery_method="Ext - law enforcement" - -veris:Internal - notified by law enforcement or government agency - -==== veris:discovery_method="Int - antivirus" - -veris:Internal - antivirus alert - -==== veris:discovery_method="Int - infrastructure monitoring" - -veris:Internal - Infrastructure monitoring - -==== veris:discovery_method="Prt - incident response" - -veris:Partner - notified while investigating another incident - -==== veris:discovery_method="Int - data loss prevention" - -veris:Internal - Data loss prevention software - -==== veris:discovery_method="Int - fraud detection" - -veris:Internal - fraud detection mechanism - -==== veris:discovery_method="Prt - monitoring service" - -veris:Partner - Reported by a monitoring service - -==== veris:discovery_method="Int - reported by employee" - -veris:Internal - reported by employee who saw something odd - -==== veris:discovery_method="Ext - actor disclosure" - -veris:External - disclosed by threat agent (e.g., public brag, private blackmail) - -=== cost_corrective_action -==== veris:cost_corrective_action="Simple and cheap" - -veris:Simple and cheap - -==== veris:cost_corrective_action="Unknown" - -veris:Unknown - -==== veris:cost_corrective_action="Something in-between" - -veris:Something in-between - -==== veris:cost_corrective_action="Difficult and expensive" - -veris:Difficult and expensive - -=== security_incident -==== veris:security_incident="Suspected" - -veris:Suspected - -==== veris:security_incident="Confirmed" - -veris:Yes - Confirmed - -==== veris:security_incident="Near miss" - -veris:Near miss (actions did not compromise asset) - -==== veris:security_incident="False positive" - -veris:False positive (response triggered, but no incident) - -=== country -==== veris:country="BD" - -veris:Bangladesh - -==== veris:country="BE" - -veris:Belgium - -==== veris:country="BF" - -veris:Burkina Faso - -==== veris:country="BG" - -veris:Bulgaria - -==== veris:country="BA" - -veris:Bosnia and Herzegovina - -==== veris:country="BB" - -veris:Barbados - -==== veris:country="WF" - -veris:Wallis and Futuna Islands - -==== veris:country="BL" - -veris:Saint-Barthelemy - -==== veris:country="BM" - -veris:Bermuda - -==== veris:country="BN" - -veris:Brunei Darussalam - -==== veris:country="BO" - -veris:Bolivia - -==== veris:country="BH" - -veris:Bahrain - -==== veris:country="BI" - -veris:Burundi - -==== veris:country="BJ" - -veris:Benin - -==== veris:country="BT" - -veris:Bhutan - -==== veris:country="JM" - -veris:Jamaica - -==== veris:country="BV" - -veris:Bouvet Island - -==== veris:country="BW" - -veris:Botswana - -==== veris:country="WS" - -veris:Samoa - -==== veris:country="BQ" - -veris:Bonaire, Saint Eustatius and Saba - -==== veris:country="BR" - -veris:Brazil - -==== veris:country="BS" - -veris:Bahamas - -==== veris:country="JE" - -veris:Jersey - -==== veris:country="BY" - -veris:Belarus - -==== veris:country="BZ" - -veris:Belize - -==== veris:country="RU" - -veris:Russian Federation - -==== veris:country="RW" - -veris:Rwanda - -==== veris:country="RS" - -veris:Serbia - -==== veris:country="TL" - -veris:Timor-Leste - -==== veris:country="RE" - -veris:Reunion - -==== veris:country="TM" - -veris:Turkmenistan - -==== veris:country="Unknown" - -veris:Unknown - -==== veris:country="TJ" - -veris:Tajikistan - -==== veris:country="RO" - -veris:Romania - -==== veris:country="TK" - -veris:Tokelau - -==== veris:country="GW" - -veris:Guinea-Bissau - -==== veris:country="GU" - -veris:Guam - -==== veris:country="GT" - -veris:Guatemala - -==== veris:country="GS" - -veris:South Georgia and the South Sandwich Islands - -==== veris:country="GR" - -veris:Greece - -==== veris:country="GQ" - -veris:Equatorial Guinea - -==== veris:country="GP" - -veris:Guadeloupe - -==== veris:country="JP" - -veris:Japan - -==== veris:country="GY" - -veris:Guyana - -==== veris:country="GG" - -veris:Guernsey - -==== veris:country="GF" - -veris:French Guiana - -==== veris:country="GE" - -veris:Georgia - -==== veris:country="GD" - -veris:Grenada - -==== veris:country="GB" - -veris:United Kingdom - -==== veris:country="GA" - -veris:Gabon - -==== veris:country="SV" - -veris:El Salvador - -==== veris:country="GN" - -veris:Guinea - -==== veris:country="GM" - -veris:Gambia - -==== veris:country="GL" - -veris:Greenland - -==== veris:country="GI" - -veris:Gibraltar - -==== veris:country="GH" - -veris:Ghana - -==== veris:country="OM" - -veris:Oman - -==== veris:country="TN" - -veris:Tunisia - -==== veris:country="JO" - -veris:Jordan - -==== veris:country="HR" - -veris:Croatia - -==== veris:country="HT" - -veris:Haiti - -==== veris:country="HU" - -veris:Hungary - -==== veris:country="HK" - -veris:Hong Kong - -==== veris:country="HN" - -veris:Honduras - -==== veris:country="HM" - -veris:Heard Island and McDonal Islands - -==== veris:country="VE" - -veris:Venezuela (Bolivarian Republic of) - -==== veris:country="PR" - -veris:Puerto Rico - -==== veris:country="PS" - -veris:Palestinian Territory, Occupied - -==== veris:country="PW" - -veris:Palau - -==== veris:country="PT" - -veris:Portugal - -==== veris:country="SJ" - -veris:Svalbard and Jan Mayen Islands - -==== veris:country="PY" - -veris:Paraguay - -==== veris:country="IQ" - -veris:Iraq - -==== veris:country="PA" - -veris:Panama - -==== veris:country="PF" - -veris:French Polynesia - -==== veris:country="PG" - -veris:Papua New Guinea - -==== veris:country="PE" - -veris:Peru - -==== veris:country="PK" - -veris:Pakistan - -==== veris:country="PH" - -veris:Philippines - -==== veris:country="PN" - -veris:Pitcairn - -==== veris:country="PL" - -veris:Poland - -==== veris:country="PM" - -veris:Saint Pierre and Miquelon - -==== veris:country="ZM" - -veris:Zambia - -==== veris:country="EH" - -veris:Western Sahara - -==== veris:country="EE" - -veris:Estonia - -==== veris:country="EG" - -veris:Egypt - -==== veris:country="ZA" - -veris:South Africa - -==== veris:country="EC" - -veris:Ecuador - -==== veris:country="IT" - -veris:Italy - -==== veris:country="VN" - -veris:Viet Nam - -==== veris:country="SB" - -veris:Solomon Islands - -==== veris:country="ET" - -veris:Ethiopia - -==== veris:country="SO" - -veris:Somalia - -==== veris:country="ZW" - -veris:Zimbabwe - -==== veris:country="SA" - -veris:Saudi Arabia - -==== veris:country="ES" - -veris:Spain - -==== veris:country="ER" - -veris:Eritrea - -==== veris:country="ME" - -veris:Montenegro - -==== veris:country="MD" - -veris:Moldova, Republic of - -==== veris:country="MG" - -veris:Madagascar - -==== veris:country="MF" - -veris:Saint Martin (French part) - -==== veris:country="MA" - -veris:Morocco - -==== veris:country="MC" - -veris:Monaco - -==== veris:country="UZ" - -veris:Uzbekistan - -==== veris:country="MM" - -veris:Myanmar - -==== veris:country="ML" - -veris:Mali - -==== veris:country="MO" - -veris:Macao - -==== veris:country="MN" - -veris:Mongolia - -==== veris:country="MH" - -veris:Marshall Islands - -==== veris:country="MK" - -veris:Macedonia, The former Yugoslav Republic of - -==== veris:country="MU" - -veris:Mauritius - -==== veris:country="MT" - -veris:Malta - -==== veris:country="MW" - -veris:Malawi - -==== veris:country="MV" - -veris:Maldives - -==== veris:country="MQ" - -veris:Martinique - -==== veris:country="MP" - -veris:Northern Mariana Islands - -==== veris:country="MS" - -veris:Montserrat - -==== veris:country="MR" - -veris:Mauritania - -==== veris:country="IM" - -veris:Isle of Man - -==== veris:country="UG" - -veris:Uganda - -==== veris:country="TZ" - -veris:Tanzania, United Republic of - -==== veris:country="MY" - -veris:Malaysia - -==== veris:country="MX" - -veris:Mexico - -==== veris:country="IL" - -veris:Israel - -==== veris:country="FR" - -veris:France - -==== veris:country="IO" - -veris:British Virgin Islands - -==== veris:country="SH" - -veris:Saint Helena - -==== veris:country="FI" - -veris:Finland - -==== veris:country="FJ" - -veris:Fiji - -==== veris:country="FK" - -veris:Faeroe Islands - -==== veris:country="FM" - -veris:Micronesia (Federated States of) - -==== veris:country="FO" - -veris:Falkland Islands (Malvinas) - -==== veris:country="NI" - -veris:Nicaragua - -==== veris:country="NL" - -veris:Netherlands - -==== veris:country="NO" - -veris:Norway - -==== veris:country="NA" - -veris:Namibia - -==== veris:country="VU" - -veris:Vanuatu - -==== veris:country="NC" - -veris:New Caledonia - -==== veris:country="NE" - -veris:Niger - -==== veris:country="NF" - -veris:Norfolk Island - -==== veris:country="NG" - -veris:Nigeria - -==== veris:country="NZ" - -veris:New Zealand - -==== veris:country="NP" - -veris:Nepal - -==== veris:country="NR" - -veris:Nauru - -==== veris:country="NU" - -veris:Niue - -==== veris:country="CK" - -veris:Cook Islands - -==== veris:country="CI" - -veris:Cote d'Ivoire - -==== veris:country="CH" - -veris:Switzerland - -==== veris:country="CO" - -veris:Colombia - -==== veris:country="CN" - -veris:China - -==== veris:country="CM" - -veris:Cameroon - -==== veris:country="CL" - -veris:Chile - -==== veris:country="CC" - -veris:Cocos (Keeling) Islands - -==== veris:country="CA" - -veris:Canada - -==== veris:country="CG" - -veris:Congo - -==== veris:country="CF" - -veris:Central African Republic - -==== veris:country="CD" - -veris:Congo, Democratic Republic of the - -==== veris:country="CZ" - -veris:Czech Republic - -==== veris:country="CY" - -veris:Cyprus - -==== veris:country="CX" - -veris:Christmas Island - -==== veris:country="CR" - -veris:Costa Rica - -==== veris:country="CW" - -veris:Curacao - -==== veris:country="CV" - -veris:Cape Verde - -==== veris:country="CU" - -veris:Cuba - -==== veris:country="SZ" - -veris:Swaziland - -==== veris:country="SY" - -veris:Syrian Arab Republic - -==== veris:country="SX" - -veris:Sint Maarten (Dutch part) - -==== veris:country="KG" - -veris:Kyrgyzstan - -==== veris:country="KE" - -veris:Kenya - -==== veris:country="SS" - -veris:South Sudan - -==== veris:country="SR" - -veris:Suriname - -==== veris:country="KI" - -veris:Kiribati - -==== veris:country="KH" - -veris:Cambodia - -==== veris:country="KN" - -veris:Saint Kitts and Nevis - -==== veris:country="KM" - -veris:Comoros - -==== veris:country="ST" - -veris:Sao Tome and Principe - -==== veris:country="SK" - -veris:Slovakia - -==== veris:country="KR" - -veris:Korea, Republic of - -==== veris:country="SI" - -veris:Slovenia - -==== veris:country="KP" - -veris:Korea, Democratic People's Republic of - -==== veris:country="KW" - -veris:Kuwait - -==== veris:country="SN" - -veris:Senegal - -==== veris:country="SM" - -veris:San Marino - -==== veris:country="SL" - -veris:Sierra Leone - -==== veris:country="SC" - -veris:Seychelles - -==== veris:country="KZ" - -veris:Kazakhstan - -==== veris:country="KY" - -veris:Cayman Islands - -==== veris:country="SG" - -veris:Singapore - -==== veris:country="SE" - -veris:Sweden - -==== veris:country="SD" - -veris:Sudan - -==== veris:country="DO" - -veris:Dominican Republic - -==== veris:country="DM" - -veris:Dominica - -==== veris:country="DJ" - -veris:Djibouti - -==== veris:country="DK" - -veris:Denmark - -==== veris:country="VG" - -veris:British Virgin Islands - -==== veris:country="DE" - -veris:Germany - -==== veris:country="YE" - -veris:Yemen - -==== veris:country="Other" - -veris:Other - -==== veris:country="DZ" - -veris:Algeria - -==== veris:country="US" - -veris:United States of America - -==== veris:country="UY" - -veris:Uruguay - -==== veris:country="YT" - -veris:Mayotte - -==== veris:country="UM" - -veris:United States Minor Outlying Islands - -==== veris:country="LB" - -veris:Lebanon - -==== veris:country="LC" - -veris:Saint Lucia - -==== veris:country="LA" - -veris:Lao People's Democratic Republic - -==== veris:country="TV" - -veris:Tuvalu - -==== veris:country="TW" - -veris:Taiwan, Province of China - -==== veris:country="TT" - -veris:Trinidad and Tobago - -==== veris:country="TR" - -veris:Turkey - -==== veris:country="LK" - -veris:Sri Lanka - -==== veris:country="LI" - -veris:Liechtenstein - -==== veris:country="LV" - -veris:Latvia - -==== veris:country="TO" - -veris:Tonga - -==== veris:country="LT" - -veris:Lithuania - -==== veris:country="LU" - -veris:Luxembourg - -==== veris:country="LR" - -veris:Liberia - -==== veris:country="LS" - -veris:Lesotho - -==== veris:country="TH" - -veris:Thailand - -==== veris:country="TF" - -veris:French Southern Territories - -==== veris:country="TG" - -veris:Togo - -==== veris:country="TD" - -veris:Chad - -==== veris:country="TC" - -veris:Turks and Caicos Islands - -==== veris:country="LY" - -veris:Libya - -==== veris:country="VA" - -veris:Holy See - -==== veris:country="VC" - -veris:Saint Vincent and the Grenadines - -==== veris:country="AE" - -veris:United Arab Emirates - -==== veris:country="AD" - -veris:Andorra - -==== veris:country="AG" - -veris:Antigua and Barbuda - -==== veris:country="AF" - -veris:Afghanistan - -==== veris:country="AI" - -veris:Anguilla - -==== veris:country="VI" - -veris:United States Virgin Islands - -==== veris:country="IS" - -veris:Iceland - -==== veris:country="IR" - -veris:Iran (Islamic Republic of) - -==== veris:country="AM" - -veris:Armenia - -==== veris:country="AL" - -veris:Albania - -==== veris:country="AO" - -veris:Angola - -==== veris:country="AQ" - -veris:Antarctica - -==== veris:country="AS" - -veris:American Samoa - -==== veris:country="AR" - -veris:Argentina - -==== veris:country="AU" - -veris:Australia - -==== veris:country="AT" - -veris:Austria - -==== veris:country="AW" - -veris:Aruba - -==== veris:country="IN" - -veris:India - -==== veris:country="AX" - -veris:Aland Islands - -==== veris:country="AZ" - -veris:Azerbaijan - -==== veris:country="IE" - -veris:Ireland - -==== veris:country="ID" - -veris:Indonesia - -==== veris:country="UA" - -veris:Ukraine - -==== veris:country="QA" - -veris:Qatar - -==== veris:country="MZ" - -veris:Mozambique - -=== impact:overall_rating -==== veris:impact:overall_rating="Insignificant" - -veris:Insignificant: Impact absorbed by normal activities - -==== veris:impact:overall_rating="Catastrophic" - -veris:Catastrophic: A business-ending event (don't choose this if the victim will continue operations) - -==== veris:impact:overall_rating="Distracting" - -veris:Distracting: Limited "hard costs", but impact felt through having to deal with the incident rather than conducting normal duties - -==== veris:impact:overall_rating="Damaging" - -veris:Damaging: Real and serious effect on the "bottom line" and/or long-term ability to generate revenue - -==== veris:impact:overall_rating="Unknown" - -veris:Unknown - -==== veris:impact:overall_rating="Painful" - -veris:Painful: Limited "hard costs", but impact felt through having to deal with the incident rather than conducting normal duties - -=== actor:motive -==== veris:actor:motive="Grudge" - -veris:Grudge or personal offense - -==== veris:actor:motive="Financial" - -veris:Financial or personal gain - -==== veris:actor:motive="NA" - -veris:Not Applicable (unintentional action) - -==== veris:actor:motive="Ideology" - -veris:Ideology or protest - -==== veris:actor:motive="Convenience" - -veris:Convenience of expediency - -==== veris:actor:motive="Other" - -veris:Other - -==== veris:actor:motive="Unknown" - -veris:Unknown - -==== veris:actor:motive="Fun" - -veris:Fun, curiosity, or pride - -==== veris:actor:motive="Fear" - -veris:Fear or duress - -==== veris:actor:motive="Espionage" - -veris:Espionage or competitive advantage - -==== veris:actor:motive="Secondary" - -veris:Aid in a different attack - -=== asset:management -==== veris:asset:management="NA" - -veris:Not applicable - -==== veris:asset:management="Internal" - -veris:Internally managed - -==== veris:asset:management="External" - -veris:Externally managed - -==== veris:asset:management="Unknown" - -veris:Unknown - -=== asset:variety -==== veris:asset:variety="M - Flash drive" - -veris:Media - Flash drive or card - -==== veris:asset:variety="S - Print" - -veris:Server - Print - -==== veris:asset:variety="P - Guard" - -veris:People - Guard - -==== veris:asset:variety="S - Database" - -veris:Server - Database - -==== veris:asset:variety="N - PBX" - -veris:Network - Private branch exchange (PBX) - -==== veris:asset:variety="M - Other" - -veris:Media - Other/Unknown - -==== veris:asset:variety="S - Other" - -veris:Server - Other/Unknown - -==== veris:asset:variety="P - System admin" - -veris:People - Administrator - -==== veris:asset:variety="S - POS controller" - -veris:Server - POS controller - -==== veris:asset:variety="T - Other" - -veris:Public Terminal - Other/Unknown - -==== veris:asset:variety="N - Camera" - -veris:Network - Camera or surveillance system - -==== veris:asset:variety="S - Unknown" - -veris:Server - Unknown - -==== veris:asset:variety="S - DHCP" - -veris:Server - DHCP - -==== veris:asset:variety="U - POS terminal" - -veris:User Device - POS terminal - -==== veris:asset:variety="N - LAN" - -veris:Network - Wired LAN - -==== veris:asset:variety="P - Manager" - -veris:People - Manager - -==== veris:asset:variety="M - Payment card" - -veris:Media - Payment card (e.g., magstripe, EMV) - -==== veris:asset:variety="N - Public WAN" - -veris:Network - Public WAN - -==== veris:asset:variety="P - Former employee" - -veris:People - Former employee - -==== veris:asset:variety="S - Authentication" - -veris:Server - Authentication - -==== veris:asset:variety="U - Mobile phone" - -veris:User Device - Mobile phone or smartphone - -==== veris:asset:variety="N - Router or switch" - -veris:Network - Router or switch - -==== veris:asset:variety="T - Kiosk" - -veris:Public Terminal - Self-service kiosk - -==== veris:asset:variety="N - HSM" - -veris:Network - Hardware security module (HSM) - -==== veris:asset:variety="U - Peripheral" - -veris:User Device - Peripheral (e.g., printer, copier, fax) - -==== veris:asset:variety="S - Code repository" - -veris:Server - Code repository - -==== veris:asset:variety="S - SCADA" - -veris:Server - SCADA system - -==== veris:asset:variety="P - End-user" - -veris:People - End-user - -==== veris:asset:variety="N - SAN" - -veris:Network - Storage area network (SAN) - -==== veris:asset:variety="T - ATM" - -veris:Public Terminal - Automated Teller Machine (ATM) - -==== veris:asset:variety="N - RTU" - -veris:Network - Remote terminal unit (RTU) - -==== veris:asset:variety="Unknown" - -veris:Unknown - -==== veris:asset:variety="M - Smart card" - -veris:Media - Identity smart card - -==== veris:asset:variety="N - IDS" - -veris:Network - IDS or IPs - -==== veris:asset:variety="N - PLC" - -veris:Network - Programmable logic controller (PLC) - -==== veris:asset:variety="N - Other" - -veris:Network - Other/Unknown - -==== veris:asset:variety="P - Cashier" - -veris:People - Cashier - -==== veris:asset:variety="P - Executive" - -veris:People - Executive - -==== veris:asset:variety="U - Desktop" - -veris:User Device - Desktop or workstation - -==== veris:asset:variety="U - Tablet" - -veris:User Device - Tablet - -==== veris:asset:variety="N - Firewall" - -veris:Network - Firewall - -==== veris:asset:variety="P - Customer" - -veris:People - Customer - -==== veris:asset:variety="S - Mainframe" - -veris:Server - Mainframe - -==== veris:asset:variety="S - Directory" - -veris:Server - Directory (LDAP, AD) - -==== veris:asset:variety="U - Auth token" - -veris:User Device - Authentication token or device - -==== veris:asset:variety="U - Media" - -veris:User Device - Media player or recorder - -==== veris:asset:variety="T - Gas terminal" - -veris:Public Terminal - Gas "pay-at-the-pump" terminal - -==== veris:asset:variety="T - PED pad" - -veris:Public Terminal - Detached PIN pad or card reader - -==== veris:asset:variety="M - Disk drive" - -veris:Media - Hard disk drive - -==== veris:asset:variety="S - VM host" - -veris:Server - Virtual Host - -==== veris:asset:variety="P - Auditor" - -veris:People - Auditor - -==== veris:asset:variety="U - VoIP phone" - -veris:User Device - VoIP phone - -==== veris:asset:variety="N - Broadband" - -veris:Network - Mobile broadband network - -==== veris:asset:variety="U - Other" - -veris:User Device - Other/Unknown - -==== veris:asset:variety="U - Telephone" - -veris:User Device - Telephone - -==== veris:asset:variety="P - Call center" - -veris:People - Call center - -==== veris:asset:variety="N - Private WAN" - -veris:Network - Private WAN - -==== veris:asset:variety="S - DNS" - -veris:Server - DNS - -==== veris:asset:variety="P - Helpdesk" - -veris:People - Helpdesk - -==== veris:asset:variety="N - Telephone" - -veris:Network - Telephone - -==== veris:asset:variety="U - Laptop" - -veris:User Device - Laptop - -==== veris:asset:variety="S - Log" - -veris:Server - Log or event management - -==== veris:asset:variety="P - Finance" - -veris:People - Finance - -==== veris:asset:variety="P - Human resources" - -veris:People - Human resources - -==== veris:asset:variety="N - VoIP adapter" - -veris:Network - VoIP adapter - -==== veris:asset:variety="S - Backup" - -veris:Server - Backup - -==== veris:asset:variety="P - Partner" - -veris:People - Partner - -==== veris:asset:variety="P - Maintenance" - -veris:People - Maintenance - -==== veris:asset:variety="S - Payment switch" - -veris:Server - Payment switch or gateway - -==== veris:asset:variety="S - DCS" - -veris:Server - Distributed control system (DCS) - -==== veris:asset:variety="P - Other" - -veris:People - Other/Unknown - -==== veris:asset:variety="S - Proxy" - -veris:Server - Proxy - -==== veris:asset:variety="S - Mail" - -veris:Server - Mail - -==== veris:asset:variety="M - Tapes" - -veris:Media - Backup tapes - -==== veris:asset:variety="S - Remote access" - -veris:Server - Remote access - -==== veris:asset:variety="N - Access reader" - -veris:Network - Access control reader (e.g., badge, biometric) - -==== veris:asset:variety="S - File" - -veris:Server - File - -==== veris:asset:variety="S - Web application" - -veris:Server - Web application - -==== veris:asset:variety="M - Documents" - -veris:Media - Documents - -==== veris:asset:variety="N - WLAN" - -veris:Network - Wireless LAN - -==== veris:asset:variety="P - Developer" - -veris:People - Developer - -==== veris:asset:variety="M - Disk media" - -veris:Media - Disk media (e.g., CDs, DVDs) - -=== asset:accessibility -==== veris:asset:accessibility="NA" - -veris:Not applicable - -==== veris:asset:accessibility="Internal" - -veris:Internally accessible - -==== veris:asset:accessibility="Unknown" - -veris:Unknown - -==== veris:asset:accessibility="External" - -veris:Publicly accessible - -==== veris:asset:accessibility="Isolated" - -veris:Internally isolated or restricted environment - -=== asset:governance -==== veris:asset:governance="3rd party hosted" - -veris:Hosted by 3rd party - -==== veris:asset:governance="Unknown" - -veris:Unknown - -==== veris:asset:governance="3rd party managed" - -veris:Managed by 3rd party - -==== veris:asset:governance="3rd party owned" - -veris:Owned by 3rd party - -==== veris:asset:governance="Personally owned" - -veris:Personally owned asset - -==== veris:asset:governance="Internally isolated" - -veris:Isolated internal asset - -=== asset:hosting -==== veris:asset:hosting="External shared" - -veris:Externally hosted in a shared envirnoment - -==== veris:asset:hosting="External dedicated" - -veris:Externally hosted in a dedicated envirnoment - -==== veris:asset:hosting="NA" - -veris:Not applicable - -==== veris:asset:hosting="Internal" - -veris:Internally hosted - -==== veris:asset:hosting="External" - -veris:Externally hosted (unsure if dedicated or shared) - -==== veris:asset:hosting="Unknown" - -veris:Unknown - -=== asset:ownership -==== veris:asset:ownership="Customer" - -veris:Customer owned - -==== veris:asset:ownership="Unknown" - -veris:Unknown - -==== veris:asset:ownership="Victim" - -veris:Victim owned - -==== veris:asset:ownership="NA" - -veris:Not applicable - -==== veris:asset:ownership="Employee" - -veris:Employee owned - -==== veris:asset:ownership="Partner" - -veris:Partner owned - -=== asset:cloud -==== veris:asset:cloud="Hosting error" - -veris:Misconfiguration or error by hosting provider - -==== veris:asset:cloud="User breakout" - -veris:Elevation of privilege by another customer in shared environment - -==== veris:asset:cloud="Unknown" - -veris:Unknown - -==== veris:asset:cloud="Other" - -veris:Other - -==== veris:asset:cloud="Hosting governance" - -veris:Lack of security process or procedure by hosting provider - -==== veris:asset:cloud="Customer attack" - -veris:Penetration of another web site on shared device - -==== veris:asset:cloud="Hypervisor" - -veris:Hypervisor break-out attack - -==== veris:asset:cloud="Partner application" - -veris:Application vulnerability in partner-developed application - -=== victim:employee_count -==== veris:victim:employee_count="1001 to 10000" - -veris:1,001 to 10,000 employees - -==== veris:victim:employee_count="Over 100000" - -veris:Over 100,0001 employees - -==== veris:victim:employee_count="Large" - -veris:Large organizations (over 1,000 employees) - -==== veris:victim:employee_count="Unknown" - -veris:Unknown number of employees - -==== veris:victim:employee_count="50001 to 100000" - -veris:50,001 to 100,000 employees - -==== veris:victim:employee_count="101 to 1000" - -veris:101 to 1,000 employees - -==== veris:victim:employee_count="25001 to 50000" - -veris:25,001 to 50,000 employees - -==== veris:victim:employee_count="10001 to 25000" - -veris:10,001 to 25,000 employees - -==== veris:victim:employee_count="Small" - -veris:Small organizations (1,000 employees or less) - -==== veris:victim:employee_count="1 to 10" - -veris:1 to 10 employees - -==== veris:victim:employee_count="11 to 100" - -veris:11 to 100 employees - -=== timeline:unit -==== veris:timeline:unit="Months" - -veris:Months - -==== veris:timeline:unit="Seconds" - -veris:Seconds - -==== veris:timeline:unit="NA" - -veris:NA - -==== veris:timeline:unit="Never" - -veris:Never - -==== veris:timeline:unit="Days" - -veris:Days - -==== veris:timeline:unit="Years" - -veris:Years - -==== veris:timeline:unit="Hours" - -veris:Hours - -==== veris:timeline:unit="Unknown" - -veris:Unknown - -==== veris:timeline:unit="Weeks" - -veris:Weeks - -==== veris:timeline:unit="Minutes" - -veris:Minutes - -=== impact:loss:rating -==== veris:impact:loss:rating="Unknown" - -veris:Unknown - -==== veris:impact:loss:rating="Major" - -veris:Major - -==== veris:impact:loss:rating="Moderate" - -veris:Moderate - -==== veris:impact:loss:rating="None" - -veris:None - -==== veris:impact:loss:rating="Minor" - -veris:Minor - -=== impact:loss:variety -==== veris:impact:loss:variety="Legal and regulatory" - -veris:Legal and regulatory costs - -==== veris:impact:loss:variety="Asset and fraud" - -veris:Asset and fraud-related losses - -==== veris:impact:loss:variety="Business disruption" - -veris:Business disruption - -==== veris:impact:loss:variety="Response and recovery" - -veris:Response and recovery costs - -==== veris:impact:loss:variety="Competitive advantage" - -veris:Loss of competitive advantage - -==== veris:impact:loss:variety="Operating costs" - -veris:Increased operating costs - -==== veris:impact:loss:variety="Brand damage" - -veris:Brand and market damage - -=== attribute:integrity:variety -==== veris:attribute:integrity:variety="Misrepresentation" - -veris:Misrepresentation - -==== veris:attribute:integrity:variety="Modify data" - -veris:Modified stored data or content - -==== veris:attribute:integrity:variety="Unknown" - -veris:Unknown - -==== veris:attribute:integrity:variety="Created account" - -veris:Created new user account - -==== veris:attribute:integrity:variety="Defacement" - -veris:Deface content - -==== veris:attribute:integrity:variety="Log tampering" - -veris:Log tampering or modification - -==== veris:attribute:integrity:variety="Modify privileges" - -veris:Modified privileges or permissions - -==== veris:attribute:integrity:variety="Software installation" - -veris:Software installation or code modification - -==== veris:attribute:integrity:variety="Other" - -veris:Other - -==== veris:attribute:integrity:variety="Fraudulent transaction" - -veris:Initiate fraudulent transaction - -==== veris:attribute:integrity:variety="Alter behavior" - -veris:Influence or alter human behavior - -==== veris:attribute:integrity:variety="Hardware tampering" - -veris:Hardware tampering or physical alteration - -==== veris:attribute:integrity:variety="Modify configuration" - -veris:Modified configuration or services - -==== veris:attribute:integrity:variety="Repurpose" - -veris:Repurposed asset for unauthorized function - -=== attribute:availability:variety -==== veris:attribute:availability:variety="Acceleration" - -veris:Acceleration - -==== veris:attribute:availability:variety="Interruption" - -veris:Interruption - -==== veris:attribute:availability:variety="Loss" - -veris:Loss - -==== veris:attribute:availability:variety="Unknown" - -veris:Unknown - -==== veris:attribute:availability:variety="Degradation" - -veris:Performance degradation - -==== veris:attribute:availability:variety="Other" - -veris:Other - -==== veris:attribute:availability:variety="Obscuration" - -veris:Conversion or obscuration - -==== veris:attribute:availability:variety="Destruction" - -veris:Destruction - -=== attribute:confidentiality:data_victim -==== veris:attribute:confidentiality:data_victim="Customer" - -veris:Customer - -==== veris:attribute:confidentiality:data_victim="Patient" - -veris:Patient - -==== veris:attribute:confidentiality:data_victim="Unknown" - -veris:Unknown - -==== veris:attribute:confidentiality:data_victim="Other" - -veris:Other - -==== veris:attribute:confidentiality:data_victim="Student" - -veris:Student - -==== veris:attribute:confidentiality:data_victim="Employee" - -veris:Employee - -==== veris:attribute:confidentiality:data_victim="Partner" - -veris:Partner - -=== attribute:confidentiality:state -==== veris:attribute:confidentiality:state="Unknown" - -veris:Unknown - -==== veris:attribute:confidentiality:state="Transmitted encrypted" - -veris:Transmitted encrypted - -==== veris:attribute:confidentiality:state="Transmitted unencrypted" - -veris:Transmitted unencrypted - -==== veris:attribute:confidentiality:state="Stored" - -veris:Stored - -==== veris:attribute:confidentiality:state="Transmitted" - -veris:Transmitted - -==== veris:attribute:confidentiality:state="Processed" - -veris:Processed - -==== veris:attribute:confidentiality:state="Stored encrypted" - -veris:Stored encrypted - -==== veris:attribute:confidentiality:state="Stored unencrypted" - -veris:Stored unencrypted - -=== attribute:confidentiality:data_disclosure -==== veris:attribute:confidentiality:data_disclosure="Unknown" - -veris:Unknown - -==== veris:attribute:confidentiality:data_disclosure="Yes" - -veris:Yes (confirmed) - -==== veris:attribute:confidentiality:data_disclosure="Potentially" - -veris:Potentially (at risk) - -==== veris:attribute:confidentiality:data_disclosure="No" - -veris:No - -=== actor:internal:job_change -==== veris:actor:internal:job_change="Lateral move" - -veris:Lateral move - -==== veris:actor:internal:job_change="Job eval" - -veris:Recent poor job evaluation - -==== veris:actor:internal:job_change="Unknown" - -veris:Unknown - -==== veris:actor:internal:job_change="Personal issues" - -veris:Personal issues - -==== veris:actor:internal:job_change="Let go" - -veris:Fired, laid off, or let go - -==== veris:actor:internal:job_change="Reprimanded" - -veris:Recently reprimanded - -==== veris:actor:internal:job_change="Hired" - -veris:Recently hired - -==== veris:actor:internal:job_change="Passed over" - -veris:Recently passed over for promotion - -==== veris:actor:internal:job_change="Demoted" - -veris:Recently demoted or hours reduced - -==== veris:actor:internal:job_change="Promoted" - -veris:Recently promoted - -==== veris:actor:internal:job_change="Resigned" - -veris:Recently resigned - -==== veris:actor:internal:job_change="Other" - -veris:Other - -=== actor:internal:variety -==== veris:actor:internal:variety="End-user" - -veris:End-user or regular employee - -==== veris:actor:internal:variety="Human resources" - -veris:Human resources staff - -==== veris:actor:internal:variety="Finance" - -veris:Finance or accounting staff - -==== veris:actor:internal:variety="Unknown" - -veris:Unknown - -==== veris:actor:internal:variety="Helpdesk" - -veris:Helpdesk staff - -==== veris:actor:internal:variety="Executive" - -veris:Executive or upper management - -==== veris:actor:internal:variety="Cashier" - -veris:Cashier, teller, or waiter - -==== veris:actor:internal:variety="Manager" - -veris:Manager or supervisor - -==== veris:actor:internal:variety="Guard" - -veris:Security guard - -==== veris:actor:internal:variety="Other" - -veris:Other - -==== veris:actor:internal:variety="Auditor" - -veris:Auditor - -==== veris:actor:internal:variety="Maintenance" - -veris:Maintenance or janitorial staff - -==== veris:actor:internal:variety="Call center" - -veris:Call center staff - -==== veris:actor:internal:variety="System admin" - -veris:System or network administrator - -==== veris:actor:internal:variety="Developer" - -veris:Software developer - -=== actor:external:variety -==== veris:actor:external:variety="Customer" - -veris:Customer (B2C) - -==== veris:actor:external:variety="Organized crime" - -veris:Organized or professional criminal group - -==== veris:actor:external:variety="Acquaintance" - -veris:Relative or acquaintance of employee - -==== veris:actor:external:variety="Competitor" - -veris:Competitor - -==== veris:actor:external:variety="Unaffiliated" - -veris:Unaffiliated person(s) - -==== veris:actor:external:variety="Force majeure" - -veris:Force majeure (nature and chance) - -==== veris:actor:external:variety="Former employee" - -veris:Former employee (no longer had access) - -==== veris:actor:external:variety="Nation-state" - -veris:Nation-state - -==== veris:actor:external:variety="Activist" - -veris:Activist group - -==== veris:actor:external:variety="Terrorist" - -veris:Terrorist group - -==== veris:actor:external:variety="Auditor" - -veris:Auditor - -==== veris:actor:external:variety="Unknown" - -veris:Unknown - -==== veris:actor:external:variety="State-affiliated" - -veris:State-sponsored or affiliated group - -==== veris:actor:external:variety="Other" - -veris:Other - -=== action:malware:vector -==== veris:action:malware:vector="Remote injection" - -veris:Remotely injected by agent (i.e. via SQLi) - -==== veris:action:malware:vector="Software update" - -veris:Included in automated software update - -==== veris:action:malware:vector="Instant messaging" - -veris:Instant Messaging - -==== veris:action:malware:vector="Email attachment" - -veris:Email via user-executed attachment - -==== veris:action:malware:vector="Direct install" - -veris:Directly installed or inserted by threat agent (after system access) - -==== veris:action:malware:vector="Download by malware" - -veris:Downloaded and installed by local malware - -==== veris:action:malware:vector="Removable media" - -veris:Removable storage media or devices - -==== veris:action:malware:vector="Web drive-by" - -veris:Web via auto-executed or "drive-by" infection - -==== veris:action:malware:vector="Email link" - -veris:Email via embedded link - -==== veris:action:malware:vector="Network propagation" - -veris:Network propagation - -==== veris:action:malware:vector="Unknown" - -veris:Unknown - -==== veris:action:malware:vector="Email autoexecute" - -veris:Email via automatic execution - -==== veris:action:malware:vector="Web download" - -veris:Web via user-executed or downloaded content - -==== veris:action:malware:vector="Other" - -veris:Other - -=== action:malware:variety -==== veris:action:malware:variety="Spam" - -veris:Send spam - -==== veris:action:malware:variety="Unknown" - -veris:Unknown - -==== veris:action:malware:variety="Packet sniffer" - -veris:Packet sniffer (capture data from network) - -==== veris:action:malware:variety="Backdoor" - -veris:Backdoor (enable remote access) - -==== veris:action:malware:variety="Exploit vuln" - -veris:Exploit vulnerability in code (vs misconfig or weakness) - -==== veris:action:malware:variety="Other" - -veris:Other - -==== veris:action:malware:variety="Password dumper" - -veris:Password dumper (extract credential hashes) - -==== veris:action:malware:variety="Scan network" - -veris:Scan or footprint network - -==== veris:action:malware:variety="Downloader" - -veris:Downloader (pull updates or other malware) - -==== veris:action:malware:variety="Adminware" - -veris:System or network utilities (e.g., PsTools, Netcat) - -==== veris:action:malware:variety="Click fraud" - -veris:Click fraud or Bitcoin mining - -==== veris:action:malware:variety="Adware" - -veris:Adware - -==== veris:action:malware:variety="C2" - -veris:Command and control (C2) - -==== veris:action:malware:variety="Worm" - -veris:Worm (propagate to other systems or devices) - -==== veris:action:malware:variety="Spyware/Keylogger" - -veris:Spyware, keylogger or form-grabber (capture user input or activity) - -==== veris:action:malware:variety="Brute force" - -veris:Brute force attack - -==== veris:action:malware:variety="Capture app data" - -veris:Capture data from application or system process - -==== veris:action:malware:variety="Ram scraper" - -veris:Ram scraper or memory parser (capture data from volatile memory) - -==== veris:action:malware:variety="Disable controls" - -veris:Disable or interfere with security controls - -==== veris:action:malware:variety="Capture stored data" - -veris:Capture data stored on system disk - -==== veris:action:malware:variety="Ransomware" - -veris:Ransomware (encrypt or seize stored data) - -==== veris:action:malware:variety="Export data" - -veris:Export data to another site or system - -==== veris:action:malware:variety="Client-side attack" - -veris:Client-side or browser attack (e.g., redirection, XSS, MitB) - -==== veris:action:malware:variety="SQL injection" - -veris:SQL injection attack - -==== veris:action:malware:variety="Rootkit" - -veris:Rootkit (maintain local privileges and stealth) - -==== veris:action:malware:variety="Destroy data" - -veris:Destroy or corrupt stored data - -==== veris:action:malware:variety="DoS" - -veris:DoS attack - -=== action:social:vector -==== veris:action:social:vector="In-person" - -veris:In-person - -==== veris:action:social:vector="Social media" - -veris:Social media or networking - -==== veris:action:social:vector="Documents" - -veris:Documents - -==== veris:action:social:vector="Unknown" - -veris:Unknown - -==== veris:action:social:vector="SMS" - -veris:SMS or texting - -==== veris:action:social:vector="Phone" - -veris:Phone - -==== veris:action:social:vector="Website" - -veris:Website - -==== veris:action:social:vector="Other" - -veris:Other - -==== veris:action:social:vector="IM" - -veris:Instant messaging - -==== veris:action:social:vector="Removable media" - -veris:Removable storage media - -==== veris:action:social:vector="Email" - -veris:Email - -==== veris:action:social:vector="Software" - -veris:Software - -=== action:social:target -==== veris:action:social:target="Customer" - -veris:Customer (B2C) - -==== veris:action:social:target="End-user" - -veris:End-user or regular employee - -==== veris:action:social:target="Human resources" - -veris:Human resources staff - -==== veris:action:social:target="Finance" - -veris:Finance or accounting staff - -==== veris:action:social:target="Unknown" - -veris:Unknown - -==== veris:action:social:target="Helpdesk" - -veris:Helpdesk staff - -==== veris:action:social:target="Executive" - -veris:Executive or upper management - -==== veris:action:social:target="Cashier" - -veris:Cashier, teller or waiter - -==== veris:action:social:target="Manager" - -veris:Manager or supervisor - -==== veris:action:social:target="Former employee" - -veris:Former employee - -==== veris:action:social:target="Guard" - -veris:Security guard - -==== veris:action:social:target="Other" - -veris:Other - -==== veris:action:social:target="Auditor" - -veris:Auditor - -==== veris:action:social:target="Maintenance" - -veris:Maintenance or janitorial staff - -==== veris:action:social:target="Call center" - -veris:Call center staff - -==== veris:action:social:target="Partner" - -veris:Partner (B2B) - -==== veris:action:social:target="System admin" - -veris:System or network administrator - -==== veris:action:social:target="Developer" - -veris:Software developer - -=== action:social:variety -==== veris:action:social:variety="Scam" - -veris:Online scam or hoax (e.g., scareware, 419 scam, auction fraud) - -==== veris:action:social:variety="Phishing" - -veris:Phishing (or any type of *ishing) - -==== veris:action:social:variety="Elicitation" - -veris:Elicitation (subtle extraction of info through conversation) - -==== veris:action:social:variety="Unknown" - -veris:Unknown - -==== veris:action:social:variety="Spam" - -veris:Spam (unsolicited or undesired email and advertisements) - -==== veris:action:social:variety="Influence" - -veris:Influence tactics (Leveraging authority or obligation, framing, etc) - -==== veris:action:social:variety="Propaganda" - -veris:Propaganda or disinformation - -==== veris:action:social:variety="Forgery" - -veris:Forgery or counterfeiting (fake hardware, software, documents, etc) - -==== veris:action:social:variety="Bribery" - -veris:Bribery or solicitation - -==== veris:action:social:variety="Other" - -veris:Other - -==== veris:action:social:variety="Pretexting" - -veris:Pretexting (dialogue leveraging invented scenario) - -==== veris:action:social:variety="Extortion" - -veris:Extortion or blackmail - -==== veris:action:social:variety="Baiting" - -veris:Baiting (planting infected media) - -=== action:environmental:variety -==== veris:action:environmental:variety="Hazmat" - -veris:Hazardous material - -==== veris:action:environmental:variety="Temperature" - -veris:Extreme temperature - -==== veris:action:environmental:variety="Unknown" - -veris:Unknown - -==== veris:action:environmental:variety="Hurricane" - -veris:Hurricane - -==== veris:action:environmental:variety="Ice" - -veris:Ice and snow - -==== veris:action:environmental:variety="Meteorite" - -veris:Meteorite - -==== veris:action:environmental:variety="Other" - -veris:Other - -==== veris:action:environmental:variety="Pathogen" - -veris:Pathogen - -==== veris:action:environmental:variety="Landslide" - -veris:Landslide - -==== veris:action:environmental:variety="Tornado" - -veris:Tornado - -==== veris:action:environmental:variety="Leak" - -veris:Water leak - -==== veris:action:environmental:variety="Earthquake" - -veris:Earthquake - -==== veris:action:environmental:variety="Particulates" - -veris:Particulate matter (e.g., dust, smoke) - -==== veris:action:environmental:variety="Power failure" - -veris:Power failure or fluctuation - -==== veris:action:environmental:variety="EMI" - -veris:Electromagnetic interference (EMI) - -==== veris:action:environmental:variety="Humidity" - -veris:Humidity - -==== veris:action:environmental:variety="Tsunami" - -veris:Tsunami - -==== veris:action:environmental:variety="ESD" - -veris:Electrostatic discharge (ESD) - -==== veris:action:environmental:variety="Deterioration" - -veris:Deterioration and degradation - -==== veris:action:environmental:variety="Volcano" - -veris:Volcanic eruption - -==== veris:action:environmental:variety="Lightning" - -veris:Lightning - -==== veris:action:environmental:variety="Wind" - -veris:Wind - -==== veris:action:environmental:variety="Flood" - -veris:Flood - -==== veris:action:environmental:variety="Vermin" - -veris:Vermin - -==== veris:action:environmental:variety="Fire" - -veris:Fire - -=== action:error:vector -==== veris:action:error:vector="Random error" - -veris:Random error (no reason, no fault) - -==== veris:action:error:vector="Carelessness" - -veris:Carelessness - -==== veris:action:error:vector="Other" - -veris:Other - -==== veris:action:error:vector="Unknown" - -veris:Unknown - -==== veris:action:error:vector="Inadequate processes" - -veris:Inadequate or insufficient processes - -==== veris:action:error:vector="Inadequate technology" - -veris:Inadequate or insufficient technology resources - -==== veris:action:error:vector="Inadequate personnel" - -veris:Inadequate or insufficient personnel - -=== action:error:variety -==== veris:action:error:variety="Disposal error" - -veris:Disposal error - -==== veris:action:error:variety="Omission" - -veris:Omission (something intended, but not done) - -==== veris:action:error:variety="Loss" - -veris:Loss or misplacement - -==== veris:action:error:variety="Unknown" - -veris:Unknown - -==== veris:action:error:variety="Maintenance error" - -veris:Maintenance error - -==== veris:action:error:variety="Misinformation" - -veris:Misinformation (unintentionally giving false info) - -==== veris:action:error:variety="Physical accidents" - -veris:Physical accidents (e.g., drops, bumps, spills) - -==== veris:action:error:variety="Publishing error" - -veris:Publishing error (private info to public doc or site) - -==== veris:action:error:variety="Malfunction" - -veris:Technical malfunction or glitch - -==== veris:action:error:variety="Capacity shortage" - -veris:Poor capacity planning - -==== veris:action:error:variety="Other" - -veris:Other - -==== veris:action:error:variety="Programming error" - -veris:Programming error (flaws or bugs in custom code) - -==== veris:action:error:variety="Data entry error" - -veris:Data entry error - -==== veris:action:error:variety="Gaffe" - -veris:Gaffe (social or verbal slip) - -==== veris:action:error:variety="Misconfiguration" - -veris:Misconfiguration - -==== veris:action:error:variety="Misdelivery" - -veris:Misdelivery (send wrong info or to wrong recipient) - -==== veris:action:error:variety="Classification error" - -veris:Classification or labeling error - -=== action:misuse:vector -==== veris:action:misuse:vector="Physical access" - -veris:Physical access within corporate facility - -==== veris:action:misuse:vector="Remote access" - -veris:Remote access connection to corporate network (i.e. VPN) - -==== veris:action:misuse:vector="LAN access" - -veris:Local network access within corporate facility - -==== veris:action:misuse:vector="Unknown" - -veris:Unknown - -==== veris:action:misuse:vector="Non-corporate" - -veris:Non-corporate facilities or networks - -==== veris:action:misuse:vector="Other" - -veris:Other - -=== action:misuse:variety -==== veris:action:misuse:variety="Unapproved software" - -veris:Use of unapproved software or services - -==== veris:action:misuse:variety="Illicit content" - -veris:Storage or distribution of illicit content - -==== veris:action:misuse:variety="Unapproved workaround" - -veris:Unapproved workaround or shortcut - -==== veris:action:misuse:variety="Unapproved hardware" - -veris:Use of unapproved hardware or devices - -==== veris:action:misuse:variety="Unknown" - -veris:Unknown - -==== veris:action:misuse:variety="Email misuse" - -veris:Inappropriate use of email or IM - -==== veris:action:misuse:variety="Possession abuse" - -veris:Abuse of physical access to asset - -==== veris:action:misuse:variety="Other" - -veris: Other - -==== veris:action:misuse:variety="Net misuse" - -veris:Inappropriate use of network or Web access - -==== veris:action:misuse:variety="Data mishandling" - -veris:Handling of data in an unapproved manner - -==== veris:action:misuse:variety="Privilege abuse" - -veris:Abuse of system access privileges - -==== veris:action:misuse:variety="Knowledge abuse" - -veris:Abuse of private or entrusted knowledge - -=== action:hacking:vector -==== veris:action:hacking:vector="Physical access" - -veris:Physical access or connection (i.e., at keyboard or via cable) - -==== veris:action:hacking:vector="Command shell" - -veris:Remote shell - -==== veris:action:hacking:vector="Unknown" - -veris:Unknown - -==== veris:action:hacking:vector="Backdoor or C2" - -veris:Backdoor or command and control channel - -==== veris:action:hacking:vector="Web application" - -veris:Web application - -==== veris:action:hacking:vector="Desktop sharing" - -veris:Graphical desktop sharing (RDP, VNC, PCAnywhere, Citrix) - -==== veris:action:hacking:vector="3rd party desktop" - -veris:3rd party online desktop sharing (LogMeIn, Go2Assist) - -==== veris:action:hacking:vector="Partner" - -veris:Partner connection or credential - -==== veris:action:hacking:vector="VPN" - -veris:VPN - -==== veris:action:hacking:vector="Other" - -veris:Other - -=== action:hacking:variety -==== veris:action:hacking:variety="XSS" - -veris:Cross-site scripting - -==== veris:action:hacking:variety="HTTP Response Splitting" - -veris:HTTP Response Splitting - -==== veris:action:hacking:variety="Unknown" - -veris:Unknown - -==== veris:action:hacking:variety="Buffer overflow" - -veris:Buffer overflow - -==== veris:action:hacking:variety="Format string attack" - -veris:Format string attack - -==== veris:action:hacking:variety="LDAP injection" - -veris:LDAP injection - -==== veris:action:hacking:variety="SSI injection" - -veris:SSI injection - -==== veris:action:hacking:variety="MitM" - -veris:Man-in-the-middle attack - -==== veris:action:hacking:variety="Path traversal" - -veris:Path traversal - -==== veris:action:hacking:variety="URL redirector abuse" - -veris:URL redirector abuse - -==== veris:action:hacking:variety="Use of backdoor or C2" - -veris:Use of Backdoor or C2 channel - -==== veris:action:hacking:variety="Mail command injection" - -veris:Mail command injection - -==== veris:action:hacking:variety="Virtual machine escape" - -veris:Virtual machine escape - -==== veris:action:hacking:variety="OS commanding" - -veris:OS commanding - -==== veris:action:hacking:variety="Soap array abuse" - -veris:Soap array abuse - -==== veris:action:hacking:variety="Footprinting" - -veris:Footprinting and fingerprinting - -==== veris:action:hacking:variety="Cryptanalysis" - -veris:Cryptanalysis - -==== veris:action:hacking:variety="SQLi" - -veris:SQL injection - -==== veris:action:hacking:variety="XML external entities" - -veris:XML external entities - -==== veris:action:hacking:variety="Abuse of functionality" - -veris:Abuse of functionality - -==== veris:action:hacking:variety="XML injection" - -veris:XML injection - -==== veris:action:hacking:variety="Routing detour" - -veris:Routing detour - -==== veris:action:hacking:variety="HTTP response smuggling" - -veris:HTTP response smuggling - -==== veris:action:hacking:variety="Forced browsing" - -veris:Forced browsing or predictable resource location - -==== veris:action:hacking:variety="Cache poisoning" - -veris:Cache poisoning - -==== veris:action:hacking:variety="Null byte injection" - -veris:Null byte injection - -==== veris:action:hacking:variety="Reverse engineering" - -veris:Reverse engineering - -==== veris:action:hacking:variety="Brute force" - -veris:Brute force or password guessing attacks - -==== veris:action:hacking:variety="Fuzz testing" - -veris:Fuzz testing - -==== veris:action:hacking:variety="Offline cracking" - -veris:Offline password or key cracking (e.g., rainbow tables, Hashcat, JtR) - -==== veris:action:hacking:variety="CSRF" - -veris:Cross-site request forgery - -==== veris:action:hacking:variety="XML entity expansion" - -veris:XML entity expansion - -==== veris:action:hacking:variety="RFI" - -veris:Remote file inclusion - -==== veris:action:hacking:variety="Session fixation" - -veris:Session fixation - -==== veris:action:hacking:variety="Integer overflows" - -veris:Integer overflows - -==== veris:action:hacking:variety="XQuery injection" - -veris:XQuery injection - -==== veris:action:hacking:variety="Pass-the-hash" - -veris:Pass-the-hash - -==== veris:action:hacking:variety="XML attribute blowup" - -veris:XML attribute blowup - -==== veris:action:hacking:variety="Session prediction" - -veris:Credential or session prediction - -==== veris:action:hacking:variety="Use of stolen creds" - -veris:Use of stolen authentication credentials - -==== veris:action:hacking:variety="HTTP request smuggling" - -veris:HTTP request smuggling - -==== veris:action:hacking:variety="XPath injection" - -veris:XPath injection - -==== veris:action:hacking:variety="Other" - -veris:Other - -==== veris:action:hacking:variety="DoS" - -veris:Denial of service - -==== veris:action:hacking:variety="Special element injection" - -veris:Special element injection - -==== veris:action:hacking:variety="HTTP request splitting" - -veris:HTTP request splitting - -==== veris:action:hacking:variety="Session replay" - -veris:Session replay - -=== action:physical:vector -==== veris:action:physical:vector="Personal vehicle" - -veris:Personal vehicle - -==== veris:action:physical:vector="Visitor privileges" - -veris:Given temporary visitor access - -==== veris:action:physical:vector="Public facility" - -veris:Public facility or area - -==== veris:action:physical:vector="Victim grounds" - -veris:Victim outdoor grounds - -==== veris:action:physical:vector="Uncontrolled location" - -veris:The location was uncontrolled (public) - -==== veris:action:physical:vector="Partner vehicle" - -veris:Partner vehicle (e.g., delivery truck) - -==== veris:action:physical:vector="Victim work area" - -veris:Victim private or work area (e.g., office space) - -==== veris:action:physical:vector="Victim secure area" - -veris:Victim high security area (e.g., server room, R&D labs) - -==== veris:action:physical:vector="Partner facility" - -veris:Partner facility or area - -==== veris:action:physical:vector="Personal residence" - -veris:Personal residence - -==== veris:action:physical:vector="Other" - -veris:Other - -==== veris:action:physical:vector="Public vehicle" - -veris:Public vehicle (e.g., plane, taxi) - -==== veris:action:physical:vector="Unknown" - -veris:Unknown - -==== veris:action:physical:vector="Victim public area" - -veris:Victim public or customer area (e.g., lobby, storefront) - -==== veris:action:physical:vector="Privileged access" - -veris:Held privileged access to location - -=== action:physical:variety -==== veris:action:physical:variety="Skimmer" - -veris:Installing card skimming device - -==== veris:action:physical:variety="Snooping" - -veris:Snooping (sneak about to gain info or access) - -==== veris:action:physical:variety="Tampering" - -veris:Tampering (alter physical form or function) - -==== veris:action:physical:variety="Unknown" - -veris:Unknown - -==== veris:action:physical:variety="Theft" - -veris:Theft (taking assets without permission) - -==== veris:action:physical:variety="Connection" - -veris:Connection - -==== veris:action:physical:variety="Surveillance" - -veris:Surveillance (monitoring and observation) - -==== veris:action:physical:variety="Assault" - -veris:Assault (threats or acts of physical violence) - -==== veris:action:physical:variety="Other" - -veris:Other - -==== veris:action:physical:variety="Wiretapping" - -veris:Wiretapping (Physical tap to comms line) - -==== veris:action:physical:variety="Bypassed controls" - -veris:Bypassed physical barriers or controls - -==== veris:action:physical:variety="Disabled controls" - -veris:Disabled physical barriers or controls - -==== veris:action:physical:variety="Destruction" - -veris:Destruction (deliberate damaging or disabling) - -=== attribute:confidentiality:data:variety -==== veris:attribute:confidentiality:data:variety="Source code" - -veris:Source code - -==== veris:attribute:confidentiality:data:variety="Personal" - -veris:Personal or identifying information (e.g., addr, ID#, credit score) - -==== veris:attribute:confidentiality:data:variety="Unknown" - -veris:Unknown - -==== veris:attribute:confidentiality:data:variety="Medical" - -veris:Medical records - -==== veris:attribute:confidentiality:data:variety="Classified" - -veris:Classified information - -==== veris:attribute:confidentiality:data:variety="System" - -veris:System information (e.g., config info, open services) - -==== veris:attribute:confidentiality:data:variety="Digital certificate" - -veris:Digital certificate - -==== veris:attribute:confidentiality:data:variety="Secrets" - -veris:Trade secrets - -==== veris:attribute:confidentiality:data:variety="Internal" - -veris:Sensitive internal data (e.g., plans, reports, emails) - -==== veris:attribute:confidentiality:data:variety="Virtual currency" - -veris:Virtual currency - -==== veris:attribute:confidentiality:data:variety="Copyrighted" - -veris:Copyrighted material - -==== veris:attribute:confidentiality:data:variety="Credentials" - -veris:Authentication credentials (e.g., pwds, OTPs, biometrics) - -==== veris:attribute:confidentiality:data:variety="Other" - -veris:Other - -==== veris:attribute:confidentiality:data:variety="Payment" - -veris:Payment card data (e.g., PAN, PIN, CVV2, Expiration) - -==== veris:attribute:confidentiality:data:variety="Bank" - -veris:Bank account data - -== ms-caro-malware-full -NOTE: ms-caro-malware-full namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/ms-caro-malware-full/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families. - -=== malware-type -==== ms-caro-malware-full:malware-type="Adware" - -ms-caro-malware-full:Adware - Software that shows you extra promotions that you cannot control as you use your PC - -==== ms-caro-malware-full:malware-type="Backdoor" - -ms-caro-malware-full:A type of trojan that gives a malicious hacker access to and control of your PC - -==== ms-caro-malware-full:malware-type="Behavior" - -ms-caro-malware-full:A type of detection based on file actions that are often associated with malicious activity - -==== ms-caro-malware-full:malware-type="BroswerModifier" - -ms-caro-malware-full:A program than makes changes to your Internet browser without your permission - -==== ms-caro-malware-full:malware-type="Constructor" - -ms-caro-malware-full:A program that can be used to automatically create malware files - -==== ms-caro-malware-full:malware-type="DDoS" - -ms-caro-malware-full:When a number of PCs are made to access a website, network or server repeatedly within a given time period. The aim of the attack is to overload the target so that it crashes and can't respond - -==== ms-caro-malware-full:malware-type="Dialer" - -ms-caro-malware-full:A program that makes unauthorized telephone calls. These calls may be charged at a premium rate and cost you a lot of money - -==== ms-caro-malware-full:malware-type="DoS" - -ms-caro-malware-full:When a target PC or server is deliberately overloaded so that it doesn't work for any visitors anymore - -==== ms-caro-malware-full:malware-type="Exploit" - -ms-caro-malware-full:A piece of code that uses software vulnerabilities to access information on your PC or install malware - -==== ms-caro-malware-full:malware-type="HackTool" - -ms-caro-malware-full:A type of tool that can be used to allow and maintain unauthorized access to your PC - -==== ms-caro-malware-full:malware-type="Joke" - -ms-caro-malware-full:A program that pretends to do something malicious but actually doesn't actually do anything harmful. For example, some joke programs pretend to delete files or format disks - -==== ms-caro-malware-full:malware-type="Misleading" - -ms-caro-malware-full:The program that makes misleading or fraudulent claims about files, registry entries or other items on your PC - -==== ms-caro-malware-full:malware-type="MonitoringTool" - -ms-caro-malware-full:A commercial program that monitors what you do on your PC. This can include monitoring what keys you press; your email or instant messages; your voice or video conversations; and your banking details and passwords. It can also take screenshots as you use your PC - -==== ms-caro-malware-full:malware-type="Program" - -ms-caro-malware-full:Software that you may or may not want installed on your PC - -==== ms-caro-malware-full:malware-type="PUA" - -ms-caro-malware-full:Potentially Unwanted Applications. Characteristics of unwanted software can include depriving users of adequate choice or control over what the software does to the computer, preventing users from removing the software, or displaying advertisements without clearly identifying their source. - -==== ms-caro-malware-full:malware-type="PWS" - -ms-caro-malware-full:A type of malware that is used steal your personal information, such as user names and passwords. It often works along with a keylogger that collects and sends information about what keys you press and websites you visit to a malicious hacker - -==== ms-caro-malware-full:malware-type="Ransom" - -ms-caro-malware-full:A detection for malicious programs that seize control of the computer on which they are installed. This trojan usually locks the screen and prevents the user from using the computer. It usually displays an alert message. - -==== ms-caro-malware-full:malware-type="RemoteAccess" - -ms-caro-malware-full:A program that gives someone access to your PC from a remote location. This type of program is often installed by the computer owner - -==== ms-caro-malware-full:malware-type="Rogue" - -ms-caro-malware-full:Software that pretends to be an antivirus program but doesn't actually provide any security. This type of software usually gives you a lot of alerts about threats on your PC that don't exist. It also tries to convince you to pay for its services - -==== ms-caro-malware-full:malware-type="SettingsModifier" - -ms-caro-malware-full:A program that changes your PC settings - -==== ms-caro-malware-full:malware-type="SoftwareBundler" - -ms-caro-malware-full:A program that installs unwanted software on your PC at the same time as the software you are trying to install, without adequate consent - -==== ms-caro-malware-full:malware-type="Spammer" - -ms-caro-malware-full:A trojan that sends large numbers of spam emails. It may also describe the person or business responsible for sending spam - -==== ms-caro-malware-full:malware-type="Spoofer" - -ms-caro-malware-full:A type of trojan that makes fake emails that look like they are from a legitimate source - -==== ms-caro-malware-full:malware-type="Spyware" - -ms-caro-malware-full:A program that collects your personal information, such as your browsing history, and uses it without adequate consent - -==== ms-caro-malware-full:malware-type="Tool" - -ms-caro-malware-full:A type of software that may have a legitimate purpose, but which may also be abused by malware authors - -==== ms-caro-malware-full:malware-type="Trojan" - -ms-caro-malware-full:A trojan is a program that tries to look innocent, but is actually a malicious application. Unlike a virus or a worm , a trojan doesn't spread by itself. Instead they try to look innocent to convince you to download and install them. Once installed, a trojan can steal your personal information, download more malware, or give a malicious hacker access to your PC - -==== ms-caro-malware-full:malware-type="TrojanClicker" - -ms-caro-malware-full:A type of trojan that can use your PC to click on websites or applications. They are usually used to make money for a malicious hacker by clicking on online advertisements and making it look like the website gets more traffic than it does. They can also be used to skew online polls, install programs on your PC, or make unwanted software appear more popular than it is - -==== ms-caro-malware-full:malware-type="TrojanDownloader" - -ms-caro-malware-full:A type of trojan that installs other malicious files, including malware, onto your PC. It can download the files from a remote PC or install them directly from a copy that is included in its file. - -==== ms-caro-malware-full:malware-type="TrojanDropper" - -ms-caro-malware-full:A type of trojan that installs other malicious files, including malware, onto your PC. It can download the files from a remote PC or install them directly from a copy that is included in its file. - -==== ms-caro-malware-full:malware-type="TrojanNotifier" - -ms-caro-malware-full:A type of trojan that sends information about your PC to a malicious hacker. It is similar to a password stealer - -==== ms-caro-malware-full:malware-type="TrojanProxy" - -ms-caro-malware-full:A type of trojan that installs a proxy server on your PC. The server can be configured so that when you use the Internet, any requests you make are sent through a server controlled by a malicious hacker. - -==== ms-caro-malware-full:malware-type="TrojanSpy" - -ms-caro-malware-full:A program that collects your personal information, such as your browsing history, and uses it without adequate consent. - -==== ms-caro-malware-full:malware-type="VirTool" - -ms-caro-malware-full:A detection that is used mostly for malware components, or tools used for malware-related actions, such as rootkits. - -==== ms-caro-malware-full:malware-type="Virus" - -ms-caro-malware-full:A type of malware. Viruses spread on their own by attaching their code to other programs, or copying themselves across systems and networks. - -==== ms-caro-malware-full:malware-type="Worm" - -ms-caro-malware-full:A type of malware that spreads to other PCs. Worms may spread using one or more of the following methods: Email programs, Instant messaging programs, File-sharing programs, Social networking sites, Network shares, Removable drives with Autorun enabled, Software vulnerabilities - -=== malware-platform -==== ms-caro-malware-full:malware-platform="AndroidOS" - -ms-caro-malware-full:Android operating system - -==== ms-caro-malware-full:malware-platform="DOS" - -ms-caro-malware-full:MS-DOS platform - -==== ms-caro-malware-full:malware-platform="EPOC" - -ms-caro-malware-full:Psion devices - -==== ms-caro-malware-full:malware-platform="FreeBSD" - -ms-caro-malware-full:FreeBSD platform - -==== ms-caro-malware-full:malware-platform="iPhoneOS" - -ms-caro-malware-full:iPhone operating system - -==== ms-caro-malware-full:malware-platform="Linux" - -ms-caro-malware-full:Linux platform - -==== ms-caro-malware-full:malware-platform="MacOS" - -ms-caro-malware-full:MAC 9.x platform or earlier - -==== ms-caro-malware-full:malware-platform="MacOS_X" - -ms-caro-malware-full:MacOS X or later - -==== ms-caro-malware-full:malware-platform="OS2" - -ms-caro-malware-full:OS2 platform - -==== ms-caro-malware-full:malware-platform="Palm" - -ms-caro-malware-full:Palm operating system - -==== ms-caro-malware-full:malware-platform="Solaris" - -ms-caro-malware-full:System V-based Unix platforms - -==== ms-caro-malware-full:malware-platform="SunOS" - -ms-caro-malware-full:Unix platforms 4.1.3 or earlier - -==== ms-caro-malware-full:malware-platform="SymbOS" - -ms-caro-malware-full:Symbian operatings system - -==== ms-caro-malware-full:malware-platform="Unix" - -ms-caro-malware-full:General Unix platforms - -==== ms-caro-malware-full:malware-platform="Win16" - -ms-caro-malware-full:Win16 (3.1) platform - -==== ms-caro-malware-full:malware-platform="Win2K" - -ms-caro-malware-full:Windows 2000 platform - -==== ms-caro-malware-full:malware-platform="Win32" - -ms-caro-malware-full:Windows 32-bit platform - -==== ms-caro-malware-full:malware-platform="Win64" - -ms-caro-malware-full:Windows 64-bit platform - -==== ms-caro-malware-full:malware-platform="Win95" - -ms-caro-malware-full:Windows 95, 98 and ME platforms - -==== ms-caro-malware-full:malware-platform="Win98" - -ms-caro-malware-full:Windows 98 platform only - -==== ms-caro-malware-full:malware-platform="WinCE" - -ms-caro-malware-full:Windows CE platform - -==== ms-caro-malware-full:malware-platform="WinNT" - -ms-caro-malware-full:WinNT - -==== ms-caro-malware-full:malware-platform="ABAP" - -ms-caro-malware-full:Advanced Business Application Programming scripts - -==== ms-caro-malware-full:malware-platform="ALisp" - -ms-caro-malware-full:ALisp scripts - -==== ms-caro-malware-full:malware-platform="AmiPro" - -ms-caro-malware-full:AmiPro script - -==== ms-caro-malware-full:malware-platform="ANSI" - -ms-caro-malware-full:American National Standards Institute scripts - -==== ms-caro-malware-full:malware-platform="AppleScript" - -ms-caro-malware-full:compiled Apple scripts - -==== ms-caro-malware-full:malware-platform="ASP" - -ms-caro-malware-full:Active Server Pages scripts - -==== ms-caro-malware-full:malware-platform="AutoIt" - -ms-caro-malware-full:AutoIT scripts - -==== ms-caro-malware-full:malware-platform="BAS" - -ms-caro-malware-full:Basic scripts - -==== ms-caro-malware-full:malware-platform="BAT" - -ms-caro-malware-full:Basic scripts - -==== ms-caro-malware-full:malware-platform="CorelScript" - -ms-caro-malware-full:Corelscript scripts - -==== ms-caro-malware-full:malware-platform="HTA" - -ms-caro-malware-full:HTML Application scripts - -==== ms-caro-malware-full:malware-platform="HTML" - -ms-caro-malware-full:HTML Application scripts - -==== ms-caro-malware-full:malware-platform="INF" - -ms-caro-malware-full:Install scripts - -==== ms-caro-malware-full:malware-platform="IRC" - -ms-caro-malware-full:mIRC/pIRC scripts - -==== ms-caro-malware-full:malware-platform="Java" - -ms-caro-malware-full:Java binaries (classes) - -==== ms-caro-malware-full:malware-platform="JS" - -ms-caro-malware-full:Javascript scripts - -==== ms-caro-malware-full:malware-platform="LOGO" - -ms-caro-malware-full:LOGO scripts - -==== ms-caro-malware-full:malware-platform="MPB" - -ms-caro-malware-full:MapBasic scripts - -==== ms-caro-malware-full:malware-platform="MSH" - -ms-caro-malware-full:Monad shell scripts - -==== ms-caro-malware-full:malware-platform="MSIL" - -ms-caro-malware-full:.Net intermediate language scripts - -==== ms-caro-malware-full:malware-platform="Perl" - -ms-caro-malware-full:Perl scripts - -==== ms-caro-malware-full:malware-platform="PHP" - -ms-caro-malware-full:Hypertext Preprocessor scripts - -==== ms-caro-malware-full:malware-platform="Python" - -ms-caro-malware-full:Python scripts - -==== ms-caro-malware-full:malware-platform="SAP" - -ms-caro-malware-full:SAP platform scripts - -==== ms-caro-malware-full:malware-platform="SH" - -ms-caro-malware-full:Shell scripts - -==== ms-caro-malware-full:malware-platform="VBA" - -ms-caro-malware-full:Visual Basic for Applications scripts - -==== ms-caro-malware-full:malware-platform="VBS" - -ms-caro-malware-full:Visual Basic scripts - -==== ms-caro-malware-full:malware-platform="WinBAT" - -ms-caro-malware-full:Winbatch scripts - -==== ms-caro-malware-full:malware-platform="WinHlp" - -ms-caro-malware-full:Windows Help scripts - -==== ms-caro-malware-full:malware-platform="WinREG" - -ms-caro-malware-full:Windows registry scripts - -==== ms-caro-malware-full:malware-platform="A97M" - -ms-caro-malware-full:Access 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware-full:malware-platform="HE" - -ms-caro-malware-full:macro scripting - -==== ms-caro-malware-full:malware-platform="O97M" - -ms-caro-malware-full:Office 97, 2000, XP, 2003, 2007, and 2010 macros - those that affect Word, Excel, and Powerpoint - -==== ms-caro-malware-full:malware-platform="PP97M" - -ms-caro-malware-full:PowerPoint 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware-full:malware-platform="V5M" - -ms-caro-malware-full:Visio5 macros - -==== ms-caro-malware-full:malware-platform="W1M" - -ms-caro-malware-full:Word1Macro - -==== ms-caro-malware-full:malware-platform="W2M" - -ms-caro-malware-full:Word2Macro - -==== ms-caro-malware-full:malware-platform="W97M" - -ms-caro-malware-full:Word 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware-full:malware-platform="WM" - -ms-caro-malware-full:Word 95 macros - -==== ms-caro-malware-full:malware-platform="X97M" - -ms-caro-malware-full:Excel 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware-full:malware-platform="XF" - -ms-caro-malware-full:Excel formulas - -==== ms-caro-malware-full:malware-platform="XM" - -ms-caro-malware-full:Excel 95 macros - -==== ms-caro-malware-full:malware-platform="ASX" - -ms-caro-malware-full:XML metafile of Windows Media .asf files - -==== ms-caro-malware-full:malware-platform="HC" - -ms-caro-malware-full:HyperCard Apple scripts - -==== ms-caro-malware-full:malware-platform="MIME" - -ms-caro-malware-full:MIME packets - -==== ms-caro-malware-full:malware-platform="Netware" - -ms-caro-malware-full:Novell Netware files - -==== ms-caro-malware-full:malware-platform="QT" - -ms-caro-malware-full:Quicktime files - -==== ms-caro-malware-full:malware-platform="SB" - -ms-caro-malware-full:StarBasic (Staroffice XML) files - -==== ms-caro-malware-full:malware-platform="SWF" - -ms-caro-malware-full:Shockwave Flash files - -==== ms-caro-malware-full:malware-platform="TSQL" - -ms-caro-malware-full:MS SQL server files - -==== ms-caro-malware-full:malware-platform="XML" - -ms-caro-malware-full:XML files - -=== malware-family -==== ms-caro-malware-full:malware-family="Zlob" - -ms-caro-malware-full:2008 - A family of trojans that often pose as downloadable media codecs. When installed, Win32/Zlob displays frequent pop-up advertisements for rogue security software - -==== ms-caro-malware-full:malware-family="Vundo" - -ms-caro-malware-full:2008 - A multiplecomponent family of programs that deliver pop-up advertisements and may download and execute arbitrary files. Vundo is often installed as a browser helper object (BHO) without a user’s consent - -==== ms-caro-malware-full:malware-family="Virtumonde" - -ms-caro-malware-full:2008 - multi-component malware family that displays pop-up advertisements for rogue security software - -==== ms-caro-malware-full:malware-family="Bancos" - -ms-caro-malware-full: 2008 - A data-stealing trojan that captures online banking credentials and relays them to the attacker. Most variants target customers of Brazilian banks. - -==== ms-caro-malware-full:malware-family="Cutwail" - -ms-caro-malware-full:2008 - A trojan that downloads and executes arbitrary files, usually to send spam. Win32/Cutwail has also been observed to transmit Win32/Newacc - -==== ms-caro-malware-full:malware-family="Oderoor" - -ms-caro-malware-full:2008 - a backdoor trojan that allows an attacker access and control of the compromised computer. This trojan may connect with remote web sites and SMTP servers. - -==== ms-caro-malware-full:malware-family="Newacc" - -ms-caro-malware-full:2008 - An attacker tool that automatically registers new e-mail accounts on Hotmail, AOL, Gmail, Lycos and other account service providers, using a Web service to decode CAPTCHA protection. - -==== ms-caro-malware-full:malware-family="Captiya" - -ms-caro-malware-full:2008 - A trojan that transmits CAPTCHA images to a botnet, in what is believed to be an effort to improve the botnet’s ability to detect characters and break CAPTCHAs more successfully - -==== ms-caro-malware-full:malware-family="Taterf" - -ms-caro-malware-full:2008 - A family of worms that spread through mapped drives in order to steal login and account details for popular online games. - -==== ms-caro-malware-full:malware-family="Frethog" - -ms-caro-malware-full:2008 - A large family of password-stealing trojans that target confidential data, such as account information, from massively multiplayer online games - -==== ms-caro-malware-full:malware-family="Tilcun" - -ms-caro-malware-full:2008 - A family of trojans that steals online game passwords and sends this captured data to remote sites. - -==== ms-caro-malware-full:malware-family="Ceekat" - -ms-caro-malware-full:2008 - A collection of trojans that steal information such as passwords for online games, usually by reading information directly from running processes in memory. Different variants target different processes. - -==== ms-caro-malware-full:malware-family="Corripio" - -ms-caro-malware-full:2008 - a loosely-related family of trojans that attempt to steal passwords for popular online games. Detections containing the name Win32/Corripio are generic, and hence may be reported for a large number of different malicious password-stealing trojans that are otherwise behaviorally dissimilar. - -==== ms-caro-malware-full:malware-family="Zuten" - -ms-caro-malware-full:2008 - A family of malware that steals information from online games. - -==== ms-caro-malware-full:malware-family="Lolyda" - -ms-caro-malware-full:2008 - A family of trojans that sends account information from popular online games to a remote server. They may also download and execute arbitrary files. - -==== ms-caro-malware-full:malware-family="Storark" - -ms-caro-malware-full:2008 - A family of trojans that steals online game passwords and sends this captured data to remote sites. - -==== ms-caro-malware-full:malware-family="Renos" - -ms-caro-malware-full:2008 - A family of trojan downloaders that installs rogue security software. - -==== ms-caro-malware-full:malware-family="ZangoSearchAssistant" - -ms-caro-malware-full:2008 - Adware that monitors the user’s Web-browsing activity and displays pop-up advertisements related to the Internet sites the user is viewing. - -==== ms-caro-malware-full:malware-family="ZangoShoppingReports" - -ms-caro-malware-full:2008 - Adware that displays targeted advertising to affected users while they browse the Internet, based on search terms entered into search engines. - -==== ms-caro-malware-full:malware-family="FakeXPA" - -ms-caro-malware-full:2008 - A rogue security software family that claims to scan for malware and then demands that the user pay to remove nonexistent threats. Some variants unlawfully use Microsoft logos and trademarks. - -==== ms-caro-malware-full:malware-family="FakeSecSen" - -ms-caro-malware-full:2008 - A rogue security software family that claims to scan for malware and then demands that the user pay to remove non-existent threats. It appears to be based on Win32/SpySheriff - -==== ms-caro-malware-full:malware-family="Hotbar" - -ms-caro-malware-full:2008 - Adware that displays a dynamic toolbar and targeted pop-up ads based on its monitoring of Web-browsing activity. - -==== ms-caro-malware-full:malware-family="Agent" - -ms-caro-malware-full:2008 - A generic detection for a number of trojans that may perform different malicious functions. The behaviors exhibited by this family are highly variable - -==== ms-caro-malware-full:malware-family="Wimad" - -ms-caro-malware-full:2008 - A detection for malicious Windows Media files that can be used to encourage users to download and execute arbitrary files on an affected machine. - -==== ms-caro-malware-full:malware-family="BaiduSobar" - -ms-caro-malware-full:2008 - A Chinese language Web browser toolbar that delivers pop-up and contextual advertisements, blocks certain other advertisements, and changes the Internet Explorer search page - -==== ms-caro-malware-full:malware-family="VB" - -ms-caro-malware-full:2008 - A detection for various threats written in the Visual Basic programming language. - -==== ms-caro-malware-full:malware-family="Antivirus2008" - -ms-caro-malware-full:2008 - A program that displays misleading security alerts in order to convince users to purchase rogue security software. It may be installed by Win32/Renos or manually by a computer