From 66b6a700cf1a4cea6cfeecd0d78eabb626784bf5 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 6 Sep 2017 08:45:57 +0200
Subject: [PATCH] Objects updated
---
objects.html | 2615 +-
objects.pdf | 68948 ++++++++++++++++++++++++++-----------------------
2 files changed, 37959 insertions(+), 33604 deletions(-)
mode change 100644 => 100755 objects.html
mode change 100644 => 100755 objects.pdf
diff --git a/objects.html b/objects.html
old mode 100644
new mode 100755
index 6034efc..c74ba36
--- a/objects.html
+++ b/objects.html
@@ -456,6 +456,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
type
text
origin
url
Type of information leak as discovered and classified by an AIL module.
+The link where the leak is (or was) accessible at first-seen.
@@ -540,6 +541,16 @@ ail-leak is a MISP object available in JSON format at
type
text
Type of information leak as discovered and classified by an AIL module.
++
first-seen
datetime
origin
url
The link where the leak is (or was) accessible at first-seen.
--
last-seen
datetime
text
text
A description of the cookie.
--
type
text
cookie-value
text
Value of the cookie (if splitted)
++
cookie-name
text
cookie-value
text
text
Value of the cookie (if splitted)
+A description of the cookie.
+
dst-port
-port
Destination port of the attack
--
total-bps
total-pps
counter
Bits per second
+Packets per second
@@ -736,6 +727,26 @@ ddos is a MISP object available in JSON format at
dst-port
port
Destination port of the attack
++
src-port
port
Port originating the attack
++
protocol
text
ip-dst
ip-dst
last-seen
datetime
Destination ID (victim)
--
total-pps
counter
Packets per second
+End of the attack
@@ -786,20 +787,20 @@ ddos is a MISP object available in JSON format at
src-port
port
total-bps
counter
Port originating the attack
+Bits per second
last-seen
datetime
ip-dst
ip-dst
End of the attack
+Destination ID (victim)
@@ -864,6 +865,16 @@ domain|ip is a MISP object available in JSON format at
ip
ip-dst
IP Address
++
text
text
ip
ip-dst
IP Address
--
entrypoint-address
+os_abi
text
Address of the entry point
--
type
text
Type of ELF
+Header operating system application binary interface (ABI)
@@ -962,16 +953,36 @@ elf is a MISP object available in JSON format at
os_abi
text
text
Header operating system application binary interface (ABI)
+Free text value to attach to the ELF
++
type
text
Type of ELF
entrypoint-address
text
Address of the entry point
++
arch
text
text
text
Free text value to attach to the ELF
--
md5
-md5
sha384
sha384
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (384 bits)
text
text
Free text value to attach to the section
--
sha224
sha224
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
sha256
-sha256
name
text
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
+Name of the section
sha512/256
sha512/256
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
sha512
-sha512
Secure Hash Algorithm 2 (512 bits)
--
type
text
flag
text
Flag of the section
--
entropy
float
sha512/224
sha512/224
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
name
+sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
text
text
Name of the section
+Free text value to attach to the section
sha384
sha384
md5
md5
Secure Hash Algorithm 2 (384 bits)
+[Insecure] MD5 hash (128 bits)
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
flag
text
Flag of the section
@@ -1218,30 +1219,40 @@ email is a MISP object available in JSON format at
to
email-dst
x-mailer
email-x-mailer
Destination email address
+X-Mailer generally tells the program that was used to draft and send the original email
from
email-src
message-id
email-message-id
Sender email address
+Message ID
to-display-name
email-dst-display-name
from-display-name
email-src-display-name
Display name of the receiver
+Display name of the sender
++
thread-index
email-thread-index
Identifies a particular conversation thread
@@ -1258,10 +1269,20 @@ email is a MISP object available in JSON format at
message-id
email-message-id
subject
email-subject
Message ID
+Subject
++
to
email-dst
Destination email address
@@ -1288,40 +1309,10 @@ email is a MISP object available in JSON format at
from-display-name
email-src-display-name
attachment
email-attachment
Display name of the sender
--
subject
email-subject
Subject
--
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
--
thread-index
email-thread-index
Identifies a particular conversation thread
+Attachment
@@ -1338,10 +1329,20 @@ email is a MISP object available in JSON format at
attachment
email-attachment
from
email-src
Attachment
+Sender email address
++
to-display-name
email-dst-display-name
Display name of the receiver
@@ -1386,146 +1387,6 @@ file is a MISP object available in JSON format at
md5
md5
[Insecure] MD5 hash (128 bits)
--
text
text
Free text value to attach to the file
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
mimetype
text
Mime type
--
filename
filename
Filename on disk
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
malware-sample
malware-sample
The file itself (binary)
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
entropy
float
