Source IP address of the network connection.
+diff --git a/objects.html b/objects.html index 7ab5622..72894c7 100755 --- a/objects.html +++ b/objects.html @@ -475,6 +475,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
IP Address information. Useful if you are pulling your ip information from ip-api.com.
++ + | ++ip-api-address is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +Multiple | +
---|---|---|---|---|
ip-src |
+ip-src |
+
+ Source IP address of the network connection. + |
+
+ + |
+
+ + |
+
asn |
+AS |
+
+ Autonomous System Number + |
+
+ + |
+
+ + |
+
organization |
+text |
+
+ organization + |
+
+ + |
+
+ + |
+
ISP |
+text |
+
+ ISP. + |
+
+ + |
+
+ + |
+
zipcode |
+text |
+
+ Zip Code. + |
+
+ + |
+
+ + |
+
city |
+text |
+
+ City. + |
+
+ + |
+
+ + |
+
state |
+text |
+
+ State. + |
+
+ + |
+
+ + |
+
country |
+text |
+
+ Country name + |
+
+ + |
+
+ + |
+
country code |
+text |
+
+ Country code + |
+
+ + |
+
+ + |
+
region |
+text |
+
+ Region. example: California. + |
+
+ + |
+
+ + |
+
region code |
+text |
+
+ Region code. example: CA + |
+
+ + |
+
+ + |
+
latitude |
+float |
+
+ The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference. + |
+
+ + |
+
+ + |
+
longitude |
+float |
+
+ The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference + |
+
+ + |
+
+ + |
+
first-seen |
+datetime |
+
+ First time the ASN was seen + |
+
+ + |
+
+ + |
+
last-seen |
+datetime |
+
+ Last time the ASN was seen + |
+
+ + |
+
+ + |
+
+
@@ -7425,7 +7663,7 @@ network-connection is a MISP object available in JSON format at
+
@@ -7438,7 +7676,7 @@ network-connection is a MISP object available in JSON format at
+
@@ -7700,7 +7938,7 @@ original-imported-file is a MISP object available in JSON format at
+
@@ -8064,6 +8302,124 @@ paste is a MISP object available in JSON format at +
Network packet capture metadata.
++ + | ++pcap-metadata is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +Multiple | +
---|---|---|---|---|
capture-length |
+text |
+
+ Capture length set on the captured interface. + |
+
+ + |
+
+ + |
+
capture-interface |
+text |
+
+ Interface name where the packet capture was running. + |
+
+ + |
+
+ + |
+
protocol |
+text |
+
+ Capture protocol (linktype name). ['LINKTYPE_NULL', 'LINKTYPE_ETHERNET'] + |
+
+ + |
+
+ + |
+
text |
+text |
+
+ A description of the packet capture. + |
+
+ + |
+
+ + |
+
first-packet-seen |
+datetime |
+
+ When the first packet has been seen. + |
+
+ + |
+
+ + |
+
last-packet-seen |
+datetime |
+
+ When the last packet has been seen. + |
+
+ + |
+
+ + |
+
social-security-number
text
Social security number
+Social security number.
nic-hdl
text
NIC Handle (Network Information Centre handle) of the person.
++
+
phone-number
phone-number
Phone number of the person.
++
+
fax-number
phone-number
Fax number of the person.
++
+
address
text
Postal address of the person.
++
+
email-src
Email address of the person.
++
+
Phishing template to describe a phishing website and its analysis..
++ + | ++phishing is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +Multiple | +
---|---|---|---|---|
url |
+url |
+
+ Original url of the phishing website + |
+
+ + |
+
+ + |
+
phishtank-id |
+text |
+
+ Phishtank ID of the reported phishing + |
+
+ + |
+
+ + |
+
phishtank-detail-url |
+link |
+
+ Phishtank detail URL to the reported phishing + |
+
+ + |
+
+ + |
+
submission-time |
+datetime |
+
+ When the phishing was submitted and/or reported + |
+
+ + |
+
+ + |
+
verified |
+text |
+
+ The phishing has been verified by the team handling the phishing ['No', 'Yes'] + |
+
+ + |
+
+ + |
+
verification-time |
+datetime |
+
+ When the phishing was verified + |
+
+ + |
+
+ + |
+
online |
+text |
+
+ If the phishing is online and operational, by default is yes ['Yes', 'No'] + |
+
+ + |
+
+ + |
+
takedown-time |
+datetime |
+
+ When the phishing was taken down + |
+
+ + |
+
+ + |
+
target |
+text |
+
+ Targeted organisation by the phishing + |
+
+ + |
+
+ + |
+
+
@@ -9085,7 +9663,7 @@ process is a MISP object available in JSON format at
+
@@ -9098,7 +9676,7 @@ process is a MISP object available in JSON format at
+
@@ -9111,7 +9689,7 @@ process is a MISP object available in JSON format at
+
@@ -13636,7 +14214,7 @@ yara is a MISP object available in JSON format at
derived-from
The information in the target object is based on information from the source object.