user. - -==== ms-caro-malware-full:malware-family="Playmp3z" - -ms-caro-malware-full:2008 - An adware family that may display advertisements in connection with the use of a 'free music player' from the site 'PlayMP3z.biz.' - -==== ms-caro-malware-full:malware-family="Tibs" - -ms-caro-malware-full:2008 - a family of Trojans that may download and run other malicious software or may steal user data and send it to the attacker via HTTP POST or email. The Win32/Tibs family frequently downloads Trojans belonging to the Win32/Harnig and Win32/Passalert families, both of which are families of Trojan downloaders which may in turn download and run other malicious software - -==== ms-caro-malware-full:malware-family="SeekmoSearchAssistant" - -ms-caro-malware-full:2008 - Adware that displays targeted search results and pop-up advertisements based on terms that the user enters for Web searches. The pop-up advertisements may include adult content. - -==== ms-caro-malware-full:malware-family="RJump" - -ms-caro-malware-full:2008 - a worm that attempts to spread by copying itself to newly attached media (such as USB memory devices or network drives). It also contains backdoor functionality that allows an attacker unauthorized access to an affected computer - -==== ms-caro-malware-full:malware-family="SpywareSecure" - -ms-caro-malware-full:2008 - A program that displays misleading warning messages in order to convince users to purchase a product that removes spyware - -==== ms-caro-malware-full:malware-family="Winfixer" - -ms-caro-malware-full:2008 - A program that locates various registry entries, Windows prefetch content, and other types of data, identifies them as privacy violations, and urges the user to purchase the product to fix them. - -==== ms-caro-malware-full:malware-family="C2Lop" - -ms-caro-malware-full:2008 - a trojan that modifies Web browser settings, adds Web browser bookmarks to advertisements, updates itself and delivers pop-up and contextual advertisements. - -==== ms-caro-malware-full:malware-family="Matcash" - -ms-caro-malware-full:2008 - a multicomponent family of trojans that downloads and executes arbitrary files. Some variants of this family may install a toolbar. observed to use the Win32/Slenfbot worm as a means of distribution. - -==== ms-caro-malware-full:malware-family="Horst" - -ms-caro-malware-full:2008 - CAPTCHA Breaker typically delivered through an executable application that masquerades as an illegal software crack or key generator - -==== ms-caro-malware-full:malware-family="Slenfbot" - -ms-caro-malware-full:2008 - A family of worms that can spread via instant messaging programs, and may spread via removable drives. They also contain backdoor functionality that allows unauthorized access to an affected machine. This worm does not spread automatically upon installation but must be ordered to spread by a remote attacker. - -==== ms-caro-malware-full:malware-family="Rustock" - -ms-caro-malware-full:2008 - A multicomponent family of rootkitenabled backdoor trojans, developed to aid in the distribution of spam. Recent variants appear to be associated with the incidence of rogue security programs. - -==== ms-caro-malware-full:malware-family="Gimmiv" - -ms-caro-malware-full:2008 - a family of trojans that are sometimes installed by exploits of a vulnerability documented in Microsoft Security Bulletin MS08-067. - -==== ms-caro-malware-full:malware-family="Yektel" - -ms-caro-malware-full:2008 - A family of trojans that display fake warnings of spyware or malware in an attempt to lure the user into installing or paying money to register rogue security products such as Win32/FakeXPA. - -==== ms-caro-malware-full:malware-family="Roron" - -ms-caro-malware-full:2008 - This virus spreads by attaching its code to other files on your PC or network. Some of the infected programs might no longer run correctly. Attempts to send personal information to a remote address. It may spread via e-mail, network shares, or peer-to-peer file sharing. - -==== ms-caro-malware-full:malware-family="Swif" - -ms-caro-malware-full:2008 - A trojan that exploits a vulnerability in Adobe Flash Player to download malicious files. Adobe has published security bulletin APSB08-11 addressing the vulnerability. - -==== ms-caro-malware-full:malware-family="Mult" - -ms-caro-malware-full:2008 - A group of threats, written in JavaScript, that attempt to exploit multiple vulnerabilities on affected computers in order to download, execute or otherwise run arbitrary code. The malicious JavaScript may be hosted on compromised or malicious websites, embedded in specially crafted PDF files, or could be called by other malicious scripts. - -==== ms-caro-malware-full:malware-family="Wukill" - -ms-caro-malware-full:2008 - a family of mass-mailing e-mail and network worms. The Win32/Wukill worm spreads to root directories on certain local and mapped drives. The worm also spreads by sending a copy of itself as an attachment to e-mail addresses found on the infected computer. - -==== ms-caro-malware-full:malware-family="Objsnapt" - -ms-caro-malware-full:2008 - A detection for a Javascript file that exploits a known vulnerability in the Microsoft Access Snapshot Viewer ActiveX Control. - -==== ms-caro-malware-full:malware-family="Redirector" - -ms-caro-malware-full:2008 - The threat is a piece of JavaScript code that is inserted on bad or hacked websites. It can direct your browser to a website you don't want to go to. You might see the detection for this threat if you visit a bad or hacked website, or if you open an email message. - -==== ms-caro-malware-full:malware-family="Xilos" - -ms-caro-malware-full:2008 - a detection for a proof-of-concept JavaScript obfuscation technique, which was originally published in 2002 in the sixth issue of 29A, an early online magazine for virus creators - -==== ms-caro-malware-full:malware-family="Decdec" - -ms-caro-malware-full:2008 - A detection for certain malicious JavaScript code injected in HTML pages. The virus will execute on user computers that visit compromised websites. - -==== ms-caro-malware-full:malware-family="BearShare" - -ms-caro-malware-full:2008 - A P2P file-sharing client that uses the decentralized Gnutella network. Free versions of BearShare have come bundled with advertising supported and other potentially unwanted software. - -==== ms-caro-malware-full:malware-family="BitAccelerator" - -ms-caro-malware-full:2008 - A program that redirects Web search results to other Web sites and may display various advertisements to users while browsing Web sites. - -==== ms-caro-malware-full:malware-family="Blubtool" - -ms-caro-malware-full:2008 - An Internet browser search toolbar that may be installed by other third-party software, such as a peer-to-peer file sharing application. It may modify Internet explorer search settings and display unwanted advertisements. - -==== ms-caro-malware-full:malware-family="RServer" - -ms-caro-malware-full:2008 - Commercial remote administration software that can be used to control a computer. These programs are typically installed by the computer owner or administrator and should only be removed if unexpected - -==== ms-caro-malware-full:malware-family="UltraVNC" - -ms-caro-malware-full:2008 - A remote access program that can be used to control a computer. This program is typically installed by the computer owner or administrator, and should only be removed if unexpected. - -==== ms-caro-malware-full:malware-family="GhostRadmin" - -ms-caro-malware-full:2008 - A remote administration tool that can be used to control a computer. These programs are typically installed by the computer owner or administrator and should only be removed if unexpected - -==== ms-caro-malware-full:malware-family="TightVNC" - -ms-caro-malware-full:2008 - A remote control program that allows full control of the computer. These programs are typically installed by the computer owner or administrator and should only be removed if unexpected - -==== ms-caro-malware-full:malware-family="DameWareMiniRemoteControl" - -ms-caro-malware-full:2008 - A detection for the DameWare Mini Remote Control tools. This program was detected by definitions prior to 1.147.1889.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. Microsoft has released definition 1.147.1889.0 which no longer detects this program. - -==== ms-caro-malware-full:malware-family="SeekmoSearchAssistant" - -ms-caro-malware-full:2008 - A detection that is triggered by modified (that is, edited and re-packed) remote control programs based on DameWare Mini Remote Control, a commercial software product - -==== ms-caro-malware-full:malware-family="Nbar" - -ms-caro-malware-full:2008 - A program that may display advertisements and redirect user searches to a certain website. It may also download malicious or unwanted content into the system without user consent. - -==== ms-caro-malware-full:malware-family="Chir" - -ms-caro-malware-full:2008 - A family with a worm component and a virus component. The worm component spreads by email and by exploiting a vulnerability addressed by Microsoft Security Bulletin MS01-020. The virus component may infect .exe, .scr, and HTML files. - -==== ms-caro-malware-full:malware-family="Sality" - -ms-caro-malware-full:2008 - A family of polymorphic file infectors that target executable files with the extensions .scr or .exe. They may execute a damaging payload that deletes files with certain extensions and terminates security-related processes and services. - -==== ms-caro-malware-full:malware-family="Obfuscator" - -ms-caro-malware-full:2008 - A detection for programs that use a combination of obfuscation techniques to hinder analysis or detection by antivirus scanners - -==== ms-caro-malware-full:malware-family="ByteVerify" - -ms-caro-malware-full:2008 - a detection of malicious code that attempts to exploit a vulnerability in the Microsoft Virtual Machine (VM). This flaw enables attackers to execute arbitrary code on a user's machine such as writing, downloading and executing additional malware. This vulnerability is addressed by update MS03-011, released in 2003. - -==== ms-caro-malware-full:malware-family="Autorun" - -ms-caro-malware-full:2008 - A family of worms that spreads by copying itself to the mapped drives of an infected computer. The mapped drives may include network or removable drives. - -==== ms-caro-malware-full:malware-family="Hamweq" - -ms-caro-malware-full:2008 - A worm that spreads through removable drives, such as USB memory sticks. It may contain an IRC-based backdoor enabling the computer to be controlled remotely by an attacker - -==== ms-caro-malware-full:malware-family="Brontok" - -ms-caro-malware-full:2008 - a family of mass-mailing e-mail worms. The worm spreads by sending a copy of itself as an e-mail attachment to e-mail addresses that it gathers from files on the infected computer. It can also copy itself to USB and pen drives. Win32/Brontok can disable antivirus and security software, immediately terminate certain applications, and cause Windows to restart immediately when certain applications run. The worm may also conduct denial of service (DoS) attacks against certain Web sites - -==== ms-caro-malware-full:malware-family="SpywareProtect" - -ms-caro-malware-full:2008 - A rogue security software family that may falsely claim that the user’s computer is infected and encourages the user to buy a product for cleaning the alleged malware from the computer - -==== ms-caro-malware-full:malware-family="Cbeplay" - -ms-caro-malware-full:2008 - A trojan that may upload computer operating system details to a remote Web site, download additional malware, and terminate debugging utilities - -==== ms-caro-malware-full:malware-family="InternetAntivirus" - -ms-caro-malware-full:2008 - A program that displays false and misleading malware alerts to convince users to purchase rogue security software. This program also displays a fake Windows Security Center message - -==== ms-caro-malware-full:malware-family="Nuwar" - -ms-caro-malware-full:2008 - A family of trojan droppers that install a distributed P2P downloader trojan. This downloader trojan in turn downloads an e-mail worm component. - -==== ms-caro-malware-full:malware-family="Rbot" - -ms-caro-malware-full:2008 - A family of backdoor trojans that allows attackers to control the computer through an IRC channel - -==== ms-caro-malware-full:malware-family="IRCbot" - -ms-caro-malware-full:2008 - A large family of backdoor trojans that drops malicious software and connects to IRC servers via a backdoor to receive commands from attackers. - -==== ms-caro-malware-full:malware-family="SkeemoSearchAssistant" - -ms-caro-malware-full:2008 - A program that displays targeted search results and pop-up advertisements based on terms that the user enters for Web searches. The pop-up advertisements may include adult content - -==== ms-caro-malware-full:malware-family="RealVNC" - -ms-caro-malware-full:2008 - A management tool that allows a computer to be controlled remotely. It can be installed for legitimate purposes, but can also be installed from a remote location by an attacker. - -==== ms-caro-malware-full:malware-family="MoneyTree" - -ms-caro-malware-full:2008 - A family of software that provides the ability to search for adult content on local disk. It may also install other potentially unwanted software, such as programs that display pop-up ads. - -==== ms-caro-malware-full:malware-family="Tracur" - -ms-caro-malware-full:2008 - A trojan that downloads and executes arbitrary files. It is sometimes distributed by ASX/Wimad. - -==== ms-caro-malware-full:malware-family="Meredrop" - -ms-caro-malware-full:2008 - This is a generic detection for trojans that install and run malware on your PC. These trojans have been deliberately created in a complex way to hide their purpose and make them difficult to analyze. - -==== ms-caro-malware-full:malware-family="Banker" - -ms-caro-malware-full:2008 - A family of data-stealing trojans that captures banking credentials such as account numbers and passwords from computer users and relays them to the attacker. Most variants target customers of Brazilian banks; some variants target customers of other banks. - -==== ms-caro-malware-full:malware-family="Ldpinch" - -ms-caro-malware-full:2008 - a family of password-stealing trojans. This trojan gathers private user data such as passwords from the host computer and sends the data to the attacker at a preset e-mail address. The Win32/Ldpinch trojans use their own Simple Mail Transfer Protocol (SMTP) engine or a web-based proxy for sending the e-mail, thus copies of the sent e-mail will not appear in the affected user's e-mail client. - -==== ms-caro-malware-full:malware-family="Advantage" - -ms-caro-malware-full:2008 - a family of adware that displays pop-up advertisements and contacts a remote server to download updates - -==== ms-caro-malware-full:malware-family="Parite" - -ms-caro-malware-full:2008 - a family of polymorphic file infectors that targets computers running Microsoft Windows. The virus infects .exe and .scr executable files on the local file system and on writeable network shares. In turn, the infected executable files perform operations that cause other .exe and .scr files to become infected. - -==== ms-caro-malware-full:malware-family="PossibleHostsFileHijack" - -ms-caro-malware-full:2008 - an indicator that the computer’s HOSTS file may have been modified by malicious or potentially unwanted software - -==== ms-caro-malware-full:malware-family="Alureon" - -ms-caro-malware-full:2008 - A data-stealing trojan that gathers confidential information such as user names, passwords, and credit card data from incoming and outgoing Internet traffic. It may also download malicious data and modify DNS settings. - -==== ms-caro-malware-full:malware-family="PowerRegScheduler" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.159.567.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. Microsoft has released definition 1.159.567.0 which no longer detects this program. - -==== ms-caro-malware-full:malware-family="APSB08-11" - -ms-caro-malware-full:2008 - A trojan that attempts to exploit a vulnerability in Adobe Flash Player. In the wild, this trojan has been used to download and execute arbitrary files, including other malware. - -==== ms-caro-malware-full:malware-family="ConHook" - -ms-caro-malware-full:2008 - A family of Trojans that installs themselves as Browser Helper Objects (BHOs), and connects to the Internet without user consent. They also terminate specific security services, and download additional malware to the computer. - -==== ms-caro-malware-full:malware-family="Starware" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.159.567.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. Microsoft has released definition 1.159.567.0 which no longer detects this program. - -==== ms-caro-malware-full:malware-family="WinSpywareProtect" - -ms-caro-malware-full:2008 - A program that may falsely claim that the user's system is infected and encourages the user to buy a promoted product for cleaning the alleged malware from the computer. - -==== ms-caro-malware-full:malware-family="MessengerSkinner" - -ms-caro-malware-full:2008 - A program, that may be distributed in the form of a freeware application, that displays advertisements, downloads additional files, and uses stealth to hide its presence - -==== ms-caro-malware-full:malware-family="Skintrim" - -ms-caro-malware-full:2008 - A trojan that downloads and executes arbitrary files. It may be distributed by as a Microsoft Office Outlook addon used to display emoticons or other animated icons within e-mail messages. - -==== ms-caro-malware-full:malware-family="AdRotator" - -ms-caro-malware-full:2008 - delivers advertisements, and as the name suggests, rotates advertisements among sponsors. AdRotator contacts remote Web sites in order to deliver updated content. This application also displays fake error messages that encourage users to download and install additional applications. - -==== ms-caro-malware-full:malware-family="Wintrim" - -ms-caro-malware-full:2008 - A family of trojans that display pop-up advertisements depending on the user’s keywords and browsing history. Its variants can monitor the user’s activities, download applications, and send system information back to a remote server. - -==== ms-caro-malware-full:malware-family="Busky" - -ms-caro-malware-full:2008 - A family of Trojans that monitor and redirect Internet traffic, gather system information and download unwanted software such as Win32/Renos and Win32/SpySheriff. Win32/Busky may be installed by a Web browser exploit or other vulnerability when visiting a malicious Web site. - -==== ms-caro-malware-full:malware-family="WhenU" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.173.303.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Mobis" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.175.2037.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Sogou" - -ms-caro-malware-full:2008 - Detected by definitions prior to 1.155.995.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. Microsoft has released definition 1.155.995.0 which no longer detects this program. - -==== ms-caro-malware-full:malware-family="Sdbot" - -ms-caro-malware-full:2008 - A family of backdoor trojans that allows attackers to control infected computers. After a computer is infected, the trojan connects to an internet relay chat (IRC) server and joins a channel to receive commands from attackers. - -==== ms-caro-malware-full:malware-family="DelfInject" - -ms-caro-malware-full:2008 - This threat can download and run files on your PC. - -==== ms-caro-malware-full:malware-family="Vapsup" - -ms-caro-malware-full:2008 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="BrowsingEnhancer" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.175.1834.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Jeefo" - -ms-caro-malware-full:2008 - virus infects executable files, such as files with a .exe extension. When an infected file runs, the virus tries to run the original content of the file while it infects other executable files on your PC. This threat might have got on your PC if you inserted a removable disk or accessed a network connection that was infected. - -==== ms-caro-malware-full:malware-family="Sezon" - -ms-caro-malware-full:2008 - An adware that redirects web browsing to advertising or search sites. - -==== ms-caro-malware-full:malware-family="RuPass" - -ms-caro-malware-full:2008 - a DLL component which may be utilized by adware or malicious programs in order to monitor an affected user's Internet usage and to capture sensitive information. Win32/RuPass has been distributed as a 420,352 byte DLL file, with the file name 'ConnectionServices.dll'. - -==== ms-caro-malware-full:malware-family="OneStepSearch" - -ms-caro-malware-full:2008 - Modifies the user's browser to deliver targeted advertisements when the user enters search keywords. It may also replace or override web browser error pages that would otherwise be displayed when unresolvable web addresses are entered into the browser's address bar. - -==== ms-caro-malware-full:malware-family="GameVance" - -ms-caro-malware-full:2008 - Software that displays advertisements and tracks anonymous usage information in exchange for a free online gaming experience at the Web address 'gamevance.com.' - -==== ms-caro-malware-full:malware-family="E404" - -ms-caro-malware-full:2008 - is a browser helper object (BHO) that takes advantage of invalid or mistyped URLs entered in the address bar by redirecting the browser to Web sites containing adware - -==== ms-caro-malware-full:malware-family="Mirar" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.175.2037.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Fotomoto" - -ms-caro-malware-full:2008 - A Trojan that lowers security settings, delivers advertisements, and sends system and network configuration details to a remote Web site. - -==== ms-caro-malware-full:malware-family="Ardamax" - -ms-caro-malware-full:2008 - The tool can capture your activity on your PC (such as the keys you press when typing in passwords) and might send this information to a hacker. - -==== ms-caro-malware-full:malware-family="Hupigon" - -ms-caro-malware-full:2008 - A family of trojans that uses a dropper to install one or more backdoor files and sometimes installs a password stealer or other malicious programs. - -==== ms-caro-malware-full:malware-family="CNNIC" - -ms-caro-malware-full:2008 - enables Chinese keyword searching in Internet Explorer and adds support for other applications to use Chinese domain names that registered with CNNIC. Also contains a kernel driver that protects its files and registry settings from being modified or deleted - -==== ms-caro-malware-full:malware-family="MotePro" - -ms-caro-malware-full:2008 - May display advertisement pop-ups, and download programs from predefined Web sites. When installed, Win32/MotePro runs as a Web Browser Helper Object (BHO). - -==== ms-caro-malware-full:malware-family="CnsMin" - -ms-caro-malware-full:2008 - Installs a browser helper object (BHO) that redirects Internet Explorer searches to a Chinese search portal. CnsMin may be installed without adequate user consent. It may prevent its files from being removed or restore files that have been previously removed. - -==== ms-caro-malware-full:malware-family="BaiduIebar" - -ms-caro-malware-full:2008 - A detection for an address line search tool. This program was detected by definitions prior to 1.153.956.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. Microsoft has released definition 1.153.956.0 which no longer detects this program. - -==== ms-caro-malware-full:malware-family="Ejik" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.175.1915.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="AlibabaIEToolBar" - -ms-caro-malware-full:2008 - This program was detected by definitions prior to 1.175.1834.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="BDPlugin" - -ms-caro-malware-full:2008 - a DLL file which is usually introduced to an affected system as a component of BrowserModifier:Win32/BaiduSobar. It may display unwanted pop-ups and advertisements on the affected system. - -==== ms-caro-malware-full:malware-family="Adialer" - -ms-caro-malware-full:2008 - A trojan dialer program that connects to a premium number, or attempts to connect to adult websites via particular phone numbers without your permission, connects to remote hosts without user consent. - -==== ms-caro-malware-full:malware-family="EGroupSexDial" - -ms-caro-malware-full:2008 - A dialer program that may attempt to dial a premium number, thus possibly resulting in international phone charges for the user. - -==== ms-caro-malware-full:malware-family="Zonebac" - -ms-caro-malware-full:2008 - A family of backdoor Trojans that allows a remote attacker to download and run arbitrary programs, and which may upload computer configuration information and other potentially sensitive data to remote Web sites. - -==== ms-caro-malware-full:malware-family="Antinny" - -ms-caro-malware-full:2008 - A family of worms that targets certain versions of Microsoft Windows. The worm spreads using a Japanese peer-to-peer file-sharing application named Winny. The worm creates a copy of itself with a deceptive file name in the Winny upload folder so that it can be downloaded by other Winny users. - -==== ms-caro-malware-full:malware-family="RewardNetwork" - -ms-caro-malware-full:2008 - A program that monitors an affected user's Internet usage and reports this usage to a remote server. Win32/RewardNetwork may be visible as an Internet Explorer toolbar. - -==== ms-caro-malware-full:malware-family="Virut" - -ms-caro-malware-full:2008 - A family of file infecting viruses that target and infect .exe and .scr files accessed on infected systems. Win32/Virut also opens a backdoor by connecting to an IRC server - -==== ms-caro-malware-full:malware-family="Allaple" - -ms-caro-malware-full:2008 - A multi-threaded, polymorphic network worm capable of spreading to other computers connected to a local area network (LAN) and performing denial-of-service (DoS) attacks against targeted remote Web sites. - -==== ms-caro-malware-full:malware-family="VKit_DA" - -ms-caro-malware-full:2008 - This virus spreads by attaching its code to other files on your PC or network. Some of the infected programs might no longer run correctly. - -==== ms-caro-malware-full:malware-family="Small" - -ms-caro-malware-full:2008 - A generic detection for a variety of threats. - -==== ms-caro-malware-full:malware-family="Netsky" - -ms-caro-malware-full:2008 - A mass-mailing worm that spreads by e-mailing itself to addresses found on an infected computer. Some variants contain a backdoor component and perform DoS attacks. - -==== ms-caro-malware-full:malware-family="Luder" - -ms-caro-malware-full:2008 - A virus that spreads by infecting executable files, by inserting itself into .RAR archive files, and by sending a copy of itself as an attachment to e-mail addresses found on the infected computer. This virus has a date-activated, file damaging payload, and may connect to a remote server and accept commands from an attacker. - -==== ms-caro-malware-full:malware-family="IframeRef" - -ms-caro-malware-full:2008 - A generic detection for specially formed IFrame tags that point to remote websites that contain malicious content. - -==== ms-caro-malware-full:malware-family="Lovelorn" - -ms-caro-malware-full:2008 - This threat is classified as a mass-mailing worm. A mass mailing email worm is self-contained malicious code that propagates by sending itself through e-mail. Typically, a mass mailing email worm uses its own SMTP engine to send itself, thus copies of the sent worm will not appear in the infected user’s outgoing or sent email folders. Technical details are currently not available. - -==== ms-caro-malware-full:malware-family="Cekar" - -ms-caro-malware-full:2008 - This threat downloads and installs other programs, including other malware, onto your PC without your consent. - -==== ms-caro-malware-full:malware-family="Dialsnif" - -ms-caro-malware-full:2008 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="Conficker" - -ms-caro-malware-full:2008 - A worm that spreads by exploiting a vulnerability addressed by Security Bulletin MS08-067. Some variants also spread via removable drives and by exploiting weak passwords. It disables several important system services and security products and downloads arbitrary files. - -==== ms-caro-malware-full:malware-family="LoveLetter" - -ms-caro-malware-full:2009 - A family of mass-mailing worms that targets computers running certain versions of Windows. It can spread as an e-mail attachment and through an Internet Relay Chat (IRC) channel. The worm can download, overwrite, delete, infect, and run files on the infected computer. - -==== ms-caro-malware-full:malware-family="VBSWGbased" - -ms-caro-malware-full:2009 - A generic detection for VBScript code that is known to be automatically generated by a particular malware tool. - -==== ms-caro-malware-full:malware-family="Slammer" - -ms-caro-malware-full:2009 - A memory resident worm that spreads through a vulnerability present in computers running either MSDE 2000 or SQL Server that have not applied Microsoft Security Bulletin MS02-039. - -==== ms-caro-malware-full:malware-family="Msblast" - -ms-caro-malware-full:2009 - A family of network worms that exploit a vulnerability addressed by security bulletin MS03-039. The worm may attempt Denial of Service (DoS) attacks on some server sites or create a backdoor on the infected system - -==== ms-caro-malware-full:malware-family="Sasser" - -ms-caro-malware-full:2009 - A family of network worms that exploit a vulnerability fixed by security bulletin MS04-011. The worm spreads by randomly scanning IP addresses for vulnerable machines and infecting any that are found - -==== ms-caro-malware-full:malware-family="Nimda" - -ms-caro-malware-full:2009 - A family of worms that spread by exploiting a vulnerability addressed by Microsoft Security Bulletin MS01-020. The worm compromises security by sharing the C drive and creating a Guest account with administrator permissions. - -==== ms-caro-malware-full:malware-family="Mydoom" - -ms-caro-malware-full:2009 - A family of massmailing worms that spread through e-mail. Some variants also spread through P2P networks. It acts as a backdoor trojan and can sometimes be used to launch DoS attacks against specific Web sites - -==== ms-caro-malware-full:malware-family="Bagle" - -ms-caro-malware-full:2009 - A worm that spreads by e-mailing itself to addresses found on an infected computer. Some variants also spread through peer-to-peer (P2P) networks. Bagle acts as a backdoor trojan and can be used to distribute other malicious software. - -==== ms-caro-malware-full:malware-family="Winwebsec" - -ms-caro-malware-full:2009 - A family of rogue security software programs that have been distributed with several different names. The user interface varies to reflect each variant’s individual branding - -==== ms-caro-malware-full:malware-family="Koobface" - -ms-caro-malware-full:2009 - A multicomponent family of malware used to compromise computers and use them to perform various malicious tasks. It spreads through the internal messaging systems of popular social networking sites - -==== ms-caro-malware-full:malware-family="Pdfjsc" - -ms-caro-malware-full:2009 - a family of specially crafted PDF files that exploits vulnerabilities in Adobe Acrobat and Adobe Reader. The files contain malicious JavaScript that executes when opened with a vulnerable program. - -==== ms-caro-malware-full:malware-family="Pointfree" - -ms-caro-malware-full:2009 - a browser modifier that redirects users when invalid Web site addresses or search terms are entered in the Windows Internet Explorer address bar - -==== ms-caro-malware-full:malware-family="Chadem" - -ms-caro-malware-full:2009 - A trojan that steals password details from an infected computer by monitoring network traffic associated with FTP connections. - -==== ms-caro-malware-full:malware-family="FakeIA" - -ms-caro-malware-full:2009 - A rogue security software family that impersonates the Windows Security Center. It may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products - -==== ms-caro-malware-full:malware-family="Waledac" - -ms-caro-malware-full:2009 - A trojan that is used to send spam. It also has the ability to download and execute arbitrary files, harvest e-mail addresses from the local machine, perform denial-of-service attacks, proxy network traffic, and sniff passwords - -==== ms-caro-malware-full:malware-family="Provis" - -ms-caro-malware-full:2009 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="Prolaco" - -ms-caro-malware-full:2009 - A family of worms that spreads via email, removable drives, Peer-to-Peer (P2P) and network shares. This worm may also drop and execute other malware. - -==== ms-caro-malware-full:malware-family="Mywife" - -ms-caro-malware-full:2009 - A mass-mailing network worm that targets certain versions of Microsoft Windows. The worm spreads through e-mail attachments and writeable network shares. It is designed to corrupt the content of specific files on the third day of every month. - -==== ms-caro-malware-full:malware-family="Melissa" - -ms-caro-malware-full:2009 - A macro worm that spreads via e-mail and by infecting Word documents and templates. It is designed to work in Word 97 and Word 2000, and it uses Outlook to reach new targets through e-mail - -==== ms-caro-malware-full:malware-family="Rochap" - -ms-caro-malware-full:2009 - A family of multicomponent trojans that download and execute additional malicious files. While downloading, some variants display a video from the Web site 'youtube.com' presumably to distract the user - -==== ms-caro-malware-full:malware-family="Gamania" - -ms-caro-malware-full:2009 - A family of trojans that steals online game passwords and sends them to remote sites. - -==== ms-caro-malware-full:malware-family="Mabezat" - -ms-caro-malware-full:2009 - a polymorphic virus that infects Windows executable files. Apart from spreading through file infection, it also attempts to spread through e-mail attachments, network shares, removable drives and by CD-burning. It also contains a date-based payload that encrypts files with particular extensions. - -==== ms-caro-malware-full:malware-family="Helpud" - -ms-caro-malware-full:2009 - A family of trojans that steals login information for popular online games. The gathered information is then sent to remote websites. - -==== ms-caro-malware-full:malware-family="PrivacyCenter" - -ms-caro-malware-full:2009 - a family of programs that claims to scan for malware and displays fake warnings of 'malicious programs and viruses'. They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. - -==== ms-caro-malware-full:malware-family="FakeRean" - -ms-caro-malware-full:2009 - This family of rogue security programs pretend to scan your PC for malware, and often report lots of infections. The program will say you have to pay for it before it can fully clean your PC. However, the program hasn't really detected any malware at all and isn't really an antivirus or antimalware scanner. It just looks like one so you'll send money to the people who made the program. Some of these programs use product names or logos that unlawfully impersonate Microsoft products. - -==== ms-caro-malware-full:malware-family="Bredolab" - -ms-caro-malware-full:2009 - A downloader that can access and execute arbitrary files from a remote host. Bredolab has been observed to download several other malware families to infected computers - -==== ms-caro-malware-full:malware-family="Rugzip" - -ms-caro-malware-full:2009 - A trojan that downloads other malware from predefined Web sites. Rugzip may itself be installed by other malware. Once it has performed its malicious routines, it deletes itself to avoid detection. - -==== ms-caro-malware-full:malware-family="Fakespypro" - -ms-caro-malware-full:2009 - A rogue security family that falsely claims that the affected computer is infected with malware and encourages the user to buy a promoted product it claims will clean the computer. - -==== ms-caro-malware-full:malware-family="Buzuz" - -ms-caro-malware-full:2009 - A trojan that downloads malware known as 'SpywareIsolator' a rogue security software program. - -==== ms-caro-malware-full:malware-family="PoisonIvy" - -ms-caro-malware-full:2009 - A family of backdoor trojans that allow unauthorized access to and control of an affected machine. Poisonivy attempts to hide by injecting itself into other processes - -==== ms-caro-malware-full:malware-family="AgentBypass" - -ms-caro-malware-full:2009 - A detection for files that attempt to inject possibly malicious code into the explorer.exe process. - -==== ms-caro-malware-full:malware-family="Enfal" - -ms-caro-malware-full:2009 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="SystemHijack" - -ms-caro-malware-full:2009 - A generic detection that uses advanced heuristics in the Microsoft Antivirus engine to detect malware that displays particular types of malicious behavior. - -==== ms-caro-malware-full:malware-family="ProcInject" - -ms-caro-malware-full:2009 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="Malres" - -ms-caro-malware-full:2009 - A trojan that drops another malware, detected as Virtool:WinNT/Malres.A, into the system. - -==== ms-caro-malware-full:malware-family="Kirpich" - -ms-caro-malware-full:2009 - a trojan that drops malicious code into the system. It also infects two system files; the infected files are detected as Virus:Win32/Kirpich.A, in the system. This does not constitute virus behavior for the trojan as it does not infect any other files and therefore does not have any conventional replication routines. TrojanDropper:Win32/Kirpich.A also disables Data Execution Protection and steals specific system information. - -==== ms-caro-malware-full:malware-family="Malagent" - -ms-caro-malware-full:2009 - A generic detection for a variety of threats. - -==== ms-caro-malware-full:malware-family="Bumat" - -ms-caro-malware-full:2009 - A generic detection for a variety of threats. - -==== ms-caro-malware-full:malware-family="Bifrose" - -ms-caro-malware-full:2009 - A backdoor trojan that allows a remote attacker to access the compromised computer and injects its processes into the Windows shell and Internet Explorer. - -==== ms-caro-malware-full:malware-family="Ripinip" - -ms-caro-malware-full:2009 - This threat can give a hacker unauthorized access and control of your PC. - -==== ms-caro-malware-full:malware-family="Riler" - -ms-caro-malware-full:2009 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="Farfli" - -ms-caro-malware-full:2009 - A trojan that drops various files detected as malware into a system. It also has backdoor capabilities that allow it to contact a remote attacker and wait for instructions. - -==== ms-caro-malware-full:malware-family="PcClient" - -ms-caro-malware-full:2009 - A backdoor trojan family with several components including a key logger, backdoor, and a rootkit. - -==== ms-caro-malware-full:malware-family="Veden" - -ms-caro-malware-full:2009 - A name used for backdoor trojan detections that have been added to Microsoft signatures after advanced automated analysis. - -==== ms-caro-malware-full:malware-family="Banload" - -ms-caro-malware-full:2009 - A family of trojans that download other malware. Banload usually downloads Win32/Banker, which steals banking credentials and other sensitive data and sends it back to a remote attacker. - -==== ms-caro-malware-full:malware-family="Microjoin" - -ms-caro-malware-full:2009 - a tool that is used to deploy malware without being detected. It is used to bundle multiple files, consisting of a clean file and malware files, into a single executable. - -==== ms-caro-malware-full:malware-family="Killav" - -ms-caro-malware-full:2009 - a trojan that terminates a large number of security-related processes, including those for antivirus, monitoring, or debugging tools, and may install certain exploits for the vulnerability addressed by Microsoft Security Bulletin MS08-067 - -==== ms-caro-malware-full:malware-family="Cinmus" - -ms-caro-malware-full:2009 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="MessengerPlus" - -ms-caro-malware-full:2009 - A non-Microsoft add-on for Microsoft’s Windows Live Messenger, called Messenger Plus!. It comes with an optional sponsor program installation, detected as Spyware:Win32/C2Lop. - -==== ms-caro-malware-full:malware-family="Haxdoor" - -ms-caro-malware-full:2009 - a backdoor trojan that allows remote control of the machine over the Internet. The trojan is rootkit-enabled, allowing it to hide processes and files related to the threat. Haxdoor lowers security settings on the computer and gathers user and system information to send to a third party - -==== ms-caro-malware-full:malware-family="Nieguide" - -ms-caro-malware-full:2009 - a detection for a DLL file that connects to a Web site and may display advertisements or download other programs - -==== ms-caro-malware-full:malware-family="Ithink" - -ms-caro-malware-full:2009 - displays pop-up advertisements; it is usually bundled with other applications - -==== ms-caro-malware-full:malware-family="Pointad" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.2145.