Entropy of the whole file
--
sha384
sha384
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
entropy
float
Entropy of the whole file
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
malware-sample
malware-sample
The file itself (binary)
++
sha1
sha1
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
text
text
Free text value to attach to the file
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
size-in-bytes
size-in-bytes
Size of the file, in bytes
++
filename
filename
Filename on disk
++
authentihash
authentihash
mimetype
text
Mime type
++
text
+region
text
A generic description of the location.
+Region.
+
altitude
-float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
--
region
text
text
Region.
+A generic description of the location.
+
city
+text
City.
++
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
++
country
text
city
text
City.
--
user-agent
+user-agent
The user agent string of the user agent
++
host
hostname
The domain name of the server
++
proxy-user
text
HTTP Proxy Username
++
content-type
other
The MIME type of the body of the request
++
url
url
Full HTTP Request URL
++
proxy-password
text
HTTP Proxy Password
++
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
++
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
++
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
++
basicauth-password
text
HTTP Basic Authentication Password
++
uri
uri
basicauth-password
text
HTTP Basic Authentication Password
--
proxy-user
text
HTTP Proxy Username
--
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
--
user-agent
user-agent
The user agent string of the user agent
--
content-type
other
The MIME type of the body of the request
--
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
--
proxy-password
text
HTTP Proxy Password
--
host
hostname
The domain name of the server
--
url
url
Full HTTP Request URL
--
dst-port
-text
Destination port
--
text
text
ip
ip-dst
dst-port
text
IP Address
+Destination port
++
src-port
text
Source port
@@ -1940,10 +1941,10 @@ ip|port is a MISP object available in JSON format at
src-port
text
ip
ip-dst
Source port
+IP Address
@@ -1998,36 +1999,6 @@ macho is a MISP object available in JSON format at
entrypoint-address
text
Address of the entry point
--
type
text
Type of Mach-O
--
text
text
Free text value to attach to the Mach-O file
--
number-sections
counter
entrypoint-address
text
Address of the entry point
++
text
text
Free text value to attach to the Mach-O file
++
type
text
Type of Mach-O
++
md5
-md5
sha384
sha384
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (384 bits)
text
text
Free text value to attach to the section
--
sha224
sha224
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
sha256
-sha256
name
text
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
+Name of the section
sha512/256
sha512/256
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
sha512
-sha512
Secure Hash Algorithm 2 (512 bits)
--
ssdeep
ssdeep
sha512/224
sha512/224
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
name
+sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
text
text
Name of the section
+Free text value to attach to the section
sha384
sha384
md5
md5
Secure Hash Algorithm 2 (384 bits)
+[Insecure] MD5 hash (128 bits)
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
rrname
-text
Resource Record name of the queried resource
--
text
text
-
-
sensor_id
text
Sensor information where the record was seen
--
zone_time_first
time_last
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
+Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
@@ -2304,6 +2275,36 @@ passive-dns is a MISP object available in JSON format at
origin
text
Origin of the Passive DNS response
++
rrname
text
Resource Record name of the queried resource
++
sensor_id
text
Sensor information where the record was seen
++
rdata
text
bailiwick
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
text
text
Best estimate of the apex of the zone where this data is authoritative
+
@@ -2344,30 +2365,10 @@ passive-dns is a MISP object available in JSON format at
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
origin
bailiwick
text
Origin of the Passive DNS response
+Best estimate of the apex of the zone where this data is authoritative
@@ -2412,96 +2413,6 @@ pe is a MISP object available in JSON format at
product-name
text
ProductName in the resources
--
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
--
text
text
Free text value to attach to the PE
--
file-version
text
FileVersion in the resources
--
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
--
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
--
original-filename
filename
OriginalFilename in the resources
--
lang-id
text
Lang ID in the resources
--
legal-copyright
text
LegalCopyright in the resources
--
company-name
text
entrypoint-address
text
Address of the entry point
--
type
text
Type of PE
--
number-sections
counter
Number of sections
--
file-description
text
internal-filename
filename
InternalFilename in the resources
++
product-version
text
internal-filename
lang-id
text
Lang ID in the resources