['misp', 'stix-2.0']
['misp', 'stix-2.0', 'alfred']
duplicate-of
related-to
The referenced source is related to the target object.
['misp', 'stix-2.0']
['misp', 'stix-2.0', 'alfred']
connected-to
contains
The referenced source is containing the target object.
['misp', 'stix-1.1']
['misp', 'stix-1.1', 'alfred']
contained-by
uses
This relationship describes the use by the source object of the target object.
['misp', 'stix-2.0']
['misp', 'stix-2.0', 'alfred']
indicates
variant-of
This relationship describes a source object which is a variant of the target object
['misp', 'stix-2.0']
['misp', 'stix-2.0', 'alfred']
impersonates
affects
This relationship describes an object affected by another object.
['misp']
['misp', 'alfred']
beacons-to
This relationship describes an object beaconing to another object.
['misp']
['misp', 'alfred']
abuses
exfiltrates-to
This relationship describes an object exfiltrating to another object.
['misp']
['misp', 'alfred']
identifies
This relationship describes an object which identifies another object.
['misp']
['misp', 'alfred']
intercepts
This relationship describes an object which intercepts another object.
['misp']
['misp', 'alfred']
calls
owner-of
This relationship describes an object which owns another object.
['cert-eu']
['cert-eu', 'alfred']
publishes-method-for
This relationships describes an object which annotates another object.
['misp']
references
This relationships describes an object which references another object or attribute.
['misp']
child-of
A child semantic link to a parent.
['alfred']
compromised
Represents the semantic link of having compromised something.
['alfred']
connects
The initiator of a connection.
['alfred']
connects-to
The destination or target of a connection.
['alfred']
cover-term-for
Represents the semantic link of one thing being the cover term for another.
['alfred']
disclosed-to
Semantic link indicating where information is disclosed to.
['alfred']
downloads
Represents the semantic link of one thing downloading another.
['alfred']
downloads-from
Represents the semantic link of malware being downloaded from a location.
['alfred']
generated
Represents the semantic link of an alert generated from a signature.
['alfred']
implements
One data object implements another.
['alfred']
initiates
Represents the semantic link of a communication initiating an event.
['alfred']
instance-of
Represents the semantic link between a FILE and FILE_BINARY.
['alfred']
issuer-of
Represents the semantic link of being the issuer of something.
['alfred']
linked-to
Represents the semantic link of being associated with something.
['alfred']
not-relevant-to
Represents the semantic link of a comm that is not relevant to an EVENT.
['alfred']
part-of
Represents the semantic link that defines one thing to be part of another in a hierachial structure from the child to the parent.
['alfred']
processed-by
Represents the semantic link of something has been processed by another program.
['alfred']
produced
Represents the semantic link of something having produced something else.
['alfred']
queried-for
The IP Address or domain being queried for.
['alfred']
query-returned
The IP Address or domain returned as the result of a query.
['alfred']
registered
Represents the semantic link of someone registered some thing.
['alfred']
registered-to
Represents the semantic link of something being registered to.
['alfred']
relates
Represents the semantic link between HBS Comms and communication addresses.
['alfred']
relevant-to
Represents the semantic link of a comm that is relevant to an EVENT.
['alfred']
resolves-to
Represents the semantic link of resolving to something.
['alfred']
responsible-for
Represents the semantic link of some entity being responsible for something.
['alfred']
seeded
Represents the semantic link of a seeded domain redirecting to another site.
['alfred']
sends
A sends semantic link meaning 'who sends what'.
['alfred']
sends-as-bcc-to
A sends to as BCC semantic link meaning 'what sends to who as BCC'.
['alfred']
sends-as-cc-to
A sends to as CC semantic link meaning 'what sends to who as CC'.
['alfred']
sends-to
A sends to semantic link meaning 'what sends to who'.
['alfred']
spoofer-of
The represents the semantic link of having spoofed something.
['alfred']
subdomain-of
Represents a domain being a subdomain of another.
['alfred']
supersedes
One data object supersedes another.
['alfred']
triggered-on
Represents the semantic link of an alert triggered on an event.
['alfred']
uploads
Represents the semantic link of one thing uploading another.
['alfred']
user-of
The represents the semantic link of being the user of something.
['alfred']
works-for
Represents the semantic link of working for something.
['alfred']