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Webdir" - -ms-caro-malware-full:2009 - A Web Browser Helper Object (BHO) used to collect user information and display targeted advertisings using Internet Explorer browser. Webdir attempts to modify certain visited urls to include affiliate IDs. - -==== ms-caro-malware-full:malware-family="Microbillsys" - -ms-caro-malware-full:2009 - a program that processes payments made to a billing Web site. It is considered potentially unwanted software because it cannot be removed from the Add/Remove Programs list in Control Panel; rather, a user requires an 'uninstall code' before the program can be removed. - -==== ms-caro-malware-full:malware-family="Kerlofost" - -ms-caro-malware-full:2009 - a browser helper object (BHO) that may modify browsing behavior; redirect searches; report user statistics, behavior, and searches back to a remote server; and display pop-up advertisements. - -==== ms-caro-malware-full:malware-family="Zwangi" - -ms-caro-malware-full:2009 - A program that runs as a service in the background and modifies Web browser settings to visit a particular Web site - -==== ms-caro-malware-full:malware-family="DoubleD" - -ms-caro-malware-full:2009 - an adware program that displays pop-up advertising, runs at each system start and is installed as an Internet Explorer toolbar. - -==== ms-caro-malware-full:malware-family="ShopAtHome" - -ms-caro-malware-full:2009 - A browser redirector that monitors Web-browsing behavior and online purchases. It claims to track points for ShopAtHome rebates when the user buys products directly from affiliated merchant Web sites. - -==== ms-caro-malware-full:malware-family="FakeVimes" - -ms-caro-malware-full:2009 - a downloading component of Win32/FakeVimes - a family of programs that claims to scan for malware and displays fake warnings of 'malicious programs and viruses'. They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. - -==== ms-caro-malware-full:malware-family="FakeCog" - -ms-caro-malware-full:2009 - This threat claims to scan your PC for malware and then shows you fake warnings. They try to convince you to pay to register the software to remove the non-existent threats. - -==== ms-caro-malware-full:malware-family="FakeAdPro" - -ms-caro-malware-full:2009 - a program that may display false and misleading alerts regarding errors and malware to entice users to purchase it. - -==== ms-caro-malware-full:malware-family="FakeSmoke" - -ms-caro-malware-full:2009 - a family of trojans consisting of a fake Security Center interface and a fake antivirus program. - -==== ms-caro-malware-full:malware-family="FakeBye" - -ms-caro-malware-full:2009 - A rogue security software family that uses a Korean-language user interface. - -==== ms-caro-malware-full:malware-family="Hiloti" - -ms-caro-malware-full:2009 - a generic detection for a trojan that interferes with an affected user's browsing habits and downloads and executes arbitrary files. - -==== ms-caro-malware-full:malware-family="Tikayb" - -ms-caro-malware-full:2009 - A trojan that attempts to establish a secure network connection to various Web sites without the user’s consent. - -==== ms-caro-malware-full:malware-family="Ursnif" - -ms-caro-malware-full:2009 - A family of trojans that steals sensitive information from an affected computer - -==== ms-caro-malware-full:malware-family="Rimecud" - -ms-caro-malware-full:2009 - A family of worms with multiple components that spreads via fixed and removable drives and via instant messaging. It also contains backdoor functionality that allows unauthorized access to an affected system - -==== ms-caro-malware-full:malware-family="Lethic" - -ms-caro-malware-full:2009 - A trojan that connects to remote servers, which may lead to unauthorized access to an affected system. - -==== ms-caro-malware-full:malware-family="CeeInject" - -ms-caro-malware-full:2009 - This threat has been 'obfuscated', which means it has tried to hide its purpose so your security software doesn't detect it. The malware that lies underneath this obfuscation can have almost any purpose. - -==== ms-caro-malware-full:malware-family="Cmdow" - -ms-caro-malware-full:2009 - a detection for a command-line tool and violated the guidelines by which Microsoft identified unwanted software. - -==== ms-caro-malware-full:malware-family="Yabector" - -ms-caro-malware-full:2009 - This trojan can use your PC to click on online advertisements without your permission or knowledge. This can earn money for a malicious hacker by making a website or application appear more popular than it is. - -==== ms-caro-malware-full:malware-family="Renocide" - -ms-caro-malware-full:2009 - a family of worms that spread via local, removable, and network drives and also using file sharing applications. They have IRC-based backdoor functionality, which may allow a remote attacker to execute commands on the affected computer. - -==== ms-caro-malware-full:malware-family="Liften" - -ms-caro-malware-full:2009 - a trojan that is used to stop affected users from downloading security updates. It is downloaded by Trojan:Win32/FakeXPA. - -==== ms-caro-malware-full:malware-family="ShellCode" - -ms-caro-malware-full:2009 - A generic detection for JavaScript-enabled objects that contain exploit code and may exhibit suspicious behavior. Malicious websites and malformed PDF documents may contain JavaScript that attempts to execute code without the affected user's consent. - -==== ms-caro-malware-full:malware-family="FlyAgent" - -ms-caro-malware-full:2009 - A backdoor trojan program that is capable of performing several actions depending on the commands of a remote attacker. - -==== ms-caro-malware-full:malware-family="Psyme" - -ms-caro-malware-full:2009 - This threat downloads and installs other programs, including other malware, onto your PC without your consent. - -==== ms-caro-malware-full:malware-family="Orsam" - -ms-caro-malware-full:2009 - A generic detection for a variety of threats. A name used for trojans that have been added to MS signatures after advanced automated analysis. - -==== ms-caro-malware-full:malware-family="AgentOff" - -ms-caro-malware-full:2009 - This threat can perform a number of actions of a malicious hacker's choice on your PC. - -==== ms-caro-malware-full:malware-family="Nuj" - -ms-caro-malware-full:2009 - a worm that copies itself to fixed, removable or network drives. Some variants of this worm may also terminate antivirus-related processes. - -==== ms-caro-malware-full:malware-family="Sohanad" - -ms-caro-malware-full:2009 - Worms automatically spread to other PCs. They can do this in a number of ways, including by copying themselves to removable drives, network folders, or spreading through email. - -==== ms-caro-malware-full:malware-family="I2ISolutions" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.2037.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Dpoint" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.1915.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Silly_P2P" - -ms-caro-malware-full:2009 - Worms automatically spread to other PCs. They can do this in a number of ways, including by copying themselves to removable drives, network folders, or spreading through email. - -==== ms-caro-malware-full:malware-family="Vobfus" - -ms-caro-malware-full:2009 - This family of worms can download other malware onto your PC, including: Win32/Beebone, Win32/Fareit, Win32/Zbot. Vobfus worms can be downloaded by other malware or spread via removable drives, such as USB flash drives. - -==== ms-caro-malware-full:malware-family="Daurso" - -ms-caro-malware-full:2009 - a family of trojans that attempts to steal sensitive information, including passwords and FTP authentication details from affected computers. This family targets particular FTP applications and also attempts to steal data from Protected Storage. - -==== ms-caro-malware-full:malware-family="MyDealAssistant" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.2037.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Adsubscribe" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.1834.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="MyCentria" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.2037.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="Fierads" - -ms-caro-malware-full:2009 - This program was detected by definitions prior to 1.175.2037.0 as it violated the guidelines by which Microsoft identified unwanted software. Based on analysis using current guidelines, the program does not have unwanted behaviors. - -==== ms-caro-malware-full:malware-family="VBInject" - -ms-caro-malware-full:2009 - This is a generic detection for malicious files that are obfuscated using particular techniques to prevent their detection or analysis. - -==== ms-caro-malware-full:malware-family="PerfectKeylogger" - -ms-caro-malware-full:2009 - a commercial monitoring program that monitors user activity, such as keystrokes typed. MonitoringTool:Win32/PerfectKeylogger is available for purchase at the company's website. It may also have been installed without user consent by a Trojan or other malware. - -==== ms-caro-malware-full:malware-family="AgoBot" - -ms-caro-malware-full:2010 VOL09 - A backdoor that communicates with a central server using IRC. - -==== ms-caro-malware-full:malware-family="Bubnix" - -ms-caro-malware-full:2010 VOL09 - A generic detection for a kernel-mode driver installed by other malware that hides its presence on an affected computer by blocking registry and file access to itself. The trojan may report its installation to a remote server and download and distribute spam email messages and could download and execute arbitrary files. - -==== ms-caro-malware-full:malware-family="Citeary" - -ms-caro-malware-full:2010 VOL09 - A kernel mode driver installed by Win32/Citeary, a worm that spreads to all available drives including the local drive, installs device drivers and attempts to download other malware from a predefined website. - -==== ms-caro-malware-full:malware-family="Fakeinit" - -ms-caro-malware-full:2010 VOL09 - A rogue security software family distributed under the names Internet Security 2010, Security Essentials 2010, and others. - -==== ms-caro-malware-full:malware-family="Oficla" - -ms-caro-malware-full:2010 VOL09 - A family of trojans that attempt to inject code into running processes in order to download and execute arbitrary files. It may download rogue security programs. - -==== ms-caro-malware-full:malware-family="Pasur" - -ms-caro-malware-full:2010 VOL09 - a name used for backdoor trojan detections that have been added to Microsoft signatures after advanced automated analysis. - -==== ms-caro-malware-full:malware-family="PrettyPark" - -ms-caro-malware-full:2010 VOL09 - A worm that spreads via email attachments. It allows backdoor access and control of an infected computer. - -==== ms-caro-malware-full:malware-family="Prorat" - -ms-caro-malware-full:2010 VOL09 - A trojan that opens random ports that allow remote access from an attacker to the affected computer. This backdoor may download and execute other malware from predefined websites and may terminate several security applications or services. - -==== ms-caro-malware-full:malware-family="Pushbot" - -ms-caro-malware-full:2010 VOL09 - A detection for a family of malware that spreads via MSN Messenger, Yahoo! Messenger, and AIM when commanded by a remote attacker. It contains backdoor functionality that allows unauthorized access and control of an affected machine. - -==== ms-caro-malware-full:malware-family="Randex" - -ms-caro-malware-full:2010 VOL09 - A worm that scans randomly generated IP addresses to attempt to spread to network shares with weak passwords. After the worm infects a computer, it connects to an IRC server to receive commands from the attacker. - -==== ms-caro-malware-full:malware-family="SDBot" - -ms-caro-malware-full:2010 VOL09 - A family of backdoor trojans that allows attackers to control infected computers over an IRC channel. - -==== ms-caro-malware-full:malware-family="Trenk" - -ms-caro-malware-full:2010 VOL09 - a name used for backdoor trojan detections that have been added to Microsoft signatures after advanced automated analysis. - -==== ms-caro-malware-full:malware-family="Tofsee" - -ms-caro-malware-full:2010 VOL09 - A multi-component family of backdoor trojans that act as a spam and traffic relay. - -==== ms-caro-malware-full:malware-family="Ursap" - -ms-caro-malware-full:2010 VOL09 - a name used for backdoor trojan detections that have been added to Microsoft signatures after advanced automated analysis. - -==== ms-caro-malware-full:malware-family="Zbot" - -ms-caro-malware-full:2010 VOL09 - A family of password stealing trojans that also contains backdoor functionality allowing unauthorized access and control of an affected machine. - -==== ms-caro-malware-full:malware-family="Ciucio" - -ms-caro-malware-full:2010 VOL10 - A family of trojans that connect to certain websites in order to download arbitrary files. - -==== ms-caro-malware-full:malware-family="ClickPotato" - -ms-caro-malware-full:2010 VOL10 - A program that displays popup and notification-style advertisements based on the user’s browsing habits. - -==== ms-caro-malware-full:malware-family="CVE-2010-0806" - -ms-caro-malware-full:2010 VOL10 - A detection for malicious JavaScript that attempts to exploit the vulnerability addressed by Microsoft Security Bulletin MS10-018. - -==== ms-caro-malware-full:malware-family="Delf" - -ms-caro-malware-full:2010 VOL10 - A detection for various threats written in the Delphi programming language. The behaviors displayed by this malware family are highly variable. - -==== ms-caro-malware-full:malware-family="FakePAV" - -ms-caro-malware-full:2010 VOL10 - A rogue security software family that masquerades as Microsoft Security Essentials. - -==== ms-caro-malware-full:malware-family="Keygen" - -ms-caro-malware-full:2010 VOL10 - A generic detection for tools that generate product keys for illegally obtained versions of various software products. - -==== ms-caro-malware-full:malware-family="Onescan" - -ms-caro-malware-full:2010 VOL10 - A Korean-language rogue security software family distributed under the names One Scan, Siren114, EnPrivacy, PC Trouble, My Vaccine, and others. - -==== ms-caro-malware-full:malware-family="Pornpop" - -ms-caro-malware-full:2010 VOL10 - A generic detection for specially-crafted JavaScript-enabled objects that attempt to display pop-under advertisements, usually with adult content. - -==== ms-caro-malware-full:malware-family="Startpage" - -ms-caro-malware-full:2010 VOL10 - A detection for various threats that change the configured start page of the affected user’s web browser, and may also perform other malicious actions. - -==== ms-caro-malware-full:malware-family="Begseabug" - -ms-caro-malware-full:2011 VOL11 - A trojan that downloads and executes arbitrary files on an affected computer. - -==== ms-caro-malware-full:malware-family="CVE-2010-0840" - -ms-caro-malware-full:2011 VOL11 - A detection for a malicious and obfuscated Java class that exploits a vulnerability described in CVE-2010-0840. Oracle Corporation addressed the vulnerability with a security update in March 2010. - -==== ms-caro-malware-full:malware-family="Cycbot" - -ms-caro-malware-full:2011 VOL11 - A backdoor trojan that allows attackers unauthorized access and control of an affected computer. After a computer is infected, the trojan connects to a specific remote server to receive commands from attackers. - -==== ms-caro-malware-full:malware-family="DroidDream" - -ms-caro-malware-full:2011 VOL11 - A malicious program that affects mobile devices running the Android operating system. It may be bundled with clean applications, and is capable of allowing a remote attacker to gain access to the mobile device. - -==== ms-caro-malware-full:malware-family="FakeMacdef" - -ms-caro-malware-full:2011 VOL11 - A rogue security software family that affects Apple Mac OS X. It has been distributed under the names MacDefender, MacSecurity, MacProtector, and possibly others. - -==== ms-caro-malware-full:malware-family="GameHack" - -ms-caro-malware-full:2011 VOL11 - Malware that is often bundled with game applications. It commonly displays unwanted pop-up advertisements and may be installed as a web browser helper object. - -==== ms-caro-malware-full:malware-family="Loic" - -ms-caro-malware-full:2011 VOL11 - An open-source network attack tool designed to perform denial-ofservice (DoS) attacks. - -==== ms-caro-malware-full:malware-family="Lotoor" - -ms-caro-malware-full:2011 VOL11 - A detection for specially crafted Android programs that attempt to exploit vulnerabilities in the Android operating system to gain root privilege. - -==== ms-caro-malware-full:malware-family="Nuqel" - -ms-caro-malware-full:2011 VOL11 - A worm that spreads via mapped drives and certain instant messaging applications. It may modify system settings, connect to certain websites, download arbitrary files, or take other malicious actions. - -==== ms-caro-malware-full:malware-family="OfferBox" - -ms-caro-malware-full:2011 VOL11 - A program that displays offers based on the user's web browsing habits. Some versions may display advertisements in a pop-under window. Win32/OfferBox may be installed without adequate user consent by malware. - -==== ms-caro-malware-full:malware-family="OpenCandy" - -ms-caro-malware-full:2011 VOL11 - An adware program that may be bundled with certain thirdparty software installation programs. Some versions may send user-specific information, including a unique machine code, operating system information, locale, and certain other information to a remote server without obtaining adequate user consent. - -==== ms-caro-malware-full:malware-family="Pameseg" - -ms-caro-malware-full:2011 VOL11 - A fake program installer that requires the user to send SMS messages to a premium number to successfully install certain programs. - -==== ms-caro-malware-full:malware-family="Pramro" - -ms-caro-malware-full:2011 VOL11 - A trojan that creates a proxy on the infected computer for email and HTTP traffic, and is used to send spam email. - -==== ms-caro-malware-full:malware-family="Ramnit" - -ms-caro-malware-full:2011 VOL11 - A family of multi-component malware that infects executable files, Microsoft Office files, and HTML files. Win32/Ramnit spreads to removable drives and steals sensitive information such as saved FTP credentials and browser cookies. It may also open a backdoor to await instructions from a remote attacker. - -==== ms-caro-malware-full:malware-family="Rlsloup" - -ms-caro-malware-full:2011 VOL11 - A family of trojans that are used to send spam email. Rlsloup consists of several components, including an installation trojan component and a spamming payload component. - -==== ms-caro-malware-full:malware-family="ShopperReports" - -ms-caro-malware-full:2011 VOL11 - Adware that displays targeted advertising to affected users while browsing the Internet, based on search terms entered into search engines. - -==== ms-caro-malware-full:malware-family="Sinowal" - -ms-caro-malware-full:2011 VOL11 - A family of password-stealing and backdoor trojans. It may try to install a fraudulent SSL certificate on the computer. Sinowal may also capture user data such as banking credentials from various user accounts and send the data to Web sites specified by the attacker. - -==== ms-caro-malware-full:malware-family="Stuxnet" - -ms-caro-malware-full:2011 VOL11 - A multi-component family that spreads via removable volumes by exploiting the vulnerability addressed by Microsoft Security Bulletin MS10-046. - -==== ms-caro-malware-full:malware-family="Swimnag" - -ms-caro-malware-full:2011 VOL11 - A worm that spreads via removable drives and drops a randomly-named DLL in the Windows system folder. - -==== ms-caro-malware-full:malware-family="Tedroo" - -ms-caro-malware-full:2011 VOL11 - A trojan that sends spam email messages. Some variants may disable certain Windows services or allow backdoor access by a remote attacker. - -==== ms-caro-malware-full:malware-family="Yimfoca" - -ms-caro-malware-full:2011 VOL11 - A worm family that spreads via common instant messaging applications and social networking sites. It is capable of connecting to a remote HTTP or IRC server to receive updated configuration data. It also modifies certain system and security settings. - -==== ms-caro-malware-full:malware-family="Bamital" - -ms-caro-malware-full:2011 VOL12 - A family of malware that intercepts web browser traffic and prevents access to specific security-related websites by modifying the Hosts file. Bamital variants may also modify specific legitimate Windows files in order to execute their payload. - -==== ms-caro-malware-full:malware-family="Blacole" - -ms-caro-malware-full:2011 VOL12 - An exploit pack, also known as Blackhole, that is installed on a compromised web server by an attacker and includes a number of exploits that target browser software. If a vulnerable computer browses a compromised website containing the exploit pack, various malware may be downloaded and run. - -==== ms-caro-malware-full:malware-family="Bulilit" - -ms-caro-malware-full:2011 VOL12 - A trojan that silently downloads and installs other programs without consent. Infection could involve the installation of additional malware or malware components to an affected computer. - -==== ms-caro-malware-full:malware-family="Dorkbot" - -ms-caro-malware-full:2011 VOL12 - A worm that spreads via instant messaging and removable drives. It also contains backdoor functionality that allows unauthorized access and control of the affected computer. Win32/Dorkbot may be distributed from compromised or malicious websites using PDF or browser exploits. - -==== ms-caro-malware-full:malware-family="EyeStye" - -ms-caro-malware-full:2011 VOL12 - A trojan that attempts to steal sensitive data using a method known as form grabbing, and sends it to a remote attacker. It may also download and execute arbitary files and use a rootkit component to hide its activities. - -==== ms-caro-malware-full:malware-family="FakeSysdef" - -ms-caro-malware-full:2011 VOL12 - A rogue security software family that claims to discover nonexistent hardware defects related to system memory, hard drives, and overall system performance, and charges a fee to fix the supposed problems. - -==== ms-caro-malware-full:malware-family="Helompy" - -ms-caro-malware-full:2011 VOL12 - A worm that spreads via removable drives and attempts to capture and steal authentication details for a number of different websites or online services, including Facebook and Gmail. - -==== ms-caro-malware-full:malware-family="Malf" - -ms-caro-malware-full:2011 VOL12 - A generic detection for malware that drops additional malicious files. - -==== ms-caro-malware-full:malware-family="Rugo" - -ms-caro-malware-full:2011 VOL12 - A program that installs silently on the user’s computer and displays advertisements. - -==== ms-caro-malware-full:malware-family="Sirefef" - -ms-caro-malware-full:2011 VOL12 - A rogue security software family distributed under the name Antivirus 2010 and others. - -==== ms-caro-malware-full:malware-family="Sisproc" - -ms-caro-malware-full:2011 VOL12 - A generic detection for a group of trojans that have been observed to perform a number of various and common malware behaviors. - -==== ms-caro-malware-full:malware-family="Swisyn" - -ms-caro-malware-full:2011 VOL12 - A trojan that drops and executes arbitrary files on an infected computer. The dropped files may be potentially unwanted or malicious programs. - -==== ms-caro-malware-full:malware-family="BlacoleRef" - -ms-caro-malware-full:2012 VOL13 - An obfuscated script, often found inserted into compromised websites, that uses a hidden inline frame to redirect the browser to a Blacole exploit server. - -==== ms-caro-malware-full:malware-family="CVE-2012-0507" - -ms-caro-malware-full:2012 VOL13 - A detection for a malicious Java applet that exploits the Java Runtime Environment (JRE) vulnerability described in CVE-2012-0507, addressed by an Oracle security update in February 2012. - -==== ms-caro-malware-full:malware-family="Flashback" - -ms-caro-malware-full:2012 VOL13 - A trojan that targets Java JRE vulnerability CVE-2012-0507 on Mac OS X to enroll the infected computer in a botnet. - -==== ms-caro-malware-full:malware-family="Gendows" - -ms-caro-malware-full:2012 VOL13 - A tool that attempts to activate Windows 7 and Windows Vista operating system installations. - -==== ms-caro-malware-full:malware-family="GingerBreak" - -ms-caro-malware-full:2012 VOL13 - A program that affects mobile devices running the Android operating system. It drops and executes an exploit that, if run successfully, gains administrator privileges on the device. - -==== ms-caro-malware-full:malware-family="GingerMaster" - -ms-caro-malware-full:2012 VOL13 - A malicious program that affects mobile devices running the Android operating system. It may be bundled with clean applications, and is capable of allowing a remote attacker to gain access to the mobile device. - -==== ms-caro-malware-full:malware-family="Mult" - -ms-caro-malware-full:2012 VOL13 - A generic detection for various exploits written in the JavaScript language. - -==== ms-caro-malware-full:malware-family="Patch" - -ms-caro-malware-full:2012 VOL13 - A family of tools intended to modify, or 'patch' programs that may be evaluation copies, or unregistered versions with limited features for the purpose of removing the limitations. - -==== ms-caro-malware-full:malware-family="Phoex" - -ms-caro-malware-full:2012 VOL13 - A malicious script that exploits the Java Runtime Environment (JRE) vulnerability discussed in CVE-2010-4452. If run in a computer running a vulnerable version of Java, it downloads and executes arbitrary files. - -==== ms-caro-malware-full:malware-family="Pluzoks" - -ms-caro-malware-full:2012 VOL13 - A trojan that silently downloads and installs other programs without consent. This could include the installation of additional malware or malware components. - -==== ms-caro-malware-full:malware-family="Popupper" - -ms-caro-malware-full:2012 VOL13 - A detection for a particular JavaScript script that attempts to display pop-under advertisements. - -==== ms-caro-malware-full:malware-family="Wizpop" - -ms-caro-malware-full:2012 VOL13 - Adware that may track user search habits and download executable programs without user consent. - -==== ms-caro-malware-full:malware-family="Wpakill" - -ms-caro-malware-full:2012 VOL13 - A family of tools that attempt to disable or bypass WPA (Windows Product Activation), WGA (Windows Genuine Advantage) checks, or WAT (Windows Activation Technologies), by altering Windows operating system files, terminating processes, or stopping services. - -==== ms-caro-malware-full:malware-family="Yeltminky" - -ms-caro-malware-full:2012 VOL13 - A family of worms that spreads by making copies of itself on all available drives and creating an autorun.inf file to execute that copy. - -==== ms-caro-malware-full:malware-family="Aimesu" - -ms-caro-malware-full:2013 VOL15 - A threat that exploits vulnerabilities in unpatched versions of Java, Adobe Reader, or Flash Player. It then installs other malare on the computer, including components of the Blackhole and Cool exploit kits. - -==== ms-caro-malware-full:malware-family="Bdaejec" - -ms-caro-malware-full:2013 VOL15 - A trojan that allows unauthorized access and control of an affected computer, and that may download and install other programs without consent. - -==== ms-caro-malware-full:malware-family="Bursted" - -ms-caro-malware-full:2013 VOL15 - A virus written in the AutoLISP scripting language used by the AutoCAD computer-aided design program. It infects other AutoLISP files with the extension .lsp. - -==== ms-caro-malware-full:malware-family="Colkit" - -ms-caro-malware-full:2013 VOL15 - A detection for obfuscated, malicious JavaScript code that redirects to or loads files that may exploit a vulnerable version of Java, Adobe Reader, or Adobe Flash, possibly in an attempt to load malware onto the computer. - -==== ms-caro-malware-full:malware-family="Coolex" - -ms-caro-malware-full:2013 VOL15 - A detection for scripts from an exploit pack known as the Cool Exploit Kit. These scripts are often used in ransomware schemes in which an attacker locks a victim’s computer or encrypts the user’s data and demands money to make it available again. - -==== ms-caro-malware-full:malware-family="CplLnk" - -ms-caro-malware-full:2013 VOL15 - A generic detection for specially crafted malicious shortcut files that attempt to exploit the vulnerability addressed by Microsoft Security Bulletin MS10-046, CVE-2010-2568. - -==== ms-caro-malware-full:malware-family="CVE-2011-1823" - -ms-caro-malware-full:2013 VOL15 - A detection for specially crafted Android programs that attempt to exploit a vulnerability in the Android operating system to gain root privilege. - -==== ms-caro-malware-full:malware-family="CVE-2012-1723" - -ms-caro-malware-full:2013 VOL15 - A family of malicious Java applets that attempt to exploit vulnerability CVE-2012-1723 in the Java Runtime Environment (JRE) to download and install files of an attacker’s choice onto the computer. - -==== ms-caro-malware-full:malware-family="DealPly" - -ms-caro-malware-full:2013 VOL15 - Adware that displays offers related to the user’s web browsing habits. It may be bundled with certain third-party software installation programs. - -==== ms-caro-malware-full:malware-family="Fareit" - -ms-caro-malware-full:2013 VOL15 - A malware family that has multiple components: a password stealing component that steals sensitive information and sends it to an attacker, and a DDoS component that could be used against other computers. - -==== ms-caro-malware-full:malware-family="FastSaveApp" - -ms-caro-malware-full:2013 VOL15 - An adware program that displays offers related to the user's web browsing habits. It may use the name 'SaveAs' or 'SaveByClick'. - -==== ms-caro-malware-full:malware-family="FindLyrics" - -ms-caro-malware-full:2013 VOL15 - An adware program that displays ads related to the user's web browsing habits. - -==== ms-caro-malware-full:malware-family="Gamarue" - -ms-caro-malware-full:2013 VOL15 - A worm that is commonly distributed via exploit kits and social engineering. Variants have been observed stealing information from the local computer and communicating with command-and-control (C&C) servers managed by attackers. - -==== ms-caro-malware-full:malware-family="Gisav" - -ms-caro-malware-full:2013 VOL15 - An adware program that displays offers related to the user's web browsing habits. It can be downloaded from the program's website, and can be bundled with some third-party software installation programs. - -==== ms-caro-malware-full:malware-family="InfoAtoms" - -ms-caro-malware-full:2013 VOL15 - An adware program that displays advertisements related to the user's web browsing habits and inserts advertisements into websites. - -==== ms-caro-malware-full:malware-family="Perl/IRCbot.E" - -ms-caro-malware-full:2013 VOL15 - A backdoor trojan that drops other malicious software and connects to IRC servers to receive commands from attackers. - -==== ms-caro-malware-full:malware-family="Javrobat" - -ms-caro-malware-full:2013 VOL15 - An exploit that tries to check whether certain versions of Adobe Acrobat or Adobe Reader are installed on the computer. If so, it tries to install malware. - -==== ms-caro-malware-full:malware-family="Kraddare" - -ms-caro-malware-full:2013 VOL15 - Adware that displays Korean-language advertisements. - -==== ms-caro-malware-full:malware-family="PriceGong" - -ms-caro-malware-full:2013 VOL15 - An adware program that shows certain deals related to the search terms entered on any web page. - -==== ms-caro-malware-full:malware-family="Protlerdob" - -ms-caro-malware-full:2013 VOL15 - A software installer with a Portuguese language user interface. It presents itself as a free movie download but bundles with it a number of programs that may charge for services. - -==== ms-caro-malware-full:malware-family="Qhost" - -ms-caro-malware-full:2013 VOL15 - A generic detection for trojans that modify the HOSTS file on the computer to redirect or limit Internet traffic to certain sites. - -==== ms-caro-malware-full:malware-family="Reveton" - -ms-caro-malware-full:2013 VOL15 - A ransomware family that targets users from certain countries or regions. It locks the computer and displays a location-specific webpage that covers the desktop and demands that the user pay a fine for the supposed possession of illicit material. - -==== ms-caro-malware-full:malware-family="Rongvhin" - -ms-caro-malware-full:2013 VOL15 - A family of malware that perpetrates click fraud. It might be delivered to the computer via hack tools for the game CrossFire. - -==== ms-caro-malware-full:malware-family="Seedabutor" - -ms-caro-malware-full:2013 VOL15 - A JavaScript trojan that attempts to redirect the browser to another website. - -==== ms-caro-malware-full:malware-family="SMSer" - -ms-caro-malware-full:2013 VOL15 - A ransomware trojan that locks an affected user’s computer and requests that the user send a text message to a premium-charge number to unlock it. - -==== ms-caro-malware-full:malware-family="Tobfy" - -ms-caro-malware-full:2013 VOL15 - A family of ransomware trojans that targets users from certain countries. It locks the computer and displays a localized message demanding the payment of a fine for the supposed possession of illicit material. Some variants may also take webcam screenshots, play audio messages, or affect certain processes or drivers. - -==== ms-caro-malware-full:malware-family="Truado" - -ms-caro-malware-full:2013 VOL15 - A trojan that poses as an update for certain Adobe software. - -==== ms-caro-malware-full:malware-family="Urausy" - -ms-caro-malware-full:2013 VOL15 - A family of ransomware trojans that locks the computer and displays a localized message, supposedly from police authorities, demanding the payment of a fine for alleged criminal activity. - -==== ms-caro-malware-full:malware-family="Wecykler" - -ms-caro-malware-full:2013 VOL15 - A family of worms that spread via removable drives, such as USB drives, that may stop security processes and other processes on the computer, and log keystrokes that are later sent to a remote attacker. - -==== ms-caro-malware-full:malware-family="Weelsof" - -ms-caro-malware-full:2013 VOL15 - A family of ransomware trojans that targets users from certain countries. It locks the computer and displays a localized message demanding the payment of a fine for the alleged possession of illicit material. Some variants may take steps that make it difficult to run or update virus protection. - -==== ms-caro-malware-full:malware-family="Yakdowpe" - -ms-caro-malware-full:2013 VOL15 - A family of trojans that connect to certain websites to silently download and install other programs without consent. - -==== ms-caro-malware-full:malware-family="Anogre" - -ms-caro-malware-full:2013 VOL16 - A threat that exploits a vulnerability addressed by Microsoft Security Bulletin MS11-087. This vulnerability can allow a hacker to install programs, view, change, or delete data or create new accounts with full administrative privileges. - -==== ms-caro-malware-full:malware-family="Brantall" - -ms-caro-malware-full:2013 VOL16 - A family of trojans that download and install other programs, including Win32/Sefnit and Win32/Rotbrow. Brantall often pretends to be an installer for other, legitimate programs. - -==== ms-caro-malware-full:malware-family="Comame" - -ms-caro-malware-full:2013 VOL16 - A generic detection for a variety of threats. - -==== ms-caro-malware-full:malware-family="Crilock" - -ms-caro-malware-full:2013 VOL16 - A ransomware family that encrypts the computer's files and displays a webpage that demands a fee to unlock them. - -==== ms-caro-malware-full:malware-family="CVE-2011-3874" - -ms-caro-malware-full:2013 VOL16 - A threat that attempts to exploit a vulnerability in the Android operating system to gain access to and control of the device Java/CVE-2012-1723. A family of malicious Java applets that attempt to exploit vulnerability CVE-2012-1723 in the Java Runtime Environment (JRE) in order to download and install files of an attacker’s choice onto the computer. - -==== ms-caro-malware-full:malware-family="Deminnix" - -ms-caro-malware-full:2013 VOL16 - A trojan that uses the computer for Bitcoin mining and changes the home page of the web browser. It can accidentally be downloaded along with other files from torrent sites. - -==== ms-caro-malware-full:malware-family="Detplock" - -ms-caro-malware-full:2013 VOL16 - A generic detection for a variety of threats. - -==== ms-caro-malware-full:malware-family="Dircrypt" - -ms-caro-malware-full:2013 VOL16 - Ransomware that encrypts the user's files and demands payment to release them. It is distributed through spam email messages and can be downloaded by other malware. - -==== ms-caro-malware-full:malware-family="DonxRef" - -ms-caro-malware-full:2013 VOL16 - A generic detection for malicious JavaScript objects that construct shellcode. The