++
type
text
Type of PE
++
original-filename
filename
InternalFilename in the resources
+OriginalFilename in the resources
entrypoint-address
text
Address of the entry point
++
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
number-sections
counter
Number of sections
++
imphash
imphash
legal-copyright
text
LegalCopyright in the resources
++
text
text
Free text value to attach to the PE
++
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
++
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
++
compilation-timestamp
datetime
file-version
text
FileVersion in the resources
++
product-name
text
ProductName in the resources
++
md5
-md5
sha384
sha384
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (384 bits)
text
text
Free text value to attach to the section
--
sha224
sha224
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
characteristic
+name
text
Characteristic of the section
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
+Name of the section
sha512/256
sha512/256
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
sha512
-sha512
Secure Hash Algorithm 2 (512 bits)
--
ssdeep
ssdeep
characteristic
text
Characteristic of the section
++
entropy
float
sha512/224
sha512/224
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
name
+sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
text
text
Name of the section
+Free text value to attach to the section
sha384
sha384
md5
md5
Secure Hash Algorithm 2 (384 bits)
+[Insecure] MD5 hash (128 bits)
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
imei
+imsi
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
--
serial-number
text
Serial Number.
--
gummei
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
@@ -2848,13 +2829,13 @@ phone is a MISP object available in JSON format at
guti
text
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
+A description of the phone.
+
text
+guti
text
A description of the phone.
+Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
+
last-seen
datetime
imei
text
When the phone has been accessible or seen for the last time.
+International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
+
imsi
gummei
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
+Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
serial-number
text
Serial Number.
++
last-seen
datetime
When the phone has been accessible or seen for the last time.
++
create-thread
-counter
gml
attachment
Amount of calls to CreateThread
+Graph export in G>raph Modelling Language format
unknown-references
shortest-path-to-create-thread
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Shortest path to the first time the binary calls CreateThread
++
callbacks
counter
Amount of callbacks (functions started as thread)
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
referenced-strings
counter
Amount of referenced strings
++
total-api
counter
Total amount of API calls
++
not-referenced-strings
counter
Amount of not referenced strings
++
text
text
Description of the r2graphity object
++
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
++
get-proc-address
counter
Amount of calls to GetProcAddress
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
create-thread
counter
Amount of calls to CreateThread
@@ -2986,36 +3087,6 @@ r2graphity is a MISP object available in JSON format at
callback-largest
counter
Largest callback
--
total-api
counter
Total amount of API calls
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
callback-average
counter
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
referenced-strings
counter
Amount of referenced strings
--
text
text
Description of the r2graphity object
--
gml
attachment
Graph export in G>raph Modelling Language format
--
r2-commit-version
text
Radare2 commit ID used to generate this object
--
local-references
counter
shortest-path-to-create-thread
counter
r2-commit-version
text
Shortest path to the first time the binary calls CreateThread
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
+Radare2 commit ID used to generate this object
@@ -3136,30 +3127,40 @@ r2graphity is a MISP object available in JSON format at
not-referenced-strings
unknown-references
counter
Amount of not referenced strings
+Amount of API calls not ending in a function (Radare2 bug, probalby)
refsglobalvar
dangling-strings
counter
Amount of API calls outside of code section (glob var, dynamic API)
+Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
callbacks
callback-largest
counter
Amount of callbacks (functions started as thread)
+Largest callback
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
@@ -3204,10 +3205,20 @@ registry-key is a MISP object available in JSON format at
data-type
reg-datatype
name
reg-name
Registry value type
+Name of the registry key
++
hive
reg-hive
Hive used to store the registry key (file on disk)
@@ -3224,10 +3235,10 @@ registry-key is a MISP object available in JSON format at
hive
reg-hive
data-type
reg-datatype
Hive used to store the registry key (file on disk)
+Registry value type
name
reg-name
Name of the registry key
--
nickname
+text
router’s nickname.