scripts may try to exploit vulnerabilities in Java, Adobe Flash Player, and Windows. - -==== ms-caro-malware-full:malware-family="Faceliker" - -ms-caro-malware-full:2013 VOL16 - A malicious script that likes content on Facebook without the user's knowledge or consent. - -==== ms-caro-malware-full:malware-family="FakeAlert" - -ms-caro-malware-full:2013 VOL16 - A malicious script that falsely claims that the computer is infected with viruses and that additional software is needed to disinfect it. - -==== ms-caro-malware-full:malware-family="Jenxcus" - -ms-caro-malware-full:2013 VOL16 - A worm that gives an attacker control of the computer. It is spread by infected removable drives, like USB flash drives. It can also be downloaded within a torrent file. - -==== ms-caro-malware-full:malware-family="Loktrom" - -ms-caro-malware-full:2013 VOL16 - Ransomware that locks the computer and displays a full-screen message pretending to be from a national police force, demanding payment to unlock the computer. - -==== ms-caro-malware-full:malware-family="Miposa" - -ms-caro-malware-full:2013 VOL16 - A trojan that downloads and runs malicious Windows Scripting Host (.wsh) files. - -==== ms-caro-malware-full:malware-family="Nitol" - -ms-caro-malware-full:2013 VOL16 - A family of trojans that perform DDoS (distributed denial of service) attacks, allow backdoor access and control, download and run files, and perform a number of other malicious activities on the computer. - -==== ms-caro-malware-full:malware-family="Oceanmug" - -ms-caro-malware-full:2013 VOL16 - A trojan that silently downloads and installs other programs without consent. - -==== ms-caro-malware-full:malware-family="Proslikefan" - -ms-caro-malware-full:2013 VOL16 - A worm that spreads through removable drives, network shares, and P2P programs. It can lower the computer's security settings and disable antivirus products. - -==== ms-caro-malware-full:malware-family="Rotbrow" - -ms-caro-malware-full:2013 VOL16 - A trojan that installs browser add-ons that claim to offer protection from other add-ons. Rotbrow can change the browser's home page, and can install the trojan Win32/Sefnit. It is commonly installed by Win32/Brantall. - -==== ms-caro-malware-full:malware-family="Sefnit" - -ms-caro-malware-full:2013 VOL16 - A family of trojans that can allow backdoor access, download files, and use the computer and Internet connection for click fraud. Some variants can monitor web browsers and hijack search results. - -==== ms-caro-malware-full:malware-family="Urntone" - -ms-caro-malware-full:2013 VOL16 - A webpage component of the Neutrino exploit kit. It checks the version numbers of popular applications installed on the computer, and attempts to install malware that targets vulnerabilities in the software. - -==== ms-caro-malware-full:malware-family="Wysotot" - -ms-caro-malware-full:2013 VOL16 - A threat that can change the start page of the user's web browser, and may download and install other files to the computer. It is installed by software bundlers that advertise free software or games. - -==== ms-caro-malware-full:malware-family="AddLyrics" - -ms-caro-malware-full:2014 VOL17 - A browser add-on that displays lyrics for songs on YouTube, and displays advertisements in the browser window. - -==== ms-caro-malware-full:malware-family="Adpeak" - -ms-caro-malware-full:2014 VOL17 - Adware that displays extra ads as the user browses the Internet, without revealing where the ads are coming from. It may be bundled with some third-party software installation programs. - -==== ms-caro-malware-full:malware-family="Axpergle" - -ms-caro-malware-full:2014 VOL17 - A detection for the Angler exploit kit, which exploits vulnerabilities in recent versions of Internet Explorer, Silverlight, Adobe Flash Player, and Java to install malware. - -==== ms-caro-malware-full:malware-family="Bepush" - -ms-caro-malware-full:2014 VOL17 - A family of trojans that download and install add-ons for the Firefox and Chrome browsers that post malicious links to social networking sites, track browser usage, and redirect the browser to specific websites. - -==== ms-caro-malware-full:malware-family="BetterSurf" - -ms-caro-malware-full:2014 VOL17 - Adware that displays unwanted ads on search engine results pages and other websites. It may be included with software bundles that offer free applications or games. - -==== ms-caro-malware-full:malware-family="Bladabindi" - -ms-caro-malware-full:2014 VOL17 - A family of backdoors created by a malicious hacker tool called NJ Rat. They can steal sensitive information, download other malware, and allow backdoor access to an infected computer. - -==== ms-caro-malware-full:malware-family="Caphaw" - -ms-caro-malware-full:2014 VOL17 - A family of backdoors that spread via Facebook, YouTube, Skype, removable drives, and drive-by download. They can make Facebook posts via the user's account, and may steal online banking details. - -==== ms-caro-malware-full:malware-family="Clikug" - -ms-caro-malware-full:2014 VOL17 - A threat that uses a computer for click fraud. It has been observed using as much as a gigabyte of bandwidth per hour. - -==== ms-caro-malware-full:malware-family="CVE-2014-0322" - -ms-caro-malware-full:This threat uses a vulnerability MS14-012, CVE-2014-0322 in Internet Explorer 9 and 10 to download and run files on your PC, including other malware. - -==== ms-caro-malware-full:malware-family="CVE-2013-0422" - -ms-caro-malware-full:2014 VOL17 - A detection for a malicious Java applet that exploits the Java Runtime Environment (JRE) vulnerability described in CVE-2013-0422, addressed by an Oracle security update in January 2013. - -==== ms-caro-malware-full:malware-family="Dowque" - -ms-caro-malware-full:2014 VOL17 - A generic detection for malicious files that are capable of installing other malware. - -==== ms-caro-malware-full:malware-family="Fashack" - -ms-caro-malware-full:2014 VOL17 - A detection for the Safehack exploit kit, also known as Flashpack. It uses vulnerabilities in Adobe Flash Player, Java, and Silverlight to install malware on a computer. - -==== ms-caro-malware-full:malware-family="Feven" - -ms-caro-malware-full:2014 VOL17 - A browser add-on for Internet Explorer, Firefox, or Chrome that displays ads on search engine results pages and other websites, and redirects the browser to specific websites. - -==== ms-caro-malware-full:malware-family="Fiexp" - -ms-caro-malware-full:2014 VOL17 - A detection for the Fiesta exploit kit, which attempts to exploit Java, Adobe Flash Player, Adobe Reader, Silverlight, and Internet Explorer to install malware. - -==== ms-caro-malware-full:malware-family="Filcout" - -ms-caro-malware-full:2014 VOL17 - An application that offers to locate and download programs to run unknown files. It has been observed installing variants in the Win32/Sefnit family. - -==== ms-caro-malware-full:malware-family="Genasom" - -ms-caro-malware-full:2014 VOL17 - A ransomware family that locks a computer and demands money to unlock it. It usually targets Russian-language users, and may open pornographic websites. - -==== ms-caro-malware-full:malware-family="Kegotip" - -ms-caro-malware-full:2014 VOL17 - A password-stealing trojan that can steal email addresses, personal information, or user account information for certain programs. - -==== ms-caro-malware-full:malware-family="Krypterade" - -ms-caro-malware-full:2014 VOL17 - Ransomware that fraudulently claims a computer has been used for unlawful activity, locks it, and demands that the user pay to unlock it. - -==== ms-caro-malware-full:malware-family="Lecpetex" - -ms-caro-malware-full:2014 VOL17 - A family of trojans that steal sensitive information, such as user names and passwords. It can also use a computer for Litecoin mining, install other malware, and post malicious content via the user's Facebook account. - -==== ms-caro-malware-full:malware-family="Lollipop" - -ms-caro-malware-full:2014 VOL17 - Adware that may be installed by third-party software bundlers. It displays ads based on search engine searches, which can differ by geographic location and may be pornographic. - -==== ms-caro-malware-full:malware-family="Meadgive" - -ms-caro-malware-full:2014 VOL17 - A detection for the Redkit exploit kit, also known as Infinity and Goon. It attempts to exploit vulnerabilities in programs such as Java and Silverlight to install other malware. - -==== ms-caro-malware-full:malware-family="Neclu" - -ms-caro-malware-full:2014 VOL17 - A detection for the Nuclear exploit kit, which attempts to exploit vulnerabilities in programs such as Java and Adobe Reader to install other malware. - -==== ms-caro-malware-full:malware-family="Ogimant" - -ms-caro-malware-full:2014 VOL17 - A threat that claims to help download items from the Internet, but actually downloads and runs files that are specified by a remote attacker. - -==== ms-caro-malware-full:malware-family="OptimizerElite" - -ms-caro-malware-full:2014 VOL17 - A misleading program that uses legitimate files in the Prefetch folder to claim that the computer is damaged, and offers to fix the damage for a price. - -==== ms-caro-malware-full:malware-family="Pangimop" - -ms-caro-malware-full:2014 VOL17 - A detection for the Magnitude exploit kit, also known as Popads. It attempts to exploit vulnerabilities in programs such as Java and Adobe Flash Player to install other malware. - -==== ms-caro-malware-full:malware-family="Phish" - -ms-caro-malware-full:2014 VOL17 - A password-stealing malicious webpage, known as a phishing page, that disguises itself as a page from a legitimate website. - -==== ms-caro-malware-full:malware-family="Prast" - -ms-caro-malware-full:2014 VOL17 - A generic detection for various password stealing trojans. - -==== ms-caro-malware-full:malware-family="Slugin" - -ms-caro-malware-full:2014 VOL17 - A file infector that infects .exe and .dll files. It may also perform backdoor actions. - -==== ms-caro-malware-full:malware-family="Spacekito" - -ms-caro-malware-full:2014 VOL17 - A threat that steals information about the computer and installs browser add-ons that display ads. - -==== ms-caro-malware-full:malware-family="Tranikpik" - -ms-caro-malware-full:This threat is a backdoor that can give a hacker unauthorized access and control of your PC - -==== ms-caro-malware-full:malware-family="Wordinvop" - -ms-caro-malware-full:2014 VOL17 - A detection for a specially-crafted Microsoft Word file that attempts to exploit the vulnerability CVE-2006-6456, addressed by Microsoft Security Bulletin MS07-014. - -==== ms-caro-malware-full:malware-family="Zegost" - -ms-caro-malware-full:2014 VOL17 - A backdoor that allows an attacker to remotely access and control a computer. - -==== ms-caro-malware-full:malware-family="Archost" - -ms-caro-malware-full:2014 VOL18 - A downloader that installs other programs on the computer without the user's consent, including other malware. - -==== ms-caro-malware-full:malware-family="Balamid" - -ms-caro-malware-full:2014 VOL18 - A trojan that can use the computer to click on online advertisements without the user's permission or knowledge. This can earn money for a malicious hacker by making a website or application appear more popular than it is. - -==== ms-caro-malware-full:malware-family="BeeVry" - -ms-caro-malware-full:2014 VOL18 - A trojan that modifies a number of settings to prevent the computer from accessing security-related websites, and lower the computer's security. - -==== ms-caro-malware-full:malware-family="Bondat" - -ms-caro-malware-full:2014 VOL18 - A family of threats that collects information about the computer, infects removable drives, and tries to stop the user from accessing files. It spreads by infecting removable drives, such as USB thumb drives and flash drives. - -==== ms-caro-malware-full:malware-family="Bregent" - -ms-caro-malware-full:2014 VOL18 - A downloader that injects malicious code into legitimate processes such as explorer.exe and svchost.exe, and downloads other malware onto the computer. - -==== ms-caro-malware-full:malware-family="Brolo" - -ms-caro-malware-full:2014 VOL18 - A ransomware family that locks the web browser and displays a message, often pretending to be from a law enforcement agency, demanding money to unlock the browser. - -==== ms-caro-malware-full:malware-family="CostMin" - -ms-caro-malware-full:2014 VOL18 - An adware family that installs itself as a browser extension for Internet Explorer, Mozilla Firefox, and Google Chrome, and displays advertisements as the user browses the Internet. - -==== ms-caro-malware-full:malware-family="CouponRuc" - -ms-caro-malware-full:2014 VOL18 - A browser modifier that changes browser settings and may also modify some computer and Internet settings. - -==== ms-caro-malware-full:malware-family="Crastic" - -ms-caro-malware-full:2014 VOL18 - A trojan that sends sensitive information to a remote attacker, such as user names, passwords and information about the computer. It can also delete System Restore points, making it harder to recover the computer to a pre-infected state. - -==== ms-caro-malware-full:malware-family="Crowti" - -ms-caro-malware-full:2014 VOL18 - A ransomware family that encrypts files on the computer and demands that the user pay a fee to decrypt them, using Bitcoins. - -==== ms-caro-malware-full:malware-family="CVE-2013-1488" - -ms-caro-malware-full:2014 VOL18 - A detection for threats that use a Java vulnerability to download and run files on your PC, including other malware. Oracle addressed the vulnerability with a security update in April 2013. - -==== ms-caro-malware-full:malware-family="DefaultTab" - -ms-caro-malware-full:2014 VOL18 - A browser modifier that redirects web browser searches and prevents the user from changing browser settings. - -==== ms-caro-malware-full:malware-family="Ippedo" - -ms-caro-malware-full:2014 VOL18 - A worm that can send sensitive information to a malicious hacker. It spreads through infected removable drives, such as USB flash drives. - -==== ms-caro-malware-full:malware-family="Kilim" - -ms-caro-malware-full:2014 VOL18 - A trojan that hijacks the user's Facebook, Twitter, or YouTube account to promote pages. It may post hyperlinks or like pages on Facebook, post comments on YouTube videos, or follow profiles and send direct messages on Twitter without permission. - -==== ms-caro-malware-full:malware-family="Mofin" - -ms-caro-malware-full:2014 VOL18 - A worm that can steal files from your PC and send them to a malicious hacker. It spreads via infected removable drives, such as USB flash drives. - -==== ms-caro-malware-full:malware-family="MpTamperSrp" - -ms-caro-malware-full:2014 VOL18 - A generic detection for an attempt to add software restriction policies to restrict Microsoft antimalware products, such as Microsoft Security Essentials and Windows Defender, from functioning properly. - -==== ms-caro-malware-full:malware-family="Mujormel" - -ms-caro-malware-full:2014 VOL18 - A password stealer that can steal personal information, such as user names and passwords, and send the stolen information to a malicious hacker. - -==== ms-caro-malware-full:malware-family="PennyBee" - -ms-caro-malware-full:2014 VOL18 - Adware that shows ads as the user browses the web. It can be installed from the program's website or bundled with some third-party software installation programs. - -==== ms-caro-malware-full:malware-family="Phdet" - -ms-caro-malware-full:2014 VOL18 - A family of backdoor trojans that is used to perform distributed denial-of service (DDoS) attacks against specified targets. - -==== ms-caro-malware-full:malware-family="Rimod" - -ms-caro-malware-full:2014 VOL18 - A generic detection for files that change various security settings in the computer Win32/Rotbrow. A trojan that installs browser add-ons that claim to offer protection from other add-ons. Rotbrow can change the browser's home page, and can install the trojan Win32/Sefnit. It is commonly installed by Win32/Brantall. - -==== ms-caro-malware-full:malware-family="Sigru" - -ms-caro-malware-full:2014 VOL18 - A virus that can stop some files from working correctly in Windows XP and earlier operating systems. It spreads by infecting the master boot record (MBR) on connected hard disks and floppy disks. - -==== ms-caro-malware-full:malware-family="SimpleShell" - -ms-caro-malware-full:2014 VOL18 - A backdoor that can give a malicious hacker unauthorized access to and control of the computer. - -==== ms-caro-malware-full:malware-family="Softpulse" - -ms-caro-malware-full:2014 VOL18 - A software bundler that no longer meets Microsoft detection criteria for unwanted software following a program update in September of 2014. - -==== ms-caro-malware-full:malware-family="SquareNet" - -ms-caro-malware-full:2014 VOL18 - A software bundler that installs other unwanted software, including adware and click-fraud malware. - -==== ms-caro-malware-full:malware-family="Tugspay" - -ms-caro-malware-full:2014 VOL18 - A downloader that spreads by posing as an installer for legitimate software, such as a Java update, or through other malware. When installed, it downloads unwanted software to the computer. - -==== ms-caro-malware-full:malware-family="Tupym" - -ms-caro-malware-full:2014 VOL18 - A worm that copies itself to the system folder of the affected computer, and attempts to contact remote hosts. - -==== ms-caro-malware-full:malware-family="Vercuser" - -ms-caro-malware-full:2014 VOL18 - A worm that typically spreads via drive-by download. It also receives commands from a remote server, and has been observed dropping other malware on the infected computer. - -==== ms-caro-malware-full:malware-family="Adnel" - -ms-caro-malware-full:2015 VOL19 - A family of macro malware that can download other threats to the computer, including TrojanDownloader:Win32/Drixed. - -==== ms-caro-malware-full:malware-family="Adodb" - -ms-caro-malware-full:2015 VOL19 - A generic detection for script trojans that exploit a vulnerability in Microsoft Data Access Components (MDAC) that allows remote code execution. Microsoft released Security Bulletin MS06-014 in April 2006 to address the vulnerability. - -==== ms-caro-malware-full:malware-family="AlterbookSP" - -ms-caro-malware-full:2015 VOL19 - A browser add-on that formerly displayed behaviors of unwanted software. Recent versions of the add-on no longer meet Microsoft detection criteria, and are no longer considered unwanted software. - -==== ms-caro-malware-full:malware-family="BrobanDel" - -ms-caro-malware-full:2015 VOL19 - A family of trojans that can modify boletos bancários, a common payment method in Brazil. They can be installed on the computer when a user opens a malicious spam email attachment. - -==== ms-caro-malware-full:malware-family="CompromisedCert" - -ms-caro-malware-full:2015 VOL19 - A detection for the Superfish VisualDiscovery advertising program that was preinstalled on some Lenovo laptops sold in 2014 and 2015. It installs a compromised trusted root certificate on the computer, which can be used to conduct man-in-the-middle attacks on the computer. - -==== ms-caro-malware-full:malware-family="CouponRuc" - -ms-caro-malware-full:2015 VOL19 - A browser modifier that changes browser settings and may also modify some computer and Internet settings. - -==== ms-caro-malware-full:malware-family="CVE-2014-6332" - -ms-caro-malware-full:2015 VOL19 - This threat uses a Microsoft vulnerability MS14-064 to download and run files on your PC, including other malware. - -==== ms-caro-malware-full:malware-family="Dyzap" - -ms-caro-malware-full:2015 VOL19 - A threat that steals login credentials for a long list of banking websites using man-in-the-browser (MITB) attacks. It is usually installed on the infected computer by TrojanDownloader:Win32/Upatre. - -==== ms-caro-malware-full:malware-family="EoRezo" - -ms-caro-malware-full:2015 VOL19 - Adware that displays targeted advertising to affected users while browsing the Internet, based on downloaded pre-configured information. - -==== ms-caro-malware-full:malware-family="FakeCall" - -ms-caro-malware-full:2015 VOL19 - This threat is a webpage that claims your PC is infected with malware. It asks you to phone a number to receive technical support to help remove the malware. - -==== ms-caro-malware-full:malware-family="Foosace" - -ms-caro-malware-full:2015 VOL19 - A threat that creates files on the compromised computer and contacts a remote host. Observed in the STRONTIUM APT. - -==== ms-caro-malware-full:malware-family="IeEnablerCby" - -ms-caro-malware-full:2015 VOL19 - A browser modifier that installs additional browser addons without the user's consent. It bypasses the normal prompts or dialogs that ask for consent to install add-ons. - -==== ms-caro-malware-full:malware-family="InstalleRex" - -ms-caro-malware-full:2015 VOL19 - A software bundler that installs unwanted software, including Win32/CouponRuc and Win32/SaverExtension. It alters its own 'Installed On' date in Programs and Features to make it more difficult for a user to locate it and remove it. - -==== ms-caro-malware-full:malware-family="JackTheRipper" - -ms-caro-malware-full:2015 VOL19 - A virus that can stop some files from working correctly in Windows XP and earlier operating systems. It spreads by infecting the master boot record (MBR) on connected hard disks and floppy disks. - -==== ms-caro-malware-full:malware-family="Kenilfe" - -ms-caro-malware-full:2015 VOL19 - A worm written in AutoCAD Lisp that only runs if AutoCAD is installed on the computer or network. It renames and deletes certain AutoCAD files, and may download and execute arbitrary files from a remote host. - -==== ms-caro-malware-full:malware-family="KipodToolsCby" - -ms-caro-malware-full:2015 VOL19 - A browser modifier that installs additional browser addons without the user's consent. It bypasses the normal prompts or dialogs that ask for consent to install add-ons. - -==== ms-caro-malware-full:malware-family="Macoute" - -ms-caro-malware-full:2015 VOL19 - A worm that can spread itself to removable USB drives, and may communicate with a remote host. - -==== ms-caro-malware-full:malware-family="NeutrinoEK" - -ms-caro-malware-full:2015 VOL19 - This threat is a webpage that spreads the exploit kit known as Neutrino. - -==== ms-caro-malware-full:malware-family="Peaac" - -ms-caro-malware-full:2015 VOL19 - A generic detection for various threats that display trojan characteristics. - -==== ms-caro-malware-full:malware-family="Peals" - -ms-caro-malware-full:2015 VOL19 - A generic detection for various threats that display trojan characteristics. - -==== ms-caro-malware-full:malware-family="Radonskra" - -ms-caro-malware-full:2015 VOL19 - A family of threats that perform a variety of malicious acts, including stealing information about the computer, showing extra advertisements as the user browses the web, performing click fraud, and downloading other programs without consent. - -==== ms-caro-malware-full:malware-family="SaverExtension" - -ms-caro-malware-full:2015 VOL19 - A browser add-on that shows ads in the browser without revealing their source, and prevents itself from being removed normally. - -==== ms-caro-malware-full:malware-family="Sdbby" - -ms-caro-malware-full:2015 VOL19 - A threat that exploits a bypass to gain administrative privileges on a machine without going through a User Access Control prompt. - -==== ms-caro-malware-full:malware-family="Simda" - -ms-caro-malware-full:2015 VOL19 - A threat that can give an attacker backdoor access and control of an infected computer. It can then steal passwords and gather information about the computer to send to the attacker. - -==== ms-caro-malware-full:malware-family="Skeeyah" - -ms-caro-malware-full:2015 VOL19 - A generic detection for various threats that display trojan characteristics. - -==== ms-caro-malware-full:malware-family="Wordjmp" - -ms-caro-malware-full:2015 VOL19 - An exploit that targets a vulnerability in Word 2002 and 2003 that could allow an attacker to remotely execute arbitrary code. Microsoft released Security Bulletin MS06-027 in June 2006 to address the vulnerability. - -==== ms-caro-malware-full:malware-family="Bayads" - -ms-caro-malware-full:2015 VOL20 - A program that displays ads as the user browses the web. It can be bundled with other software. It may call itself bdraw, delta, dlclient, Pay-ByAds, or pricehorse in Programs and Features. - -==== ms-caro-malware-full:malware-family="CandyOpen" - -ms-caro-malware-full:2015 VOL20 - This application can also affect the quality of your computing experience. We have seen this leading to the following potentially unwanted behaviors on PCs: Adds files that run at startup, Modifies boot configuration data, Modifies file associations, Injects into other processes on your system, Changes browser settings, Adds a local proxy, Modifies your system DNS settings, Stops Windows Update, Disables User Access Control (UAC), These applications are most commonly software bundlers or installers for applications such as toolbars, adware, or system optimizers. We have observed this application installing software that you might not have intended on your PC. - -==== ms-caro-malware-full:malware-family="Colisi" - -ms-caro-malware-full:2015 VOL20 - Behavioral detection of certain files acting in a malicious way. - -==== ms-caro-malware-full:malware-family="Creprote" - -ms-caro-malware-full:2015 VOL20 - These programs are most commonly software bundlers or installers for software such as toolbars, adware, or system optimizers. The software might modify your homepage, your search provider, or perform other actions that you might not have intended. - -==== ms-caro-malware-full:malware-family="Diplugem" - -ms-caro-malware-full:2015 VOL20 - A browser modifier that installs browser add-ons without obtaining the user’s consent. The add-ons show extra advertisements as the user browses the web, and can inject additional ads into web search results pages. - -==== ms-caro-malware-full:malware-family="Dipsind" - -ms-caro-malware-full:2015 VOL20 - A threat that is often used in targeted attacks. It can give an attacker access to the computer to download and run files, steal domain credentials, and perform other malicious actions. - -==== ms-caro-malware-full:malware-family="Donoff" - -ms-caro-malware-full:2015 VOL20 - A threat that uses an infected Microsoft Office file to download other malware onto the computer. It can arrive as a spam email attachment, usually as a Word file (.doc). - -==== ms-caro-malware-full:malware-family="Dorv" - -ms-caro-malware-full:2015 VOL20 - A trojan is a type of malware that can’t spread on its own. It relies on you to run them on your PC by mistake, or visit a hacked or malicious webpage. They can steal your personal information, download more malware, or give a malicious hacker access to your PC. - -==== ms-caro-malware-full:malware-family="Dowadmin" - -ms-caro-malware-full:2015 VOL20 - A software bundler that does not provide the user with the option to decline installation of unwanted software. - -==== ms-caro-malware-full:malware-family="Fourthrem" - -ms-caro-malware-full:2015 VOL20 - A program that installs unwanted software without adequate consent on the computer at the same time as the software the user is trying to install. - -==== ms-caro-malware-full:malware-family="Hao123" - -ms-caro-malware-full:2015 VOL20 - This threat is a modified Internet Explorer shortcut that changes your Internet Explorer homepage. It might arrive on your PC through bundlers that offer free software. The threat will run a separate threat-related file that changes the Internet Explorer. - -==== ms-caro-malware-full:malware-family="Mizenota" - -ms-caro-malware-full:2015 VOL20 - This program is a software bundler that installs unwanted software on your PC at the same time as the software you are trying to install. It may install one of the following: BrowserModifier:Win32/SupTab, BrowserModifier:Win32/Sasquor, BrowserModifier:Win32/Smudplu, SoftwareBundler:Win32/Pokavampo, BrowserModifier:Win32/Shopperz, Adware:Win32/EoRezo - -==== ms-caro-malware-full:malware-family="Mytonel" - -ms-caro-malware-full:2015 VOL20 - A program that downloads and installs other programs onto the computer without the user's consent, including other malware. - -==== ms-caro-malware-full:malware-family="OutBrowse" - -ms-caro-malware-full:2015 VOL20 - A software bundler that installs additional unwanted programs alongside software that the user wishes to install. It can remove or hide the installer’s close button, leaving no way to decline the additional applications. - -==== ms-caro-malware-full:malware-family="Peapoon" - -ms-caro-malware-full:2015 VOL20 - An adware program that shows users ads that they cannot control as they browse the web. It may identify itself as Coupon in Programs and Features. - -==== ms-caro-malware-full:malware-family="Pokki" - -ms-caro-malware-full:2015 VOL20 - A browser add-on that formerly displayed behaviors of unwanted software. Recent versions of the add-on no longer meet Microsoft detection criteria, and are no longer considered unwanted software. - -==== ms-caro-malware-full:malware-family="Putalol" - -ms-caro-malware-full:2015 VOL20 - An adware program that shows users ads that they cannot control as they browse the web. It may identify itself as Lolliscan in Programs and Features. - -==== ms-caro-malware-full:malware-family="SpigotSearch" - -ms-caro-malware-full:2015 VOL20 - This application can affect the quality of your computing experience. For example, some potentially unwanted applications can: Install additional bundled software, Modify your homepage, Modify your search provider. These applications are most commonly software bundlers or installers for applications such as toolbars, adware, or system optimizers. We have observed this application installing software that you might not have intended on your PC. - -==== ms-caro-malware-full:malware-family="Spursint" - -ms-caro-malware-full:2015 VOL20 - This threat has been detected as one of the executable malware that are distributed through URLs. - -==== ms-caro-malware-full:malware-family="Sulunch" - -ms-caro-malware-full:2015 VOL20 - A generic detection for a group of trojans that perform a number of common malware behaviors. - -==== ms-caro-malware-full:malware-family="SupTab" - -ms-caro-malware-full:2015 VOL20 - A browser modifier that installs itself and changes the browser’s default search provider, without obtaining the user’s consent for either action. - -==== ms-caro-malware-full:malware-family="Sventore" - -ms-caro-malware-full:2015 VOL20 - This trojan can install other malware or unwanted software onto your PC. - -==== ms-caro-malware-full:malware-family="Tillail" - -ms-caro-malware-full:2015 VOL20 - A software bundler that installs unwanted software alongside the software the user is trying to install. It has been observed to install the browser modifier Win32/SupTab. - -==== ms-caro-malware-full:malware-family="VOPackage" - -ms-caro-malware-full:2015 VOL20 - This application can also affect the quality of your computing experience. We have seen this leading to the following potentially unwanted behaviors on PCs: Adds files that run at startup, Installs a driver, Injects into other processes on your system, Injects into browsers, Changes browser settings, Changes browser shortcuts, Installs browser extensions, Adds a local proxy, Tampers with root certificate trust, Modifies the system hosts file, Modifies your system DNS settings, Disables anti-virus products, Tampers with system Group Policy settings, These applications are most commonly software bundlers or installers for applications such as toolbars, adware, or system optimizers. We have observed this application installing software that you might not have intended on your PC. - -==== ms-caro-malware-full:malware-family="Xiazai" - -ms-caro-malware-full:2015 VOL20 - A program that installs unwanted software on the computer at the same time as the software the user is trying to install, without adequate consent. - -== malware_classification -NOTE: malware_classification namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/malware_classification/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Classification based on different categories. Based on https://www.sans.org/reading-room/whitepapers/incident/malware-101-viruses-32848 - -=== malware-category -==== malware_classification:malware-category="Virus" - -malware_classification:Virus - -==== malware_classification:malware-category="Worm" - -malware_classification:Worm - -==== malware_classification:malware-category="Trojan" - -malware_classification:Trojan - -==== malware_classification:malware-category="Ransomware" - -malware_classification:Ransomware - -==== malware_classification:malware-category="Rootkit" - -malware_classification:Rootkit - -==== malware_classification:malware-category="Downloader" - -malware_classification:Downloader - -==== malware_classification:malware-category="Adware" - -malware_classification:Adware - -==== malware_classification:malware-category="Spyware" - -malware_classification:Spyware - -==== malware_classification:malware-category="Botnet" - -malware_classification:Botnet - -=== obfuscation-technique -==== malware_classification:obfuscation-technique="no-obfuscation" - -malware_classification:No obfuscation is used - -==== malware_classification:obfuscation-technique="encryption" - -malware_classification:encryption - -==== malware_classification:obfuscation-technique="oligomorphism" - -malware_classification:oligomorphism - -==== malware_classification:obfuscation-technique="metamorphism" - -malware_classification:metamorphism - -==== malware_classification:obfuscation-technique="stealth" - -malware_classification:stealth - -==== malware_classification:obfuscation-technique="armouring" - -malware_classification:armouring - -==== malware_classification:obfuscation-technique="encryption" - -malware_classification:encryption - -==== malware_classification:obfuscation-technique="tunneling" - -malware_classification:tunneling - -==== malware_classification:obfuscation-technique="XOR" - -malware_classification:XOR - -==== malware_classification:obfuscation-technique="BASE64" - -malware_classification:BASE64 - -==== malware_classification:obfuscation-technique="ROT13" - -malware_classification:ROT13 - -=== payload-classification -==== malware_classification:payload-classification="no-payload" - -malware_classification:No payload - -==== malware_classification:payload-classification="non-destructive" - -malware_classification:Non-Destructive - -==== malware_classification:payload-classification="destructive" - -malware_classification:Destructive - -==== malware_classification:payload-classification="dropper" - -malware_classification:Dropper - -=== memory-classification -==== malware_classification:memory-classification="resident" - -malware_classification:In memory - -==== malware_classification:memory-classification="temporary-resident" - -malware_classification:In memory temporarily - -==== malware_classification:memory-classification="swapping-mode" - -malware_classification:Only a part loaded in memory temporarily - -==== malware_classification:memory-classification="non-resident" - -malware_classification:Not in memory - -==== malware_classification:memory-classification="user-process" - -malware_classification:As a user level process - -==== malware_classification:memory-classification="kernel-process" - -malware_classification:As a process in the kernel - -== fr-classif -NOTE: fr-classif namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/fr-classif/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -French gov information classification system - -=== classifiees-defense -==== fr-classif:classifiees-defense="TRES_SECRET_DEFENSE" - -fr-classif:TRES SECRET DEFENSE - -==== fr-classif:classifiees-defense="SECRET_DEFENSE" - -fr-classif:SECRET DEFENSE - -==== fr-classif:classifiees-defense="CONFIDENTIEL_DEFENSE" - -fr-classif:CONFIDENTIEL DEFENSE - -=== non-classifiees-defense -==== fr-classif:non-classifiees-defense="SECRET" - -fr-classif:SECRET - -==== fr-classif:non-classifiees-defense="CONFIDENTIEL" - -fr-classif:CONFIDENTIEL - -==== fr-classif:non-classifiees-defense="DIFFUSION_RESTREINTE" - -fr-classif:DIFFUSION RESTREINTE - -=== non-classifiees -==== fr-classif:non-classifiees="NON-CLASSIFIEES" - -fr-classif:NON CLASSIFIEES - -== admiralty-scale -NOTE: admiralty-scale namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/admiralty-scale/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The Admiralty Scale (also called the NATO System) is used to rank the reliability of a source and the credibility of an information. - -=== source-reliability -==== admiralty-scale:source-reliability="a" - -admiralty-scale:Completely reliable - -==== admiralty-scale:source-reliability="b" - -admiralty-scale:Usually reliable - -==== admiralty-scale:source-reliability="c" - -admiralty-scale:Fairly reliable - -==== admiralty-scale:source-reliability="d" - -admiralty-scale:Not usually reliable - -==== admiralty-scale:source-reliability="e" - -admiralty-scale:Unreliable - -==== admiralty-scale:source-reliability="f" - -admiralty-scale:Reliability cannot be judged - -=== information-credibility -==== admiralty-scale:information-credibility="1" - -admiralty-scale:Confirmed by other sources - -==== admiralty-scale:information-credibility="2" - -admiralty-scale:Probably true - -==== admiralty-scale:information-credibility="3" - -admiralty-scale:Possibly true - -==== admiralty-scale:information-credibility="4" - -admiralty-scale:Doubtful - -==== admiralty-scale:information-credibility="5" - -admiralty-scale:Improbable - -==== admiralty-scale:information-credibility="6" - -admiralty-scale:Truth cannot be judged - -== ms-caro-malware -NOTE: ms-caro-malware namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/ms-caro-malware/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families. - -=== malware-type -==== ms-caro-malware:malware-type="Adware" - -ms-caro-malware:Adware - Software that shows you extra promotions that you cannot control as you use your PC - -==== ms-caro-malware:malware-type="Backdoor" - -ms-caro-malware:A type of trojan that gives a malicious hacker access to and control of your PC - -==== ms-caro-malware:malware-type="Behavior" - -ms-caro-malware:A type of detection based on file actions that are often associated with malicious activity - -==== ms-caro-malware:malware-type="BroswerModifier" - -ms-caro-malware:A program than makes changes to your Internet browser without your permission - -==== ms-caro-malware:malware-type="Constructor" - -ms-caro-malware:A program that can be used to automatically create malware files - -==== ms-caro-malware:malware-type="DDoS" - -ms-caro-malware:When a number of PCs are made to access a website, network or server repeatedly within a given time period. The aim of the attack is to overload the target so that it crashes and can't respond - -==== ms-caro-malware:malware-type="Dialer" - -ms-caro-malware:A program that makes unauthorized telephone calls. These calls may be charged at a premium rate and cost you a lot of money - -==== ms-caro-malware:malware-type="DoS" - -ms-caro-malware:When a target PC or server is deliberately overloaded so that it doesn't work for any visitors anymore - -==== ms-caro-malware:malware-type="Exploit" - -ms-caro-malware:A piece of code that uses software vulnerabilities to access information on your PC or install malware - -==== ms-caro-malware:malware-type="HackTool" - -ms-caro-malware:A type of tool that can be used to allow and maintain unauthorized access to your PC - -==== ms-caro-malware:malware-type="Joke" - -ms-caro-malware:A program that pretends to do something malicious but actually doesn't actually do anything harmful. For example, some joke programs pretend to delete files or format disks - -==== ms-caro-malware:malware-type="Misleading" - -ms-caro-malware:The program that makes misleading or fraudulent claims about files, registry entries or other items on your PC - -==== ms-caro-malware:malware-type="MonitoringTool" - -ms-caro-malware:A commercial program that monitors what you do on your PC. This can include monitoring what keys you press; your email or instant messages; your voice or video conversations; and your banking details and passwords. It can also take screenshots as you use your PC - -==== ms-caro-malware:malware-type="Program" - -ms-caro-malware:Software that you may or may not want installed on your PC - -==== ms-caro-malware:malware-type="PUA" - -ms-caro-malware:Potentially Unwanted Applications. Characteristics of unwanted software can include depriving users of adequate choice or control over what the software does to the computer, preventing users from removing the software, or displaying advertisements without clearly identifying their source. - -==== ms-caro-malware:malware-type="PWS" - -ms-caro-malware:A type of malware that is used steal your personal information, such as user names and passwords. It often works along with a keylogger that collects and sends information about what keys you press and websites you visit to a malicious hacker - -==== ms-caro-malware:malware-type="Ransom" - -ms-caro-malware:A detection for malicious programs that seize control of the computer on which they are installed. This trojan usually locks the screen and prevents the user from using the computer. It usually displays an alert message. - -==== ms-caro-malware:malware-type="RemoteAccess" - -ms-caro-malware:A program that gives someone access to your PC from a remote location. This type of program is often installed by the computer owner - -==== ms-caro-malware:malware-type="Rogue" - -ms-caro-malware:Software that pretends to be an antivirus program but doesn't actually provide any security. This type of software usually gives you a lot of alerts about threats on your PC that don't exist. It also tries to convince you to pay for its services - -==== ms-caro-malware:malware-type="SettingsModifier" - -ms-caro-malware:A program that changes your PC settings - -==== ms-caro-malware:malware-type="SoftwareBundler" - -ms-caro-malware:A program that installs unwanted software on your PC at the same time as the software you are trying to install, without adequate consent - -==== ms-caro-malware:malware-type="Spammer" - -ms-caro-malware:A trojan that sends large numbers of spam emails. It may also describe the person or business responsible for sending spam - -==== ms-caro-malware:malware-type="Spoofer" - -ms-caro-malware:A type of trojan that makes fake emails that look like they are from a legitimate source - -==== ms-caro-malware:malware-type="Spyware" - -ms-caro-malware:A program that collects your personal information, such as your browsing history, and uses it without adequate consent - -==== ms-caro-malware:malware-type="Tool" - -ms-caro-malware:A type of software that may have a legitimate purpose, but which may also be abused by malware authors - -==== ms-caro-malware:malware-type="Trojan" - -ms-caro-malware:A trojan is a program that tries to look innocent, but is actually a malicious application. Unlike a virus or a worm , a trojan doesn't spread by itself. Instead they try to look innocent to convince you to download and install them. Once installed, a trojan can steal your personal information, download more malware, or give a malicious hacker access to your PC - -==== ms-caro-malware:malware-type="TrojanClicker" - -ms-caro-malware:A type of trojan that can use your PC to click on websites or applications. They are usually used to make money for a malicious hacker by clicking on online advertisements and making it look like the website gets more traffic than it does. They can also be used to skew online polls, install programs on your PC, or make unwanted software appear more popular than it is - -==== ms-caro-malware:malware-type="TrojanDownloader" - -ms-caro-malware:A type of trojan that installs other malicious files, including malware, onto your PC. It can download the files from a remote PC or install them directly from a copy that is included in its file. - -==== ms-caro-malware:malware-type="TrojanDropper" - -ms-caro-malware:A type of trojan that installs other malicious files, including malware, onto your PC. It can download the files from a remote PC or install them directly from a copy that is included in its file. - -==== ms-caro-malware:malware-type="TrojanNotifier" - -ms-caro-malware:A type of trojan that sends information about your PC to a malicious hacker. It is similar to a password stealer - -==== ms-caro-malware:malware-type="TrojanProxy" - -ms-caro-malware:A type of trojan that installs a proxy server on your PC. The server can be configured so that when you use the Internet, any requests you make are sent through a server controlled by a malicious hacker. - -==== ms-caro-malware:malware-type="TrojanSpy" - -ms-caro-malware:A program that collects your personal information, such as your browsing history, and uses it without adequate consent. - -==== ms-caro-malware:malware-type="VirTool" - -ms-caro-malware:A detection that is used mostly for malware components, or tools used for malware-related actions, such as rootkits. - -==== ms-caro-malware:malware-type="Virus" - -ms-caro-malware:A type of malware. Viruses spread on their own by attaching their code to other programs, or copying themselves across systems and networks. - -==== ms-caro-malware:malware-type="Worm" - -ms-caro-malware:A type of malware that spreads to other PCs. Worms may spread using one or more of the following methods: Email programs, Instant messaging programs, File-sharing programs, Social networking sites, Network shares, Removable drives with Autorun enabled, Software vulnerabilities - -=== malware-platform -==== ms-caro-malware:malware-platform="AndroidOS" - -ms-caro-malware:Android operating system - -==== ms-caro-malware:malware-platform="DOS" - -ms-caro-malware:MS-DOS platform - -==== ms-caro-malware:malware-platform="EPOC" - -ms-caro-malware:Psion devices - -==== ms-caro-malware:malware-platform="FreeBSD" - -ms-caro-malware:FreeBSD platform - -==== ms-caro-malware:malware-platform="iPhoneOS" - -ms-caro-malware:iPhone operating system - -==== ms-caro-malware:malware-platform="Linux" - -ms-caro-malware:Linux platform - -==== ms-caro-malware:malware-platform="MacOS" - -ms-caro-malware:MAC 9.x platform or earlier - -==== ms-caro-malware:malware-platform="MacOS_X" - -ms-caro-malware:MacOS X or later - -==== ms-caro-malware:malware-platform="OS2" - -ms-caro-malware:OS2 platform - -==== ms-caro-malware:malware-platform="Palm" - -ms-caro-malware:Palm operating system - -==== ms-caro-malware:malware-platform="Solaris" - -ms-caro-malware:System V-based Unix platforms - -==== ms-caro-malware:malware-platform="SunOS" - -ms-caro-malware:Unix platforms 4.1.3 or earlier - -==== ms-caro-malware:malware-platform="SymbOS" - -ms-caro-malware:Symbian operatings system - -==== ms-caro-malware:malware-platform="Unix" - -ms-caro-malware:General Unix platforms - -==== ms-caro-malware:malware-platform="Win16" - -ms-caro-malware:Win16 (3.1) platform - -==== ms-caro-malware:malware-platform="Win2K" - -ms-caro-malware:Windows 2000 platform - -==== ms-caro-malware:malware-platform="Win32" - -ms-caro-malware:Windows 32-bit platform - -==== ms-caro-malware:malware-platform="Win64" - -ms-caro-malware:Windows 64-bit platform - -==== ms-caro-malware:malware-platform="Win95" - -ms-caro-malware:Windows 95, 98 and ME platforms - -==== ms-caro-malware:malware-platform="Win98" - -ms-caro-malware:Windows 98 platform only - -==== ms-caro-malware:malware-platform="WinCE" - -ms-caro-malware:Windows CE platform - -==== ms-caro-malware:malware-platform="WinNT" - -ms-caro-malware:WinNT - -==== ms-caro-malware:malware-platform="ABAP" - -ms-caro-malware:Advanced Business Application Programming scripts - -==== ms-caro-malware:malware-platform="ALisp" - -ms-caro-malware:ALisp scripts - -==== ms-caro-malware:malware-platform="AmiPro" - -ms-caro-malware:AmiPro script - -==== ms-caro-malware:malware-platform="ANSI" - -ms-caro-malware:American National Standards Institute scripts - -==== ms-caro-malware:malware-platform="AppleScript" - -ms-caro-malware:compiled Apple scripts - -==== ms-caro-malware:malware-platform="ASP" - -ms-caro-malware:Active Server Pages scripts - -==== ms-caro-malware:malware-platform="AutoIt" - -ms-caro-malware:AutoIT scripts - -==== ms-caro-malware:malware-platform="BAS" - -ms-caro-malware:Basic scripts - -==== ms-caro-malware:malware-platform="BAT" - -ms-caro-malware:Basic scripts - -==== ms-caro-malware:malware-platform="CorelScript" - -ms-caro-malware:Corelscript scripts - -==== ms-caro-malware:malware-platform="HTA" - -ms-caro-malware:HTML Application scripts - -==== ms-caro-malware:malware-platform="HTML" - -ms-caro-malware:HTML Application scripts - -==== ms-caro-malware:malware-platform="INF" - -ms-caro-malware:Install scripts - -==== ms-caro-malware:malware-platform="IRC" - -ms-caro-malware:mIRC/pIRC scripts - -==== ms-caro-malware:malware-platform="Java" - -ms-caro-malware:Java binaries (classes) - -==== ms-caro-malware:malware-platform="JS" - -ms-caro-malware:Javascript scripts - -==== ms-caro-malware:malware-platform="LOGO" - -ms-caro-malware:LOGO scripts - -==== ms-caro-malware:malware-platform="MPB" - -ms-caro-malware:MapBasic scripts - -==== ms-caro-malware:malware-platform="MSH" - -ms-caro-malware:Monad shell scripts - -==== ms-caro-malware:malware-platform="MSIL" - -ms-caro-malware:.Net intermediate language scripts - -==== ms-caro-malware:malware-platform="Perl" - -ms-caro-malware:Perl scripts - -==== ms-caro-malware:malware-platform="PHP" - -ms-caro-malware:Hypertext Preprocessor scripts - -==== ms-caro-malware:malware-platform="Python" - -ms-caro-malware:Python scripts - -==== ms-caro-malware:malware-platform="SAP" - -ms-caro-malware:SAP platform scripts - -==== ms-caro-malware:malware-platform="SH" - -ms-caro-malware:Shell scripts - -==== ms-caro-malware:malware-platform="VBA" - -ms-caro-malware:Visual Basic for Applications scripts - -==== ms-caro-malware:malware-platform="VBS" - -ms-caro-malware:Visual Basic scripts - -==== ms-caro-malware:malware-platform="WinBAT" - -ms-caro-malware:Winbatch scripts - -==== ms-caro-malware:malware-platform="WinHlp" - -ms-caro-malware:Windows Help scripts - -==== ms-caro-malware:malware-platform="WinREG" - -ms-caro-malware:Windows registry scripts - -==== ms-caro-malware:malware-platform="A97M" - -ms-caro-malware:Access 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware:malware-platform="HE" - -ms-caro-malware:macro scripting - -==== ms-caro-malware:malware-platform="O97M" - -ms-caro-malware:Office 97, 2000, XP, 2003, 2007, and 2010 macros - those that affect Word, Excel, and Powerpoint - -==== ms-caro-malware:malware-platform="PP97M" - -ms-caro-malware:PowerPoint 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware:malware-platform="V5M" - -ms-caro-malware:Visio5 macros - -==== ms-caro-malware:malware-platform="W1M" - -ms-caro-malware:Word1Macro - -==== ms-caro-malware:malware-platform="W2M" - -ms-caro-malware:Word2Macro - -==== ms-caro-malware:malware-platform="W97M" - -ms-caro-malware:Word 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware:malware-platform="WM" - -ms-caro-malware:Word 95 macros - -==== ms-caro-malware:malware-platform="X97M" - -ms-caro-malware:Excel 97, 2000, XP, 2003, 2007, and 2010 macros - -==== ms-caro-malware:malware-platform="XF" - -ms-caro-malware:Excel formulas - -==== ms-caro-malware:malware-platform="XM" - -ms-caro-malware:Excel 95 macros - -==== ms-caro-malware:malware-platform="ASX" - -ms-caro-malware:XML metafile of Windows Media .asf files - -==== ms-caro-malware:malware-platform="HC" - -ms-caro-malware:HyperCard Apple scripts - -==== ms-caro-malware:malware-platform="MIME" - -ms-caro-malware:MIME packets - -==== ms-caro-malware:malware-platform="Netware" - -ms-caro-malware:Novell Netware files - -==== ms-caro-malware:malware-platform="QT" - -ms-caro-malware:Quicktime files - -==== ms-caro-malware:malware-platform="SB" - -ms-caro-malware:StarBasic (Staroffice XML) files - -==== ms-caro-malware:malware-platform="SWF" - -ms-caro-malware:Shockwave Flash files - -==== ms-caro-malware:malware-platform="TSQL" - -ms-caro-malware:MS SQL server files - -==== ms-caro-malware:malware-platform="XML" - -ms-caro-malware:XML files - -== adversary -NOTE: adversary namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/adversary/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -An overview and description of the adversary infrastructure - -=== infrastructure-status -==== adversary:infrastructure-status="unknown" - -adversary:Infrastructure ownership and status is unknown - -==== adversary:infrastructure-status="compromised" - -adversary:Infrastructure compromised by or in the benefit of the adversary - -==== adversary:infrastructure-status="own-and-operated" - -adversary:Infrastructure own and operated by the adversary - -=== infrastructure-type -==== adversary:infrastructure-type="unknown" - -adversary:Infrastructure usage by the adversary is unknown - -==== adversary:infrastructure-type="proxy" - -adversary:Infrastructure used as proxy between the target and the adversary - -==== adversary:infrastructure-type="drop-zone" - -adversary:Infrastructure used by the adversary to store information related to his campaigns - -==== adversary:infrastructure-type="exploit-distribution-point" - -adversary:Infrastructure used to distribute exploit towards target(s) - -==== adversary:infrastructure-type="vpn" - -adversary:Infrastructure used by the adversary as Virtual Private Network to hide activities and reduce the traffic analysis surface - -==== adversary:infrastructure-type="panel" - -adversary:Panel used by the adversary to control or maintain his infrastructure - -==== adversary:infrastructure-type="tds" - -adversary:Traffic Distribution Systems including exploit delivery or/and web monetization channels - -=== infrastructure-state -==== adversary:infrastructure-state="unknown" - -adversary:Infrastructure state is unknown or cannot be evaluated - -==== adversary:infrastructure-state="active" - -adversary:Infrastructure state is active and actively used by the adversary - -==== adversary:infrastructure-state="down" - -adversary:Infrastructure state is known to be down - -=== infrastructure-action -==== adversary:infrastructure-action="passive-only" - -adversary:Only passive requests shall be performed to avoid detection by the adversary - -==== adversary:infrastructure-action="take-down" - -adversary:Take down requests can be performed in order to deactivate the adversary infrastructure - -==== adversary:infrastructure-action="monitoring-active" - -adversary:Monitoring requests are ongoing on the adversary infrastructure - -==== adversary:infrastructure-action="pending-law-enforcement-request" - -adversary:Law enforcement requests are ongoing on the adversary infrastructure - -== dni-ism -NOTE: dni-ism namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/dni-ism/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -A subset of Information Security Marking Metadata ISM as required by Executive Order (EO) 13526. As described by DNI.gov as Data Encoding Specifications for Information Security Marking Metadata in Controlled Vocabulary Enumeration Values for ISM - -=== classification:all -==== dni-ism:classification:all="R" - -dni-ism:RESTRICTED - -==== dni-ism:classification:all="C" - -dni-ism:CONFIDENTIAL - -==== dni-ism:classification:all="S" - -dni-ism:SECRET - -==== dni-ism:classification:all="TS" - -dni-ism:TOP SECRET - -==== dni-ism:classification:all="U" - -dni-ism:UNCLASSIFIED - -=== classification:us -==== dni-ism:classification:us="C" - -dni-ism:CONFIDENTIAL - -==== dni-ism:classification:us="S" - -dni-ism:SECRET - -==== dni-ism:classification:us="TS" - -dni-ism:TOP SECRET - -==== dni-ism:classification:us="U" - -dni-ism:UNCLASSIFIED - -=== complies:with -==== dni-ism:complies:with="USGov" - -dni-ism:Document claims compliance with all rules encoded in ISM for documents produced by the US Federal Government. This is the minimum set of rules for US documents to adhere to, and all US documents should claim compliance with USGov. - -==== dni-ism:complies:with="USIC" - -dni-ism:Document claims compliance with all rules encoded in ISM for documents produced by the US Intelligence Community. Documents that claim compliance with USIC MUST also claim compliance with USGov. - -==== dni-ism:complies:with="USDOD" - -dni-ism:Document claims compliance with all rules encoded in ISM for documents produced by the US Department of Defense. Documents that claim compliance with USDOD MUST also claim compliance with USGov. - -==== dni-ism:complies:with="OtherAuthority" - -dni-ism:Document claims compliance with an authority other than the USGov, USIC, or USDOD. - -=== dissem -==== dni-ism:dissem="RS" - -dni-ism:RISK SENSITIVE - -==== dni-ism:dissem="FOUO" - -dni-ism:FOR OFFICIAL USE ONLY - -==== dni-ism:dissem="OC" - -dni-ism:ORIGINATOR CONTROLLED - -==== dni-ism:dissem="OC-USGOV" - -dni-ism:ORIGINATOR CONTROLLED US GOVERNMENT - -==== dni-ism:dissem="IMC" - -dni-ism:CONTROLLED IMAGERY - -==== dni-ism:dissem="NF" - -dni-ism:NOT RELEASABLE TO FOREIGN NATIONALS - -==== dni-ism:dissem="PR" - -dni-ism:CAUTION-PROPRIETARY INFORMATION INVOLVED - -==== dni-ism:dissem="REL" - -dni-ism:AUTHORIZED FOR RELEASE TO - -==== dni-ism:dissem="RELIDO" - -dni-ism:RELEASABLE BY INFORMATION DISCLOSURE OFFICIAL - -==== dni-ism:dissem="DSEN" - -dni-ism:DEA SENSITIVE - -==== dni-ism:dissem="FISA" - -dni-ism:FOREIGN INTELLIGENCE SURVEILLANCE ACT - -==== dni-ism:dissem="DISPLAYONLY" - -dni-ism:AUTHORIZED FOR DISPLAY BUT NOT RELEASE TO - -=== nonic -==== dni-ism:nonic="NNPI" - -dni-ism:NAVAL NUCLEAR PROPULSION INFORMATION - -==== dni-ism:nonic="DS" - -dni-ism:LIMITED DISTRIBUTION - -==== dni-ism:nonic="XD" - -dni-ism:EXCLUSIVE DISTRIBUTION - -==== dni-ism:nonic="ND" - -dni-ism:NO DISTRIBUTION - -==== dni-ism:nonic="SBU" - -dni-ism:SENSITIVE BUT UNCLASSIFIED - -==== dni-ism:nonic="SBU-NF" - -dni-ism:SENSITIVE BUT UNCLASSIFIED NOFORN - -==== dni-ism:nonic="LES" - -dni-ism:LAW ENFORCEMENT SENSITIVE - -==== dni-ism:nonic="LES-NF" - -dni-ism:LAW ENFORCEMENT SENSITIVE NOFORN - -==== dni-ism:nonic="SSI" - -dni-ism:SENSITIVE SECURITY INFORMATION - -=== nonuscontrols -==== dni-ism:nonuscontrols="ATOMAL" - -dni-ism:NATO Atomal mark - -==== dni-ism:nonuscontrols="BOHEMIA" - -dni-ism:NATO Bohemia mark - -==== dni-ism:nonuscontrols="BALK" - -dni-ism:NATO Balk mark - -=== notice -==== dni-ism:notice="FISA" - -dni-ism:FISA Warning statement - -==== dni-ism:notice="IMC" - -dni-ism:IMCON Warning statement - -==== dni-ism:notice="CNWDI" - -dni-ism:Controled Nuclear Weapon Design Information Warning statement - -==== dni-ism:notice="RD" - -dni-ism:RD Warning statement - -==== dni-ism:notice="FRD" - -dni-ism:FRD Warning statement - -==== dni-ism:notice="DS" - -dni-ism:LIMDIS caveat - -==== dni-ism:notice="LES" - -dni-ism:LES Notice - -==== dni-ism:notice="LES-NF" - -dni-ism:LES-NF Notice - -==== dni-ism:notice="DSEN" - -dni-ism:DSEN Notice - -==== dni-ism:notice="DoD-Dist-A" - -dni-ism:DoD Distribution statement A from DoD Directive 5230.24 - -==== dni-ism:notice="DoD-Dist-B" - -dni-ism:DoD Distribution statement B from DoD Directive 5230.24 - -==== dni-ism:notice="DoD-Dist-C" - -dni-ism:DoD Distribution statement C from DoD Directive 5230.24 - -==== dni-ism:notice="DoD-Dist-D" - -dni-ism:DoD Distribution statement D from DoD Directive 5230.24 - -==== dni-ism:notice="DoD-Dist-E" - -dni-ism:DoD Distribution statement E from DoD Directive 5230.24 - -==== dni-ism:notice="DoD-Dist-F" - -dni-ism:DoD Distribution statement F from DoD Directive 5230.24 - -==== dni-ism:notice="DoD-Dist-X" - -dni-ism:DoD Distribution statement X from DoD Directive 5230.24 - -==== dni-ism:notice="US-Person" - -dni-ism:US Person info Notice - -==== dni-ism:notice="pre13526ORCON" - -dni-ism:Indicates that an instance document must abide by rules pertaining to ORIGINATOR CONTROLLED data issued prior to Executive Order 13526. - -==== dni-ism:notice="POC" - -dni-ism:Indicates that the contents of this notice specify the contact information for a required point-of-contact. - -==== dni-ism:notice="COMSEC" - -dni-ism:COMSEC Notice - -=== scicontrols -==== dni-ism:scicontrols="EL" - -dni-ism:ENDSEAL - -==== dni-ism:scicontrols="EL-EU" - -dni-ism:ECRU - -==== dni-ism:scicontrols="EL-NK" - -dni-ism:NONBOOK - -==== dni-ism:scicontrols="HCS" - -dni-ism:HCS - -==== dni-ism:scicontrols="HCS-O" - -dni-ism:HCS-O - -==== dni-ism:scicontrols="HCS-P" - -dni-ism:HCS-P - -==== dni-ism:scicontrols="KDK" - -dni-ism:KLONDIKE - -==== dni-ism:scicontrols="KDK-BLFH" - -dni-ism:KDK BLUEFISH - -==== dni-ism:scicontrols="KDK-IDIT" - -dni-ism:KDK IDITAROD - -==== dni-ism:scicontrols="KDK-KAND" - -dni-ism:KDK KANDIK - -==== dni-ism:scicontrols="RSV" - -dni-ism:RESERVE - -==== dni-ism:scicontrols="SI" - -dni-ism:SPECIAL INTELLIGENCE - -==== dni-ism:scicontrols="SI-G" - -dni-ism:SI-GAMMA - -==== dni-ism:scicontrols="TK" - -dni-ism:TALENT KEYHOLE - -=== atomicenergymarkings -==== dni-ism:atomicenergymarkings="RD" - -dni-ism:RESTRICTED DATA - -==== dni-ism:atomicenergymarkings="RD-CNWDI" - -dni-ism:RD-CRITICAL NUCLEAR WEAPON DESIGN INFORMATION - -==== dni-ism:atomicenergymarkings="FRD" - -dni-ism:FORMERLY RESTRICTED DATA - -==== dni-ism:atomicenergymarkings="DCNI" - -dni-ism:DoD CONTROLLED NUCLEAR INFORMATION - -==== dni-ism:atomicenergymarkings="UCNI" - -dni-ism:DoE CONTROLLED NUCLEAR INFORMATION - -==== dni-ism:atomicenergymarkings="TFNI" - -dni-ism:TRANSCLASSIFIED FOREIGN NUCLEAR INFORMATION - -== osint -NOTE: osint namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/osint/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Open Source Intelligence - Classification (MISP taxonomies) - -=== source-type -==== osint:source-type="blog-post" - -osint:Blog post - -==== osint:source-type="technical-report" - -osint:Technical or analysis report - -==== osint:source-type="news-report" - -osint:News report - -==== osint:source-type="pastie-website" - -osint:Pastie-like website - -==== osint:source-type="electronic-forum" - -osint:Electronic forum - -==== osint:source-type="mailing-list" - -osint:Mailing-list - -==== osint:source-type="block-or-filter-list" - -osint:Block or Filter List - -==== osint:source-type="expansion" - -osint:Expansion - -=== lifetime -==== osint:lifetime="perpetual" - -osint:Perpetual - -==== osint:lifetime="ephemeral" - -osint:Ephemeral - -=== certainty -==== osint:certainty="100" - -osint:100% Certainty - -==== osint:certainty="93" - -osint:93% Almost certain - -==== osint:certainty="75" - -osint:75% Probable - -==== osint:certainty="50" - -osint:50% Chances about even - -==== osint:certainty="30" - -osint:30% Probably not - -==== osint:certainty="7" - -osint:7% Almost certainly not - -==== osint:certainty="0" - -osint:0% Impossibility - -== domain-abuse -NOTE: domain-abuse namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/domain-abuse/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Domain Name Abuse - taxonomy to tag domain names used for cybercrime. Use europol-incident to tag abuse-activity - -=== domain-access-method -==== domain-abuse:domain-access-method="criminal-registration" - -domain-abuse:Criminal registration - -==== domain-abuse:domain-access-method="compromised-webserver" - -domain-abuse:Compromised webserver - -==== domain-abuse:domain-access-method="compromised-dns" - -domain-abuse:Compromised DNS - -==== domain-abuse:domain-access-method="sinkhole" - -domain-abuse:Sinkhole - -=== domain-status -==== domain-abuse:domain-status="active" - -domain-abuse:Registered & active - -==== domain-abuse:domain-status="inactive" - -domain-abuse:Registered & inactive - -==== domain-abuse:domain-status="suspended" - -domain-abuse:Registered & suspended - -==== domain-abuse:domain-status="not-registered" - -domain-abuse:Not registered - -==== domain-abuse:domain-status="not-registrable" - -domain-abuse:Not registrable - -==== domain-abuse:domain-status="grace-period" - -domain-abuse:Grace period - -== iep -NOTE: iep namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/iep/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) framework - -=== id -==== iep:id="$text" - -iep:An id value is required - -=== version -==== iep:version="$text" - -iep:A version value is required - -=== name -==== iep:name="$text" - -iep:A name value is required - -=== start-date -==== iep:start-date="$text" - -iep:A start-date value is required - -=== end-date -==== iep:end-date="$text" - -iep:An end-date value is required - -=== reference -==== iep:reference="$text" - -iep:A reference value is required - -=== commercial-use -==== iep:commercial-use="MAY" - -iep:Recipients MAY use this information in commercial products or services. - -==== iep:commercial-use="MUST NOT" - -iep:Recipients MUST NOT use this information in commercial products or services. - -=== external-reference -==== iep:external-reference="$text" - -iep:An external-reference value is required - -=== encrypt-in-transit -==== iep:encrypt-in-transit="MUST" - -iep:Recipients MUST encrypt the information received when it is retransmitted or redistributed. - -==== iep:encrypt-in-transit="MAY" - -iep:Recipients MAY encrypt the information received when it is retransmitted or redistributed. - -=== encrypt-at-rest -==== iep:encrypt-at-rest="MUST" - -iep:Recipients MUST encrypt the information received when it is stored at rest. - -==== iep:encrypt-at-rest="MAY" - -iep:Recipients MAY encrypt the information received when it is stored at rest. - -=== permitted-actions -==== iep:permitted-actions="NONE" - -iep:Recipients MUST contact the Providers before acting upon the information received. - -==== iep:permitted-actions="CONTACT FOR INSTRUCTION" - -iep:Recipients MUST contact the Providers before acting upon the information received. - -==== iep:permitted-actions="INTERNALLY VISIBLE ACTIONS" - -iep:Recipients MAY conduct actions on the information received that are only visible on the Recipients internal networks and systems, and MUST NOT conduct actions that are visible outside of the Recipients networks and systems, or visible to third parties. - -==== iep:permitted-actions="EXTERNALLY VISIBLE INDIRECT ACTIONS" - -iep:Recipients MAY conduct indirect, or passive, actions on the information received that are externally visible and MUST NOT conduct direct, or active, actions. - -==== iep:permitted-actions="EXTERNALLY VISIBLE DIRECT ACTIONS" - -iep:Recipients MAY conduct direct, or active, actions on the information received that are externally visible. - -=== affected-party-notifications -==== iep:affected-party-notifications="MAY" - -iep:Recipients MAY notify affected parties of a potential compromise or threat. - -==== iep:affected-party-notifications="MUST NOT" - -iep:Recipients MUST NOT notify affected parties of potential compromise or threat. - -=== traffic-light-protocol -==== iep:traffic-light-protocol="RED" - -iep:Personal for identified recipients only. - -==== iep:traffic-light-protocol="AMBER" - -iep:Limited sharing on the basis of need-to-know. - -==== iep:traffic-light-protocol="GREEN" - -iep:Community wide sharing. - -==== iep:traffic-light-protocol="WHITE" - -iep:Unlimited sharing. - -=== provider-attribution -==== iep:provider-attribution="MAY" - -iep:Recipients MAY attribute the Provider when redistributing the information received. - -==== iep:provider-attribution="MUST" - -iep:Recipients MUST attribute the Provider when redistributing the information received. - -==== iep:provider-attribution="MUST NOT" - -iep:Recipients MUST NOT attribute the Provider when redistributing the information received. - -=== obfuscate-affected-parties -==== iep:obfuscate-affected-parties="MAY" - -iep:Recipients MAY obfuscate information about the specific affected parties. - -==== iep:obfuscate-affected-parties="MUST" - -iep:Recipients MUST obfuscate information about the specific affected parties. - -==== iep:obfuscate-affected-parties="MUST NOT" - -iep:Recipients MUST NOT obfuscate information about the specific affected parties. - -=== unmodified-resale -==== iep:unmodified-resale="MAY" - -iep:Recipients MAY resell the information received. - -==== iep:unmodified-resale="MUST NOT" - -iep:Recipients MUST NOT resell the information received unmodified or in a semantically equivalent format. - -== stealth_malware -NOTE: stealth_malware namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/stealth_malware/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Classification based on malware stealth techniques. Described in https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf - -=== type -==== stealth_malware:type="0" - -stealth_malware:No OS or system compromise. The malware runs as a normal user process using only official API calls. - -==== stealth_malware:type="I" - -stealth_malware:The malware modifies constant sections of the kernel and/or processes such as code sections. - -==== stealth_malware:type="II" - -stealth_malware:The malware does not modify constant sections but only the dynamic sections of the kernel and/or processes such as data sections. - -==== stealth_malware:type="III" - -stealth_malware:The malware does not modify any sections of the kernel and/or processes but influences the system without modifying the OS. For example using hardware virtualization techniques. - -== stealth_malware -NOTE: stealth_malware namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/stealth_malware/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Classification based on malware stealth techniques. Described in https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf - -=== type -==== stealth_malware:type="0" - -stealth_malware:No OS or system compromise. The malware runs as a normal user process using only official API calls. - -==== stealth_malware:type="I" - -stealth_malware:The malware modifies constant sections of the kernel and/or processes such as code sections. - -==== stealth_malware:type="II" - -stealth_malware:The malware does not modify constant sections but only the dynamic sections of the kernel and/or processes such as data sections. - -==== stealth_malware:type="III" - -stealth_malware:The malware does not modify any sections of the kernel and/or processes but influences the system without modifying the OS. For example using hardware virtualization techniques. - -== open_threat -NOTE: open_threat namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/open_threat/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Open Threat Taxonomy v1.1 base on James Tarala of SANS http://www.auditscripts.com/resources/open_threat_taxonomy_v1.1a.pdf, https://files.sans.org/summit/Threat_Hunting_Incident_Response_Summit_2016/PDFs/Using-Open-Tools-to-Convert-Threat-Intelligence-into-Practical-Defenses-James-Tarala-SANS-Institute.pdf, https://www.youtube.com/watch?v=5rdGOOFC_yE, and https://www.rsaconference.com/writable/presentations/file_upload/str-r04_using-an-open-source-threat-model-for-prioritized-defense-final.pdf - -=== threat-category -==== open_threat:threat-category="Physical" - -open_threat:Threats to the confidentiality, integrity, or availability of information systems that are physical in nature. These threats generally describe actions that could lead to the theft, harm, or destruction of information systems. - -==== open_threat:threat-category="Resource" - -open_threat:Threats to the confidentiality, integrity, or availability of information systems that are the result of a lack of resources required by the information system. These threats often cause failures of information systems through a disruption of resources required for operations. - -==== open_threat:threat-category="Personal" - -open_threat:Threats to the confidentiality, integrity, or availability of information systems that are the result of failures or actions performed by an organization’s personnel. These threats can be the result of deliberate or accidental actions that cause harm to information systems. - -==== open_threat:threat-category="Technical" - -open_threat:Threats to the confidentiality, integrity, or availability of information systems that are technical in nature. These threats are most often considered when identifying threats and constitute the technical actions performed by a threat actor that can cause harm to an information system. - -=== threat-name -==== open_threat:threat-name="PHY-001" - -open_threat:Loss of Property - Rating: 5.0 - -==== open_threat:threat-name="PHY-002" - -open_threat:Theft of Property - Rating: 5.0 - -==== open_threat:threat-name="PHY-003" - -open_threat:Accidental Destruction of Property - Rating: 3.0 - -==== open_threat:threat-name="PHY-004" - -open_threat:Natural Destruction of Property - Rating: 3.0 - -==== open_threat:threat-name="PHY-005" - -open_threat:Intentional Destruction of Property - Rating: 2.0 - -==== open_threat:threat-name="PHY-006" - -open_threat:Intentional Sabotage of Property - Rating: 2.0 - -==== open_threat:threat-name="PHY-007" - -open_threat:Intentional Vandalism of Property - Rating: 2.0 - -==== open_threat:threat-name="PHY-008" - -open_threat:Electrical System Failure - Rating: 4.0 - -==== open_threat:threat-name="PHY-009" - -open_threat:Heating, Ventilation, Air Conditioning (HVAC) Failure - Rating: 3.0 - -==== open_threat:threat-name="PHY-010" - -open_threat:Structural Facility Failure - Rating: 2.0 - -==== open_threat:threat-name="PHY-011" - -open_threat:Water Distribution System Failure - Rating: 2.0 - -==== open_threat:threat-name="PHY-012" - -open_threat:Sanitation System Failure - Rating: 1.0 - -==== open_threat:threat-name="PHY-013" - -open_threat:Natural Gas Distribution Failure - Rating: 1.0 - -==== open_threat:threat-name="PHY-014" - -open_threat:Electronic Media Failure - Rating: 3.0 - -==== open_threat:threat-name="RES-001" - -open_threat:Disruption of Water Resources - Rating: 2.0 - -==== open_threat:threat-name="RES-002" - -open_threat:Disruption of Fuel Resources - Rating: 2.0 - -==== open_threat:threat-name="RES-003" - -open_threat:Disruption of Materials Resources - Rating: 2.0 - -==== open_threat:threat-name="RES-004" - -open_threat:Disruption of Electrical Resources - Rating: 4.0 - -==== open_threat:threat-name="RES-005" - -open_threat:Disruption of Transportation Services - Rating: 1.0 - -==== open_threat:threat-name="RES-006" - -open_threat:Disruption of Communications Services - Rating: 4.0 - -==== open_threat:threat-name="RES-007" - -open_threat:Disruption of Emergency Services - Rating: 1.0 - -==== open_threat:threat-name="RES-008" - -open_threat:Disruption of Governmental Services - Rating: 1.0 - -==== open_threat:threat-name="RES-009" - -open_threat:Supplier Viability - Rating: 2.0 - -==== open_threat:threat-name="RES-010" - -open_threat:Supplier Supply Chain Failure - Rating: 2.0 - -==== open_threat:threat-name="RES-011" - -open_threat:Logistics Provider Failures - Rating: 1.0 - -==== open_threat:threat-name="RES-012" - -open_threat:Logistics Route Disruptions - Rating: 1.0 - -==== open_threat:threat-name="RES-013" - -open_threat:Technology Services Manipulation - Rating: 3.0 - -==== open_threat:threat-name="PER-001" - -open_threat:Personnel Labor / Skills Shortage - Rating: 5.0 - -==== open_threat:threat-name="PER-002" - -open_threat:Loss of Personnel Resources - Rating: 3.0 - -==== open_threat:threat-name="PER-003" - -open_threat:Disruption of Personnel Resources - Rating: 3.0 - -==== open_threat:threat-name="PER-004" - -open_threat:Social Engineering of Personnel Resources - Rating: 4.0 - -==== open_threat:threat-name="PER-005" - -open_threat:Negligent Personnel Resources - Rating: 4.0 - -==== open_threat:threat-name="PER-006" - -open_threat:Personnel Mistakes / Errors - Rating: 4.0 - -==== open_threat:threat-name="PER-007" - -open_threat:Personnel Inaction - Rating: 3.0 - -==== open_threat:threat-name="TEC-001" - -open_threat:Organizational Fingerprinting via Open Sources - Rating: - -==== open_threat:threat-name="TEC-002" - -open_threat:System Fingerprinting via Open Sources - Rating: 2.0 - -==== open_threat:threat-name="TEC-003" - -open_threat:System Fingerprinting via Scanning - Rating: 2.0 - -==== open_threat:threat-name="TEC-004" - -open_threat:System Fingerprinting via Sniffing - Rating: 2.0 - -==== open_threat:threat-name="TEC-005" - -open_threat:Credential Discovery via Open Sources - Rating: 4.0 - -==== open_threat:threat-name="TEC-006" - -open_threat:Credential Discovery via Scanning - Rating: 3.0 - -==== open_threat:threat-name="TEC-007" - -open_threat:Credential Discovery via Sniffing - Rating: 4.0 - -==== open_threat:threat-name="TEC-008" - -open_threat:Credential Discovery via Brute Force - Rating: 4.0 - -==== open_threat:threat-name="TEC-009" - -open_threat:Credential Discovery via Cracking - Rating: 4.0 - -==== open_threat:threat-name="TEC-010" - -open_threat:Credential Discovery via Guessing - Rating: 2.0 - -==== open_threat:threat-name="TEC-011" - -open_threat:Credential Discovery via Pre-Computational Attacks - Rating: 3.0 - -==== open_threat:threat-name="TEC-012" - -open_threat:Misuse of System Credentials - Rating: 3.0 - -==== open_threat:threat-name="TEC-013" - -open_threat:Escalation of Privilege - Rating: 5.0 - -==== open_threat:threat-name="TEC-014" - -open_threat:Abuse of System Privileges - Rating: 4.0 - -==== open_threat:threat-name="TEC-015" - -open_threat:Memory Manipulation - Rating: 4.0 - -==== open_threat:threat-name="TEC-016" - -open_threat:Cache Poisoning - Rating: 3.0 - -==== open_threat:threat-name="TEC-017" - -open_threat:Physical Manipulation of Technical Device - Rating: 2.0 - -==== open_threat:threat-name="TEC-018" - -open_threat:Manipulation of Trusted System - Rating: 4.0 - -==== open_threat:threat-name="TEC-019" - -open_threat:Cryptanalysis - Rating: 1.0 - -==== open_threat:threat-name="TEC-020" - -open_threat:Data Leakage / Theft - Rating: 3.0 - -==== open_threat:threat-name="TEC-021" - -open_threat:Denial of Service - Rating: 2.0 - -==== open_threat:threat-name="TEC-022" - -open_threat:Maintaining System Persistence - Rating: 5.0 - -==== open_threat:threat-name="TEC-023" - -open_threat:Manipulation of Data in Transit / Use - Rating: 2.0 - -==== open_threat:threat-name="TEC-024" - -open_threat:Capture of Data in Transit / Use via Sniffing - Rating: 3.0 - -==== open_threat:threat-name="TEC-025" - -open_threat:Capture of Data in Transit / Use via Debugging - Rating: 2.0 - -==== open_threat:threat-name="TEC-026" - -open_threat:Capture of Data in Transit / Use via Keystroke Logging - Rating: 3.0 - -==== open_threat:threat-name="TEC-027" - -open_threat:Replay