++
address
ip-src
IP address of the Tor node seen.
++
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
published
datetime
router’s publication time. This can be different from first-seen and last-seen.
++
fingerprint
text
router’s fingerprint.
++
description
text
Tor node description.
++
flags
text
nickname
text
router’s nickname.
--
first-seen
datetime
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
document
text
Raw document from the consensus.
--
published
datetime
router’s publication time. This can be different from first-seen and last-seen.
--
description
text
Tor node description.
--
version_line
text
document
text
Raw document from the consensus.
++
last-seen
datetime
fingerprint
text
router’s fingerprint.
--
address
ip-src
IP address of the Tor node seen.
--
domain
+domain
Full domain
++
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
++
query_string
text
Query (after path, preceded by '?')
++
url
url
Full URL
++
port
text
tld
domain_without_tld
text
Top-Level Domain
--
first-seen
datetime
First time this URL has been seen
+Domain without Top-Level Domain
@@ -3510,16 +3541,6 @@ url is a MISP object available in JSON format at
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
--
credential
text
query_string
text
Query (after path, preceded by '?')
--
last-seen
first-seen
datetime
Last time this URL has been seen
+First time this URL has been seen
@@ -3570,10 +3581,10 @@ url is a MISP object available in JSON format at
domain
domain
last-seen
datetime
Full domain
+Last time this URL has been seen
@@ -3590,20 +3601,10 @@ url is a MISP object available in JSON format at
url
url
Full URL
--
domain_without_tld
tld
text
Domain without Top-Level Domain
+Top-Level Domain
@@ -3648,20 +3649,20 @@ vulnerability is a MISP object available in JSON format at
vulnerable_configuration
summary
text
The vulnerable configuration is described in CPE format
+Summary of the vulnerability
id
vulnerability
modified
datetime
Vulnerability ID (generally CVE, but not necessarely)
+Last modification date
@@ -3688,10 +3689,20 @@ vulnerability is a MISP object available in JSON format at
modified
datetime
id
vulnerability
Last modification date
+Vulnerability ID (generally CVE, but not necessarely)
++
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
summary
text
Summary of the vulnerability
--
modification-date
-datetime
registar
whois-registar
Last update of the whois entry
--
text
text
Full whois entry
--
domain
domain
Domain of the whois entry
--
expiration-date
datetime
Expiration of the whois entry
--
registrant-phone
whois-registrant-phone
Registrant phone number
+Registar of the whois entry
@@ -3816,16 +3777,6 @@ whois is a MISP object available in JSON format at
registar
whois-registar
Registar of the whois entry
--
registrant-name
whois-registrant-name
domain
domain
Domain of the whois entry
++
text
text
Full whois entry
++
registrant-phone
whois-registrant-phone
Registrant phone number
++
registrant-email
whois-registrant-email
expiration-date
datetime
Expiration of the whois entry
++
modification-date
datetime
Last update of the whois entry
++
raw-base64
-text
Raw certificate base64 encoded
--
x509-fingerprint-sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
text
text
Free text description of hte certificate
--
pubkey-info-algorithm
text
validity-not-before
datetime
Certificate invalid before that date
--
x509-fingerprint-sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
validity-not-after
datetime
Certificate invalid after that date
--
pubkey-info-exponent
text
x509-fingerprint-md5
md5
[Insecure] MD5 hash (128 bits)
--
issuer
text
text
Issuer of the certificate
+Free text description of hte certificate
@@ -3994,20 +3925,20 @@ x509 is a MISP object available in JSON format at
subject
text
validity-not-after
datetime
Subject of the certificate
+Certificate invalid after that date
pubkey-info-modulus
subject
text
Modulus of the public key
+Subject of the certificate
issuer
text
Issuer of the certificate
++
x509-fingerprint-sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
x509-fingerprint-sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
x509-fingerprint-md5
md5
[Insecure] MD5 hash (128 bits)
++
validity-not-before
datetime
Certificate invalid before that date
++
raw-base64
text
Raw certificate base64 encoded
++
pubkey-info-modulus
text
Modulus of the public key
++
Default type of relationships in MISP objects.
+Relationships are part of MISP object and available in JSON format at this location. The JSON format can be freely reused in your application or automatically enabled in MISP.
+Name of relationship | +Description | +Format | +
---|---|---|
derived-from |
+The information in the target object is based on information from the source object. |
+['misp', 'stix-2.0'] |
+
duplicate-of |
+The referenced source and target objects are semantically duplicates of each other. |
+['misp', 'stix-2.0'] |
+
related-to |
+The referenced source is related to the target object. |
+['misp', 'stix-2.0'] |
+
attributed-to |
+This referenced source is attributed to the target object. |
+['misp', 'stix-2.0'] |
+
targets |
+This relationship describes that the source object targets the target object. |
+['misp', 'stix-2.0'] |
+
uses |
+This relationship describes the use by the source object of the target object. |
+['misp', 'stix-2.0'] |
+
indicates |
+This relationships describes that the source object indicates the target object. |
+['misp', 'stix-2.0'] |
+
mitigates |
+This relationship describes a source object which mitigates the target object. |
+['misp', 'stix-2.0'] |
+
variant-of |
+This relationship describes a source object which is a variant of the target object |
+['misp', 'stix-2.0'] |
+
impersonates |
+This relationship describe a source object which impersonates the target object |
+['misp', 'stix-2.0'] |
+
authored-by |
+This relationship describes the author of a specific object. |
+['misp'] |
+
located |
+This relationship describes the location (of any type) of a specific object. |
+['misp'] |
+
included-in |
+This relationship describes an object included in another object. |
+['misp'] |
+
analysed-with |
+This relationship describes an object analysed by another object. |
+['misp'] |
+
claimed-by |
+This relationship describes an object claimed by another object. |
+['misp'] |
+
communicates-with |
+This relationship describes an object communicating with another object. |
+['misp'] |
+
dropped-by |
+This relationship describes an object dropped by another object. |
+['misp'] |
+
executed-by |
+This relationship describes an object executed by another object. |
+['misp'] |
+
affects |
+This relationship describes an object affected by another object. |
+['misp'] |
+
beacons_to |
+This relationship describes an object beaconing to another object. |
+['misp'] |
+
abuses |
+This relationship describes an object which abuses another object. |
+['misp'] |
+
exfiltrates_to |
+This relationship describes an object exfiltrating to another object. |
+['misp'] |
+
identifies |
+This relationship describes an object which identifies another object. |
+['misp'] |
+
intercepts |
+This relationship describes an object which intercepts another object. |
+['misp'] |
+
calls |
+This relationship describes an object which calls another objects. |
+['misp'] |
+