of Data in Transit / Use - Rating: 2.0 - -==== open_threat:threat-name="TEC-028" - -open_threat:Misdelivery of Data - Rating: 2.0 - -==== open_threat:threat-name="TEC-029" - -open_threat:Capture of Stored Data - Rating: 3.0 - -==== open_threat:threat-name="TEC-030" - -open_threat:Manipulation of Stored Data - Rating: 3.0 - -==== open_threat:threat-name="TEC-031" - -open_threat:Application Exploitation via Input Manipulation - Rating: 5.0 - -==== open_threat:threat-name="TEC-032" - -open_threat:Application Exploitation via Parameter Injection - Rating: 4.0 - -==== open_threat:threat-name="TEC-033" - -open_threat:Application Exploitation via Code Injection - Rating: 4.0 - -==== open_threat:threat-name="TEC-034" - -open_threat:Application Exploitation via Command Injection - Rating: 4.0 - -==== open_threat:threat-name="TEC-035" - -open_threat:Application Exploitation via Path Traversal - Rating: 3.0 - -==== open_threat:threat-name="TEC-036" - -open_threat:Application Exploitation via API Abuse - Rating: 3.0 - -==== open_threat:threat-name="TEC-037" - -open_threat:Application Exploitation via Fuzzing - Rating: 3.0 - -==== open_threat:threat-name="TEC-038" - -open_threat:Application Exploitation via Reverse Engineering - Rating: 3.0 - -==== open_threat:threat-name="TEC-039" - -open_threat:Application Exploitation via Resource Location Guessing - Rating: 2.0 - -==== open_threat:threat-name="TEC-040" - -open_threat:Application Exploitation via Source Code Manipulation - Rating: 3.0 - -==== open_threat:threat-name="TEC-041" - -open_threat:Application Exploitation via Authentication Bypass - Rating: 2.0 - -== targeted-threat-index -NOTE: targeted-threat-index namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/targeted-threat-index/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The Targeted Threat Index is a metric for assigning an overall threat ranking score to email messages that deliver malware to a victim’s computer. The TTI metric was first introduced at SecTor 2013 by Seth Hardy as part of the talk “RATastrophe: Monitoring a Malware Menagerie” along with Katie Kleemola and Greg Wiseman. - -=== targeting-sophistication-base-value -==== targeted-threat-index:targeting-sophistication-base-value="not-targeted" - -targeted-threat-index:Not targeted, e.g. spam or financially motivated malware. - -==== targeted-threat-index:targeting-sophistication-base-value="targeted-but-not-customized" - -targeted-threat-index:Targeted but not customized. Sent with a message that is obviously false with little to no validation required. - -==== targeted-threat-index:targeting-sophistication-base-value="targeted-and-poorly-customized" - -targeted-threat-index:Targeted and poorly customized. Content is generally relevant to the target. May look questionable. - -==== targeted-threat-index:targeting-sophistication-base-value="targeted-and-customized" - -targeted-threat-index:Targeted and customized. May use a real person/organization or content to convince the target the message is legitimate. Content is specifically relevant to the target and looks legitimate. - -==== targeted-threat-index:targeting-sophistication-base-value="targeted-and-well-customized" - -targeted-threat-index:Targeted and well-customized. Uses a real person/organization and content to convince the target the message is legitimate. Probably directly addressing the recipient. Content is specifically relevant to the target, looks legitimate, and can be externally referenced (e.g. by a website). May be sent from a hacked account. - -==== targeted-threat-index:targeting-sophistication-base-value="targeted-and-highly-customized-using-sensitive-data" - -targeted-threat-index:Targeted and highly customized using sensitive data. Individually targeted and customized, likely using inside/sensitive information that is directly relevant to the target. - -=== technical-sophistication-multiplier -==== targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-no code-protection" - -targeted-threat-index:The sample contains no code protection such as packing, obfuscation (e.g. simple rotation of C2 names or other interesting strings), or anti-reversing tricks. - -==== targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-a-simple-method-of-protection" - -targeted-threat-index:The sample contains a simple method of protection, such as one of the following: code protection using publicly available tools where the reverse method is available, such as UPX packing; simple anti-reversing techniques such as not using import tables, or a call to IsDebuggerPresent(); self-disabling in the presence of AV software. - -==== targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-multiple-minor-code-protection-techniques" - -targeted-threat-index:The sample contains multiple minor code protection techniques (anti-reversing tricks, packing, VM / reversing tools detection) that require some low-level knowledge. This level includes malware where code that contains the core functionality of the program is decrypted only in memory. - -==== targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-minor-code-protection-techniques-plus-one-advanced" - -targeted-threat-index:The sample contains minor code protection techniques along with at least one advanced protection method such as rootkit functionality or a custom virtualized packer. - -==== targeted-threat-index:technical-sophistication-multiplier="the-sample-contains-multiple-advanced-protection-techniques" - -targeted-threat-index:The sample contains multiple advanced protection techniques, e.g. rootkit capability, virtualized packer, multiple anti-reversing techniques, and is clearly designed by a professional software engineering team. - -== rt_event_status -NOTE: rt_event_status namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/rt_event_status/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Status of events used in Request Tracker. - -=== event-status -==== rt_event_status:event-status="new" - -rt_event_status:New - -==== rt_event_status:event-status="open" - -rt_event_status:Open - -==== rt_event_status:event-status="stalled" - -rt_event_status:Stalled - -==== rt_event_status:event-status="rejected" - -rt_event_status:rejected - -==== rt_event_status:event-status="resolved" - -rt_event_status:Resolved - -==== rt_event_status:event-status="deleted" - -rt_event_status:Deleted - -== europol-incident -NOTE: europol-incident namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/europol-incident/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -This taxonomy was designed to describe the type of incidents by class. - -=== malware -==== europol-incident:malware="infection" - -europol-incident:Infection - -==== europol-incident:malware="distribution" - -europol-incident:Distribution - -==== europol-incident:malware="c&c" - -europol-incident:C&C - -==== europol-incident:malware="undetermined" - -europol-incident:Undetermined - -=== availability -==== europol-incident:availability="dos-ddos" - -europol-incident:DoS/DDoS - -==== europol-incident:availability="sabotage" - -europol-incident:Sabotage - -=== information-gathering -==== europol-incident:information-gathering="scanning" - -europol-incident:Scanning - -==== europol-incident:information-gathering="sniffing" - -europol-incident:Sniffing - -==== europol-incident:information-gathering="phishing" - -europol-incident:Phishing - -=== intrusion-attempt -==== europol-incident:intrusion-attempt="exploitation-vulnerability" - -europol-incident:Exploitation of vulnerability - -==== europol-incident:intrusion-attempt="login-attempt" - -europol-incident:Login attempt - -=== intrusion -==== europol-incident:intrusion="exploitation-vulnerability" - -europol-incident:Exploitation of vulnerability - -==== europol-incident:intrusion="compromising-account" - -europol-incident:Compromising an account - -=== information-security -==== europol-incident:information-security="unauthorized-access" - -europol-incident:Unauthorised access - -==== europol-incident:information-security="unauthorized-modification" - -europol-incident:Unauthorised modification/deletion - -=== fraud -==== europol-incident:fraud="illegitimate-use-resources" - -europol-incident:Misuse or unauthorised use of resources - -==== europol-incident:fraud="illegitimate-use-name" - -europol-incident:Illegitimate use of the name of a third party - -=== abusive-content -==== europol-incident:abusive-content="spam" - -europol-incident:SPAM - -==== europol-incident:abusive-content="copyright" - -europol-incident:Copyright - -==== europol-incident:abusive-content="content-forbidden-by-law" - -europol-incident:Dissemination of content forbidden by law. - -=== other -==== europol-incident:other="other" - -europol-incident:Other - -== diamond-model -NOTE: diamond-model namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/diamond-model/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The Diamond Model for Intrusion Analysis, a phase-based model developed by Lockheed Martin, aims to help categorise and identify the stage of an attack. - -=== Adversary -==== diamond-model:Adversary - -diamond-model:An adversary is the actor/organization responsible for utilizing a capability against the victim to achieve their intent. - -=== Capability -==== diamond-model:Capability - -diamond-model:The capability describes the tools and/or techniques of the adversary used in the event. It includes all means to affect the victim from the most manual “unsophisticated” methods (e.g., manual password guessing) to the most sophisticated automated techniques. - -=== Infrastructure -==== diamond-model:Infrastructure - -diamond-model:The infrastructure feature describes the physical and/or logical communication structures the adversary uses to deliver a capability, maintain control of capabilities (e.g., commandand-control/C2), and effect results from the victim (e.g., exfiltrate data). As with the other features, the infrastructure can be as specific or broad as necessary. Examples include: Internet Protocol (IP) addresses, domain names, e-mail addresses, Morse code flashes from a phone’s voice-mail light watched from across a street, USB devices found in a parking lot and inserted into a workstation, or the compromising emanations from hardware (e.g., Van Eck Phreaking) being collected by a nearby listening post. - -=== Victim -==== diamond-model:Victim - -diamond-model:A victim is the target of the adversary and against whom vulnerabilities and exposures are exploited and capabilities used. A victim can be described in whichever way necessary and appropriate: organization, person, target email address, IP address, domain, etc. However, it is useful to define the victim persona and their assets separately as they serve different analytic functions. Victim personae are useful in non-technical analysis such as cyber-victimology and social-political centered approaches whereas victim assets are associated with common technical approaches such as vulnerability analysis.. - -== euci -NOTE: euci namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/euci/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -EU classified information (EUCI) means any information or material designated by a EU security classification, the unauthorised disclosure of which could cause varying degrees of prejudice to the interests of the European Union or of one or more of the Member States. - -=== TS-UE/EU-TS -==== euci:TS-UE/EU-TS - -euci:TRES SECRET UE/EU TOP SECRET - - -euci:Information and material the unauthorised disclosure of which could cause exceptionally grave prejudice to the essential interests of the European Union or of one or more of the Member States. - -=== S-UE/EU-S -==== euci:S-UE/EU-S - -euci:SECRET UE/EU SECRET - - -euci:Information and material the unauthorised disclosure of which could seriously harm the essential interests of the European Union or of one or more of the Member States. - -=== C-UE/EU-C -==== euci:C-UE/EU-C - -euci:CONFIDENTIEL UE/EU CONFIDENTIAL - - -euci:Information and material the unauthorised disclosure of which could harm the essential interests of the European Union or of one or more of the Member States. - -=== R-UE/EU-R -==== euci:R-UE/EU-R - -euci:RESTREINT UE/EU RESTRICTED - - -euci:Information and material the unauthorised disclosure of which could be disadvantageous to the interests of the European Union or of one or more of the Member States. - -== misp -NOTE: misp namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/misp/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -MISP taxonomy to infer with MISP behavior or operation. - -=== ui -==== misp:ui="hide" - -misp:tag to hide from the user-interface. - -=== api -==== misp:api="hide" - -misp:tag to hide from the API. - -=== contributor -==== misp:contributor="pgpfingerprint" - -misp:OpenPGP Fingerprint - -=== confidence-level -==== misp:confidence-level="completely-confident" - -misp:Completely confident - -==== misp:confidence-level="usually-confident" - -misp:Usually confident - -==== misp:confidence-level="fairly-confident" - -misp:Fairly confident - -==== misp:confidence-level="rarely-confident" - -misp:Rarely confident - -==== misp:confidence-level="unconfident" - -misp:Unconfident - -==== misp:confidence-level="confidence-cannot-be-evalued" - -misp:Confidence cannot be evaluated - -=== threat-level -==== misp:threat-level="no-risk" - -misp:No risk - -==== misp:threat-level="low-risk" - -misp:Low risk - -==== misp:threat-level="medium-risk" - -misp:Medium risk - -==== misp:threat-level="high-risk" - -misp:High risk - -=== should-not-sync -== nato -NOTE: nato namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/nato/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -NATO classification markings. - -=== classification -==== nato:classification="CTS" - -nato:COSMIC TOP SECRET - -==== nato:classification="CTS-B" - -nato:COSMIC TOP SECRET BOHEMIA - -==== nato:classification="NS" - -nato:NATO SECRET - -==== nato:classification="NC" - -nato:NATO CONFIDENTIAL - -==== nato:classification="NR" - -nato:NATO RESTRICTED - -==== nato:classification="NU" - -nato:NATO UNCLASSIFIED - -==== nato:classification="CTS-A" - -nato:COSMIC TOP SECRET ATOMAL - -==== nato:classification="NS-A" - -nato:SECRET ATOMAL - -==== nato:classification="NC-A" - -nato:CONFIDENTIAL ATOMAL - -== eu-marketop-and-publicadmin -NOTE: eu-marketop-and-publicadmin namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/eu-marketop-and-publicadmin/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Market operators and public administrations that must comply to some notifications requirements under EU NIS directive - -=== critical-infra-operators -==== eu-marketop-and-publicadmin:critical-infra-operators="transport" - -eu-marketop-and-publicadmin:Transport - -==== eu-marketop-and-publicadmin:critical-infra-operators="energy" - -eu-marketop-and-publicadmin:Energy - -==== eu-marketop-and-publicadmin:critical-infra-operators="health" - -eu-marketop-and-publicadmin:Health - -==== eu-marketop-and-publicadmin:critical-infra-operators="financial" - -eu-marketop-and-publicadmin:Financial market operators - -==== eu-marketop-and-publicadmin:critical-infra-operators="banking" - -eu-marketop-and-publicadmin:Banking - -=== info-services -==== eu-marketop-and-publicadmin:info-services="e-commerce" - -eu-marketop-and-publicadmin:e-commerce platforms - -==== eu-marketop-and-publicadmin:info-services="internet-payment" - -eu-marketop-and-publicadmin:Internet payment - -==== eu-marketop-and-publicadmin:info-services="cloud" - -eu-marketop-and-publicadmin:cloud computing - -==== eu-marketop-and-publicadmin:info-services="search-engines" - -eu-marketop-and-publicadmin:search engines - -==== eu-marketop-and-publicadmin:info-services="socnet" - -eu-marketop-and-publicadmin:social networks - -==== eu-marketop-and-publicadmin:info-services="app-stores" - -eu-marketop-and-publicadmin:application stores - -=== public-admin -==== eu-marketop-and-publicadmin:public-admin="public-admin" - -eu-marketop-and-publicadmin:Public Administrations - -== de-vs -NOTE: de-vs namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/de-vs/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -German (DE) Government classification markings (VS). - -=== Einstufung -==== de-vs:Einstufung="STRENG GEHEIM" - -de-vs:STRENG GEHEIM - -==== de-vs:Einstufung="GEHEIM" - -de-vs:GEHEIM - -==== de-vs:Einstufung="VS-VERTRAULICH" - -de-vs:VS-VERTRAULICH - -==== de-vs:Einstufung="VS-NfD" - -de-vs:VS-NUR FÜR DEN DIENSTGEBRAUCH - -=== Schutzwort -==== de-vs:Schutzwort="Dummy" - -de-vs:Dummy - -== dhs-ciip-sectors -NOTE: dhs-ciip-sectors namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/dhs-ciip-sectors/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -DHS critical sectors as in https://www.dhs.gov/critical-infrastructure-sectors - -=== DHS-critical-sectors -==== dhs-ciip-sectors:DHS-critical-sectors="chemical" - -dhs-ciip-sectors:Chemical - -==== dhs-ciip-sectors:DHS-critical-sectors="commercial-facilities" - -dhs-ciip-sectors:Commercial Facilities - -==== dhs-ciip-sectors:DHS-critical-sectors="communications" - -dhs-ciip-sectors:Communications - -==== dhs-ciip-sectors:DHS-critical-sectors="critical-manufacturing" - -dhs-ciip-sectors:Critical Manufacturing - -==== dhs-ciip-sectors:DHS-critical-sectors="dams" - -dhs-ciip-sectors:Dams - -==== dhs-ciip-sectors:DHS-critical-sectors="dib" - -dhs-ciip-sectors:Defense Industrial Base - -==== dhs-ciip-sectors:DHS-critical-sectors="emergency-services" - -dhs-ciip-sectors:Emergency services - -==== dhs-ciip-sectors:DHS-critical-sectors="energy" - -dhs-ciip-sectors:energy - -==== dhs-ciip-sectors:DHS-critical-sectors="financial-services" - -dhs-ciip-sectors:Financial Services - -==== dhs-ciip-sectors:DHS-critical-sectors="food-agriculture" - -dhs-ciip-sectors:Food and Agriculture - -==== dhs-ciip-sectors:DHS-critical-sectors="government-facilities" - -dhs-ciip-sectors:Government Facilities - -==== dhs-ciip-sectors:DHS-critical-sectors="healthcare-public" - -dhs-ciip-sectors:Healthcare and Public Health - -==== dhs-ciip-sectors:DHS-critical-sectors="it" - -dhs-ciip-sectors:Information Technology - -==== dhs-ciip-sectors:DHS-critical-sectors="nuclear" - -dhs-ciip-sectors:Nuclear - -==== dhs-ciip-sectors:DHS-critical-sectors="transport" - -dhs-ciip-sectors:Transportation Systems - -==== dhs-ciip-sectors:DHS-critical-sectors="water" - -dhs-ciip-sectors:Water and water systems - -=== sector -== information-security-indicators -NOTE: information-security-indicators namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/information-security-indicators/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -A full set of operational indicators for organizations to use to benchmark their security posture. - -=== IEX -==== information-security-indicators:IEX="FGY.1" - -information-security-indicators:Forged domain or brand names impersonating or imitating legitimate and genuine names - -==== information-security-indicators:IEX="FGY.2" - -information-security-indicators:Wholly or partly forged websites (excluding parking pages) spoiling company's image or business - -==== information-security-indicators:IEX="SPM.1" - -information-security-indicators:Not requested received bulk messages (spam) targeting organization's registered users - -==== information-security-indicators:IEX="PHI.1" - -information-security-indicators:Phishing targeting company's customers' workstations spoiling company's image or business - -==== information-security-indicators:IEX="PHI.2" - -information-security-indicators:Spear phishing or whaling carried out using social engineering and targeting organization's specific registered users - -==== information-security-indicators:IEX="INT.1" - -information-security-indicators:Intrusion attempts on externally accessible servers - -==== information-security-indicators:IEX="INT.2" - -information-security-indicators:Intrusion on externally accessible servers - -==== information-security-indicators:IEX="INT.3" - -information-security-indicators:Intrusions on internal servers - -==== information-security-indicators:IEX="DFC.1" - -information-security-indicators:Obvious and visible websites defacements - -==== information-security-indicators:IEX="MIS.1" - -information-security-indicators:Servers resources misappropriation by external attackers - -==== information-security-indicators:IEX="DOS.1" - -information-security-indicators:Denial of service attacks on websites - -==== information-security-indicators:IEX="MLW.1" - -information-security-indicators:Attempts to install malware on workstations - -==== information-security-indicators:IEX="MLW.2" - -information-security-indicators:Attempts to install malware on servers - -==== information-security-indicators:IEX="MLW.3" - -information-security-indicators:Malware installed on workstations - -==== information-security-indicators:IEX="MLW.4" - -information-security-indicators:Malware installed on internal servers - -==== information-security-indicators:IEX="PHY.1" - -information-security-indicators:Human intrusion into the organization's perimeter - -=== IMF -==== information-security-indicators:IMF="BRE.1" - -information-security-indicators:Workstations accidental breakdowns or malfunctions - -==== information-security-indicators:IMF="BRE.2" - -information-security-indicators:Servers accidental breakdowns or malfunctions - -==== information-security-indicators:IMF="BRE.3" - -information-security-indicators:Mainframes accidental breakdowns or malfunctions - -==== information-security-indicators:IMF="BRE.4" - -information-security-indicators:Networks accidental breakdowns or malfunctions - -==== information-security-indicators:IMF="MDL.1" - -information-security-indicators:Delivery of email to wrong recipient - -==== information-security-indicators:IMF="LOM.1" - -information-security-indicators:Loss (or theft) of mobile devices belonging to the organization - -==== information-security-indicators:IMF="LOG.1" - -information-security-indicators:Downtime or malfunction of the log production function with possible legal impact - -==== information-security-indicators:IMF="LOG.2" - -information-security-indicators:Absence of possible tracking of the person involved in a security event with possible legal impact - -==== information-security-indicators:IMF="LOG.3" - -information-security-indicators:Downtime or malfunction of the log production function for recordings with evidential value for access to or handling of information that, at this level, is subject to law or regulatory requirements - -=== IDB -==== information-security-indicators:IDB="UID.1" - -information-security-indicators:User impersonation - -==== information-security-indicators:IDB="RGH.1" - -information-security-indicators:Privilege escalation by exploitation of software or configuration vulnerability on an externally accessible server - -==== information-security-indicators:IDB="RGH.2" - -information-security-indicators:Privilege escalation on a server or central application by social engineering - -==== information-security-indicators:IDB="RGH.3" - -information-security-indicators: Use on a server or central application of administrator rights illicitly granted by an administrator - -==== information-security-indicators:IDB="RGH.4" - -information-security-indicators:Use on a server or central application of time-limited granted rights after the planned period - -==== information-security-indicators:IDB="RGH.5" - -information-security-indicators:Abuse of privileges by an administrator on a server or central application - -==== information-security-indicators:IDB="RGH.6" - -information-security-indicators:Abuse of privileges by an operator or a plain user on a server or central application - -==== information-security-indicators:IDB="RGH.7" - -information-security-indicators:Illicit use on a server or central application of rights not removed after departure or position change within the organization - -==== information-security-indicators:IDB="MIS.1" - -information-security-indicators:Server resources misappropriation by an internal source - -==== information-security-indicators:IDB="IAC.1" - -information-security-indicators:Access to hacking Website - -==== information-security-indicators:IDB="LOG.1" - -information-security-indicators:Deactivating of logs recording by an administrator - -=== IWH -==== information-security-indicators:IWH="VNP.1" - -information-security-indicators:Exploitation of a software vulnerability without available patch - -==== information-security-indicators:IWH="VNP.2" - -information-security-indicators:Exploitation of a non-patched software vulnerability - -==== information-security-indicators:IWH="VNP.3" - -information-security-indicators:Exploitation of a poorly-patched software vulnerability - -==== information-security-indicators:IWH="VCN.1" - -information-security-indicators:Exploitation of a configuration flaw - -==== information-security-indicators:IWH="UKN.1" - -information-security-indicators:Not categorized security incidents - -==== information-security-indicators:IWH="UNA.1" - -information-security-indicators:Security incidents on non-inventoried and/or not managed assets - -=== VBH -==== information-security-indicators:VBH="PRC.1" - -information-security-indicators:Server accessed by an administrator with unsecure protocols - -==== information-security-indicators:VBH="PRC.2" - -information-security-indicators:P2P client in a workstation - -==== information-security-indicators:VBH="PRC.3" - -information-security-indicators:VoIP clients in a workstation - -==== information-security-indicators:VBH="PRC.4" - -information-security-indicators:Outbound connection dangerously set up - -==== information-security-indicators:VBH="PRC.5" - -information-security-indicators:Not compliant laptop computer used to establish a connection - -==== information-security-indicators:VBH="PRC.6" - -information-security-indicators:Other unsecure protocols used - -==== information-security-indicators:VBH="IAC.1" - -information-security-indicators:Outbound controls bypassed to access Internet - -==== information-security-indicators:VBH="IAC.2" - -information-security-indicators:Anonymization site used to access Internet - -==== information-security-indicators:VBH="FTR.1" - -information-security-indicators:Files recklessly downloaded - -==== information-security-indicators:VBH="FTR.2" - -information-security-indicators:Personal public instant messaging account used for business file exchanges - -==== information-security-indicators:VBH="FTR.3" - -information-security-indicators:Personal public messaging account used for business file exchanges - -==== information-security-indicators:VBH="WTI.1" - -information-security-indicators:Workstations accessed in administrator mode - -==== information-security-indicators:VBH="WTI.2" - -information-security-indicators:Personal storage devices used - -==== information-security-indicators:VBH="WTI.3" - -information-security-indicators:Personal devices used without compartmentalization (BYOD) - -==== information-security-indicators:VBH="WTI.4" - -information-security-indicators:Not encrypted sensitive files exported - -==== information-security-indicators:VBH="WTI.5" - -information-security-indicators:Personal software used - -==== information-security-indicators:VBH="WTI.6" - -information-security-indicators:Mailbox or Internet access with admin mode - -==== information-security-indicators:VBH="PSW.1" - -information-security-indicators:Weak passwords used - -==== information-security-indicators:VBH="PSW.2" - -information-security-indicators:Passwords not changed - -==== information-security-indicators:VBH="PSW.3" - -information-security-indicators:Administrator passwords not changed - -==== information-security-indicators:VBH="RGH.1" - -information-security-indicators:Not compliant user rights granted illicitly by an administrator - -==== information-security-indicators:VBH="HUW.1" - -information-security-indicators:Human weakness exploited by a spear phishing message meant to entice or appeal to do something possibly harmful to the organization - -==== information-security-indicators:VBH="HUW.2" - -information-security-indicators: Human weakness exploited by exchanges meant to entice or appeal to tell some secrets to be used later - -=== VSW -==== information-security-indicators:VSW="WSR.1" - -information-security-indicators:Web applications software vulnerabilities - -==== information-security-indicators:VSW="OSW.1" - -information-security-indicators:OS software vulnerabilities regarding servers - -==== information-security-indicators:VSW="WBR.1" - -information-security-indicators:Web browsers software vulnerabilities - -=== VCF -==== information-security-indicators:VCF="DIS.1" - -information-security-indicators:Dangerous or illicit services on externally accessible servers - -==== information-security-indicators:VCF="LOG.1" - -information-security-indicators:Insufficient size of the space allocated for logs - -==== information-security-indicators:VCF="FWR.1" - -information-security-indicators:Weak firewall filtering rules - -==== information-security-indicators:VCF="WTI.1" - -information-security-indicators:Workstation wrongly configured - -==== information-security-indicators:VCF="WTI.2" - -information-security-indicators:Autorun feature enabled on workstations - -==== information-security-indicators:VCF="UAC.1" - -information-security-indicators:Access rights configuration not compliant with the security policy - -==== information-security-indicators:VCF="UAC.2" - -information-security-indicators:Not compliant access rights on logs - -==== information-security-indicators:VCF="UAC.3" - -information-security-indicators:Generic and shared administrator accounts - -==== information-security-indicators:VCF="UAC.4" - -information-security-indicators:Accounts without owners - -==== information-security-indicators:VCF="UAC.5" - -information-security-indicators:Inactive accounts - -=== VTC -==== information-security-indicators:VTC="BKP.1" - -information-security-indicators:Malfunction of server-hosted sensitive data safeguards - -==== information-security-indicators:VTC="IDS.1" - -information-security-indicators:Full unavailability of IDS/IPS - -==== information-security-indicators:VTC="WFI.1" - -information-security-indicators:Wi-Fi devices installed on the network without any official authorization - -==== information-security-indicators:VTC="RAP.1" - -information-security-indicators:Remote access points used to gain unauthorized access - -==== information-security-indicators:VTC="NRG.1" - -information-security-indicators:Devices or servers connected to the organization's network without being registered and managed - -==== information-security-indicators:VTC="PHY.1" - -information-security-indicators:Not operational physical access control means - -=== VOR -==== information-security-indicators:VOR="DSC.1" - -information-security-indicators:Discovery of attacks - -==== information-security-indicators:VOR="VNP.1" - -information-security-indicators:Excessive time of window of risk exposure - -==== information-security-indicators:VOR="VNP.2" - -information-security-indicators:Rate of not patched systems - -==== information-security-indicators:VOR="VNR.1" - -information-security-indicators:Rate of not reconfigured systems - -==== information-security-indicators:VOR="RCT.1" - -information-security-indicators:Reaction plans launched without experience feedback - -==== information-security-indicators:VOR="RCT.2" - -information-security-indicators:Reaction plans unsuccessfully launched - -==== information-security-indicators:VOR="PRT.1" - -information-security-indicators:Launch of new IT projects without information classification - -==== information-security-indicators:VOR="PRT.2" - -information-security-indicators:Launch of new specific IT projects without risk analysis - -==== information-security-indicators:VOR="PRT.3" - -information-security-indicators: Launch of new IT projects of a standard type without identification of vulnerabilities and threats - -=== IMP -==== information-security-indicators:IMP="COS.1" - -information-security-indicators:Average cost to tackle a critical security incident - -==== information-security-indicators:IMP="TIM.1" - -information-security-indicators:Average time of Websites downtime due to whole security incidents - -==== information-security-indicators:IMP="TIM.2" - -information-security-indicators:Average time of Websites downtime due to successful malicious attacks - -==== information-security-indicators:IMP="TIM.3" - -information-security-indicators:Average time of Websites downtime due to malfunctions or unintentional security incidents - -== europol-event -NOTE: europol-event namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/europol-event/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -This taxonomy was designed to describe the type of events - -=== infected-by-known-malware -==== europol-event:infected-by-known-malware - -europol-event:System(s) infected by known malware - - -europol-event:The presence of any of the types of malware was detected in a system. - -=== dissemination-malware-email -==== europol-event:dissemination-malware-email - -europol-event:Dissemination of malware by email - - -europol-event:Malware attached to a message or email message containing link to malicious URL. - -=== hosting-malware-webpage -==== europol-event:hosting-malware-webpage - -europol-event:Hosting of malware on web page - - -europol-event: Web page disseminating one or various types of malware. - -=== c&c-server-hosting -==== europol-event:c&c-server-hosting - -europol-event:Hosting of malware on web page - - -europol-event:Web page disseminating one or various types of malware. - -=== worm-spreading -==== europol-event:worm-spreading - -europol-event:Replication and spreading of a worm - - -europol-event:System infected by a worm trying to infect other systems. - -=== connection-malware-port -==== europol-event:connection-malware-port - -europol-event:Connection to (a) suspicious port(s) linked to specific malware - - -europol-event:System attempting to gain access to a port normally linked to a specific type of malware. - -=== connection-malware-system -==== europol-event:connection-malware-system - -europol-event:Connection to (a) suspicious system(s) linked to specific malware - - -europol-event:System attempting to gain access to an IP address or URL normally linked to a specific type of malware, e.g. C&C or a distribution page for components linked to a specific botnet. - -=== flood -==== europol-event:flood - -europol-event:Flood of requests - - -europol-event:Mass mailing of requests (network packets, emails, etc...) from one single source to a specific service, aimed at affecting its normal functioning. - -=== exploit-tool-exhausting-resources -==== europol-event:exploit-tool-exhausting-resources - -europol-event:Exploit or tool aimed at exhausting resources (network, processing capacity, sessions, etc...) - - -europol-event:One single source using specially designed software to affect the normal functioning of a specific service, by exploiting a vulnerability. - -=== packet-flood -==== europol-event:packet-flood - -europol-event:Packet flooding - - -europol-event:Mass mailing of requests (network packets, emails, etc...) from various sources to a specific service, aimed at affecting its normal functioning. - -=== exploit-framework-exhausting-resources -==== europol-event:exploit-framework-exhausting-resources - -europol-event:Exploit or tool distribution aimed at exhausting resources - - -europol-event:Various sources using specially designed software to affect the normal functioning of a specific service, by exploiting a vulnerability. - -=== vandalism -==== europol-event:vandalism - -europol-event:Vandalism - - -europol-event:Logical and physical activities which – although they are not aimed at causing damage to information or at preventing its transmission among systems – have this effect. - -=== disruption-data-transmission -==== europol-event:disruption-data-transmission - -europol-event:Intentional disruption of data transmission and processing mechanisms - - -europol-event:Logical and physical activities aimed at causing damage to information or at preventing its transmission among systems. - -=== system-probe -==== europol-event:system-probe - -europol-event:System probe - - -europol-event:Single system scan searching for open ports or services using these ports for responding. - -=== network-scanning -==== europol-event:network-scanning - -europol-event:Network scanning - - -europol-event:Scanning a network aimed at identifying systems which are active in the same network. - -=== dns-zone-transfer -==== europol-event:dns-zone-transfer - -europol-event:DNS zone transfer - - -europol-event:Transfer of a specific DNS zone. - -=== wiretapping -==== europol-event:wiretapping - -europol-event:Wiretapping - - -europol-event:Logical or physical interception of communications. - -=== dissemination-phishing-emails -==== europol-event:dissemination-phishing-emails - -europol-event:Dissemination of phishing emails - - -europol-event:Mass emailing aimed at collecting data for phishing purposes with regard to the victims. - -=== hosting-phishing-sites -==== europol-event:hosting-phishing-sites - -europol-event:Hosting phishing sites - - -europol-event:Hosting web sites for phishing purposes. - -=== aggregation-information-phishing-schemes -==== europol-event:aggregation-information-phishing-schemes - -europol-event:Aggregation of information gathered through phishing schemes - - -europol-event:Collecting data obtained through phishing attacks on web pages, email accounts, etc... - -=== exploit-attempt -==== europol-event:exploit-attempt - -europol-event:Exploit attempt - - -europol-event:Unsuccessful use of a tool exploiting a specific vulnerability of the system. - -=== sql-injection-attempt -==== europol-event:sql-injection-attempt - -europol-event:SQL injection attempt - - -europol-event:Unsuccessful attempt to manipulate or read the information of a database by using the SQL injection technique. - -=== xss-attempt -==== europol-event:xss-attempt - -europol-event:XSS attempt - - -europol-event:Unsuccessful attempts to perform attacks by using cross-site scripting techniques. - -=== file-inclusion-attempt -==== europol-event:file-inclusion-attempt - -europol-event:File inclusion attempt - - -europol-event:Unsuccessful attempt to include files in the system under attack by using file inclusion techniques. - -=== brute-force-attempt -==== europol-event:brute-force-attempt - -europol-event:Brute force attempt - - -europol-event:Unsuccessful login attempt by using sequential credentials for gaining access to the system. - -=== password-cracking-attempt -==== europol-event:password-cracking-attempt - -europol-event:Password cracking attempt - - -europol-event:Attempt to acquire access credentials by breaking the protective cryptographic keys. - -=== dictionary-attack-attempt -==== europol-event:dictionary-attack-attempt - -europol-event:Dictionary attack attempt - - -europol-event:Unsuccessful login attempt by using system access credentials previously loaded into a dictionary. - -=== exploit -==== europol-event:exploit - -europol-event:Use of a local or remote exploit - - -europol-event:Successful use of a tool exploiting a specific vulnerability of the system. - -=== sql-injection -==== europol-event:sql-injection - -europol-event:SQL injection - - -europol-event:Manipulation or reading of information contained in a database by using the SQL injection technique. - -=== xss -==== europol-event:xss - -europol-event:XSS - - -europol-event:Attacks performed with the use of cross-site scripting techniques. - -=== file-inclusion -==== europol-event:file-inclusion - -europol-event:File inclusion - - -europol-event:Inclusion of files into a system under attack with the use of file inclusion techniques. - -=== control-system-bypass -==== europol-event:control-system-bypass - -europol-event:Control system bypass - - -europol-event:Unauthorised access to a system or component by bypassing an access control system in place. - -=== theft-access-credentials -==== europol-event:theft-access-credentials - -europol-event:Theft of access credentials - - -europol-event:Unauthorised access to a system or component by using stolen access credentials. - -=== unauthorized-access-system -==== europol-event:unauthorized-access-system - -europol-event:Unauthorised access to a system - - -europol-event:Unauthorised access to a system or component. - -=== unauthorized-access-information -==== europol-event:unauthorized-access-information - -europol-event:Unauthorised access to information - - -europol-event:Unauthorised access to a set of information. - -=== data-exfiltration -==== europol-event:data-exfiltration - -europol-event:Data exfiltration - - -europol-event:Unauthorised access to and sharing of a specific set of information. - -=== modification-information -==== europol-event:modification-information - -europol-event:Modification of information - - -europol-event:Unauthorised changes to a specific set of information. - -=== deletion-information -==== europol-event:deletion-information - -europol-event:Deletion of information - - -europol-event:Unauthorised deleting of a specific set of information. - -=== illegitimate-use-resources -==== europol-event:illegitimate-use-resources - -europol-event:Misuse or unauthorised use of resources - - -europol-event:Use of institutional resources for purposes other than those intended. - -=== illegitimate-use-name -==== europol-event:illegitimate-use-name - -europol-event:Illegitimate use of the name of an institution or third party - - -europol-event:Using the name of an institution without permission to do so. - -=== email-flooding -==== europol-event:email-flooding - -europol-event:Email flooding - - -europol-event:Sending an unusually large quantity of email messages. - -=== spam -==== europol-event:spam - -europol-event:Sending an unsolicited message - - -europol-event:Sending an email message that was unsolicited or unwanted by the recipient. - -=== copyrighted-content -==== europol-event:copyrighted-content - -europol-event:Distribution or sharing of copyright protected content - - -europol-event:Distribution or sharing of content protected by copyright and related rights. - -=== content-forbidden-by-law -==== europol-event:content-forbidden-by-law - -europol-event:Dissemination of content forbidden by law (publicly prosecuted offences) - - -europol-event:Distribution or sharing of illegal content such as child pornography, racism, xenophobia, etc... - -=== unspecified -==== europol-event:unspecified - -europol-event:Other unspecified event - - -europol-event:Other unlisted events. - -=== undetermined -==== europol-event:undetermined - -europol-event:Undetermined - - -europol-event:Field aimed at the classification of unprocessed events, which have remained undetermined from the beginning. - -== kill-chain -NOTE: kill-chain namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/kill-chain/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The Cyber Kill Chain, a phase-based model developed by Lockheed Martin, aims to help categorise and identify the stage of an attack. - -=== Reconnaissance -==== kill-chain:Reconnaissance - -kill-chain:Research, identification and selection of targets, often represented as crawling Internet websites such as conference proceedings and mailing lists for email addresses, social relationships, or information on specific technologies. - -=== Weaponisation -==== kill-chain:Weaponisation - -kill-chain:Coupling a remote access trojan with an exploit into a deliverable payload, typically by means of an automated tool (weaponizer). Increasingly, client application data files such as Adobe Portable Document Format (PDF) or Microsoft Office documents serve as the weaponized deliverable. - -=== Delivery -==== kill-chain:Delivery - -kill-chain:Transmission of the weapon to the targeted environment. The three most prevalent delivery vectors for weaponized payloads by APT actors, as observed by the Lockheed Martin Computer Incident Response Team (LM-CIRT) for the years 2004-2010, are email attachments, websites, and USB removable media. - -=== Exploitation -==== kill-chain:Exploitation - -kill-chain:After the weapon is delivered to victim host, exploitation triggers intruders' code. Most often, exploitation targets an application or operating system vulnerability, but it could also more simply exploit the users themselves or leverage an operating system feature that auto-executes code. - -=== Installation -==== kill-chain:Installation - -kill-chain:Installation of a remote access trojan or backdoor on the victim system allows the adversary to maintain persistence inside the environment. - -=== Command and Control -==== kill-chain:Command and Control - -kill-chain:Typically, compromised hosts must beacon outbound to an Internet controller server to establish a C2 channel. APT malware especially requires manual interaction rather than conduct activity automatically. Once the C2 channel establishes, intruders have 'hands on the keyboard' access inside the target environment. - -=== Actions on Objectives -==== kill-chain:Actions on Objectives - -kill-chain:Only now, after progressing through the first six phases, can intruders take actions to achieve their original objectives. Typically, this objective is data exfiltration which involves collecting, encrypting and extracting information from the victim environment; violations of data integrity or availability are potential objectives as well. Alternatively, the intruders may only desire access to the initial victim box for use as a hop point to compromise additional systems and move laterally inside the network. - -== tlp -NOTE: tlp namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/tlp/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The Traffic Light Protocol - or short: TLP - was designed with the objective to create a favorable classification scheme for sharing sensitive information while keeping the control over its distribution at the same time. - -=== red -==== tlp:red - -tlp:(TLP:RED) Information exclusively and directly given to (a group of) individual recipients. Sharing outside is not legitimate. - - -tlp:Not for disclosure, restricted to participants only. Sources may use TLP:RED when information cannot be effectively acted upon by additional parties, and could lead to impacts on a party's privacy, reputation, or operations if misused. Recipients may not share TLP:RED information with any parties outside of the specific exchange, meeting, or conversation in which it was originally disclosed. In the context of a meeting, for example, TLP:RED information is limited to those present at the meeting. In most circumstances, TLP:RED should be exchanged verbally or in person. - -=== amber -==== tlp:amber - -tlp:(TLP:AMBER) Information exclusively given to an organization; sharing limited within the organization to be effectively acted upon. - - -tlp:Limited disclosure, restricted to participants’ organizations. Sources may use TLP:AMBER when information requires support to be effectively acted upon, yet carries risks to privacy, reputation, or operations if shared outside of the organizations involved. Recipients may only share TLP:AMBER information with members of their own organization, and with clients or customers who need to know the information to protect themselves or prevent further harm. Sources are at liberty to specify additional intended limits of the sharing: these must be adhered to. - -=== green -==== tlp:green - -tlp:(TLP:GREEN) Information given to a community or a group of organizations at large. The information cannot be publicly released. - - -tlp:Limited disclosure, restricted to the community. Sources may use TLP:GREEN when information is useful for the awareness of all participating organizations as well as with peers within the broader community or sector. Recipients may share TLP:GREEN information with peers and partner organizations within their sector or community, but not via publicly accessible channels. Information in this category can be circulated widely within a particular community. TLP:GREEN information may not be released outside of the community. - -=== white -==== tlp:white - -tlp:(TLP:WHITE) Information can be shared publicly in accordance with the law. - - -tlp:Disclosure is not limited. Sources may use TLP:WHITE when information carries minimal or no foreseeable risk of misuse, in accordance with applicable rules and procedures for public release. Subject to standard copyright rules, TLP:WHITE information may be distributed without restriction. - -=== ex:chr -==== tlp:ex:chr - -tlp:(TLP:EX:CHR) Information extended with a specific tag called Chatham House Rule (CHR). When this specific CHR tag is mentioned, the attribution (the source of information) must not be disclosed. This additional rule is at the discretion of the initial sender who can decide to apply or not the CHR tag. - -== csirt_case_classification -NOTE: csirt_case_classification namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/csirt_case_classification/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -It is critical that the CSIRT provide consistent and timely response to the customer, and that sensitive information is handled appropriately. This document provides the guidelines needed for CSIRT Incident Managers (IM) to classify the case category, criticality level, and sensitivity level for each CSIRT case. This information will be entered into the Incident Tracking System (ITS) when a case is created. Consistent case classification is required for the CSIRT to provide accurate reporting to management on a regular basis. In addition, the classifications will provide CSIRT IM’s with proper case handling procedures and will form the basis of SLA’s between the CSIRT and other Company departments. - -=== incident-category -==== csirt_case_classification:incident-category="DOS" - -csirt_case_classification:Denial of service / Distributed Denial of service - -==== csirt_case_classification:incident-category="forensics" - -csirt_case_classification:Forensics work - -==== csirt_case_classification:incident-category="compromised-information" - -csirt_case_classification:Attempted or successful destruction, corruption, or disclosure of sensitive corporate information or Intellectual Property - -==== csirt_case_classification:incident-category="compromised-asset" - -csirt_case_classification:Compromised host (root account, Trojan, rootkit), network device, application, user account. - -==== csirt_case_classification:incident-category="unlawful-activity" - -csirt_case_classification:Theft / Fraud / Human Safety / Child Porn - -==== csirt_case_classification:incident-category="internal-hacking" - -csirt_case_classification:Reconnaissance or Suspicious activity originating from inside the Company corporate network, excluding malware - -==== csirt_case_classification:incident-category="external-hacking" - -csirt_case_classification:Reconnaissance or Suspicious Activity originating from outside the Company corporate network (partner network, Internet), excluding malware. - -==== csirt_case_classification:incident-category="malware" - -csirt_case_classification:A virus or worm typically affecting multiple corporate devices. This does not include compromised hosts that are being actively controlled by an attacker via a backdoor or Trojan. - -==== csirt_case_classification:incident-category="email" - -csirt_case_classification:Spoofed email, SPAM, and other email security-related events. - -==== csirt_case_classification:incident-category="consulting" - -csirt_case_classification:Security consulting unrelated to any confirmed incident - -==== csirt_case_classification:incident-category="policy-violation" - -csirt_case_classification:Violation of various policies - -=== criticality-classification -==== csirt_case_classification:criticality-classification="1" - -csirt_case_classification:Incident affecting critical systems or information with potential to be revenue or customer impacting. - -==== csirt_case_classification:criticality-classification="2" - -csirt_case_classification:Incident affecting non-critical systems or information, not revenue or customer impacting. Employee investigations that are time sensitive should typically be classified at this level. - -==== csirt_case_classification:criticality-classification="3" - -csirt_case_classification:Possible incident, non-critical systems. Incident or employee investigations that are not time sensitive. Long-term investigations involving extensive research and/or detailed forensic work. - -=== sensitivity-classification -==== csirt_case_classification:sensitivity-classification="1" - -csirt_case_classification:Extremely Sensitive - -==== csirt_case_classification:sensitivity-classification="2" - -csirt_case_classification:Sensitive - -==== csirt_case_classification:sensitivity-classification="3" - -csirt_case_classification:Not Sensitive - -== ecsirt -NOTE: ecsirt namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/ecsirt/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Incident Classification by the ecsirt.net project WP4 clearinghouse policy and updated by IntelMQ. - -=== abusive-content -==== ecsirt:abusive-content="spam" - -ecsirt:spam - -=== malicious-code -==== ecsirt:malicious-code="malware" - -ecsirt:malware - -==== ecsirt:malicious-code="botnet-drone" - -ecsirt:botnet drone - -==== ecsirt:malicious-code="ransomware" - -ecsirt:ransomware - -==== ecsirt:malicious-code="malware-configuration" - -ecsirt:malware configuration - -==== ecsirt:malicious-code="c&c" - -ecsirt:c&c - -=== information-gathering -==== ecsirt:information-gathering="scanner" - -ecsirt:scanner - -=== intrusion-attempts -==== ecsirt:intrusion-attempts="exploit" - -ecsirt:exploit - -==== ecsirt:intrusion-attempts="brute-force" - -ecsirt:brute-force - -==== ecsirt:intrusion-attempts="ids-alert" - -ecsirt:ids alerts - -=== intrusions -==== ecsirt:intrusions="defacement" - -ecsirt:defacement - -==== ecsirt:intrusions="compromised" - -ecsirt:compromised - -==== ecsirt:intrusions="backdoor" - -ecsirt:backdoor - -=== availability -==== ecsirt:availability="ddos" - -ecsirt:ddos - -=== information-security -=== information-content-security -==== ecsirt:information-content-security="dropzone" - -ecsirt:dropzone - -=== vulnerable -==== ecsirt:vulnerable="vulnerable-service" - -ecsirt:Vulnerable service - -=== fraud -==== ecsirt:fraud="phishing" - -ecsirt:phishing - -=== other -==== ecsirt:other="blacklist" - -ecsirt:blacklist - -==== ecsirt:other="unknown" - -ecsirt:unknown - -=== test -==== ecsirt:test="test" - -ecsirt:Test - -== PAP -NOTE: PAP namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/PAP/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used. - -=== RED -==== PAP:RED - -PAP:(PAP:RED) Non-detectable actions only. Recipients may not use PAP:RED information on the network. Only passive actions on logs, that are not detectable from the outside. - -=== AMBER -==== PAP:AMBER - -PAP:(PAP:AMBER) Passive cross check. Recipients may use PAP:AMBER information for conducting online checks, like using services provided by third parties (e.g. VirusTotal), or set up a monitoring honeypot. - -=== GREEN -==== PAP:GREEN - -PAP:(PAP:GREEN) Active actions allowed. Recipients may use PAP:GREEN information to ping the target, block incoming/outgoing traffic from/to the target or specifically configure honeypots to interact with the target. - -=== WHITE -==== PAP:WHITE - -PAP:(PAP:WHITE) No restrictions in using this information. - -== enisa -NOTE: enisa namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/enisa/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -The present threat taxonomy is an initial version that has been developed on the basis of available ENISA material. This material has been used as an ENISA-internal structuring aid for information collection and threat consolidation purposes. It emerged in the time period 2012-2015. - -=== physical-attack -==== enisa:physical-attack="fraud" - -enisa:Fraud - -==== enisa:physical-attack="fraud-by-employees" - -enisa:Fraud committed by employees - -==== enisa:physical-attack="sabotage" - -enisa:Sabotage - -==== enisa:physical-attack="vandalism" - -enisa:Vandalism - -==== enisa:physical-attack="theft" - -enisa:Theft (of devices, storage media and documents) - -==== enisa:physical-attack="theft-of-mobile-devices" - -enisa:Theft of mobile devices (smartphones/ tablets) - -==== enisa:physical-attack="theft-of-fixed-hardware" - -enisa:Theft of fixed hardware - -==== enisa:physical-attack="theft-of-documents" - -enisa:Theft of documents - -==== enisa:physical-attack="theft-of-backups" - -enisa:Theft of backups - -==== enisa:physical-attack="information-leak-or-unauthorised-sharing" - -enisa:Information leak /sharing - -==== enisa:physical-attack="unauthorised-physical-access-or-unauthorised-entry-to-premises" - -enisa:Unauthorized physical access / Unauthorised entry to premises - -==== enisa:physical-attack="coercion-or-extortion-or-corruption" - -enisa:Coercion, extortion or corruption - -==== enisa:physical-attack="damage-from-the-wafare" - -enisa:Damage from the warfare - -==== enisa:physical-attack="terrorist-attack" - -enisa:Terrorist attack - -=== unintentional-damage -==== enisa:unintentional-damage="information-leak-or-sharing-due-to-human-error" - -enisa:Information leak /sharing due to human error - -==== enisa:unintentional-damage="accidental-leaks-or-sharing-of-data-by-employees" - -enisa:Accidental leaks/sharing of data by employees - -==== enisa:unintentional-damage="leaks-of-data-via-mobile-applications" - -enisa:Leaks of data via mobile applications - -==== enisa:unintentional-damage="leaks-of-data-via-web-applications" - -enisa:Leaks of data via Web applications - -==== enisa:unintentional-damage="leaks-of-information-transferred-by-network" - -enisa:Leaks of information transferred by network - -==== enisa:unintentional-damage="erroneous-use-or-administration-of-devices-and-systems" - -enisa:Erroneous use or administration of devices and systems - -==== enisa:unintentional-damage="loss-of-information-due-to-maintenance-errors-or-operators-errors" - -enisa:Loss of information due to maintenance errors / operators' errors - -==== enisa:unintentional-damage="loss-of-information-due-to-configuration-or-installation error" - -enisa:Loss of information due to configuration/ installation error - -==== enisa:unintentional-damage="increasing-recovery-time" - -enisa:Increasing recovery time - -==== enisa:unintentional-damage="lost-of-information-due-to-user-errors" - -enisa:Loss of information due to user errors - -==== enisa:unintentional-damage="using-information-from-an-unreliable-source" - -enisa:Using information from an unreliable source - -==== enisa:unintentional-damage="unintentional-change-of-data-in-an-information-system" - -enisa:Unintentional change of data in an information system - -==== enisa:unintentional-damage="inadequate-design-and-planning-or-improper-adaptation" - -enisa:Inadequate design and planning or improper adaptation - -==== enisa:unintentional-damage="damage-caused-by-a-third-party" - -enisa:Damage caused by a third party - -==== enisa:unintentional-damage="security-failure-caused-by-third-party" - -enisa:Security failure caused by third party - -==== enisa:unintentional-damage="damages-resulting-from-penetration-testing" - -enisa:Damages resulting from penetration testing - -==== enisa:unintentional-damage="loss-of-information-in-the-cloud" - -enisa:Loss of information in the cloud - -==== enisa:unintentional-damage="loss-of-(integrity-of)-sensitive-information" - -enisa:Loss of (integrity of) sensitive information - -==== enisa:unintentional-damage="loss-of-integrity-of-certificates" - -enisa:Loss of integrity of certificates - -==== enisa:unintentional-damage="loss-of-devices-and-storage-media-and-documents" - -enisa:Loss of devices, storage media and documents - -==== enisa:unintentional-damage="loss-of-devices-or-mobile-devices" - -enisa:Loss of devices/ mobile devices - -==== enisa:unintentional-damage="loss-of-storage-media" - -enisa:Loss of storage media - -==== enisa:unintentional-damage="loss-of-documentation-of-IT-Infrastructure" - -enisa:Loss of documentation of IT Infrastructure - -==== enisa:unintentional-damage="destruction-of-records" - -enisa:Destruction of records - -==== enisa:unintentional-damage="infection-of-removable-media" - -enisa:Infection of removable media - -==== enisa:unintentional-damage="abuse-of-storage" - -enisa:Abuse of storage - -=== disaster -==== enisa:disaster="disaster" - -enisa:Disaster (natural earthquakes, floods, landslides, tsunamis, heavy rains, heavy snowfalls, heavy winds) - -==== enisa:disaster="fire" - -enisa:Fire - -==== enisa:disaster="pollution-dust-corrosion" - -enisa:Pollution, dust, corrosion - -==== enisa:disaster="thunderstrike" - -enisa:Thunderstrike - -==== enisa:disaster="water" - -enisa:Water - -==== enisa:disaster="explosion" - -enisa:Explosion - -==== enisa:disaster="dangerous-radiation-leak" - -enisa:Dangerous radiation leak - -==== enisa:disaster="unfavourable-climatic-conditions" - -enisa:Unfavourable climatic conditions - -==== enisa:disaster="loss-of-data-or-accessibility-of-IT-infrastructure-as-a-result-of-heightened-humidity" - -enisa:Loss of data or accessibility of IT infrastructure as a result of heightened humidity - -==== enisa:disaster="lost-of-data-or-accessibility-of-IT-infrastructure-as-a-result-of-very-high-temperature" - -enisa:Lost of data or accessibility of IT infrastructure as a result of very high temperature - -==== enisa:disaster="threats-from-space-or-electromagnetic-storm" - -enisa:Threats from space / Electromagnetic storm - -==== enisa:disaster="wildlife" - -enisa:Wildlife - -=== failures-malfunction -==== enisa:failures-malfunction="failure-of-devices-or-systems" - -enisa:Failure of devices or systems - -==== enisa:failures-malfunction="failure-of-data-media" - -enisa:Failure of data media - -==== enisa:failures-malfunction="hardware-failure" - -enisa:Hardware failure - -==== enisa:failures-malfunction="failure-of-applications-and-services" - -enisa:Failure of applications and services - -==== enisa:failures-malfunction="failure-of-parts-of-devices-connectors-plug-ins" - -enisa:Failure of parts of devices (connectors, plug-ins) - -==== enisa:failures-malfunction="failure-or-disruption-of-communication-links-communication networks" - -enisa:Failure or disruption of communication links (communication networks) - -==== enisa:failures-malfunction="failure-of-cable-networks" - -enisa:Failure of cable networks - -==== enisa:failures-malfunction="failure-of-wireless-networks" - -enisa:Failure of wireless networks - -==== enisa:failures-malfunction="failure-of-mobile-networks" - -enisa:Failure of mobile networks - -==== enisa:failures-malfunction="failure-or-disruption-of-main-supply" - -enisa:Failure or disruption of main supply - -==== enisa:failures-malfunction="failure-or-disruption-of-power-supply" - -enisa:Failure or disruption of power supply - -==== enisa:failures-malfunction="failure-of-cooling-infrastructure" - -enisa:Failure of cooling infrastructure - -==== enisa:failures-malfunction="failure-or-disruption-of-service-providers-supply-chain" - -enisa:Failure or disruption of service providers (supply chain) - -==== enisa:failures-malfunction="malfunction-of-equipment-devices-or-systems" - -enisa:Malfunction of equipment (devices or systems) - -=== outages -==== enisa:outages="absence-of-personnel" - -enisa:Absence of personnel - -==== enisa:outages="strike" - -enisa:Strike - -==== enisa:outages="loss-of-support-services" - -enisa:Loss of support services - -==== enisa:outages="internet-outage" - -enisa:Internet outage - -==== enisa:outages="network-outage" - -enisa:Network outage - -==== enisa:outages="outage-of-cable-networks" - -enisa:Outage of cable networks - -==== enisa:outages="Outage-of-short-range-wireless-networks" - -enisa:Outage of short-range wireless networks - -==== enisa:outages="outages-of-long-range-wireless-networks" - -enisa:Outages of long-range wireless networks - -=== eavesdropping-interception-hijacking -==== enisa:eavesdropping-interception-hijacking="war-driving" - -enisa:War driving - -==== enisa:eavesdropping-interception-hijacking="intercepting-compromising-emissions" - -enisa:Intercepting compromising emissions - -==== enisa:eavesdropping-interception-hijacking="interception-of-information" - -enisa:Interception of information - -==== enisa:eavesdropping-interception-hijacking="corporate-espionage" - -enisa:Corporate espionage - -==== enisa:eavesdropping-interception-hijacking="nation-state-espionage" - -enisa:Nation state espionage - -==== enisa:eavesdropping-interception-hijacking="information-leakage-due-to-unsecured-wi-fi-like-rogue-access-points" - -enisa:Information leakage due to unsecured Wi-Fi, rogue access points - -==== enisa:eavesdropping-interception-hijacking="interfering-radiation" - -enisa:Interfering radiation - -==== enisa:eavesdropping-interception-hijacking="replay-of-messages" - -enisa:Replay of messages - -==== enisa:eavesdropping-interception-hijacking="network-reconnaissance-network-traffic-manipulation-and-information-gathering" - -enisa:Network Reconnaissance, Network traffic manipulation and Information gathering - -==== enisa:eavesdropping-interception-hijacking="man-in-the-middle-session-hijacking" - -enisa:Man in the middle/ Session hijacking - -=== nefarious-activity-abuse -==== enisa:nefarious-activity-abuse="identity-theft-identity-fraud-account)" - -enisa:Identity theft (Identity Fraud/ Account) - -==== enisa:nefarious-activity-abuse="credentials-stealing-trojans" - -enisa:Credentials-stealing trojans - -==== enisa:nefarious-activity-abuse="receiving-unsolicited-e-mail" - -enisa:Receiving unsolicited E-mail - -==== enisa:nefarious-activity-abuse="spam" - -enisa:SPAM - -==== enisa:nefarious-activity-abuse="unsolicited-infected-e-mails" - -enisa:Unsolicited infected e-mails - -==== enisa:nefarious-activity-abuse="denial-of-service" - -enisa:Denial of service - -==== enisa:nefarious-activity-abuse="distributed-denial-of-network-service-network-layer-attack" - -enisa:Distributed denial of network service (DDoS) (network layer attack i.e. Protocol exploitation / Malformed packets / Flooding / Spoofing) - -==== enisa:nefarious-activity-abuse="distributed-denial-of-network-service-application-layer-attack" - -enisa:Distributed denial of application service (DDoS) (application layer attack i.e. Ping of Death / XDoS / WinNuke / HTTP Floods) - -==== enisa:nefarious-activity-abuse="distributed-denial-of-network-service-amplification-reflection-attack" - -enisa:Distributed DoS (DDoS) to both network and application services (amplification/reflection methods i.e. NTP/ DNS /.../ BitTorrent) - -==== enisa:nefarious-activity-abuse="malicious-code-software-activity" - -enisa:Malicious code/ software/ activity - -==== enisa:nefarious-activity-abuse="search-engine-poisoning" - -enisa:Search Engine Poisoning - -==== enisa:nefarious-activity-abuse="exploitation-of-fake-trust-of-social-media" - -enisa:Exploitation of fake trust of social media - -==== enisa:nefarious-activity-abuse="worms-trojans" - -enisa:Worms/ Trojans - -==== enisa:nefarious-activity-abuse="rootkits" - -enisa:Rootkits - -==== enisa:nefarious-activity-abuse="mobile-malware" - -enisa:Mobile malware - -==== enisa:nefarious-activity-abuse="infected-trusted-mobile-apps" - -enisa:Infected trusted mobile apps - -==== enisa:nefarious-activity-abuse="elevation-of-privileges" - -enisa:Elevation of privileges - -==== enisa:nefarious-activity-abuse="web-application-attacks-injection-attacks-code-injection-SQL-XSS" - -enisa:Web application attacks / injection attacks (Code injection: SQL, XSS) - -==== enisa:nefarious-activity-abuse="spyware-or-deceptive-adware" - -enisa:Spyware or deceptive adware - -==== enisa:nefarious-activity-abuse="viruses" - -enisa:Viruses - -==== enisa:nefarious-activity-abuse="rogue-security-software-rogueware-scareware" - -enisa:Rogue security software/ Rogueware / Scareware - -==== enisa:nefarious-activity-abuse="ransomware" - -enisa:Ransomware - -==== enisa:nefarious-activity-abuse="exploits-exploit-kits" - -enisa:Exploits/Exploit Kits - -==== enisa:nefarious-activity-abuse="social-engineering" - -enisa:Social Engineering - -==== enisa:nefarious-activity-abuse="phishing-attacks" - -enisa:Phishing attacks - -==== enisa:nefarious-activity-abuse="spear-phishing-attacks" - -enisa:Spear phishing attacks - -==== enisa:nefarious-activity-abuse="abuse-of-information-leakage" - -enisa:Abuse of Information Leakage - -==== enisa:nefarious-activity-abuse="leakage-affecting-mobile-privacy-and-mobile-applications" - -enisa:Leakage affecting mobile privacy and mobile applications - -==== enisa:nefarious-activity-abuse="leakage-affecting-web-privacy-and-web-applications" - -enisa:Leakage affecting web privacy and web applications - -==== enisa:nefarious-activity-abuse="leakage-affecting-network-traffic" - -enisa:Leakage affecting network traffic - -==== enisa:nefarious-activity-abuse="leakage-affecting-cloud-computing" - -enisa:Leakage affecting cloud computing - -==== enisa:nefarious-activity-abuse="generation-and-use-of-rogue-certificates" - -enisa:Generation and use of rogue certificates - -==== enisa:nefarious-activity-abuse="loss-of-integrity-of-sensitive-information" - -enisa:Loss of (integrity of) sensitive information - -==== enisa:nefarious-activity-abuse="man-in-the-middle-session-hijacking" - -enisa:Man in the middle / Session hijacking - -==== enisa:nefarious-activity-abuse="social-engineering-via-signed-malware" - -enisa:Social Engineering / signed malware - -==== enisa:nefarious-activity-abuse="fake-SSL-certificates" - -enisa:Fake SSL certificates - -==== enisa:nefarious-activity-abuse="manipulation-of-hardware-and-software" - -enisa:Manipulation of hardware and software - -==== enisa:nefarious-activity-abuse="anonymous-proxies" - -enisa:Anonymous proxies - -==== enisa:nefarious-activity-abuse="abuse-of-computing-power-of-cloud-to-launch-attacks-cybercrime-as-a-service)" - -enisa:Abuse of computing power of cloud to launch attacks (cybercrime as a service) - -==== enisa:nefarious-activity-abuse="abuse-of-vulnerabilities-0-day-vulnerabilities" - -enisa:Abuse of vulnerabilities, 0-day vulnerabilities - -==== enisa:nefarious-activity-abuse="access-of-web-sites-through-chains-of-HTTP-Proxies-Obfuscation" - -enisa:Access of web sites through chains of HTTP Proxies (Obfuscation) - -==== enisa:nefarious-activity-abuse="access-to-device-software" - -enisa:Access to device software - -==== enisa:nefarious-activity-abuse="alternation-of-software" - -enisa:Alternation of software - -==== enisa:nefarious-activity-abuse="rogue-hardware" - -enisa:Rogue hardware - -==== enisa:nefarious-activity-abuse="manipulation-of-information" - -enisa:Manipulation of information - -==== enisa:nefarious-activity-abuse="repudiation-of-actions" - -enisa:Repudiation of actions - -==== enisa:nefarious-activity-abuse="address-space-hijacking-IP-prefixes" - -enisa:Address space hijacking (IP prefixes) - -==== enisa:nefarious-activity-abuse="routing-table-manipulation" - -enisa:Routing table manipulation - -==== enisa:nefarious-activity-abuse="DNS-poisoning-or-DNS-spoofing-or-DNS-Manipulations" - -enisa:DNS poisoning / DNS spoofing / DNS Manipulations - -==== enisa:nefarious-activity-abuse="falsification-of-record" - -enisa:Falsification of record - -==== enisa:nefarious-activity-abuse="autonomous-system-hijacking" - -enisa:Autonomous System hijacking - -==== enisa:nefarious-activity-abuse="autonomous-system-manipulation" - -enisa:Autonomous System manipulation - -==== enisa:nefarious-activity-abuse="falsification-of-configurations" - -enisa:Falsification of configurations - -==== enisa:nefarious-activity-abuse="misuse-of-audit-tools" - -enisa:Misuse of audit tools - -==== enisa:nefarious-activity-abuse="misuse-of-information-or-information systems-including-mobile-apps" - -enisa:Misuse of information/ information systems (including mobile apps) - -==== enisa:nefarious-activity-abuse="unauthorized-activities" - -enisa:Unauthorized activities - -==== enisa:nefarious-activity-abuse="Unauthorised-use-or-administration-of-devices-and-systems" - -enisa:Unauthorised use or administration of devices and systems - -==== enisa:nefarious-activity-abuse="unauthorised-use-of-software" - -enisa:Unauthorised use of software - -==== enisa:nefarious-activity-abuse="unauthorized-access-to-the-information-systems-or-networks-like-IMPI-Protocol-DNS-Registrar-Hijacking)" - -enisa:Unauthorized access to the information systems-or-networks (IMPI Protocol / DNS Registrar Hijacking) - -==== enisa:nefarious-activity-abuse="network-intrusion" - -enisa:Network Intrusion - -==== enisa:nefarious-activity-abuse="unauthorized-changes-of-records" - -enisa:Unauthorized changes of records - -==== enisa:nefarious-activity-abuse="unauthorized-installation-of-software" - -enisa:Unauthorized installation of software - -==== enisa:nefarious-activity-abuse="Web-based-attacks-drive-by-download-or-malicious-URLs-or-browser-based-attacks" - -enisa:Web based attacks (Drive-by download / malicious URLs / Browser based attacks) - -==== enisa:nefarious-activity-abuse="compromising-confidential-information-like-data-breaches" - -enisa:Compromising confidential information (data breaches) - -==== enisa:nefarious-activity-abuse="hoax" - -enisa:Hoax - -==== enisa:nefarious-activity-abuse="false-rumour-and-or-fake-warning" - -enisa:False rumour and/or fake warning - -==== enisa:nefarious-activity-abuse="remote-activity-execution" - -enisa:Remote activity (execution) - -==== enisa:nefarious-activity-abuse="remote-command-execution" - -enisa:Remote Command Execution - -==== enisa:nefarious-activity-abuse="remote-access-tool" - -enisa:Remote Access Tool (RAT) - -==== enisa:nefarious-activity-abuse="botnets-remote-activity" - -enisa:Botnets / Remote activity - -==== enisa:nefarious-activity-abuse="targeted-attacks" - -enisa:Targeted attacks (APTs etc.) - -==== enisa:nefarious-activity-abuse="mobile-malware" - -enisa:Mobile malware - -==== enisa:nefarious-activity-abuse="spear-phishing-attacks" - -enisa:Spear phishing attacks - -==== enisa:nefarious-activity-abuse="installation-of-sophisticated-and-targeted-malware" - -enisa:Installation of sophisticated and targeted malware - -==== enisa:nefarious-activity-abuse="watering-hole-attacks" - -enisa:Watering Hole attacks - -==== enisa:nefarious-activity-abuse="failed-business-process" - -enisa:Failed business process - -==== enisa:nefarious-activity-abuse="brute-force" - -enisa:Brute force - -==== enisa:nefarious-activity-abuse="abuse-of-authorizations" - -enisa:Abuse of authorizations - -=== legal -==== enisa:legal="violation-of-rules-and-regulations-breach-of-legislation" - -enisa:Violation of rules and regulations / Breach of legislation - -==== enisa:legal="failure-to-meet-contractual-requirements" - -enisa:Failure to meet contractual requirements - -==== enisa:legal="failure-to-meet-contractual-requirements-by-third-party" - -enisa:Failure to meet contractual requirements by third party - -==== enisa:legal="unauthorized-use-of-IPR-protected-resources" - -enisa:Unauthorized use of IPR protected resources - -==== enisa:legal="illegal-usage-of-file-sharing-services" - -enisa:Illegal usage of File Sharing services - -==== enisa:legal="abuse-of-personal-data" - -enisa:Abuse of personal data - -==== enisa:legal="judiciary-decisions-or-court-order" - -enisa:Judiciary decisions/court order - -== circl -NOTE: circl namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/circl/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection - -=== incident-classification -==== circl:incident-classification="spam" - -circl:Spam - -==== circl:incident-classification="system-compromise" - -circl:System compromise - -==== circl:incident-classification="scan" - -circl:Scan - -==== circl:incident-classification="denial-of-service" - -circl:Denial of Service - -==== circl:incident-classification="copyright-issue" - -circl:Copyright issue - -==== circl:incident-classification="phishing" - -circl:Phishing - -==== circl:incident-classification="malware" - -circl:Malware - -==== circl:incident-classification="XSS" - -circl:XSS - -==== circl:incident-classification="vulnerability" - -circl:Vulnerability - -==== circl:incident-classification="fastflux" - -circl:Fastflux - -==== circl:incident-classification="sql-injection" - -circl:SQL Injection - -==== circl:incident-classification="information-leak" - -circl:Information leak - -==== circl:incident-classification="scam" - -circl:Scam - -=== topic -==== circl:topic="finance" - -circl:Finance - -==== circl:topic="ict" - -circl:ICT - -==== circl:topic="individual" - -circl:Individual - -==== circl:topic="industry" - -circl:Industry - -==== circl:topic="medical" - -circl:Medical - -==== circl:topic="services" - -circl:Services - -==== circl:topic="undefined" - -circl:Undefined - -== estimative-language -NOTE: estimative-language namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/master/estimative-language/machinetag.json[*this location*]. The JSON format can be freely reused in your application or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy. - -Estimative language to describe quality and credibility of underlying sources, data, and methodologies based Intelligence Community Directive 203 (ICD 203) - -=== likelihood-probability -==== estimative-language:likelihood-probability="almost-no-chance" - -estimative-language:Almost no chance - remote - 01-05% - -==== estimative-language:likelihood-probability="very-unlikely" - -estimative-language:Very unlikely - highly improbable - 05-20% - -==== estimative-language:likelihood-probability="unlikely" - -estimative-language:Unlikely - improbable (improbably) - 20-45% - -==== estimative-language:likelihood-probability="roughly-even-chance" - -estimative-language:Roughly even change - roughly even odds - 45-55% - -==== estimative-language:likelihood-probability="likely" - -estimative-language:Likely - probable (probably) - 55-80% - -==== estimative-language:likelihood-probability="very-likely" - -estimative-language:Very likely - highly probable - 80-95% - -==== estimative-language:likelihood-probability="almost-certain" - -estimative-language:Almost certain(ly) - nearly certain - 95-99% -